USENIX Security2021Top-tier venue
A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized Enterprises
Nicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke, Yasemin Acar, Arne Dreißigacker, Sascha Fahl
Abstract
Cybercrime is on the rise. Attacks by hackers, organized crime and nation-state adversaries are an economic threat for companies world-wide. Small and medium-sized enterprises (SMEs) have increasingly become victims of cyberattacks in recent years. SMEs often lack the awareness and resources to deploy extensive information security measures. However, the health of SMEs is critical for society: For example, in Germany, 38.8% of all employees work in SMEs, which contributed 31.9% of the German annual gross domestic product in 2018. Many guidelines and recommendations encourage companies to invest more into their information security measures. However, there is a lack of understanding of the adoption of security measures in SMEs, their risk perception with regards to cybercrime and their experiences with cyberattacks. To address this gap in research, we performed 5,000 computer-assisted telephone-interviews (CATIs) with representatives of SMEs in Germany. We report on their experiences with cybercrime, management of information security and risk perception. We present and discuss empirical results of the adoption of both technical and organizational security measures and risk awareness in SMEs. We find that many technical security measures and basic awareness have been deployed in the majority of companies. We uncover differences in reporting cybercrime incidences for SMEs based on their industry sector, company size and security awareness. We conclude our work with a discussion of recommendations for future research, industry and policy makers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eeb19514-e35f-4d38-b5d8-adfabd78e700Cited by top-tier papers14
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaignsSunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas et al.USENIX Security 2021 · 15 citations
- Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert et al.CCS 2024 · 5 citations
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
Builds on2
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern et al.USENIX Security 2018 · 51 citations
Related papers
- Cyber Threat Awareness, Protective Measures and Communication Preferences in Germany: Implications from Three Representative Surveys (2021-2024)Marc-André Kaufhold, Julian Bäumler, Marius Bajorski, Christian ReuterCHI 2025 · 4 citations
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm et al.CHI 2026 · 2 citations
- A Large-Scale Measurement of Cybercrime Against IndividualsCasey F. Breen, Cormac Herley, Elissa M. RedmilesCHI 2022 · 26 citations
- Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User GroupsFranziska Herbert, Steffen Becker, Annalina Buckmann, Marvin Kowalewski et al.S&P 2024 · 13 citations
- The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized EnterprisesLaura Kocksch, Torben Elgaard JensenCSCW 2024 · 5 citations
