Matthew Rand, Maria Bada, Steven Furnell, Jason R. C. Nurse, Neeshe Khan
Small and medium-sized enterprises (SMEs) encounter cyber security risks, yet the factors underlying variation in these risks remain unclear. This study examined whether 1) cyber security controls, 2) awareness, knowledge, attitude, culture and 3) support routes vary according to SME characteristics (size, type, maturity and sector). It also explored the factors that shape SMEs’ decisions to access resources that help reduce cyber security risk. A mixed-methods design combined a survey of 374 participants and interviews with 12 SMEs. ANOVAs analyzed differences across organizational categories, and thematic analysis was applied to qualitative data. The study shows that many SMEs in the sample have inadequate security controls and limited awareness, knowledge and capability in cyber security. Qualitative insights show that SMEs may underestimate risk, face competing priorities and are unsure where to find support. These findings highlight the need for practical, accessible support to help SMEs implement effective cyber security.