Small and medium-sized enterprises are considered an essential part of the EU economy, however, highly vulnerable to cyberattacks. SMEs have specific characteristics which separate them from large companies and influence their adoption of good cybersecurity practices. To mitigate the SMEs' cybersecurity adoption issues and raise their awareness of cyber threats, we have designed a self-paced security assessment and capability improvement method, CYSEC. CYSEC is a security awareness and training method that utilises self-reporting questionnaires to collect companies' information about cybersecurity awareness, practices, and vulnerabilities to generate automated recommendations for counselling. However, confidentiality concerns about cybersecurity information have an impact on companies' willingness to share their information. Security information sharing decreases the risk of incidents and increases users' self-efficacy in security awareness programs. This paper presents the results of semi-structured interviews with seven chief information security officers of SMEs to evaluate the impact of online consent communication on motivation for information sharing. The results were analysed in respect of the Self Determination Theory. The findings demonstrate that online consent with multiple options for indicating a suitable level of agreement improved motivation for information sharing. This allows many SMEs to participate in security information sharing activities and supports security experts to have a better overview of common vulnerabilities. The final publication is available at Springer via https://doi.org/10.1007/978-3-030-57404-8_22
翻译:中小企业被视为欧盟经济的一个重要部分,但极易受到网络攻击。中小企业具有将中小企业与大公司分开并影响其采用良好网络安全做法的具体特点。为了减轻中小企业的网络安全问题,并提高其对网络威胁的认识,我们设计了一种自定速度的安全评估和能力改进方法,即SYSEC。CYSEC是一种安全意识和培训方法,利用自我报告调查表收集公司关于网络安全意识、做法和脆弱性的信息,以生成自动咨询建议。然而,对网络安全信息的保密关切影响到公司共享信息的意愿。安全信息共享降低了事件风险,提高了用户在安全意识方案中的自我效能。本文介绍了与中小企业7名首席信息安全官员进行半结构性访谈的结果,以评估在线同意通信对信息共享动机的影响。对“自我确定理论”的分析结果表明,网上同意并提出了多种备选方案,表明信息分享的动力得到了适当的提高。允许许多中小企业参与安全信息共享活动,并支持安全专家通过Sprooglement 204 - 5-030 支持安全专家通过Spruplemental 207 - 207 - 5/10_Sy smal 10_Ormmmmissional dismissional dismissional dismissional dismissional