科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Information Security Journal A Global Perspective2026-04-03· Thematic analysis

Understanding cyber security practices in SMEs: A mixed-methods Investigation

Matthew Rand, Maria Bada, Steven Furnell, Jason R. C. Nurse, Neeshe Khan

原始摘要(英文原文)· Original abstract
Small and medium-sized enterprises (SMEs) encounter cyber security risks, yet the factors underlying variation in these risks remain unclear. This study examined whether 1) cyber security controls, 2) awareness, knowledge, attitude, culture and 3) support routes vary according to SME characteristics (size, type, maturity and sector). It also explored the factors that shape SMEs’ decisions to access resources that help reduce cyber security risk. A mixed-methods design combined a survey of 374 participants and interviews with 12 SMEs. ANOVAs analyzed differences across organizational categories, and thematic analysis was applied to qualitative data. The study shows that many SMEs in the sample have inadequate security controls and limited awareness, knowledge and capability in cyber security. Qualitative insights show that SMEs may underestimate risk, face competing priorities and are unsure where to find support. These findings highlight the need for practical, accessible support to help SMEs implement effective cyber security.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Understanding cyber security practices in SMEs: A mixed-methods Investigation — 科研速览 Science Skim