Towards a Conceptual Framework for Cybersecurity Skill Requirements in Small and Medium-Sized Enterprises

Ndimamkele Mkhulisi, Shopee Dube, Fani Radebe

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Cybersecurity poses a critical challenge for small and medium-sized enterprises (SMEs), which often operate with limited resources and expertise. Despite the growing recognition of these challenges, existing literature frequently neglects the specific needs and constraints of SMEs, particularly regarding tailored frameworks to enhance their resilience against cyberthreats. This study addresses this gap by proposing a conceptual framework designed to bolster the cybersecurity posture of SMEs. Key components of the framework include comprehensive training initiatives aimed at increasing awareness and preparedness for cyberthreats. The framework emphasizes a risk-based approach, advocating for threat-based cybersecurity risk assessments to effectively prioritize mitigation efforts. Additionally, it provides implementation guidelines for strong password policies and other fundamental security measures. By focusing on these areas, the framework seeks to cultivate a proactive cybersecurity culture within SMEs, empowering employees to identify and respond to threats. Ultimately, the study aims to equip SMEs with practical tools and strategies to navigate the complex and ever-evolving cybersecurity landscape, thereby fostering resilience and sustainability in the digital business environment.

Original languageEnglish
Title of host publicationProceedings of 2024 4th International Multidisciplinary Information Technology and Engineering Conference, IMITEC 2024
EditorsTranos Zuva, Andrew Brown, Musa Rikhotso
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages408-415
Number of pages8
ISBN (Electronic)9798350387988
DOIs
Publication statusPublished - 2024
Event4th International Multidisciplinary Information Technology and Engineering Conference, IMITEC 2024 - Vanderbijlpark, South Africa
Duration: 27 Nov 202429 Nov 2024

Publication series

NameProceedings of 2024 4th International Multidisciplinary Information Technology and Engineering Conference, IMITEC 2024

Conference

Conference4th International Multidisciplinary Information Technology and Engineering Conference, IMITEC 2024
Country/TerritorySouth Africa
CityVanderbijlpark
Period27/11/2429/11/24

Keywords

  • cybersecurity
  • cyberthreats
  • employees
  • small and medium-sized enterprises (SMEs)
  • training

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Networks and Communications
  • Hardware and Architecture
  • Information Systems
  • Safety, Risk, Reliability and Quality
  • Control and Optimization
  • Modeling and Simulation

Fingerprint

Dive into the research topics of 'Towards a Conceptual Framework for Cybersecurity Skill Requirements in Small and Medium-Sized Enterprises'. Together they form a unique fingerprint.

Cite this