No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
Raha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk, Elda Paja
Abstract
Software developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration.It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration.In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-tobusiness model, conducting semi-structured interviews (𝑁 = 16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (𝑁 = 6).Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof.We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed. CCS Concepts• Security and privacy → Social aspects of security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 36a7582a-a896-4fdd-9667-d2138e4f1b9fBuilds on3
- Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and BehaviorClaire C. Chen, Dillon Shu, Hamsini Ravishankar, Xinran Li et al.CHI 2024 · 27 citations
- Comparing the Use and Usefulness of Four IoT Security LabelsPeter J. Caven, Zitao Zhang, Jacob Abbott, Xinyao Ma et al.CHI 2024 · 15 citations
- Not as easy as just update: Survey of System Administrators and Patching BehavioursAdam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami VanieaCHI 2024 · 10 citations
Related papers
- The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized EnterprisesLaura Kocksch, Torben Elgaard JensenCSCW 2024 · 5 citations
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm et al.CHI 2026 · 2 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- "My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security SoftwareJonah Stegman, Patrick J. Trottier, Caroline Hillier, Hassan Khan et al.USENIX Security 2023
