Cybersecurity Risk Management in Small and Medium-Sized Enterprises: A Systematic Review of Recent Evidence

No ratings

Presented at CyberScience2020 2020 by

Even though small and medium-sized enterprises (SMEs) have been encouraged to take advantage ofany possible business opportunities by utilizing and adopting new technologies such as cloud computing services,there is a huge misunderstanding of their cyber threats from the management perspective. Underestimation ofcybersecurity threats by SMEs leads to an increase in their vulnerabilities and risks, which unfortunately can becomeactual challenges to them and other related parties. The purpose of this paper is to provide a systematic literaturereview based on recently available evidence on cybersecurity risk management in SMEs in order to understand thecurrent situation. The authors aim to reveal the role the SMEs' management is playing in addressing cybersecurityrisks in recent years, as found in the literature, and to suggest avenues for further research. The paper follows a wellknown method by [1] for conducting a systematic literature review. Starting with a keyword search and an assessmentof fitness for this review, 15 papers out of 50 have been analysed by NVivo software according to bibliographicalinformation, research design and findings. The review identified 5 major perspectives that play a key role in SMEs’cybersecurity risk management, which are threats, behaviours, practices, awareness, and decision-makingrespectively. Importantly, empirical research on cybersecurity risk management in SMEs would be appreciated.