“Probably put some sort of fear in”: investigating the role of heuristics in cyber awareness messaging for small to medium sized enterprises

Dominic Button*, Jacques Ophoff, Alastair Irons, Sharon McDonald

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Citation (Scopus)

Abstract

Cyber-attacks are increasing at an exponential rate, targeting organisation irrespective of size. Small to medium sized enterprises (SMEs) are particularly vulnerable yet often lack cybersecurity awareness. This entails that an individual or organisation becomes aware of the cyber threats they face in addition to the protective actions and behaviours they can take. Despite the positive intentions of current cybersecurity awareness initiatives, there is a lack of adoption by SMEs. To better understand the situation this study explores SME owner or manager perceptions of cybersecurity awareness messages, leveraging psychological heuristics and message framing. Empirical data was collected through interviews with 16 participants representing SMEs in the North-East of England. Findings reflect that the framing of messages towards fear is more accepted by SMEs as opposed to positivity messages. Moreover, heuristics of self-efficacy and cost are seen to instil a desire to comply with cyber security behaviours. However, not all SMEs could agree on an approach thus suggesting that SMEs require bespoke messaging relating to the businesses and the owner.
Original languageEnglish
Title of host publicationHuman Aspects of Information Security and Assurance
Subtitle of host publication18th IFIP WG 11.12 International Symposium, HAISA 2024, Skövde, Sweden, July 9–11, 2024, proceedings, part II
EditorsNathan Clarke, Steven Furnell
Place of PublicationCham
PublisherSpringer
Pages101-115
Number of pages15
ISBN (Electronic)9783031725630
ISBN (Print)9783031725623, 9783031725654
DOIs
Publication statusPublished - 28 Nov 2024
Event18th International Symposium on Human Aspects of Information Security & Assurance - University of Skövde, Skövde, Sweden
Duration: 9 Jul 202411 Jul 2024
Conference number: 18th

Publication series

NameIFIP Advances in Information and Communication Technology (IFIPAICT)
PublisherSpringer
Volume722
ISSN (Print)1868-4238
ISSN (Electronic)1868-422X

Conference

Conference18th International Symposium on Human Aspects of Information Security & Assurance
Abbreviated titleHAISA 2024
Country/TerritorySweden
CitySkövde
Period9/07/2411/07/24

Keywords

  • Cyber security
  • Awareness messaging
  • Small to medium enterprises

Fingerprint

Dive into the research topics of '“Probably put some sort of fear in”: investigating the role of heuristics in cyber awareness messaging for small to medium sized enterprises'. Together they form a unique fingerprint.

Cite this