Classifying SMEs for Approaching Cybersecurity Competence and Awareness

10/11/2021
by   Alireza Shojaifar, et al.
0

Cybersecurity is increasingly a concern for small and medium-sized enterprises (SMEs), and there exist many awareness training programs and tools for them. The literature mainly studies SMEs as a unitary type of company and provides one-size-fits-all recommendations and solutions. However, SMEs are not homogeneous. They are diverse with different vulnerabilities, cybersecurity needs, and competencies. Few studies considered such differences in standards and certificates for security tools adoption and cybersecurity tailoring for these SMEs. This study proposes a classification framework with an outline of cybersecurity improvement needs for each class. The framework suggests five SME types based on their characteristics and specific security needs: cybersecurity abandoned SME, unskilled SME, expert-connected SME, capable SME, and cybersecurity provider SME. In addition to describing the five classes, the study explains the framework's usage in sampled SMEs. The framework proposes solutions for each class to approach cybersecurity awareness and competence more consistent with SME needs. The final publication is available at ACM Digital Library via this https URL https://doi.org/10.1145/3465481.3469200

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/13/2020

SMEs Confidentiality Concerns for Security Information Sharing

Small and medium sized enterprises are considered an essential part of t...
research
06/23/2019

Developing cybersecurity education and awareness programmes for Small and medium-sized enterprises (SMEs)

Purpose: An essential component of an organisation's cybersecurity strat...
research
08/29/2023

A Study of Different Awareness Campaigns in a Company

Phishing is a major cyber threat to organizations that can cause financi...
research
12/12/2021

Evaluation of Security Training and Awareness Programs: Review of Current Practices and Guideline

Evaluating the effectiveness of security awareness and training programs...
research
09/14/2023

From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program

There is a growing recognition of the need for a transformation from org...
research
04/15/2020

Empirical Models for the Realistic Generation of Cooperative Awareness Messages in Vehicular Networks

Most V2X (Vehicle-to-Everything) applications rely on broadcasting aware...

Please sign up or login with your details

Forgot password? Click here to reset