Classifying SMEs for Approaching Cybersecurity Competence and Awareness
Alireza Shojaifar, Heini Jarvinen

TL;DR
This paper introduces a classification framework for SMEs based on their cybersecurity needs, enabling tailored awareness and competence strategies to address their diverse vulnerabilities.
Contribution
It proposes a novel five-class SME framework that differentiates cybersecurity needs, guiding more effective and customized security solutions for diverse SME types.
Findings
Framework identifies five distinct SME cybersecurity classes.
Tailored solutions improve cybersecurity awareness for each SME class.
Framework usage demonstrated on sampled SMEs.
Abstract
Cybersecurity is increasingly a concern for small and medium-sized enterprises (SMEs), and there exist many awareness training programs and tools for them. The literature mainly studies SMEs as a unitary type of company and provides one-size-fits-all recommendations and solutions. However, SMEs are not homogeneous. They are diverse with different vulnerabilities, cybersecurity needs, and competencies. Few studies considered such differences in standards and certificates for security tools adoption and cybersecurity tailoring for these SMEs. This study proposes a classification framework with an outline of cybersecurity improvement needs for each class. The framework suggests five SME types based on their characteristics and specific security needs: cybersecurity abandoned SME, unskilled SME, expert-connected SME, capable SME, and cybersecurity provider SME. In addition to describing the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
