A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs
Autor: | Jacques Ophoff, Karen Renaud |
---|---|
Rok vydání: | 2022 |
Předmět: |
Empirical data
Situation awareness Best practice 05 social sciences 02 engineering and technology Space (commercial competition) Computer security computer.software_genre Security controls Resource (project management) 020204 information systems 0502 economics and business 0202 electrical engineering electronic engineering information engineering 050211 marketing Business computer |
DOI: | 10.6084/m9.figshare.17091371.v1 |
Popis: | PurposeThere is widespread concern about the fact that small- and medium-sized enterprises (SMEs) seem to be particularly vulnerable to cyberattacks. This is perhaps because smaller businesses lack sufficient situational awareness to make informed decisions in this space, or because they lack the resources to implement security controls and precautions.Design/methodology/approachIn this paper, Endsley’s theory of situation awareness was extended to propose a model of SMEs’ cyber situational awareness, and the extent to which this awareness triggers the implementation of cyber security measures. Empirical data were collected through an online survey of 361 UK-based SMEs; subsequently, the authors used partial least squares modeling to validate the model.FindingsThe results show that heightened situational awareness, as well as resource availability, significantly affects SMEs’ implementation of cyber precautions and controls.Research limitations/implicationsWhile resource limitations are undoubtedly a problem for SMEs, their lack of cyber situational awareness seems to be the area requiring most attention.Practical implicationsThe findings of this study are reported and recommendations were made that can help to improve situational awareness, which will have the effect of encouraging the implementation of cyber security measures.Originality/valueThis is the first study to apply the situational awareness theory to understand why SMEs do not implement cyber security best practice measures. |
Databáze: | OpenAIRE |
Externí odkaz: |