[论文解读] Unaware, Unfunded and Uneducated: A Systematic Review of SME Cybersecurity
本篇系统性综述整合了2017至2023年间77项关于中小企业(SME)网络安全的研究,识别出三大核心障碍:对网络威胁的认知水平低、财务与数字资源有限,以及网络安全素养不足。研究发现,该领域研究存在重复性与发展不足的问题,缺乏新的实证洞察,呼吁采用标准化、严谨的研究实践,以提升未来研究的质量与影响力。
Small and Medium Enterprises (SMEs) are pivotal in the global economy, accounting for over 90% of businesses and 60% of employment worldwide. Despite their significance, SMEs are often disregarded in cybersecurity initiatives, rendering them ill-equipped to deal with the growing frequency, sophistication, and destructiveness of cyberattacks. We systematically reviewed the cybersecurity literature on SMEs published between 2017 and 2024. We focus on research discussing cyber threats, adopted controls, challenges, and constraints SMEs face in pursuing cybersecurity resilience. Our search yielded 1090 studies that we narrowed to 132 relevant papers. We identified 44 unique themes and categorised them as novel findings or established knowledge. This distinction revealed that research on SMEs is shallow and has made little progress in understanding SMEs' roles, threats, and needs. Studies often repeated early discoveries without replicating or offering new insights. Existing research indicates that the main challenges to attaining cybersecurity resilience of SMEs are a lack of awareness of cybersecurity risks, limited cybersecurity literacy, and constrained financial resources. Resource availability varied between developed and developing countries. Our analysis indicated a relationship among these themes, suggesting that limited literacy is the root cause of awareness and resource constraint issues.
研究动机与目标
- 确定并综合2017至2023年间关于中小企业网络安全的现有知识状态。
- 区分中小企业网络安全研究中的既有知识与新型实证发现。
- 探讨中小企业易受网络威胁影响的根本原因,尤其聚焦于认知水平、资源状况与素养水平。
- 评估现有中小企业网络安全文献在方法论质量与报告标准方面的表现。
- 提出研究实践改进建议,以增强未来该领域研究的可靠性与影响力。
提出的方法
- 采用PRISMA指南开展系统性文献综述,以识别与中小企业网络安全相关的研究。
- 通过多个数据库检索2017年1月至2023年12月间发表的研究,重点关注同行评审的学术论文。
- 通过题名、摘要与全文分析筛选出916项研究,最终选定77项相关文献进行主题分析。
- 采用归纳式主题分析方法,识别出44个独特主题,并将其归类为既有知识或新型发现。
- 通过评估方法论严谨性、报告标准与数据可靠性,对所选研究的研究质量进行评估。
- 采用定性综合方法,探讨主题之间的关系,特别是网络安全素养低下与其它障碍之间的因果联系。
实验结果
研究问题
- RQ1中小企业在实现网络安全韧性方面,最常报告的挑战与制约因素是什么?
- RQ2现有中小企业网络安全研究在多大程度上提供了新的实证证据,而非重复早期发现?
- RQ3网络安全素养、对威胁的认知水平与资源约束之间存在何种关系?
- RQ4方法论不一致与报告标准低下如何影响中小企业网络安全研究的可靠性与有效性?
- RQ5为增强未来中小企业网络安全研究的质量与影响力,需在研究实践中做出哪些改进?
主要发现
- 文献中识别出44个独特主题,其中大多数为重复的既有知识,而非新的实证洞察。
- 中小企业网络安全韧性的最主要障碍是:对网络威胁缺乏认知、财务与数字资源受限,以及人员网络安全素养水平低。
- 观察到一种因果关系:网络安全素养低下是导致认知水平低与资源约束的根本原因,表明其为关键根源。
- 研究质量参差不齐,66%的被评研究存在数据不完整问题,25%的研究在计算或数据报告中存在错误,与以往对网络安全文献的评估结果一致。
- 文献分散于46种不同的期刊与出版物中,包括非技术性出版物,表明该领域缺乏学科凝聚力与方法论标准化。
- 2022年仅有17%的英国中小企业开展了漏洞审计,凸显尽管威胁水平持续上升,但系统性主动网络安全措施仍严重缺失。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。