A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs

Renaud, Karen and Ophoff, Jacques (2021) A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs. Organizational Cyber Security, 1 (1). pp. 24-46. ISSN 2635-0289 (https://doi.org/10.1108/OCJ-03-2021-0004)

[thumbnail of Renaud-Ophoff-OCS-2021-An-SME-specific-cyber-situational-awareness-model-to-predict-the-implementation]
Preview
Text. Filename: Renaud_Ophoff_OCS_2021_An_SME_specific_cyber_situational_awareness_model_to_predict_the_implementation.pdf
Accepted Author Manuscript

Download (742kB)| Preview
[thumbnail of A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs]
Preview
Text. Filename: A_cyber_situational_awareness_model_to_predict_the_implementation_of_cyber_security_controls_and_precautions_by_SMEs.pdf
Final Published Version
License: Creative Commons Attribution 4.0 logo

Download (3MB)| Preview

Abstract

There is widespread concern about the fact that small and medium-sized enterprises (SMEs) seem to be particularly vulnerable to cyber attacks. This is perhaps because smaller businesses lack sufficient situational awareness to make informed decisions in this space, or because they lack the resources to implement security controls and precautions. In this paper, we extend Endsley's theory of situation awareness to propose a model of SMEs' cyber situational awareness, and the extent to which this awareness triggers the implementation of cyber security measures. We collected empirical data through an online survey of 361 UK-based SMEs, subsequently using Partial Least Squares Structural Equation Modelling to validate our model. The results show that heightened situational awareness, as well as resource availability, significantly impacts SMEs' implementation of cyber precautions and controls. We report on our findings and make recommendations that can help to improve situational awareness, which will have the effect of encouraging the implementation of cyber security measures.