Pith. sign in

REVIEW 6 major objections 5 minor 51 references

Mind the Gap: Revealing Security Barriers through Situational Awareness of Small and Medium Business Key Decision-Makers

T0 review · 6 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Small and medium business leaders' cybersecurity decisions are shaped by a measurable five-level awareness gap, and low awareness tracks company size, sector, technology use, and prior attack experience.

desk verdict Useful qualitative map of SMB decision-maker security perception, but the SEM's Level 4-cautiousness path is largely an artifact of its own construction. read the letter →

arxiv 2506.10025 v1 pith:4R3II5SP submitted 2025-06-09 cs.CR cs.CYcs.HC

classification cs.CRcs.CYcs.HC
keywords situationalawarenessSMBcybersecuritykeydecision-makersriskperceptionstructuralequationmodelmixedmethodslevelssmallandmediumbusiness
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Small and medium businesses are not underprotected simply because they are small; the paper argues that what their owners and executives perceive is systematically out of line with the risks their businesses actually face. Using 21 interviews and 322 surveys of SMB key decision-makers, the authors characterize cybersecurity awareness as five levels, from not recognizing that security matters to lacking the resources to act, and show that leaders with low awareness are more common among smaller firms, certain sectors, and businesses that have never experienced an attack. The paper traces low awareness to three root causes: weak risk management, difficulty navigating the flood of security information, and low technological orientation. If the account is right, interventions aimed at these causes rather than at generic security training could close the gap.

What carries the argument

The carrying object is the five-level cyber situational awareness framework adapted to SMB decision-making: level 1, unaware that security matters to business continuity; level 2, unaware of attack likelihood; level 3, unaware of precautions; level 4, unaware of the need to act; and level 5, lacking resources. What does the work is the operationalization: level 1 is the standardized residual of a logistic regression of perceived damage on business attributes, level 4 is the distance from the 45-degree line between self-assessed protection and relative cautiousness, and the whole structure is connected by a structural equation model showing significant paths among root causes, awareness levels, attack experience, and relative cautiousness. This turns a psychological framework into a measurable index that can be regressed onto business characteristics and used to target interventions.

What would settle it

Take the 322 survey respondents and have independent security experts, blind to the regression residuals, rate each firm's actual exposure and each leader's awareness from anonymized business descriptions; if the residual-defined low-awareness groups do not match the expert ratings better than chance, the central measure fails.

Watch

Extended reading notes

Core claim

The central claim is that a leader's cybersecurity awareness can be measured as the gap between what they perceive and what their business's attributes would predict, and that this gap has an internal structure: five maturity-like levels where each level feeds the next, and where higher perceived knowledge can actually reduce the perceived need to act. Level 1 awareness is quantified as the residual from a logistic regression predicting a leader's expected damage from business attributes, while level 4 awareness is the distance between self-assessed protection and relative cautiousness, itself the residual from a regression predicting how many precautions a comparable business takes. These measures, together with the three root causes, are joined in a structural equation model that links awareness levels to each other and to security caution, with prior attack experience acting as the strongest natural driver of higher awareness. The result is a map of why SMB decision-makers under-invest and where targeted interventions could intervene.

Load-bearing premise

The load-bearing premise is that a leader's awareness is correctly measured by how far their self-reported damage estimate and precaution count fall below the average relationship predicted from business attributes, meaning the regression line is the right baseline and the leftover variation reflects awareness rather than unmeasured risks, differences in how people use rating scales, or self-report bias.

Editorial extensions

If this is right

  • If the five-level measure is valid, low-awareness SMBs can be identified from survey data alone, without waiting for an attack or an audit.
  • Because previous attack experience is the strongest natural predictor of higher awareness, red-team exercises and attack simulations may substitute for real incidents as learning events.
  • The negative path from level 3 to level 4 implies that teaching leaders about precautions can, if it breeds confidence, actually reduce their perceived need to act, so awareness programs must be paired with reminders of incomplete protection.
  • The three root causes (risk management, information navigation, technological orientation) are statistically linked to awareness, making them the levers a policy could pull.
  • Sector and size patterns, such as 6-to-10-employee firms and low-technology firms being more likely at low levels, give a concrete targeting list for public cyber guidance.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper: the residual-versus-predicted technique for measuring awareness could transfer to other self-reported risk domains, such as privacy attitudes or compliance behavior, wherever objective risk is unobserved.
  • Beyond the paper: the cross-sectional design does not test whether the proposed interventions actually move leaders up the levels; a randomized controlled trial measuring pre-post awareness shifts would be the natural next step.
  • The negative level 3-to-level 4 link suggests a testable hypothesis worth checking: security training that increases confidence without conveying residual uncertainty may increase complacency rather than caution.
  • The sample comes from one country's SMBs, so the specific sectors and coefficient magnitudes may not generalize; the framework, rather than the numbers, is the portable result.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

6 major / 5 minor

Summary. The manuscript studies cybersecurity situational awareness (SA) of small and medium business (SMB) key decision-makers through 21 semi-structured interviews and a survey of 322 Israeli decision-makers. It defines five levels of low SA, uses logistic regressions to associate low awareness with business attributes such as size, sector, technological intensity, and prior attack experience, and fits a structural equation model (SEM) that links root causes, SA levels, and relative cautiousness. The paper concludes with proposed interventions for improving SMB cybersecurity awareness.

Significance. The mixed-method design and the transparent appendices (survey instrument, interview guide, codebook, and coefficient tables) are strengths, and the qualitative themes about perceived assets, defenses, information sources, and decision factors are plausible and useful. If the quantitative SA measures and the SEM were valid, the paper would offer a valuable map of where SMB decision-makers are least aware and which root causes matter. However, the central quantitative evidence is currently compromised by a partly circular Level 4 variable, an ambiguous Level 4 coding rule, post-hoc thresholds with an explicit override, marginal significance without multiple-comparison correction, and unreported SEM fit. These issues must be resolved before the causal paths and intervention recommendations can be accepted.

major comments (6)
  1. [§5.2.1, §6.2, Fig. 4] Equation (2) defines Relative Cautiousness as the standardized residual u_i from a regression of Precautions_i on business attributes. Level 4 SA is then constructed as the distance from the 45-degree line between self-reported protection (Q33) and this same u_i. The SEM in Figure 4 reports a direct path from Level 4 to Relative Cautiousness of 0.68***. Because u_i appears in both the independent and dependent variables of this path, the coefficient is at least partly a mathematical consequence of the operationalization, not independent evidence that awareness drives precaution-taking. This undermines the causal reading that motivates the interventions in §7.2. Please re-estimate the SEM with Level 4 defined independently of u_i, or explicitly model and separately report the shared-component contribution.
  2. [§5.2.1, Level 4] The text states that decision-makers above the 45-degree line show low awareness and those below show high awareness, but then says 'We defined those at the lowest 20% as having low level 4 SA.' If the distance is signed, low awareness should correspond to the largest positive deviations (above the line), not the lowest 20%; if the distance is absolute, the lowest 20% are the best calibrated, not the least aware. Moreover, the positive 0.68*** path from Level 4 to Relative Cautiousness in Figure 4 is hard to reconcile with the stated direction: being above the line (protection greater than cautiousness) should predict lower, not higher, cautiousness. Please define the Level 4 score with an explicit formula and recheck the sign of the SEM path.
  3. [§5.2.1, Eqs. (1)–(2)] The entire low-awareness classification rests on the assumption that residual variation from the sample-average regressions reflects awareness rather than unmeasured business risk factors, differences in how respondents use rating scales, or self-report bias. For example, a respondent who systematically uses only the lower part of the rating scale will mechanically appear to underestimate damage in Eq. (1). This assumption is not tested. Please provide validity evidence, for instance convergence with interview-based SA judgments or with objective security indicators, or temper the claim that regression residuals measure awareness.
  4. [§5.2.1, Appendix F] The cutoffs for low awareness (20%, 23%, 27%, 20%, 25%) are not motivated by theory or pre-registered, and the Level 1 footnote overrides the residual mechanism for extreme answers: respondents reporting no damage are always low Level 1, and those reporting severe damage are never low Level 1. Because these classifications are the dependent variables of all logistic regressions in §6.1 and inputs to the SEM, the results may be sensitive to these choices. Please provide a sensitivity analysis varying the cutoffs across a plausible range and justify the Level 1 override.
  5. [§6.1, Appendix F] Many of the reported associations are significant only at the 10% level (e.g., size 6-10 for Level 2, revenue undisclosed for Level 4, size 51-100 for Level 5 and for 'No Low Awareness'), and the analysis tests a large number of hypotheses across five levels and several outcomes without any multiple-comparison correction. The narrative in §6.1 routinely interprets these marginal effects as findings. Please report adjusted p-values (e.g., Benjamini-Hochberg) or explicitly flag these as exploratory results.
  6. [§6.2, Fig. 4] The SEM is presented without model fit statistics, estimation method, or confidence intervals. With 322 observations and a model containing five SA levels, four root causes, attack experience, relative cautiousness, and multiple paths, the reader cannot evaluate identification or goodness of fit. Please report standard SEM diagnostics (chi-square, CFI/TLI, RMSEA, SRMR) and the full path coefficient table with standard errors.
minor comments (5)
  1. [§5.2.1, Level 2] The threshold description says 'below the 23% threshold (1: 12.8% or 2: 10.6%)' but does not state explicitly whether values 1 and 2 both count as low Level 2; please state the exact classification rule.
  2. [§5.2.1, Level 4] The phrase 'We stressed a 45◦ line' should be 'drew' or 'defined', and the x- and y-axis variables should be named explicitly in the text rather than only in the surrounding prose.
  3. [Appendix E] The Level 4 regression coefficients (e.g., constant 215.9 with SE 185.8, 'Has Cyber Insurance' 25.68 with SE 15.75) are not interpretable for a count of protective measures on the scale described in Eq. (2); please report the model specification and units or move the raw output to a supplement.
  4. [Table 3] The column headers 'R.M.', 'I.N.', 'T.I.', and 'C.D.M' are defined only in the table note; please spell them out in the header or include the definitions in the caption for readability.
  5. [§5.1, Technological Intensity] The threshold for high versus low technological intensity is described as the sample average of a six-point score; please state what happens to respondents with missing items and whether the split uses the mean or median.

Circularity Check

2 steps flagged · score 6.0 of 10

Level 4 awareness is constructed from relative cautiousness, yet Figure 4 reports a path from Level 4 to relative cautiousness; the 0.68*** coefficient is partly mechanical.

  1. self definitional [Section 5.2.1 (Level 4 definition) and Section 6.2 / Figure 4 (SEM path)]
    "The residual term ui represents business i’s deviation from the average number of precautions over our population sample. A large ui stands for over-cautiousness, and a low ui stands for under-cautiousness relative to other SMBs. We refer to the standardized ui as relative cautiousness. ... Level 4 SA equals the distance from the 45◦ line between participants’ answers ... and relative cautiousness (x-axis)... The model also suggests that levels 2, 3, and 4 directly influence relative cautiousness."

    Equation (2) defines Relative Cautiousness as the standardized residual u_i from regressing the count of protective measures on SMB attributes. Level 4 SA is then defined as the distance from the 45° line between self-reported protection (Q33) and this same u_i. Figure 4 / Section 6.2 then report a direct path Level 4 → Relative Cautiousness (0.68***). Since u_i appears on both sides of the path, the association is partly a mathematical consequence of the operationalization: the 'need to act' variable was constructed from the very cautiousness score it is said to cause.

  2. fitted input called prediction [Section 5.2.1 (Level 1 definition via Eq. 1) and Section 6.1 (Figure 3 logistic regression)]
    "logit(pr(Damage i =1)) = β0 + ∑ βj X Level1 ij + ε i (1) ... The residual term εi represents business i’s deviation from the average relationship. ... We standardized εi and used it as a measure for level 1 awareness. We defined a key decision-maker as having low level 1 awareness if its εi is of the lowest 20%. ... Figure 3 shows the marginal probabilities for low SA based on a logistic regression with business attributes (number of employees, business sector, annual revenue level, technological intensity, and cyber-attack experience)."

    Low Level 1 is defined as the lower tail of ε_i, the residual from Eq. (1), which regresses perceived potential damage on business attributes (X^{Level1} includes number of digital assets, website functionality, employees, sector, revenue, etc.). Section 6.1 then uses the same class of business attributes in a logistic regression to 'predict' low Level 1 (Figure 3). Because the outcome was constructed by removing the average effect of those attributes, any reported association is a re-description of the residualization (plus leftover nonlinearities and the ad hoc no-damage/severe-damage overrides), not an independent relationship between attributes and awareness.

full rationale

The strongest circularity is in the SEM: Level 4 SA is operationalized as the distance between a self-reported protection score and Eq. (2)'s residual u_i, which is renamed 'relative cautiousness.' Figure 4 then draws a direct arrow from Level 4 to relative cautiousness with a 0.68*** coefficient. Because the same u_i enters both the definition of Level 4 and the outcome variable of the path, the path is not an independent causal finding; it is partly a re-statement of the construction rule. A secondary issue affects Level 1: low Level 1 awareness is defined as the lower tail of the residual from Eq. (1), which regresses perceived damage on business attributes, and Section 6.1 then uses business attributes in a logistic regression to 'predict' that same residual-based outcome, so the Level 1 attribute associations are partly a re-description of the residualization. The other parts of the paper (interviews, descriptive statistics, Levels 2/3/5, root-cause scales) are defined independently and are not circular; there is no load-bearing self-citation chain. On balance, the central SEM claim is partially definitional, so the score is 6, not 0-2.

Assumptions & free parameters 3 free parameters · 4 assumptions · 0 invented entities

No new entities such as particles, forces, or dimensions are introduced. The constructed variable 'relative cautiousness' is a derived measure, not an independent entity.

free parameters (3)
  • Low-SA classification thresholds = 20%, 23%, 27%, 20%, 25% for Levels 1-5
    Chosen by the authors to split respondents into low-awareness groups; prevalence and regression results depend on these cutoffs.
  • Technological intensity split = Sample mean of the six-point Digital Intensity Index
    Businesses are labeled high or low technological intensity relative to the survey sample average, so the split is sample-dependent.
  • 45-degree line criterion for Level 4 SA = Standardized difference between self-reported protection and relative cautiousness
    Distance from the line defines level 4 awareness; this construction shares a component with relative cautiousness, inducing a mechanical association in the SEM.
assumptions (4)
  • domain assumption The five-level cyber situational awareness framework is a valid characterization of SMB key decision-makers' security awareness.
    Section 2 and Section 5.2.1 map survey items to SA levels without validating the mapping for this population.
  • domain assumption Self-reported responses reflect real business attributes and security posture.
    All quantitative measures come from self-report; the authors acknowledge self-report bias in the Limitations paragraphs of Sections 3 and 5.
  • ad hoc to paper Deviations from the sample-average regression indicate awareness rather than unmeasured risk or response-style bias.
    Equations (1) and (2) use residuals to define low Level 1 and Level 4 awareness; this assumes the average crowd prediction is the correct baseline.
  • standard math Linear regression provides the same results as Poisson for the count outcome Precautions.
    Footnote 3 in Section 5.2.1 asserts equivalence without reporting the Poisson fit, which is needed to justify the linear model for count data.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Mind the Gap: Revealing Security Barriers through Situational Awareness of Small and Medium Business Key Decision-Makers." pith.science (2026). https://pith.science/paper/4R3II5SP

@misc{pith2026250610025,
  author       = {Pith},
  title        = {Pith review of: Mind the Gap: Revealing Security Barriers through Situational Awareness of Small and Medium Business Key Decision-Makers},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/4R3II5SP}},
  note         = {Machine review of arXiv:2506.10025}
}
read the original abstract

Key decision-makers in small and medium businesses (SMBs) often lack the awareness and knowledge to implement cybersecurity measures effectively. To gain a deeper understanding of how SMB executives navigate cybersecurity decision-making, we deployed a mixed-method approach, conducting semi-structured interviews (n=21) and online surveys (n=322) with SMB key decision-makers. Using thematic analysis, we revealed SMB decision-makers' perceived risks in terms of the digital assets they valued, and found reasons for their choice of defense measures and factors impacting security perception. We employed the situational awareness model to characterize decision-makers based on cybersecurity awareness, identifying those who have comparatively low awareness in the fight against adversaries. We further explored the relationship between awareness and business attributes, and constructed a holistic structural equation model to understand how awareness can be improved. Finally, we proposed interventions to help SMBs overcome potential challenges.

Figures

Figures reproduced from arXiv: 2506.10025 by the authors.

Figure 1
Figure 1. SMB cybersecurity with Endsley’s theory of SA. [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Percentage of SMBs owning digital assets, websites, and protective measures deployed (N = 322). [PITH_FULL_IMAGE:figures/full_fig_p008_2.png] view at source ↗
Figure 3
Figure 3. Margins from logistic regressions predicting the probabilities of decision-makers having low awareness. [PITH_FULL_IMAGE:figures/full_fig_p010_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: Structural equation model of situational awareness, [PITH_FULL_IMAGE:figures/full_fig_p011_4.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

51 extracted references · 50 canonical work pages

  1. [1]

    Cybersecurity risk management in small and medium-sized enterprises: A systematic review of recent evidence

    Abdulmajeed Alahmari and Bob Duncan. Cybersecurity risk management in small and medium-sized enterprises: A systematic review of recent evidence. In2020 interna- tional conference on cyber situational awareness, data analytics and assessment (CyberSA), pages 1–5. IEEE, 2020

  2. [2]

    Investigating potential barriers to cybersecurity risk management investment in SMEs

    Abdulmajeed Abdullah Alahmari and Robert Anderson Duncan. Investigating potential barriers to cybersecurity risk management investment in SMEs. In2021 13th In- ternational Conference on Electronics, Computers and Artificial Intelligence (ECAI), pages 1–6. IEEE, 2021

  3. [3]

    World Bank SME finance: Development news, research, data.World Bank, 2022

    World Bank. World Bank SME finance: Development news, research, data.World Bank, 2022

  4. [4]

    Pervasive ehealth services a security and privacy risk awareness survey

    Xavier Bellekens, Andrew Hamilton, Preetila Seeam, Kamila Nieradzinska, Quentin Franssen, and Amar Seeam. Pervasive ehealth services a security and privacy risk awareness survey. In2016 International Confer- ence On Cyber Situational Awareness, Data Analytics And Assessment (CyberSA), pages 1–4. IEEE, 2016

  5. [5]

    The effectiveness of workshops as managerial learning opportunities.Education+ Training, 51(8/9):733–746, 2009

    Leo Billington, Robyn Neeson, and Rowena Barrett. The effectiveness of workshops as managerial learning opportunities.Education+ Training, 51(8/9):733–746, 2009

  6. [6]

    Using thematic anal- ysis in psychology.Qualitative research in psychology, 3(2):77–101, 2006

    Virginia Braun and Victoria Clarke. Using thematic anal- ysis in psychology.Qualitative research in psychology, 3(2):77–101, 2006

  7. [7]

    Identifying expertise to extract the wisdom of crowds.Management science, 61(2):267–280, 2015

    David V Budescu and Eva Chen. Identifying expertise to extract the wisdom of crowds.Management science, 61(2):267–280, 2015

  8. [8]

    Meeting managers’ information needs

    Helen Butcher et al. Meeting managers’ information needs. 1998

Show all 51 references
  1. [9]

    Cyber security: Bull’s-eye on small busi- nesses.J

    Jane Chen. Cyber security: Bull’s-eye on small busi- nesses.J. Int’l Bus. & L., 16:97, 2016

  2. [10]

    Exploring user reactions and men- tal models towards perceptual manipulation attacks in mixed reality

    Kaiming Cheng, Jeffery F Tian, Tadayoshi Kohno, and Franziska Roesner. Exploring user reactions and men- tal models towards perceptual manipulation attacks in mixed reality. InUSENIX Security, volume 18, 2023

  3. [11]

    A survey on the cyber security of small-to- medium businesses: Challenges, research focus and rec- ommendations.IEEE Access, 10:85701–85719, 2022

    Alladean Chidukwani, Sebastian Zander, and Polychro- nis Koutsakis. A survey on the cyber security of small-to- medium businesses: Challenges, research focus and rec- ommendations.IEEE Access, 10:85701–85719, 2022

  4. [12]

    Benefits of regular cloud security assess- ments for your business!, 2023

    CloudIBN. Benefits of regular cloud security assess- ments for your business!, 2023

  5. [13]

    No one drinks from the firehose: How organizations filter and prioritize vulnerability information

    Stephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham, and Michel van Eeten. No one drinks from the firehose: How organizations filter and prioritize vulnerability information. In2023 IEEE Sym- posium on Security and Privacy (SP), 2023

  6. [14]

    Digital intensity index descrip- tion

    dimodim. Digital intensity index descrip- tion. https://circabc.europa.eu/ui/group/ 89577311-0f9b-4fc0-b8c2-2aaa7d3ccb91/ library/30b83b9c-3d0c-4086-bf52-77905e19b4eb/ details, 2022

  7. [15]

    How open system intermediaries address institutional failures: The case of business incubators in emerging-market coun- tries.Academy of Management Journal, 59(3):818–840, 2016

    Nilanjana Dutt, Olga Hawn, Elena Vidal, Aaron Chat- terji, Anita McGahan, and Will Mitchell. How open system intermediaries address institutional failures: The case of business incubators in emerging-market coun- tries.Academy of Management Journal, 59(3):818–840, 2016

  8. [16]

    The problem of information overload in business organisations: a review of the literature.International journal of information management, 20(1):17–28, 2000

    Angela Edmunds and Anne Morris. The problem of information overload in business organisations: a review of the literature.International journal of information management, 20(1):17–28, 2000

  9. [17]

    Toward a theory of situation awareness in dynamic systems.Human factors, 37(1):32–64, 1995

    Mica R Endsley. Toward a theory of situation awareness in dynamic systems.Human factors, 37(1):32–64, 1995

  10. [18]

    Theoretical underpinnings of situation awareness: A critical review

    Mica R Endsley, Daniel J Garland, et al. Theoretical underpinnings of situation awareness: A critical review. Situation awareness analysis and measurement, 1(1):3– 21, 2000

  11. [19]

    Why are smbs most vulnerable to cyber- attacks? https://www.fortinet.com/resources/ cyberglossary/smb-cyberattacks, 2023

    Fortinet. Why are smbs most vulnerable to cyber- attacks? https://www.fortinet.com/resources/ cyberglossary/smb-cyberattacks, 2023

  12. [20]

    Open-system orchestration as a relational source of sensing capabilities: Evidence from a venture asso- ciation.Academy of Management Journal, 61(4):1369– 1402, 2018

    Alessandro Giudici, Patrick Reinmoeller, and Davide Ravasi. Open-system orchestration as a relational source of sensing capabilities: Evidence from a venture asso- ciation.Academy of Management Journal, 61(4):1369– 1402, 2018

  13. [21]

    Margareta Heidt, Jin P Gerlach, and Peter Buxmann. In- vestigating the security divide between SME and large companies: How SME characteristics influence organi- zational IT security investments.Information Systems Frontiers, 21:1285–1305, 2019

  14. [22]

    Sage, 1995

    Rick H Hoyle.Structural equation modeling: Concepts, issues, and applications. Sage, 1995

  15. [23]

    A large-scale interview study on information security in and attacks against small and medium-sized enterprises

    Nicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke, Yasemin Acar, Arne Dreißi- gacker, and Sascha Fahl. A large-scale interview study on information security in and attacks against small and medium-sized enterprises. In30th USENIX Security Symposium (US...

  16. [24]

    Sok: contemporary issues and challenges to enable cyber situational awareness for network security

    Martin Husák, Tomáš Jirsík, and Shanchieh Jay Yang. Sok: contemporary issues and challenges to enable cyber situational awareness for network security. InProceed- ings of the 15th International Conference on Availabil- ity, Reliability and Security, ARES ’20, New York, NY , US...

  17. [25]

    Eyes wide open: The role of situational information security awareness for security-related behaviour.Information Systems Journal, 31(3):429–472, 2021

    Lennart Jaeger and Andreas Eckhardt. Eyes wide open: The role of situational information security awareness for security-related behaviour.Information Systems Journal, 31(3):429–472, 2021

  18. [26]

    We are a startup to the core

    Dilara Keküllüo˘glu and Yasemin Acar. "We are a startup to the core": A qualitative interview study on the security and privacy development practices in turkish software startups. In2023 IEEE Symposium on Security and Privacy (SP), pages 2015–2031. IEEE, 2023

  19. [27]

    Phishing in organizations: Findings from a large-scale and long-term study

    Daniele Lain, Kari Kostiainen, and Srdjan ˇCapkun. Phishing in organizations: Findings from a large-scale and long-term study. In2022 IEEE Symposium on Se- curity and Privacy (SP), pages 842–859. IEEE, 2022

  20. [28]

    Survey of economic sectors

    The Israeli National Bureau of Statistics . Survey of economic sectors. https://www.cbs.gov.il/he/ mediarelease/DocLib/2023/247/29_23_247b. pdf, 2019

  21. [29]

    Statistical division and others.Inter- national Standard Industrial Classification of All Eco- nomic Activities (ISIC) Revision 4, 2008

    United Nations. Statistical division and others.Inter- national Standard Industrial Classification of All Eco- nomic Activities (ISIC) Revision 4, 2008

  22. [30]

    Maturity assessment models: a design science research approach.International Journal of Society Systems Science, 3(1-2):81–98, 2011

    Tobias Mettler. Maturity assessment models: a design science research approach.International Journal of Society Systems Science, 3(1-2):81–98, 2011

  23. [31]

    The wisdom of crowds in mat- ters of taste.Management Science, 64(4):1779–1803, 2018

    Johannes Müller-Trede, Shoham Choshen-Hillel, Meir Barneron, and Ilan Yaniv. The wisdom of crowds in mat- ters of taste.Management Science, 64(4):1779–1803, 2018

  24. [32]

    OECD.Financing SMEs and Entrepreneurs 2022. 2022

  25. [33]

    Department of the Treasury

    U.S. Department of the Treasury. Small business pro- grams, Mar 2024

  26. [34]

    Risk and the small-scale cyber security decision making dialogue—a uk case study.The Computer Journal, 61(4):472–495, 2018

    Emma Osborn and Andrew Simpson. Risk and the small-scale cyber security decision making dialogue—a uk case study.The Computer Journal, 61(4):472–495, 2018

  27. [35]

    Panel4All.https://www.panel4all.co.il/, 2023

  28. [36]

    Karen Renaud and Jacques Ophoff. A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs.Organi- zational Cybersecurity Journal: Practice, Process and People, 1(1):24–46, 2021

  29. [37]

    Small and medium business status report in 2023, 2023

    Small and Medium Business Agency. Small and medium business status report in 2023, 2023

  30. [38]

    My privacy for their security

    Jonah Stegman, Patrick J Trottier, Caroline Hillier, Has- san Khan, and Mohammad Mannan. “My privacy for their security”: Employees’ privacy perspectives and expectations when using enterprise security software. arXiv preprint arXiv:2209.11878, 2022

  31. [39]

    Microblogging during two natural haz- ards events: what twitter may contribute to situational awareness

    Sarah Vieweg, Amanda L Hughes, Kate Starbird, and Leysia Palen. Microblogging during two natural haz- ards events: what twitter may contribute to situational awareness. InProceedings of the SIGCHI conference on human factors in computing systems, pages 1079–1088, 2010

  32. [40]

    IT se- curity threats and challenges for small firms: Managers’ perceptions.International journal of the academic busi- ness world, 12(1):23–30, 2018

    Mahmoud Watad, Sal Washah, and Cesar Perez. IT se- curity threats and challenges for small firms: Managers’ perceptions.International journal of the academic busi- ness world, 12(1):23–30, 2018

  33. [41]

    Security obstacles and motivations for small businesses from a CISO’s perspective

    Flynn Wolf, Adam J Aviv, and Ravi Kuber. Security obstacles and motivations for small businesses from a CISO’s perspective. In30th USENIX Security Sympo- sium (USENIX Security 21), pages 1199–1216, 2021

  34. [42]

    Netsecradar: A visualization system for network security situational awareness

    Fangfang Zhou, Ronghua Shi, Ying Zhao, Yezi Huang, and Xing Liang. Netsecradar: A visualization system for network security situational awareness. InCyberspace Safety and Security: 5th International Symposium, CSS 2013, Zhangjiajie, China, November 13-15, 2013, Pro- ceedings 5...

  35. [43]

    Please start by telling me about yourself, including your edu- cation and familiarity with computer technology

  36. [44]

    Please tell me about your company, what it does, how long it has been operating, and the annual turnover

  37. [45]

    What kind of systems do you use and what information is stored? What is something you think has a high risk of losing and needs to be protected?

  38. [46]

    Who is in charge of IT information security? If a third party is in charge, is there any specific reason that you hired him/them?

  39. [47]

    What are the risks and consequences of your business being attacked? Have you heard talk of cyberattacks in your field?

  40. [48]

    What are the protective measures that the company is using? Was there some cyber defense that you were unable to imple- ment?

  41. [49]

    Has the company experienced attacks before? What did you do after the attack?

  42. [50]

    Can you share with me your sources of information for learning about cyber protection?

  43. [51]

    Which of the following best describes your business ownership? ⃝Privately Owned ⃝Publicly Owned ⃝ Cooperative Owned ⃝Non-profit ⃝ Government Owned Q2

    Is there anything else you would like to share? 14 B Survey Instrument Screening Q1. Which of the following best describes your business ownership? ⃝Privately Owned ⃝Publicly Owned ⃝ Cooperative Owned ⃝Non-profit ⃝ Government Owned Q2. How many employees are in your business? ...

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.