Innovative Cybersecurity Awareness Programs in SMEs: Empowering Employee Behavior Against Social Engineering Threats
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
Small and medium enterprises (SMEs) are a great driver in every country’s economy. Nowadays, SMEs are trying to reach every corner of the globe, and to do that, they are using new technologies. It is evident that with new technologies come cyber risks that can threaten SMEs with financial and reputation damages. Social engineering, which is manipulating individuals to give away sensitive information, is a threat every SME faces. Therefore, there is a great need for employees in SMEs to be aware of the threats that they are facing online to keep themselves and their organizations safe. The only way to prevent such threats from happening is to have innovative awareness programs in place so every employee in SMEs is aware of social engineering threats and knows how to behave if and when they face such threats. Innovative awareness programs use creative and engaging methods such as self-paced programs or e-learning tailored to specific departments, real-world examples and simulations, and gamification to educate people about online threats. This study found the answer to the question, “How can innovative information security awareness programs in SMEs raise employee awareness and, in turn, lower the number of cyber security incidents?” A qualitative multiple-case study approach using semi-structured interviews was used for data collection. Data were then analyzed using pattern-matching to find themes, themes were then compared with the literature, and finally, a conclusion was drawn. This study had four participants from the clothing sector; two were IT professionals and two were regular employees working in SMEs. The findings show that regular, customized, and innovative awareness programs positively change employees' behavior when dealing with social engineering threats and increase employee engagement and knowledge retention. However, due to SMEs' financial problems, there is less attention to conducting innovative cybersecurity awareness programs. In addition, the lack of time, IT experts, and management support are other challenges SMEs face regarding having regular, engaging, and innovative awareness programs.
Place, publisher, year, edition, pages
2024.
Keywords [en]
Social Engineering, Phishing, SMEs, Small and Medium Enterprises, Information security awareness, cyber security awareness
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:su:diva-242751OAI: oai:DiVA.org:su-242751DiVA, id: diva2:1955683
2025-04-302025-04-30