A quest for research and knowledge gaps in cybersecurity awareness for small and medium-sized enterprises☆

被引:12
作者
Chaudhary, Sunil [1 ]
Gkioulos, Vasileios [2 ]
Katsikas, Sokratis [2 ]
机构
[1] Maastricht Univ, Fac Law, European Ctr Privacy & Cybersecur ECPC, Bouillonstr 3, NL-6211 LH Maastricht, Netherlands
[2] Norwegian Univ Sci & Technol, Dept Informat Secur & Commun Technol, Teknologivegen 22, N-2815 Gjovik, Norway
关键词
Cybersecurity awareness; Small and medium-sized enterprises; Systematic literature review; Research and knowledge gaps; INFORMATION SECURITY AWARENESS; HOME COMPUTER; MOBILE USERS; BEHAVIOR; MANAGEMENT; IMPACT;
D O I
10.1016/j.cosrev.2023.100592
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The proliferation of information and communication technologies in enterprises enables them to develop new business models and enhance their operational and commercial activities. Nevertheless, this practice also introduces new cybersecurity risks and vulnerabilities. This may not be an issue for large organizations with the resources and mature cybersecurity programs in place; the situation with small and medium-sized enterprises (SMEs) is different since they often lack the resources, expertise, and incentives to prioritize cybersecurity. In such cases, cybersecurity awareness can be a critical component of cyberdefense. However, research studies dealing with cybersecurity awareness or related domains exclusively for SMEs are rare, indicating a pressing need for research addressing the cybersecurity awareness requirements of SMEs. Prior to that, though, it is crucial to identify which aspects of cybersecurity awareness require further research in order to adapt or conform to the needs of SMEs. In this study, we conducted a systematic literature review that focused on cybersecurity awareness, prioritizing those performed with a particular focus on SMEs. The study seeks to analyze and evaluate such studies primarily to determine knowledge and research gaps in the cybersecurity awareness field for SMEs, thus providing a direction for future research.
引用
收藏
页数:20
相关论文
共 176 条
[1]   User preference of cyber security awareness delivery methods [J].
Abawajy, Jemal .
BEHAVIOUR & INFORMATION TECHNOLOGY, 2014, 33 (03) :236-247
[2]  
Abawajy J, 2010, COMM COM INF SC, V122, P142
[3]   Users are not the enemy [J].
Adams, A ;
Sasse, MA .
COMMUNICATIONS OF THE ACM, 1999, 42 (12) :41-46
[4]  
Aguilar L.A., 2015, NEED GREATER FOCUS C
[5]  
Ahmad Z, 2016, 2016 4TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICOICT)
[6]  
Aitel D, 2012, Why you shouldn't train employees for security awareness
[7]  
Al-Hadadi M, 2013, INT CONF CURR TREND, P166, DOI 10.1109/CTIT.2013.6749496
[8]  
Al-Hamdani W.A., 2006, ACM P 3 ANN C INFORM, P102, DOI DOI 10.1145/1231047.1231069
[9]   A qualitative study of users' view on information security [J].
Albrechtsen, Eirik .
COMPUTERS & SECURITY, 2007, 26 (04) :276-289
[10]  
Aldawood H, 2018, PR IEEE INT CONF TEA, P62, DOI 10.1109/TALE.2018.8615162