The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized Enterprises
Laura Kocksch, Torben Elgaard Jensen
Abstract
Small-and medium-sized enterprises (SMEs) are an essential part of the global economy and paramount to local communities and employment markets. They are also considered to be particularly vulnerable to cyberattacks as they lack technical competencies, strict controls, and organizational routines. We present the results of an ethnographic study of 30 SMEs in Denmark to further our understanding of how companies in this segment handle cybersecurity in their daily practices. We suggest that cybersecurity is dealt with as a mundane art: instead of striving for solutions, SMEs must leave things undone, endure partially broken systems, and resort to making things slightly better or worse but never good. In line with CSCW scholarship on care in broken worlds, we emphasize the various tactics of living with insecure technologies. In a broken world, securing is often not about assurance or following rules but about handling dilemmas, breaking things a little but not a lot, or waiting things out.
CCS Concepts: • Security and privacy → Social aspects of security and privacy; • Human-centered computing → Empirical studies in collaborative and social computing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2975411a-ce20-45a7-be7a-060227a768d4Builds on2
Related papers
- No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business ModelRaha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk et al.CHI 2025 · 2 citations
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm et al.CHI 2026 · 2 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 4 citations
- Selling the Dream: How Intimate Insiders and Identity-Based Attackers Disrupt Micro-businessesNazanin Sabri, Arkaprabha Bhattacharya, Sterling Williams-Ceci, Daniel V. Bailey et al.USENIX Security 2026
