At Antwerp Management School's Master in IT Risk & Cyber Security Management we noticed that SMEs are struggling to adequately address cybersecurity risks and are taking a slightly different approach than large(r) organizations. So we decided to have a closer look at the typical SME cybersecurity risks and approaches. This not only resulted in extensive research, but also in the development of the SMB Cybersecurity Canvas by Vincent van Dijk.
SMEs are key players in most economies and highly contribute to improving human welfare worldwide. They are, however, hit hard by cyber risks; 60% of small companies are out of business within 6 months after a cyberattack. Because of their typically low equity ratio, they are more vulnerable than larger enterprises to external events.
To reduce the effect of cyber risks, organizations need to align their cybersecurity maturity to their risk appetite. Cybersecurity maturity is managed and measured through standards such as the ISO27001 and the NIST Cybersecurity Framework. SMEs, however, are unable to effectivity adopt these standards because of high implementation cost, lack of resources, lack of technical solutions, lack of awareness, etc.
“SMEs cannot adopt current cybersecurity standards effectively because of the lack of standards tailored toward SMEs.”
Hence, we propose a cybersecurity standard tailored to SMEs, starting from the following primary research question:
"What components of a cybersecurity standard are tailored to SMEs with a low adoption barrier that effectively manage cybersecurity risks?"
As our research demonstrates, lack of resources and the implementation cost prevent SMEs from successfully adopting a cybersecurity standard. We also observed that a cybersecurity standard has 6 crucial components:
Due to the complexity and unpredictability of today's business climate, businesses need to continuously adapt to survive. Adaptability has thus become key for SMEs and needs to be deliberately promoted and supported by internal procedures. Likewise, a cybersecurity management standard for SMEs needs deliberate flexibility.
Our solution is the SMB cybersecurity canvas, that can be used to engage individuals in a strategic perspective of risks, cybersecurity, and measures.
On the left, the basic canvas provides company specifications and risk assessment:
Finally, we also developed a useful checklist, based on our research and consultancy expertise, that can be used separately from the SMB Cybersecurity Canvas:
Want to find out more about our research? The thesis also dives into topics such as:
Prof. Dr. Yuri Bobbert is Academic Director at AMS and supervised Vincent during his research project.
> Find out more on the AMS Master in IT Risk Management and Cybersecurity.