CISPA
Browse

File(s) not publicly available

A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized Enterprises

conference contribution
posted on 2023-11-29, 18:16 authored by Nicolas Huaman, Bennet von Skarczinski, dominik.wermke, Christian Stransky, Yasemin Acar, Arne Dreißigacker, Sascha FahlSascha Fahl
Cybercrime is on the rise. Attacks by hackers, organized crime and nation-state adversaries are an economic threat for companies world-wide. Small and medium-sized enterprises (SMEs) have increasingly become victims of cyberattacks in recent years. SMEs often lack the awareness and resources to deploy extensive information security measures. However, the health of SMEs is critical for society: For example, in Germany, 38.8% of all employees work in SMEs, which contributed 31.9% of the German annual gross domestic product in 2018. Many guidelines and recommendations encourage companies to invest more into their information security measures. However, there is a lack of understanding of the adoption of security measures in SMEs, their risk perception with regards to cybercrime and their experiences with cyberattacks. To address this gap in research, we performed 5,000 computer-assisted telephone-interviews (CATIs) with representatives of SMEs in Germany. We report on their experiences with cybercrime, management of information security and risk perception. We present and discuss empirical results of the adoption of both technical and organizational security measures and risk awareness in SMEs. We find that many technical security measures and basic awareness have been deployed in the majority of companies. We uncover differences in reporting cybercrime incidences for SMEs based on their industry sector, company size and security awareness. We conclude our work with a discussion of recommendations for future research, industry and policy makers.

History

Preferred Citation

Nicolas Huaman, Skarczinski von, Dominik Wermke, Christian Stransky, Yasemin Acar, Arne Dreißigacker and Sascha Fahl. A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized Enterprises. In: Usenix Security Symposium (USENIX-Security). 2021.

Primary Research Area

  • Empirical and Behavioral Security

Name of Conference

Usenix Security Symposium (USENIX-Security)

Legacy Posted Date

2021-07-05

Open Access Type

  • Unknown

BibTeX

@inproceedings{cispa_all_3437, title = "A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized Enterprises", author = "Huaman, Nicolas and von Skarczinski, Bennet and Wermke, Dominik and Stransky, Christian and Acar, Yasemin and Dreißigacker, Arne and Fahl, Sascha", booktitle="{Usenix Security Symposium (USENIX-Security)}", year="2021", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC