{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T20:20:07Z","timestamp":1784665207330,"version":"3.55.0"},"reference-count":58,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2019,7,8]],"date-time":"2019-07-08T00:00:00Z","timestamp":1562544000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2019,7,8]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>The purpose of this study is to focus on organisation\u2019s cybersecurity strategy and propose a high-level programme for cybersecurity education and awareness to be used when targeting small- and medium-sized enterprises\/businesses (SMEs\/SMBs) at a city-level. An essential component of an organisation\u2019s cybersecurity strategy is building awareness and education of online threats and how to protect corporate data and services. This programme is based on existing research and provides a unique insight into an ongoing city-based project with similar aims.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>To structure this work, a scoping review was conducted of the literature in cybersecurity education and awareness, particularly for SMEs\/SMBs. This theoretical analysis was complemented using a case study and reflecting on an ongoing, innovative programme that seeks to work with these businesses to significantly enhance their security posture. From these analyses, best practices and important lessons\/recommendations to produce a high-level programme for cybersecurity education and awareness were recommended.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>While the literature can be informative at guiding education and awareness programmes, it may not always reach real-world programmes. However, existing programmes, such as the one explored in this study, have great potential, but there can be room for improvement. Knowledge from each of these areas can, and should, be combined to the benefit of the academic and practitioner communities.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>The study contributes to current research through the outline of a high-level programme for cybersecurity education and awareness targeting SMEs\/SMBs. Through this research, literature in this space was examined and insights into the advances and challenges faced by an on-going programme were presented. These analyses allow us to craft a proposal for a core programme that can assist in improving the security education, awareness and training that targets SMEs\/SMBs.<\/jats:p><\/jats:sec>","DOI":"10.1108\/ics-07-2018-0080","type":"journal-article","created":{"date-parts":[[2019,6,11]],"date-time":"2019-06-11T09:04:11Z","timestamp":1560243851000},"page":"393-410","source":"Crossref","is-referenced-by-count":132,"title":["Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)"],"prefix":"10.1108","volume":"27","author":[{"given":"Maria","family":"Bada","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jason R.C.","family":"Nurse","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"issue":"1","key":"key2020052710224132000_ref001","article-title":"A taxonomy of cyber-harms: defining the impacts of cyber-attacks and understanding how they propagate","volume":"4","year":"2018","journal-title":"Journal of Cybersecurity"},{"key":"key2020052710224132000_ref002","first-page":"72","article-title":"Enhancing information security education and awareness: proposed characteristics for a model","volume-title":"The 2nd International Conference on Information Security and Cyber Forensics","year":"2015"},{"key":"key2020052710224132000_ref003","unstructured":"ANSSI Certification (2014), \u201cFrance cybersecurity label\u201d, available at: www.francecybersecurity.fr (accessed 21 March 2019)."},{"issue":"1","key":"key2020052710224132000_ref004","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1080\/1364557032000119616","article-title":"Scoping studies: towards a methodological framework","volume":"8","year":"2005","journal-title":"International Journal of Social Research Methodology"},{"key":"key2020052710224132000_ref005","unstructured":"Asti, A. (2017), \u201cCyber defense challenges from the small and medium sized business perspective\u201d, SANS Institute, InfoSec Reading Room, available at: www.sans.org\/reading-room\/whitepapers\/hsoffice\/paper\/38160 (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref006","first-page":"118","article-title":"Cyber security awareness campaigns: why do they fail to change behaviour?","volume-title":"The International Conference on Cyber Security for Sustainable Society","year":"2015"},{"key":"key2020052710224132000_ref007","article-title":"Reviewing national cybersecurity awareness in Africa: an empirical study","year":"2018"},{"key":"key2020052710224132000_ref008","volume-title":"Qualitative Research Methods for the Social Sciences","year":"2004"},{"key":"key2020052710224132000_ref009","first-page":"3","article-title":"On information security guidelines for small\/medium enterprises","volume-title":"ICEIS","year":"2004"},{"key":"key2020052710224132000_ref010","unstructured":"Cisco (2018), \u201cSmall and midmarket businesses: small and mighty\u201d, avaialble at: www.cisco.com\/c\/dam\/en\/us\/products\/collateral\/security\/small-mighty-threat.pdf (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref011","unstructured":"CIPESA (2017), \u201cBridging cyber security gaps: SMEs trained in Uganda\u201d, available at: https:\/\/cipesa.org\/2017\/09\/bridging-cyber-security-gaps-smes-trained-in-uganda\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref012","article-title":"Cyber security culture is a collective effort","year":"2015"},{"key":"key2020052710224132000_ref013","unstructured":"DBEIS (2015), \u201cCyber essentials scheme: overview\u201d, available at: www.gov.uk\/government\/publications\/cyber-essentials-scheme-overview (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref014","unstructured":"DBEIS (2017), \u201cBusiness population estimate for the UK and regions: 2017 statistical release\u201d, available at: www.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/663235\/bpe_2017_statistical_release.pdf (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref015","doi-asserted-by":"crossref","unstructured":"DBIS and DCMS (2015), \u201cCyber security: advice for small businesses\u201d, available at: www.gov.uk\/government\/publications\/cyber-security-what-small-businesses-need-to-know (accessed 21 March 2019).","DOI":"10.1007\/978-3-030-31239-8_4"},{"key":"key2020052710224132000_ref016","article-title":"Approaches to IT security in small and medium enterprises","volume-title":"2nd Australian Information Security Management Conference","year":"2004"},{"key":"key2020052710224132000_ref017","article-title":"Challenges in fostering an information security culture in Australian small and medium sized enterprises","volume-title":"5th European Conference on Information Warfare and Security","year":"2006"},{"key":"key2020052710224132000_ref018","first-page":"1560","article-title":"Fostering information security culture in small and medium size enterprises: an interpretive study in Australia","volume-title":"ECIS","year":"2007"},{"key":"key2020052710224132000_ref019","unstructured":"ENISA (2019), \u201cCybersecurity culture guidelines: behavioural aspects of cybersecurity\u201d, available at: www.enisa.europa.eu\/publications\/cybersecurity-culture-guidelines-behavioural-aspects-of-cybersecurity\/ (accessed 31 January 2019)."},{"key":"key2020052710224132000_ref020","unstructured":"ENISA (2010), \u201cTraining material for SMEs\u201d, available at: www.enisa.europa.eu\/publications\/archive\/training-material-SMEs (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref021","unstructured":"Federal Trade Commission (2018), \u201cFTC to launch campaign to help small businesses strengthen their cyber defences\u201d, available at: www.ftc.gov\/news-events\/press-releases\/2018\/04\/ftc-launch-campaign-help-small-businesses-strengthen-their-cyber (accessed 21 March 2019)."},{"issue":"11","key":"key2020052710224132000_ref022","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1016\/S1361-3723(09)70139-3","article-title":"Recognising and addressing \u2018security fatigue\u2019","volume":"2009","year":"2009","journal-title":"Computer Fraud and Security"},{"key":"key2020052710224132000_ref023","article-title":"Promoting security awareness and training within small organisations","volume-title":"The Australian Information Security Management Workshop","year":"2000"},{"key":"key2020052710224132000_ref024","unstructured":"GOV.UK (2015), \u201cNew \u00a35000 government grant for small businesses to boost cyber security\u201d, Available at: www.gov.uk\/government\/news\/new-5000-government-grant-for-small-businesses-to-boost-cyber-security (accessed 21 March 2019)."},{"issue":"2","key":"key2020052710224132000_ref025","article-title":"Ignorance to awareness: towards an information security awareness process","volume":"104","year":"2013","journal-title":"South African Institute of Electrical Engineering"},{"key":"key2020052710224132000_ref026","unstructured":"IASME (2018), \u201cGovernance standard\u201d, available at: www.iasme.co.uk\/the-iasme-standard\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref027","unstructured":"InfoSecurity (2017), \u201cUK SMEs still do not educate their staff on the risk of cyber security\u201d, available at: www.infosecurity-magazine.com\/news\/uks-smes-failing-on-cyber-training\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref028","unstructured":"Italian Cyber Security Framework (2017), available at: www.cyberwiser.eu\/italy-it (accessed 21 March 2019)."},{"issue":"1","key":"key2020052710224132000_ref029","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1186\/s13673-016-0065-2","article-title":"Baiting the hook: factors impacting susceptibility to phishing attacks","volume":"6","year":"2016","journal-title":"Human-Centric Computing and Information Sciences Journal"},{"key":"key2020052710224132000_ref030","first-page":"414","article-title":"Network security testing tools for SMEs (small and medium enterprises)","year":"2018"},{"issue":"3","key":"key2020052710224132000_ref031","doi-asserted-by":"crossref","first-page":"269","DOI":"10.1080\/10919392.2018.1484598","article-title":"Exploring SME cybersecurity practices in developing countries","volume":"28","year":"2018","journal-title":"Journal of Organizational Computing and Electronic Commerce"},{"key":"key2020052710224132000_ref032","unstructured":"KPMG (2017), \u201cCyber accelerate: fast-track to cyber security for SMEs\u201d, available at: https:\/\/assets.kpmg.com\/content\/dam\/kpmg\/nz\/pdf\/May\/cyber-accelerate-brochure-web-version-kpmgnz.PDF (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref033","volume-title":"Union Democracy","year":"1956"},{"key":"key2020052710224132000_ref034","unstructured":"London Digital Security Centre (LDSC) (2017), \u201cLDSC: helping to make London the safest place to innovate online\u201d, available at: https:\/\/londondsc.co.uk\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref035","doi-asserted-by":"crossref","unstructured":"National Cyber Security Centre (NCSC) (2017), \u201cCyber security: small business guide\u201d, available at: www.ncsc.gov.uk\/smallbusiness (accessed 21 March 2019).","DOI":"10.2307\/j.ctvrnfqsx.8"},{"key":"key2020052710224132000_ref036","unstructured":"NIST (2003), \u201cBuilding an information technology security awareness and training program\u201d, by Mark Wilson and Joan Hash, available at: https:\/\/nvlpubs.nist.gov\/nistpubs\/Legacy\/SP\/nistspecialpublication800-50.pdf (accessed 23 September 2018)."},{"key":"key2020052710224132000_ref037","doi-asserted-by":"crossref","unstructured":"NIST (2018), \u201cFramework for improving critical infrastructure cybersecurity version 1.1\u201d, available at: www.nist.gov\/cyberframework (accessed 23 September 2018).","DOI":"10.2307\/j.ctv4cbhfx.6"},{"key":"key2020052710224132000_ref039","article-title":"Cybercrime and you: how criminals attack and the human factors that they seek to exploit","volume-title":"The Oxford Handbook of Cyberpsychology","year":"2018"},{"key":"key2020052710224132000_ref038","first-page":"60","article-title":"Trustworthy and effective communication of cybersecurity risks: a review","volume-title":"Workshop on Socio-Technical Aspects in Security and Trust","year":"2011"},{"key":"key2020052710224132000_ref040","unstructured":"OAS (2015), \u201cCybersecurity awareness campaign toolkit\u201d, available at: www.sites.oas.org\/cyber\/Documents\/2015%20OAS%20-%20Cyber%20Security%20Awareness%20Campaign%20Toolkit%20(English).pdf (accessed 23 September 2018)."},{"issue":"8","key":"key2020052710224132000_ref041","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1109\/MC.2016.223","article-title":"Cybersecuring small businesses","volume":"49","year":"2016","journal-title":"Computer"},{"issue":"3","key":"key2020052710224132000_ref042","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1097\/XEB.0000000000000050","article-title":"Guidance for conducting systematic scoping reviews","volume":"13","year":"2015","journal-title":"International Journal of Evidence-Based Healthcare"},{"issue":"8","key":"key2020052710224132000_ref043","first-page":"10","article-title":"How smaller businesses struggle with security advice","year":"2016","journal-title":"Computer Fraud and Security"},{"issue":"4","key":"key2020052710224132000_ref044","doi-asserted-by":"crossref","first-page":"30","DOI":"10.3390\/fi8030030","article-title":"The importance of the security culture in SMEs as regards the correct management of the security of their assets","volume":"8","year":"2016","journal-title":"Future Internet"},{"key":"key2020052710224132000_ref045","unstructured":"SANS (2018a), \u201cNational cyber security awareness month toolkit\u201d, available at: www.sans.org\/security-awareness-training\/resources\/security-awareness-planning-toolkit (accessed 21 February 2019)."},{"key":"key2020052710224132000_ref046","unstructured":"SANS (2018b), \u201cSecurity awareness metrics \u2013 measuring human risk\u201d, available at: www.sans.org\/security-awareness-training\/blog\/security-awareness-metrics-measuring-human-risk (accessed 21 February 2019)."},{"key":"key2020052710224132000_ref047","first-page":"88","article-title":"Are We there yet? Understanding the challenges faced in complying with the general data protection regulation (GDPR)","volume-title":"The 2nd International Workshop on Multimedia Privacy and Security at ACM\u2019CCS","year":"2018"},{"key":"key2020052710224132000_ref048","unstructured":"Symantec (2018), \u201cSecurity awareness services\u201d, available at: www.symantec.com\/en\/ca\/services\/education-services\/campaigns\/security-awareness (accessed 23 September 2018)."},{"key":"key2020052710224132000_ref049","first-page":"331","article-title":"Managing information security in small and medium sized enterprises: a holistic approach","volume-title":"Securing Electronic Business Processes","year":"2007"},{"issue":"3","key":"key2020052710224132000_ref050","first-page":"280","article-title":"SMEs and eBusiness","volume":"11","year":"2004","journal-title":"Journal of Small Business and Enterprise Development"},{"key":"key2020052710224132000_ref051","unstructured":"United Nations Secretariat (2014), \u201cCountry classification\u201d, available at: www.un.org\/en\/development\/desa\/policy\/wesp\/wesp_current\/2014wesp_country_classification.pdf (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref052","unstructured":"U.S. Department of Homeland Security (US DHS) (2018), \u201cSTOP. THINK. CONNECT campaign\u201d, available at: www.stopthinkconnect.org\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref053","unstructured":"The National Archives\/Cabinet Office (NA) (2017), \u201cResponsible for information\u2019 for SMEs\u201d, available at: www.nationalarchives.gov.uk\/sme\/ (accessed 21 March 2019)."},{"key":"key2020052710224132000_ref054","first-page":"71","article-title":"Small to medium enterprise cyber security awareness: an initial survey of Western Australian business","volume-title":"The International Conference on Security and Management","year":"2014"},{"key":"key2020052710224132000_ref055","unstructured":"Vertrauen Durch Sicherheit (VdS) (2019), \u201cA brief assessment for SMEs\u201d, available at: www.vds-quick-check.de\/en\/ (accessed 28 January 2019)."},{"key":"key2020052710224132000_ref056","first-page":"63","article-title":"Fear appeal theory","volume":"5","year":"2012","journal-title":"Research in Business and Economics Journal"},{"key":"key2020052710224132000_ref057","volume-title":"Case Study Research: Design and Methods","year":"1994","edition":"2nd ed."},{"key":"key2020052710224132000_ref058","volume-title":"Case Study Research: design and Methods","year":"2002"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-07-2018-0080\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-07-2018-0080\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:02Z","timestamp":1753406582000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/27\/3\/393-410\/105969"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,8]]},"references-count":58,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2019,7,8]]}},"alternative-id":["10.1108\/ICS-07-2018-0080"],"URL":"https:\/\/doi.org\/10.1108\/ics-07-2018-0080","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"value":"2056-4961","type":"print"},{"value":"2056-4961","type":"print"}],"subject":[],"published":{"date-parts":[[2019,7,8]]}}}