Cascading information on best practice: Cyber security risk management in UK micro and small businesses and the role of IT companies

被引:7
作者
Cartwright, Anna [1 ]
Cartwright, Edward [2 ]
Edun, Esther Solomon [3 ]
机构
[1] Oxford Brookes Univ, Oxford Brookes Business Sch, Oxford, England
[2] De Montfort Univ, Dept Accounting Finance & Econ, Leicester, England
[3] Cranfield Univ, Sch Aerosp Transport & Mfg, Dept Transport, Cranfield, Beds, England
关键词
Cyber security; Risk management; IT companies; Cyber essentials; Micro business; Small business; CYBERSECURITY; TECHNOLOGY; ADOPTION;
D O I
10.1016/j.cose.2023.103288
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Micro and small businesses are increasingly reliant on digital and online technology. They have, though, very limited resources and expertise to devote to cyber security. There is, thus, a pressing economic and social challenge of how to improve cyber security in small businesses. We look at the potential role of IT companies as a conduit through which to cascade information on best practice, focusing on the United Kingdom. We first present an analysis of the UK's Cyber Security Breaches Survey (2018-2021) distinguishing different channels through which micro and small businesses access information on cyber security. We find that the main channel, by far, is through IT companies. Very few businesses directly access information from the government or law enforcement. To further explore the role of IT companies we conducted a series of focus groups and interviews with experts in IT and cyber security for small businesses in the UK. One theme to emerge is that IT companies, while they can be part of the solution, can also be part of the problem and so a number of interventions are needed if IT companies are to effectively disseminate best practice. These include advice and guidance for micro and small businesses on how to distinguish 'good' IT companies, as well as appropriate support for IT companies, who themselves are typically micro and small businesses that lack expertise on cyber security. & COPY; 2023 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
引用
收藏
页数:15
相关论文
共 60 条
[1]   Entrepreneurship, economic development and institutions [J].
Acs, Zoltan J. ;
Desai, Sameeksha ;
Hessels, Jolanda .
SMALL BUSINESS ECONOMICS, 2008, 31 (03) :219-234
[2]  
Akpan I.J., 2022, Journal of Small Business & Entrepreneurship, V34, P123, DOI [10.1080/08276331.2020.1820185, DOI 10.1080/08276331.2020.1820185]
[3]  
Al-Qirim N.A., 2003, Journal of Information Technology Cases and Applications, V5, P32
[4]   Cybersecurity Risk Management in Small and Medium-Sized Enterprises: A Systematic Review of Recent Evidence [J].
Alahmari, Abdulmajeed ;
Duncan, Bob .
2020 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA 2020), 2020,
[5]   Marketing technology for adoption by small business [J].
Alford, Philip ;
Page, Stephen John .
SERVICE INDUSTRIES JOURNAL, 2015, 35 (11-12) :655-669
[6]  
Antunes M, 2021, J CYBERSECUR PRIV, V1, P219, DOI 10.3390/jcp1020012
[7]   A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs [J].
Armenia, Stefano ;
Angelini, Marco ;
Nonino, Fabio ;
Palombi, Giulia ;
Schlitzer, Mario Francesco .
DECISION SUPPORT SYSTEMS, 2021, 147
[8]  
Attaran M., 2019, Journal of Small Business and Entrepreneurship, V31, P495, DOI [10.1080/08276331.2018.1466850, DOI 10.1080/08276331.2018.1466850]
[9]  
Bada A., 2019, arXiv
[10]  
Bada M., 2019, Information & Computer Security