{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T05:39:53Z","timestamp":1781329193866,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T00:00:00Z","timestamp":1745539200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4,26]]},"DOI":"10.1145\/3706598.3713931","type":"proceedings-article","created":{"date-parts":[[2025,4,28]],"date-time":"2025-04-28T14:16:17Z","timestamp":1745849777000},"page":"1-17","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-1109-9696","authenticated-orcid":false,"given":"Raha","family":"Asadi","sequence":"first","affiliation":[{"name":"IT University of Copenhagen, Copenhagen, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0830-2968","authenticated-orcid":false,"given":"Bodil","family":"Biering","sequence":"additional","affiliation":[{"name":"Cyberjuice, Copenhagen, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4600-6440","authenticated-orcid":false,"given":"Vincent","family":"van Dijk","sequence":"additional","affiliation":[{"name":"Security Scientist, Copenhagen, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4218-1658","authenticated-orcid":false,"given":"Oksana","family":"Kulyk","sequence":"additional","affiliation":[{"name":"IT University of Copenhagen, Copenhagen, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8346-2467","authenticated-orcid":false,"given":"Elda","family":"Paja","sequence":"additional","affiliation":[{"name":"IT University of Copenhagen, Copenhagen, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,25]]},"reference":[{"key":"e_1_3_3_3_2_2","unstructured":"[n. d.]. D-m\u00e6rket: Danmarks nationale m\u00e6rke for it-sikkerhed. https:\/\/www.d-maerket.dk\/ Accessed: 2024-12-11."},{"key":"e_1_3_3_3_3_2","unstructured":"[n. d.]. International Organization for Standardization (ISO). https:\/\/www.iso.org\/home.html Accessed: 2024-12-11."},{"key":"e_1_3_3_3_4_2","doi-asserted-by":"publisher","unstructured":"Muhammad Ali\u00a0Babar June Verner and Phong Nguyen. 2007. Establishing and maintaining trust in software outsourcing relationships: An empirical investigation. Journal of Systems and Software 80 (09 2007) 1438\u20131449. 10.1016\/j.jss.2006.10.038","DOI":"10.1016\/j.jss.2006.10.038"},{"key":"e_1_3_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3290605.3300519"},{"key":"e_1_3_3_3_6_2","unstructured":"AuditBoard. [n. d.]. What is a Security Audit?https:\/\/www.auditboard.com\/blog\/what-is-security-audit\/ Accessed: 2024-08-13."},{"key":"e_1_3_3_3_7_2","doi-asserted-by":"crossref","unstructured":"V. Braun and V. Clarke. 2006. Using Thematic Analysis in Psychology. Qualitative Research in Psychology 3 (2006) 77\u2013101.","DOI":"10.1191\/1478088706qp063oa"},{"key":"e_1_3_3_3_8_2","volume-title":"The SAGE Handbook of Qualitative Research in Psychology","author":"Brinkmann S.","year":"2017","unstructured":"S. Brinkmann and S. Kvale. 2017. The SAGE Handbook of Qualitative Research in Psychology. Sage."},{"key":"e_1_3_3_3_9_2","volume-title":"Kvalitative Metoder, En Grundbog","author":"Brinkmann S.","year":"2010","unstructured":"S. Brinkmann and L. Tanggaard. 2010. Kvalitative Metoder, En Grundbog. Vol.\u00a01. Hans Reitzels Forlag."},{"key":"e_1_3_3_3_10_2","volume-title":"Penetration Testing Report Guide","unstructured":"BrowserStack. [n. d.]. Penetration Testing Report Guide. https:\/\/www.browserstack.com\/guide\/penetration-testing-report-guide Accessed: 2024-08-13."},{"key":"e_1_3_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613904.3642951"},{"key":"e_1_3_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613904.3642011"},{"key":"e_1_3_3_3_13_2","doi-asserted-by":"publisher","unstructured":"Alladean Chidukwani Sebastian Zander and Polychronis Koutsakis. 2022. A Survey on the Cyber Security of Small-to-Medium Businesses: Challenges Research Focus and Recommendations. IEEE Access 10 (01 2022) 1\u20131. 10.1109\/ACCESS.2022.3197899","DOI":"10.1109\/ACCESS.2022.3197899"},{"key":"e_1_3_3_3_14_2","unstructured":"European Commission. 2024. Small and Medium-Sized Enterprises (SMEs). https:\/\/single-market-economy.ec.europa.eu\/smes_en Accessed: 2024-04-10."},{"key":"e_1_3_3_3_15_2","doi-asserted-by":"publisher","unstructured":"Asmita Dalela Saverio Giallorenzo Oksana Kulyk Jacopo Mauro and Elda Paja. 2022. A Study on Security and Privacy Practices in Danish Companies. 10.14722\/ndss.2022.23xxx","DOI":"10.14722\/ndss.2022.23xxx"},{"key":"e_1_3_3_3_16_2","unstructured":"DIGITAL SME Alliance. 2022. New SME Guide on Information Security Controls. https:\/\/www.digitalsme.eu\/new-sme-guide-on-information-security-controls\/ Accessed: 2024-11-27."},{"key":"e_1_3_3_3_17_2","unstructured":"NIS2 Directive. 2024. NIS2 Requirements. https:\/\/nis2directive.eu\/nis2-requirements\/ Accessed: 2024-11-27."},{"key":"e_1_3_3_3_18_2","unstructured":"NIS2 Directive. 2024. Who Are Affected by NIS2?https:\/\/nis2directive.eu\/who-are-affected-by-nis2\/ Accessed: 2024-11-27."},{"key":"e_1_3_3_3_19_2","volume-title":"SMV - Definition and meaning of Small and Medium-sized Enterprises","year":"2024","unstructured":"E-conomic. 2024. SMV - Definition and meaning of Small and Medium-sized Enterprises. https:\/\/www.e-conomic.dk\/regnskabsprogram\/ordbog\/smv Accessed: 2024-08-13."},{"key":"e_1_3_3_3_20_2","unstructured":"Center for Cybersecurity. 2019. Trusselsvurdering Cyberangreb mod leverand\u00f8rer. Forsvarets Efterretningstjeneste K\u00f8benhavn \u00d8. Copenhagen Denmark."},{"key":"e_1_3_3_3_21_2","doi-asserted-by":"publisher","unstructured":"Domingo Gaitero Marcela Genero and Mario Piattini. 2021. System quality and security certification in seven weeks: A multi-case study in Spanish SMEs. Journal of Systems and Software 178 (2021) 110960. 10.1016\/j.jss.2021.110960","DOI":"10.1016\/j.jss.2021.110960"},{"key":"e_1_3_3_3_22_2","unstructured":"UK Government. 2024. Cyber Essentials Scheme Overview. https:\/\/www.gov.uk\/government\/publications\/cyber-essentials-scheme-overview Accessed: 2024-11-27."},{"key":"e_1_3_3_3_23_2","doi-asserted-by":"crossref","unstructured":"Sofia Guerra and Luke Hinde. 2021. The Role of Certification in the Safety Demonstration of COTS EDDs. 12th Nuclear Plant Instrumentation Control and Human-Machine Interface Technologies (NPIC&HMIT 2021) (2021). https:\/\/api.semanticscholar.org\/CorpusID:247687468","DOI":"10.13182\/T124-34507"},{"key":"e_1_3_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/B978-0-12-800894-2.00006-5"},{"key":"e_1_3_3_3_25_2","unstructured":"ISACA. 2024. COBIT - Framework for Governance and Management of Enterprise IT. https:\/\/www.isaca.org\/resources\/cobit#1 Accessed: 2024-12-11."},{"key":"e_1_3_3_3_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3613904.3642456"},{"key":"e_1_3_3_3_27_2","unstructured":"Liberating Structures. 2024. 1-1-2-4-All. https:\/\/www.liberatingstructures.com\/1-1-2-4-all\/ Accessed: 2024-07-31."},{"key":"e_1_3_3_3_28_2","unstructured":"Liberating Structures. 2024. 9. 1-2-4-All. https:\/\/www.liberatingstructures.com\/14-min-specs\/ Accessed: 2024-07-31."},{"key":"e_1_3_3_3_29_2","unstructured":"H. Lipmanowicz and K. McCandless. 2024. Liberating Structures. Creative Commons License. https:\/\/www.liberatingstructures.com\/15-improv-prototyping\/ Accessed: 2024-03-21."},{"key":"e_1_3_3_3_30_2","unstructured":"National Institute of Standards and Technology. 2024. NIST - National Institute of Standards and Technology. https:\/\/www.nist.gov\/ Accessed: 2024-12-11."},{"key":"e_1_3_3_3_31_2","unstructured":"Birgit Nielsen. 2014-01-01. Dansk Branchekode DB07. https:\/\/www.dst.dk\/da\/Statistik\/dokumentation\/nomenklaturer\/db07 Accessed: 2024-12-10."},{"key":"e_1_3_3_3_32_2","doi-asserted-by":"publisher","unstructured":"Bilge\u00a0Yigit Ozkan and Marco Spruit. 2023. Adaptable Security Maturity Assessment and Standardization for Digital SMEs. Journal of Computer Information Systems 63 4 (2023) 965\u2013987. 10.1080\/08874417.2022.2119442 arXiv:10.1080\/08874417.2022.2119442","DOI":"10.1080\/08874417.2022.2119442"},{"key":"e_1_3_3_3_33_2","doi-asserted-by":"publisher","unstructured":"Marcel Pfeifer. 2021. IT security in SMEs \u2013 Threats and Chances for Supply Chains. Journal of Supply Chain and Customer Relationship Management (10 2021) 1\u20138. 10.5171\/2021.435883","DOI":"10.5171\/2021.435883"},{"key":"e_1_3_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-34339-2_20"},{"key":"e_1_3_3_3_35_2","unstructured":"Security Scientist. 2022. Cybersecurity Canvas. https:\/\/www.securityscientist.net\/content\/files\/2022\/11\/Cybersecurity-Canvas.pdf Accessed: 2024-11-27."},{"key":"e_1_3_3_3_36_2","unstructured":"Danmarks Statistik. 2024. It i virksomheder. https:\/\/www.dst.dk\/da\/Statistik\/emner\/erhvervsliv\/erhvervslivets-struktur\/it-i-virksomheder. https:\/\/www.dst.dk\/da\/Statistik\/emner\/erhvervsliv\/erhvervslivets-struktur\/it-i-virksomheder Accessed: 2024-06-18."},{"key":"e_1_3_3_3_37_2","doi-asserted-by":"crossref","unstructured":"Mohammad Tahaei and Kami Vaniea. 2019. A Survey on Developer-Centred Security. 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) (2019) 129\u2013138. https:\/\/api.semanticscholar.org\/CorpusID:199516521","DOI":"10.1109\/EuroSPW.2019.00021"},{"key":"e_1_3_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173574.3173836"},{"key":"e_1_3_3_3_39_2","doi-asserted-by":"publisher","unstructured":"J\u00f6rn-Henrik Thun Martin Dr\u00fcke and Daniel Hoenig. 2011. Managing Uncertainty - an Empirical Analysis of Supply Chain Risk Management in Small and Medium-Sized Enterprises. International Journal of Production Research 49 18 (2011) 5511\u20135525. 10.1080\/00207543.2011.563901","DOI":"10.1080\/00207543.2011.563901"},{"key":"e_1_3_3_3_40_2","unstructured":"Virksomhedsguiden. 2024. Sikkerhedstjekket. https:\/\/virksomhedsguiden.dk\/content\/ydelser\/sikkerhedstjekket\/fffe471f-dbad-49a6-ab69-e4d9a01691ab\/ Accessed: 2024-11-27."}],"event":{"name":"CHI 2025: CHI Conference on Human Factors in Computing Systems","location":"Yokohama Japan","acronym":"CHI '25","sponsor":["SIGCHI ACM Special Interest Group on Computer-Human Interaction"]},"container-title":["Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706598.3713931","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3706598.3713931","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T05:37:58Z","timestamp":1751607478000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706598.3713931"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,25]]},"references-count":39,"alternative-id":["10.1145\/3706598.3713931","10.1145\/3706598"],"URL":"https:\/\/doi.org\/10.1145\/3706598.3713931","relation":{},"subject":[],"published":{"date-parts":[[2025,4,25]]},"assertion":[{"value":"2025-04-25","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}