Skip to main navigation Skip to search Skip to main content

Prioritising social engineering risk reduction measures for UK-based small and medium-sized enterprises

Research output: Contribution to conferencePaper

2 Downloads (Pure)

Abstract

The field of cybersecurity devotes time and effort to raising awareness of threats and measures to be implemented to reduce the risks. It is difficult for organisations, especially small ones with limited resources, to implement all possible threat mitigation measures. They have to satisfice by implementing only the measures they can afford and those that make the biggest impact in terms of reducing their vulnerability. Unfortunately, there is limited evidence to support such prioritisation. We explored the prevalence of threats and the relative efficacy of a range of commonly implemented measures that mitigate the most pervasive of these. First, to explore prevalence, we consulted industry and government reports. Second, to explore mitigations, we analysed data gathered by the UK government on the cost and impact of cyberattacks on businesses, charities, and educational institutions, as well as the risk mitigation measures they take (n = 3991). Social engineering was identified as the most common UK threat vector, and the most effective mitigations to social engineering were (1) National Cybersecurity Centre’s Cyber Essentials (standard) certification and (2) up-to-date malware protection. These findings can inform small business' prioritisation of threat mitigation measures.
Original languageEnglish
Number of pages12
Publication statusPublished - 4 Nov 2025
Event19. International Conference on Computer Science, Cybersecurity and Information Technology - Digital event, Cape Town, South Africa
Duration: 3 Nov 20254 Nov 2025
Conference number: 19th
https://waset.org/computer-science-cybersecurity-and-information-technology-conference-in-november-2025-in-cape-town

Conference

Conference19. International Conference on Computer Science, Cybersecurity and Information Technology
Abbreviated titleICCSCIT 2025
Country/TerritorySouth Africa
CityCape Town
Period3/11/254/11/25
Internet address

Keywords

  • Social engineering
  • Threat prevalence
  • Threat mitigation
  • Prioritisation

Fingerprint

Dive into the research topics of 'Prioritising social engineering risk reduction measures for UK-based small and medium-sized enterprises'. Together they form a unique fingerprint.

Cite this