Export Publication

The publication can be exported in the following formats: APA (American Psychological Association) reference format, IEEE (Institute of Electrical and Electronics Engineers) reference format, BibTeX and RIS.

Export Reference (APA)
Ramalho, D., Fernandes, A. D., Mira da Silva, M. & Pereira, R. (2025). Digital risk: A systematic multivocal literature review. Information Security Journal. 34 (3), 214-234
Export Reference (IEEE)
D. Ramalho et al.,  "Digital risk: A systematic multivocal literature review", in Information Security Journal, vol. 34, no. 3, pp. 214-234, 2025
Export BibTeX
@article{ramalho2025_1765063637484,
	author = "Ramalho, D. and Fernandes, A. D. and Mira da Silva, M. and Pereira, R.",
	title = "Digital risk: A systematic multivocal literature review",
	journal = "Information Security Journal",
	year = "2025",
	volume = "34",
	number = "3",
	doi = "10.1080/19393555.2024.2419920",
	pages = "214-234",
	url = "https://www.tandfonline.com/journals/uiss20"
}
Export RIS
TY  - JOUR
TI  - Digital risk: A systematic multivocal literature review
T2  - Information Security Journal
VL  - 34
IS  - 3
AU  - Ramalho, D.
AU  - Fernandes, A. D.
AU  - Mira da Silva, M.
AU  - Pereira, R.
PY  - 2025
SP  - 214-234
SN  - 1939-3555
DO  - 10.1080/19393555.2024.2419920
UR  - https://www.tandfonline.com/journals/uiss20
AB  - Crime rates in digital spaces are rising each year, involving increasingly innovative attack methods that organizations are unable to handle, or prepare for, with their obsolete management structures. This paper presents a Multivocal Literature Review in which expertise is collected from the academia and industry on how Digital Risk is perceived, interpreted and handled. Findings from the analysis of 82 selected works, out of an initial set of 519, support the necessity of a paradigm shift in Risk Management to appropriately counter the vulnerabilities specific to digitalization and to abolish the existing siloed organizational approach in favor of a more holistic, cooperative system where individuals are empowered to make decisions and oversight is specialized and dedicated. After analyzing the definitions, compositions, domain contextualizations and organizational structurings attributed to Digital Risk in the literature, a new definition for this concept is proposed, accompanied by a conceptual map and a diagram for structural changes in organizations, to provide an understanding of the area and a contribution to the theoretical foundations of Digital Risk, so that better solutions can be pursued in the future, improving the effectiveness of Risk Management practices in modern organizations.
ER  -