'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector
Judith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm, Vincent Charles Keating, Louise Alison Tumchewics, Olivier Schmitt, Amelie Theussen, Peter Mayer
Abstract
Small and medium-sized enterprises (SMEs) are facing growing cybersecurity threats amidst limited resources and regulatory complexity. This complexity stems from diverse stakeholders in the regulatory process, including policymakers, industry associations, and companies that must implement the regulations. Misalignments between these different stakeholders can further compound the complexity. Against this backdrop, we investigate the cybersecurity mental models held by three stakeholder groups in Denmark’s defence sector and how these mental models might influence regulatory processes. Using a qualitative approach combining focus groups with 6 policymakers, 11 policy promoters (industry associations), and 12 policy implementers (SMEs), we reveal key misalignments in perceptions of risk, threats, cyber readiness, and policy interpretation. Our findings further show that SMEs often treat cybersecurity as a compliance task, while policymakers assume strategic readiness. Based on our results, we suggest recommendations for aligning governance frameworks with organisational realities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cf16e5a6-2116-4fd8-b3fc-a21e55b74b7eRelated papers
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized EnterprisesLaura Kocksch, Torben Elgaard JensenCSCW 2024 · 5 citations
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 18 citations
- "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision MakingJens Opdenbusch, Jonas Hielscher, M. Angela SasseNDSS 2025
- "A five-year-old could understand it" versus "This is way too confusing": Exploring Non-expert Understandings and Perceptions of Cybersecurity DefinitionsLorenzo C. Neil, Charlotte Healy, Julie M. HaneyCHI 2025 · 1 citation
