Cybersecurity is essential for the protection of companies against cyber threats. Traditionally, cybersecurity experts assess and improve a company's capabilities. However, many small and medium-sized businesses (SMBs) consider such services not to be affordable. We explore an alternative do-it-yourself (DIY) approach to bringing cybersecurity to SMBs. Our method and tool, CYSEC, implements the Self-Determination Theory (SDT) to guide and motivate SMBs to adopt good cybersecurity practices. CYSEC uses assessment questions and recommendations to communicate cybersecurity knowledge to the end-user SMBs and encourage self-motivated change. In this paper, the operationalisation of SDT in CYSEC is presented and the results of a multi-case study shown that offer insight into how SMBs adopted cybersecurity practices with CYSEC. Effective automated cybersecurity communication depended on the SMB's hands-on skills, tools adaptedness, and the users' willingness to documenting confidential information. The SMBs wanted to learn in simple, incremental steps, allowing them to understand what they do. An SMB's motivation to improve security depended on the fitness of assessment questions and recommendations with the SMB's business model and IT infrastructure. The results of this study indicate that automated counselling can help many SMBs in security adoption. The final publication is available at Springer via https://link.springer.com/chapter/10.1007%2F978-3-030-59291-2_8
翻译:网络安全是保护公司不受网络威胁所必不可少的。传统上,网络安全专家评估和提高公司的能力。然而,许多中小企业认为这类服务是负担不起的。我们探索了一种将网络安全带给SMB的替代“自做自做”(DIY)方法。我们的方法和工具,即CYSEC,实施自我决定理论(SDT)来指导和激励SMB采用良好的网络安全做法。CYSEC利用评估问题和建议向终端用户SMB传播网络知识,并鼓励自我驱动的变革。在本文中,SDT在SYSEC的运行和一项多案例研究的结果显示,SDBS采用网络安全做法的方式。有效的自动化网络安全通信取决于SMB的亲身技能、调整的工具以及用户记录保密信息的意愿。SMB10想要以简单、渐进的步骤向他们学习,让他们了解他们所做的事情。SMB的动机取决于SDS-287S-3SDS-MB的可靠性和SMBS-MDS-25S-ML的最后研究。S-MBS-S/Simplearalmentalalalalalment 。SMBSMBS-SMB/SMB/SB/Syalals_SMBisalmentalmentaldaldals。SBismal_SBismal_SMism_Bs。SMisal_SBAR_SBs_SBAR_BAR_SBs_SBAR_SBAR_SBAR_BAR_BAR_BAR_BAR_SBAR_S_S_S_BAR_BAR_BAR_BAR_BAR_BAR_BAR_SBAR_BAR_BAR_S_S_S_BAR_S_BAR_S_S_S_S_SMBAR_SMBAR_BAR_BAR_BAR_BAR_BAR_SBAR_BAR_