Security Obstacles and Motivations for Small Businesses from a CISO's Perspective

dc.contributor.authorWolf, Flynn
dc.contributor.authorAviv, Adam J.
dc.contributor.authorKuber, Ravi
dc.date.accessioned2021-08-24T18:09:38Z
dc.date.available2021-08-24T18:09:38Z
dc.date.issued2021
dc.description30th USENIX Security Symposiumen_US
dc.description.abstractSmall businesses (SBs) are often ill-informed and under-resourced against increasing online threats. Chief Information Security Officers (CISOs) have a key role in contextualizing trade-offs between competing costs and priorities for SB management. To explore the challenges CISOs' face when guiding SBs towards improved security we conducted two interview studies. Firstly, an exploratory study with CISOs with SB experience to identify themes related to their work (n=8). Secondly, we refined ourethods and conducted broader structured interviews with a larger non-overlapping group of similarly qualified SB CISOs (n=19) to validate those themes and extend outcomes. We found CISOs confirmed common observations that SBs are generally unprepared for online threats, and uninformed about issues such as insurance and regulation. We also found that despite perceived usability problems with language and formatting, the effectiveness of government-authored guidance (a key reference source for CISOs and SBs) was deemed on par with commercial resources. These observations yield recommendations for better formatting, prioritizing, and timing of security guidance for SBs, such as better tailoring checklists, investment suggestions, and scenario-based exercises.en_US
dc.description.urihttps://www.usenix.org/conference/usenixsecurity21/presentation/wolfen_US
dc.format.extent17 pagesen_US
dc.genrepresentations (communicative events)en_US
dc.genreconference papers and proceedings
dc.identifierdoi:10.13016/m2rcs6-o3wq
dc.identifier.citationWolf, Flynn; Aviv, Adam J.; Kuber, Ravi; Security Obstacles and Motivations for Small Businesses from a CISO's Perspective; 30th {USENIX} Security Symposium ({USENIX} Security 21), 2021; https://www.usenix.org/conference/usenixsecurity21/presentation/wolfen_US
dc.identifier.urihttp://hdl.handle.net/11603/22649
dc.language.isoen_USen_US
dc.publisherUSENIXen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Student Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.en_US
dc.titleSecurity Obstacles and Motivations for Small Businesses from a CISO's Perspectiveen_US
dc.typeTexten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
sec21_slides_wolf.pdf
Size:
796.6 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: