An SME-specific cyber situational awareness model to predict the implementation of cyber security controls and precautions

Karen Renaud, Jacques Ophoff

Research output: Contribution to journalArticlepeer-review

Abstract

There is widespread concern about the fact that small and medium-sized enterprises (SMEs) seem to be particularly vulnerable to cyber attacks. This is perhaps because smaller businesses lack sufficient situational awareness to make informed decisions in this space, or because they lack the resources to implement security controls and precautions. In this paper, we extend Endsley's theory of situation awareness to propose a model of SMEs' cyber situational awareness, and the extent to which this awareness triggers the implementation of cyber security measures. We collected empirical data through an online survey of 361 UK-based SMEs, subsequently using Partial Least Squares Structural Equation Modelling to validate our model. The results show that heightened situational awareness, as well as resource availability, significantly impacts SMEs' implementation of cyber precautions and controls. We report on our findings and make recommendations that can help to improve situational awareness, which will have the effect of encouraging the implementation of cyber security measures.
Original languageEnglish
Number of pages29
JournalOrganizational Cyber Security
Publication statusAccepted/In press - 18 Jun 2021

Keywords

  • small and medium size enterprise (SME)
  • cyber security
  • security control implementation

Fingerprint

Dive into the research topics of 'An SME-specific cyber situational awareness model to predict the implementation of cyber security controls and precautions'. Together they form a unique fingerprint.

Cite this