Author:
Shojaifar Alireza,Fricker Samuel A.
Abstract
Purpose
This paper aims to present the evaluation of a self-paced tool, CyberSecurity Coach (CYSEC), and discuss the adoption of CYSEC for cybersecurity capability improvement in small- and medium-sized enterprises (SMEs). Cybersecurity is increasingly a concern for SMEs. Previous literature has explored the role of tools for awareness raising. However, few studies validated the effectiveness and usefulness of cybersecurity tools for SMEs in real-world practices.
Design/methodology/approach
This study is built on a qualitative approach to investigating how CYSEC is used in SMEs to support awareness raising and capability improvement. CYSEC was placed in operation in 12 SMEs. This study first conducted a survey study and then nine structured interviews with chief executive officers (CEOs) and chief information security officers (CISO).
Findings
The results emphasise that SMEs are heterogeneous. Thus, one cybersecurity solution may not suit all SMEs. The findings specify that the tool’s adoption varied quite widely. Four factors are primary determinants influencing the adoption of CYSEC: personalisation features, CEOs’ or CISOs’ awareness level, CEOs’ or CISOs’ cybersecurity and IT knowledge and skill and connection to cybersecurity expertise.
Originality/value
This empirical study provides new insights into how a self-paced tool has been used in SMEs. This study advances the understanding of cybersecurity activities in SMEs by studying the adoption of CYSEC. Moreover, this study proposes significant dimensions for future research.
Subject
Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems
Reference74 articles.
1. The influence of hardiness and habit on security behaviour intention;Behaviour and Information Technology,2022
2. Cybersecurity risk management in small and medium-sized enterprises: a systematic review of recent evidence,2020
3. A qualitative study of users’ view on information security;Computers and Security,2007
4. The information security digital divide between information security managers and users;Computers and Security,2009
5. Enhancing information security education and awareness: proposed characteristics for a model,2015
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Balancing talent and technology: Navigating cybersecurity and privacy in SMEs;Telematics and Informatics Reports;2024-09
2. Unlocking Success: How Indonesian SMEs' Revenue Shapes Digital Financial Adoption and Security;2024 4th International Conference on Innovative Research in Applied Science, Engineering and Technology (IRASET);2024-05-16