SMEs Confidentiality Concerns for Security Information Sharing

07/13/2020
by   Alireza Shojaifar, et al.
0

Small and medium sized enterprises are considered an essential part of the EU economy, however, highly vulnerable to cyberattacks. SMEs have specific characteristics which separate them from large companies and influence their adoption of good cybersecurity practices. To mitigate the SMEs cybersecurity adoption issues and raise their awareness of cyber threats, we have designed a self paced security assessment and capability improvement method, CYSEC. CYSEC is a security awareness and training method that utilises self reporting questionnaires to collect companies information about cybersecurity awareness, practices, and vulnerabilities to generate automated recommendations for counselling. However, confidentiality concerns about cybersecurity information have an impact on companies willingness to share their information. Security information sharing decreases the risk of incidents and increases users self efficacy in security awareness programs. This paper presents the results of semi structured interviews with seven chief information security officers of SMEs to evaluate the impact of online consent communication on motivation for information sharing. The results were analysed in respect of the Self Determination Theory. The findings demonstrate that online consent with multiple options for indicating a suitable level of agreement improved motivation for information sharing. This allows many SMEs to participate in security information sharing activities and supports security experts to have a better overview of common vulnerabilities.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/16/2020

SMEs Confidentiality Issues and Adoption of Good Cybersecurity Practices

Small and medium-sized enterprises (SME) are considered more vulnerable ...
research
07/15/2020

Automating the Communication of Cybersecurity Knowledge: Multi-Case Study

Cybersecurity is essential for the protection of companies against cyber...
research
10/11/2021

Classifying SMEs for Approaching Cybersecurity Competence and Awareness

Cybersecurity is increasingly a concern for small and medium-sized enter...
research
05/17/2021

Confidence Assertions in Cyber-Security for an Information-Sharing Environment

Information sharing is vital in resisting cyberattacks, and the volume a...
research
06/11/2019

Sharing of vulnerability information among companies -- a survey of Swedish companies

Software products are rarely developed from scratch and vulnerabilities ...
research
09/14/2023

From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program

There is a growing recognition of the need for a transformation from org...

Please sign up or login with your details

Forgot password? Click here to reset