Abstract
The field of cybersecurity devotes time and effort to raising awareness of threats and measures to be implemented to reduce the risks. It is difficult for organisations, especially small ones with limited resources, to implement all possible threat mitigation measures. They have to satisfice by implementing only the measures they can afford and those that make the biggest impact in terms of reducing their vulnerability. Unfortunately, there is limited evidence to support such prioritisation. We explored the prevalence of threats and the relative efficacy of a range of commonly implemented measures that mitigate the most pervasive of these. First, to explore prevalence, we consulted industry and government reports. Second, to explore mitigations, we analysed data gathered by the UK government on the cost and impact of cyberattacks on businesses, charities, and educational institutions, as well as the risk mitigation measures they take (n = 3991). Social engineering was identified as the most common UK threat vector, and the most effective mitigations to social engineering were (1) National Cybersecurity Centre’s Cyber Essentials (standard) certification and (2) up-to-date malware protection. These findings can inform small business' prioritisation of threat mitigation measures.
| Original language | English |
|---|---|
| Number of pages | 12 |
| Publication status | Published - 4 Nov 2025 |
| Event | 19. International Conference on Computer Science, Cybersecurity and Information Technology - Digital event, Cape Town, South Africa Duration: 3 Nov 2025 → 4 Nov 2025 Conference number: 19th https://waset.org/computer-science-cybersecurity-and-information-technology-conference-in-november-2025-in-cape-town |
Conference
| Conference | 19. International Conference on Computer Science, Cybersecurity and Information Technology |
|---|---|
| Abbreviated title | ICCSCIT 2025 |
| Country/Territory | South Africa |
| City | Cape Town |
| Period | 3/11/25 → 4/11/25 |
| Internet address |
Keywords
- Social engineering
- Threat prevalence
- Threat mitigation
- Prioritisation
Fingerprint
Dive into the research topics of 'Prioritising social engineering risk reduction measures for UK-based small and medium-sized enterprises'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver