PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 24, 2023Information and Computer Security14 citations

Design and evaluation of a self-paced cybersecurity tool

View Full Paper
ASAlireza ShojaifarSFSamuel A. Fricker

Key Points

  • This research evaluates the CyberSecurity Coach (CYSEC) tool and its adoption for enhancing cybersecurity capabilities in SMEs.
  • Qualitative approach, including a survey and nine structured interviews with CEOs and CISOs from 12 SMEs.
  • Investigation focused on how CYSEC supports awareness raising and capability improvement.
  • Adoption of CYSEC varied significantly among SMEs due to their heterogeneous nature.
  • Four key determinants influencing adoption identified: personalisation features, awareness levels, cybersecurity knowledge and skills of CEOs/CISOs, and connection to cybersecurity expertise.

Abstract

Purpose This paper aims to present the evaluation of a self-paced tool, CyberSecurity Coach (CYSEC), and discuss the adoption of CYSEC for cybersecurity capability improvement in small- and medium-sized enterprises (SMEs). Cybersecurity is increasingly a concern for SMEs. Previous literature has explored the role of tools for awareness raising. However, few studies validated the effectiveness and usefulness of cybersecurity tools for SMEs in real-world practices. Design/methodology/approach This study is built on a qualitative approach to investigating how CYSEC is used in SMEs to support awareness raising and capability improvement. CYSEC was placed in operation in 12 SMEs. This study first conducted a survey study and then nine structured interviews with chief executive officers (CEOs) and chief information security officers (CISO). Findings The results emphasise that SMEs are heterogeneous. Thus, one cybersecurity solution may not suit all SMEs. The findings specify that the tool’s adoption varied quite widely. Four factors are primary determinants influencing the adoption of CYSEC: personalisation features, CEOs’ or CISOs’ awareness level, CEOs’ or CISOs’ cybersecurity and IT knowledge and skill and connection to cybersecurity expertise. Originality/value This empirical study provides new insights into how a self-paced tool has been used in SMEs. This study advances the understanding of cybersecurity activities in SMEs by studying the adoption of CYSEC. Moreover, this study proposes significant dimensions for future research.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Shojaifar et al. (2023) studied this question.

synapsesocial.com/papers/6a153d0937103a43379f6d83https://doi.org/10.1108/ics-09-2021-0145
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1A prototype tool for information security awareness and training2002 · 86 citations
  2. 2Antecedents of Employees' Information Security Awareness - Review, Synthesis, and Directions for Future Research2017 · 24 citations
  3. 3Improving Employees' Compliance Through Information Systems Security Training: An Action Research Study12010 · 639 citations
  4. 4Cyber Security Awareness Campaigns: Why do they fail to change behaviour?2019 · 207 citations
  5. 5Embedding security practices in contemporary information systems development approaches2001 · 55 citations