Strategies Cybersecurity Professionals Use to
Mitigate Cybersecurity Threats in Small Businesses
Section 1: Foundation of the Study
Background of the Problem
Cybersecurity is one of the most complicated and challenging issues facing
businesses in the digital age. Data breaches are a more common occurrence with reports
of major corporations being held financially liable and customers being outraged at how
their personal data is being treated. Moreover, small businesses are becoming more
attractive targets due to the lack of security and financial resources of larger enterprises
(Selznick & LaMacchia, 2017). But the role that small businesses have on the national
economy is significant. According to the U.S Small Business Administration (SBA),
there are over 33 million small businesses in the United States, which is defined as an
establishment with fewer than 500 employees. According to the U.S. Census (2022),
there were over 7.9 million small businesses in 2020. These small businesses account for
over 60% of net new jobs, creating over 17 million new positions (SBA, 2023). Small
businesses employ 61.7 million workers and represent 46.4% of private sector employees
(SBA, 2023). Small businesses also produce 43.5% of the gross domestic product (GDP),
comprise of 13.3 trillion dollars in private sector receipts, and have a known export value
of 413.3 billion dollars across the United States (SBA, 2023). Small businesses are
essential to the United States and global economy as the primary provider of financial
growth.
Despite their importance, resources are limited for small businesses. According to
the Small Business Administration (SBA), 60% of all small businesses have fewer than
100 employees (SBA, 2023). Compounding the constraints for information technology
(IT) staff such as budget and qualified technical resources is the limited certified
professional cyber security resources available in the very competitive job market. This
leads to a disadvantage for small businesses when it comes to securing their
organizations. As cyber criminals get more sophisticated capabilities and tools,
businesses need additional layers of cyber defense to prevent intrusion and exploitation of
vital information technology assets (Florea & Craus, 2022) that lead to data breaches,
financial losses, and reputational damage (D’Arcy et al., 2020). These cyber security
threats can cause significant damage to the company, customers, and partners. To address
these risks, small businesses need to develop comprehensive cybersecurity strategies that
are tailored to their specific business needs and risk profiles. This includes cyber
awareness training for employees, understanding key business processes and data,
identifying potential threats, creating impact and risk assessments, and implementing
specific controls to mitigate the risks. By taking a holistic approach to cybersecurity,
small businesses could better protect their assets and maintain the trust of their customers
and stakeholders (Falch et al., 2023; Kemp et al., 2023). But the current tools and
personnel to secure a business are expensive, and many small business owners are
struggling with the increasing cost of cyber security as well as the number of threats and
vulnerabilities to information technology systems. This study was conducted to
understand what strategies cyber security professionals use and how they can be adopted
to protect small businesses from this growing threat.
Problem Statement
Cybercriminals have an increasing number of new attack strategies, tools, and
techniques that are used to defeat any single defensive cyber security strategy (Koïta et
al., 2022). Cases of cyber terrorism, fraud, identity theft and other forms of cybercrime
have increased by 22.7% in the last 5 years (Mukdasanit & Kantabutra, 2021). The
general IT problem that prompted me to search the literature is the high percentage of
cybersecurity professionals who lack strategies to combat cyber threats targeting small
businesses, even though small and medium businesses contain the same level of private
customer data, sensitive financial data, and intellectual property as their larger
counterparts. The specific IT problem is that some cybersecurity professionals in small
businesses lack strategies to mitigate cybersecurity threats.
Purpose Statement
The purpose of this qualitative pragmatic inquiry study was to explore successful
strategies some cybersecurity professionals use to mitigate cybersecurity threats in small
businesses. The target population for this study is 10 cybersecurity professionals and IT
managers with at least 2 years of cybersecurity experience and experience in another
information technology discipline from LinkedIn. IT function is defined as but not
limited to network/system engineer, systems analyst, system(s)/network/firewall
administrator, support staff, and developer. Holistic cybersecurity strategies may
contribute to social change by increasing an organization’s security posture. The increase
in an organization’s security posture protects customer and organizational data from
cyber threats, identity theft, intellectual property theft, and extortion through ransomware.
Increasing customer confidence and could attribute to industry and market growth.
Nature of the Study
This study used qualitative pragmatic methodology to research the perceptions
and experiences of a practical cyber security problem. Researchers use qualitative
methods to understand phenomena and motivations within real life problems (Baškarada,
2014). A qualitative methodology was appropriate to gain insights into strategies
cybersecurity professionals use to mitigate cybersecurity threats in small businesses. I
reviewed other methodologies, such as quantitative and mixed methodologies. I rejected
the quantitative research methodology because I did not intend to prove a hypothesis
using statistical data or variables (Franklin, 2023). Mixed methodologies integrate
meaningfully connected data collected from the fundamentally different quantitative and
qualitative research methods to solve a research problems (Schoonenboom, 2023). I
rejected mixed methodology because I do not intend to collect statistical data related to
the mitigation of cybersecurity threats based on cybersecurity strategies.
Qualitative pragmatic research was appropriate for this study because the research
question is complex, currently not well-defined, practical, and contextual. Pragmatic
inquiry allows researchers to explore what has been done and the consequences of those
actions. The analysis and synthesis of strategies within systems thinking enables
researchers to work through the complex system and social issues and the human factors
in security (Kelley & Nahser, 2014).
I researched other qualitative designs such as grounded theory, phenomenological,
and ethnographic designs. Grounded theory provides the opportunity for a researcher to
extend a previous theory or generate a new theory (Strauss & Corbin, 1998). I did not
select this design because my intent was not to extend an existing theory or create a new
theory. The qualitative phenomenological method allows the researcher to delve into the
perceptions, perspectives, understandings, and feelings of the participants who have
experienced the phenomenon or situation that is of interest to the researcher (Flynn &
Korcuska, 2018). This design was inappropriate because I was not researching a specific
event based on how the participants feel about things during the event. Finally,
ethnographic studies are used to explore the representation of a socioculture and
individuals to understand how these groups function. An ethnographic study is an
immersion study of a community, during which interviews and observations are used to
study local perceptions and social representations and practices (Sissoko et al., 2022).
This study did not focus on a community or social practice; therefore, ethnographic
design is not appropriate for this study.
Research Question
What successful strategies do some cybersecurity professionals use to mitigate
cybersecurity threats in small businesses?
Interview Questions
1. What experiences have you had implementing risk management strategies toward
the IT security and administration of organizations?
2. What cyber-security strategies have you implemented or seen implemented to
mitigate threats and reduce the attack surface of an organization?
3. What are some strategies you use to secure networks and systems from cyber
security attacks?
4. What types of resources did you use to create your cyber-security strategies?
5. In your experience what risk mitigation strategies have you used as part of your
cyber security strategy to secure businesses from cyber-security incidents and
attacks? Patch management, cyber security frameworks (zero-trust)
6. How would you recommend security controls be assessed and monitored after
implementation?
7. What are the processes you have seen or put in place to support periodic
assessments to sustain the security posture of organizations?
8. In your experience how can a business protect its customers, reputation and
operations from being hacked?
a. In your professional opinion, if a business has a security breach or is
infected with malware what plans and/or policies can be put into place
to prevent a security incident from being unrecoverable?
9. In your experience, what specific continuity of operations plans have you seen
implemented that are effective mitigations in the event of a cyber security
incident and have been used to mitigate cyber threats?
a. Have you seen regular drills performed to test these plans and the
operations?
10. In your experience, are there specific strategies, plans or policies that work well
and/or complement each other? An example is network and computer use policies
with user training.
11. In your experience, what cyber-security strategies have you implemented or seen
implemented but have found are not useful?
12. What would you recommend to a business leader building a cyber strategy?
Theoretical or Conceptual Framework
The conceptual framework for this study used general system theory (GST).
Ludwig Von Bertalanffy (1950) introduced GST to solve real-world problems using the
holistic interpretation that the whole is greater than the sum of its parts. Von Bertalanffy
proposed GST as a framework to view the world as an organization, stipulating that the
whole is more than the sum of its parts and that the elements or characteristics of the
whole are not explainable by the elements or characteristics of individual isolated parts
(Laszlo & Krippner, 1998). The model for GST was originally developed in relation to
biological systems but was found to be relevant to multiple disciplines to explain the
complex relationships between distinct parts of a whole in relation to the whole, thus a
system of systems.
Businesses, organizations, governments, and biological organisms can be looked
at as complex systems of systems. The nature of a business is complex, and the systems
that support the business are complex. Acknowledging that a system based on a system of
systems is exponentially more complex and the interactions between each system element
adds to this complexity is called systems thinking (Checkland, 1994; Rousseau, 2019).
This larger system has dependencies on other divisions or organizations, thus making the
whole of an organization or business. GST can be used as the lens to view the complex
relationships between businesses, people, processes, and technology, understanding the
business process as an element with inputs and outputs but also as a part of the larger
whole business. For example, the relationships between recruiting, human resources
(HR), payroll, IT, and the business transactions demonstrate how each of these
departments and associated systems produce a larger organization. Understanding the
processes of each system and the relationship to the larger system, whether it is a division
or the whole business, is critical to producing a holistic cybersecurity strategy. Some
approaches to cyber security do not take the relationships between the different IT
elements and the business into context. This could cause critical systems to be excluded
by the security teams’ assessments.
Due to the nature and complexity of these “systems” interactions, I selected Von
Bertalanffy’s GST as the conceptual framework for this study. Cybersecurity strategies
are complex systems of systems consisting of interconnected elements that work together
to achieve a common goal of protecting an organization’s assets from cyber threats. A
cyber security strategy aims to prevent cyber-attacks from occurring, mitigating threats
and monitoring vulnerabilities to the business. To build a cybersecurity strategy requires
the use of multiple frameworks, governance, policies and cultural norms to be effective
(AlGhamdi et al., 2020). The logical collaboration and dependencies between these
system elements working as a holistic system aligns with GST, which describes the
complex interactive components, concepts, and mechanization of the centralized sum of
all the parts. This systematic thinking is needed to analyze several different components
of a system to evaluate the larger organization (Beitelspacher & Rodgers, 2018). GST
enables organizations to meet objectives and declared that organizations that
incrementally adapt management practices create a competitive advantage (Shin &
Konrad, 2017). GST was appropriate to my research in explaining and understanding
how to build a holistic cybersecurity strategy due to the complexity of securing a system
of interconnected business processes and technology.
Definition of Terms
Cyber hygiene: The users’ abilities and habits that help users and organizations
mitigate the networks potential vulnerability to cyber-attacks and enhance resilience
against threats of cyber-attacks (Mednikarov et al., 2023, p. 156).
Cyber security risk management: The process of detecting an organization’s
security threats, discovering security gaps in order to determine the attack scenario, and
deciding on how to address the cybersecurity risk (Melaku, 2023, p. 1).
Cyber-crime: Generally refers to the unauthorized access to network and
information systems, which can lead to further cybercrimes, such as the “exfiltration” of
data (i.e. the creation of unauthorized copies for dissemination, sale, or for blackmailing
through the information contained in such data; Porcedda, 2018, p. 1077)
Malware: Malicious software penetrating different software and data without user
authorization. The malicious software targets and infects individual computers or an
organization’s network. A malware infection has terrible consequences, such as stealing
passwords, and data theft (Alzahrani et al., 2022, p. 1).
Small business: A small business is an establishment with fewer than 500
employees (SBA, 2023)
Systems thinking: A way of making sense of the complexity of the world by
looking at it in terms of wholes and relationships rather than by splitting it down into its
parts (Narang, 2023, p. 9).
Assumptions, Limitations, and Delimitations
Assumptions
Researchers bring a certain number of assumptions to their research whether
consciously aware or not; these assumptions include the researchers’ values or beliefs,
understanding and existence of the objects they are researching and what the researcher
understands about human knowledge (Almasri & McDonald, 2021). The first assumption
was that qualitative methodology is the correct methodology to use to study cybersecurity
strategies. The second was that the interviewees or participants were honest and
forthcoming with information in all aspects of the interview to give a proper perspective
without fear of reprisal or harm to their reputations or customer base. The third
assumption was that participants were qualified to answer questions regarding
cybersecurity strategies due to their experience with a specific subject of cybersecurity
and another information technology domain. The combination should produce a more
well-rounded participant. Fourth was the assumption that the number of participants
included in the study was sufficient to provide enough quality data to address the research
question of “What strategies do some cybersecurity professionals use to mitigate
cybersecurity threats in small businesses?”
Limitations
Research limitations of a study are the potential weaknesses outside of the
researcher’s control and are closely associated with research design, statistical model
constraints, imposed restrictions or other factors (Theofanidis & Fountouki, 2019). This
study did not include international organizations, current government employees, or law
enforcement. The cyber strategies from these organizations may differ from those of
small businesses and have external governing influences such as federal policies, and
international treaties. Due diligence was taken in the selection of interviewees; however,
the truthfulness and willingness of the participant is outside of the control of the
researcher. The participants may have also lacked experience around a specific subject of
cybersecurity, management, and the use of strategies. This would hinder the collection of
data from affected participants on those possible themes.
Delimitations
Delimitations are the limits the researcher imposes on the study. This binds the
scope of the study to the criteria purposefully included and excluded from the study
(Coker, 2022). The delimitations chosen for this study are limiting the participants to
cybersecurity professionals and managers with at least 2 years of cybersecurity
experience and experience in another IT domain or function. This was done to understand
the interactions between cybersecurity and other business process or technology in a
business. This study started with a sample size of 10 participants and continued until data
saturation was reached. I connected with potential interview candidates that identified
themselves as having cyber security, management, and some other information
technology experience using the social media platform, LinkedIn.
Significance of the Study
Contribution to Information Technology Practice
Prior studies have indicated that cyber-attacks are on the rise, targeting small
businesses who are not properly equipped to negate evolving cyber threats. With small
businesses accounting for over 12 million jobs created between 1995 and 2020 and
making up 99.9% of all U.S,-based businesses, this is a significant threat to both business
owners and local economies (SBA, 2021; Rowinski, 2022). Small business leaders who
can develop a cybersecurity strategy could better understand their business risk posture
and what tools are available to protect their business and customers. The significance of
this study is that small business leaders might gain insights into how to protect their
organization’s data from cybersecurity threats. Small business leaders need the value
provided by a holistic cybersecurity strategy to allow them to mitigate cyber threats,
address and understand the business risk posture, and gain understanding about IT
vulnerabilities.
Implications for Social Change
This study may contribute to social change by including information that can be
used to formulate cybersecurity strategies, allowing small and medium business owners
the ability to align business and IT strategies. It may inform, improve, or mature an
organization’s overall security posture while understanding the risks, threats, and options
for small businesses. This could also lead to additional job creation within small
businesses that cater to and provide services to other small businesses in the form of
cybersecurity consulting. Implications for positive social change include additional
economic opportunities such as protecting customers and organizational data from
network attacks and protecting customers’ personal identifiable information (PII).
A Review of the Professional and Academic Literature The purpose of
this qualitative pragmatic study was to explore strategies cybersecurity professionals use
to mitigate cybersecurity threats in small businesses. Continuous media reports of cyber-
attacks focused on businesses and a critical analysis of scholarly literature provided the
motivation for my research on strategies cyber security professionals use to mitigate
cybersecurity threats in small businesses. This study included analyzing the risk
mitigation strategies, threat mitigation strategies, and prevention strategies that are
available to cyber security professionals and to determine their effectiveness in small
businesses. Due to the impact and breadth of cybersecurity strategies, I searched for
different aspects of cybersecurity to analyze the impact on businesses and how the
threats, risks, and mitigations for each threat technique apply to system thinking and GST
to understand how each part fits into a holistic cyber strategy for small businesses.
The literature review was based on the GST, which was the conceptual framework
to explore the strategies cybersecurity professionals use to mitigate cybersecurity threats
in small businesses. This study focused on several essential concepts when reviewing the
academic literature for this study: the strategies used by businesses and cyber
professionals to mitigate and prevent cybersecurity threats, the applicability of GST as a
conceptual framework to identify how different cybersecurity methods are beneficial to a
holistic small business cybersecurity strategy, and the use of pragmatic qualitative inquiry
research design to study these phenomena.
Literature Review Strategy
A comprehensive search of the following databases was performed for this
literature review: (a) Emerald, (b) Academic Search Complete/ Premier, (c) EBSCOhost,
(d) ProQuest Central, (e) Walden University, and (f) Sage Premier. These databases
contained books, conference proceedings, dissertations, magazines, and peer-reviewed
scholarly articles. To ensure that the scope was narrowed and to find resources relevant to
this study, the following phrases or keywords were used in the search criteria:
cybersecurity breaches, start with security awareness, information security awareness,
General System Theory, and industrial control systems. This literature review consisted
of 126 references, of which 109 sources (86.50%) were peer reviewed and published
between 2018 and 2023. Three sources (2.38%) were peer-reviewed but not published
between 2018 and 2023, and 12 sources (9.52%) were published between 2018 and 2023
but not peer-reviewed. The literature review includes zero dissertations, 111 scholarly
magazines, two industry websites, three government websites, and 10 journal articles.
The General System Theory
GST is a framework that can be used to understand the entire organization or
business and how the different parts work together in a single complex system to achieve
business objectives (Simola, 2018). The GST was used in this study as the conceptual
framework to depict how organizations can achieve their business goals and objectives
using the presented strategies. GST can be used to develop a holistic cyber security
strategy by using system thinking and taking a holistic approach to protecting not just
critical portions of systems but the overarching whole system of systems.
The GST was first proposed in 1946 as a framework researchers can use to
identify relationships between objects that work together to achieve a common goal. Von
Bertalanffy developed GST in the mid-20th century as a response to reductionism and the
need for a unified approach to studying complex systems (Von Bertalanffy & Sutherland,
1974). Von Bertalanffy’s GST proposed that independent parts of a complex structure
contribute to an entire system. Prior to Von Bertalanffy’s GST, science focused on
explaining observable phenomena through decomposing interaction between elementary
units capable of being investigated separately (Von Bertalanffy, 1968). GST proposes a
holistic approach to understanding systems across different disciplines by emphasizing
systems' interrelationships, interactions, and structures rather than the isolated individual
parts (Von Bertalanffy, 1968). GST has influenced the development of other theories
such as systems theory, contingency theory, mathematical general system theory,
behavioral system theory, complex adaptive systems theory, complex system theory,
critical system theory, ecological system theory, sociotechnical system theory, systems
thinking, gestalt psychology, systems biology, cybernetics, organizational system theory
and control theory (Drack & Schwarz, 2010; Hammond, 1970; Laszlo & Krippner, 1998;
Rapuano & Valickas, 2021; Rousseau, 2019; van Assche et al., 2019).
GST is a comprehensive framework used to understand the wholeness of
organizations when all parts of the system work together to achieve a common goal
(Simola, 2018). When a part of a system fails, it prevents the entire system from
functioning as desired (Mar, 2019). One of the fundamental principles of GST is that a
system is more than just the sum of its parts. Instead, the relationships and interactions
between these parts give rise to emergent properties and behaviors. By studying these
relationships, systems thinkers aim to better understand how different elements within a
system influence one another and contribute to its overall functioning.
Von Bertalanffy and Sutherland (1974) composed GST of three main concepts:
(a) the complete system is more extensive than the sum of its parts, (b) the nature of the
components of a system is defined by the whole of the system, and (c) behaviors and
theories used in describing a system apply to other systems. The concepts of GST predict
the completeness of principles that govern systems, whether open or closed, regardless of
the scientific discipline, whether biological, social, physical, or chemical. GST assumes
that all systems are elements or components of a larger whole and that those elements
have similarities in structures and functions independent of their respective scientific
domain (Von Bertalanffy, 1968; Von Bertalanffy & Sutherland, 1974). An open system
exchanges information, energy, or material with other environments, such as biological
and social systems (Kast & Rosenzweig, 1972). Open systems are not bound and do not
have a separation from external or environmental forces. However, closed systems are
bound and have a boundary that protects the system (Turner & Baker, 2019).
Researchers utilize GST as a theoretical device to understand the totality of an
organizational system by gathering data on each individual-related function or subsystem
comprised of several different elements to understand the wholeness of a system that
provides evolutions of adaptation, self-organization, and dynamics in systems, science of
network, and complexity science (Turner & Baker., 2019). Through GST, researchers can
understand how different independent elements of an organization must function to
accomplish an objective. GST was used in the current study because small businesses
have integrated communication, operational systems, and transactional systems across
computers, the internet, and cloud services. There is the possibility that these integrated
systems be compromised when malicious or cyber criminals attack these computers,
cloud services or communications. Understanding how the interactions between business
systems, business processes, procedures during operations is necessary to protect these
crucial functions (Tarafdar & Bose, 2019). GST applies to this study because businesses
are “open systems” that use cybersecurity to protect the interoperability of multiple
complex systems, people, and processes. A high-level cybersecurity defense system aims
to maximize security, minimize risk, and is preventive rather than reactive (Samonek,
2020). GST and its principles provided a comprehensive, inclusive, and open framework
to study the complexities and the dynamic nature of the phenomena.
Application of General System Theory
GST has been used to study different aspects of cybersecurity to deal with the
complex and dynamic cyber-ecosystem that is an organization’s information technology
systems. For example, Tarafdar and Bose (2019) utilized a safety-hazard analysis model
and systems theory to critically analyze the cyber features of the Aadhaar system, noting
that cybersecurity is a holistic system with properties of a system and not just the sum of
its components; due to this structure small changes in the system or component parts can
have catastrophic consequences for the overall cybersecurity of the system. Similarly,
Gołȩbiewski et al. (2022) suggested that systems work well with well-defined inputs and
outputs and that this can be applied to economic aspects of power systems, allowing the
analysis of not only statistics but also the crucial properties of a system. They found that
accounting for the controllability of a system and its interactions enables optimization of
the system and allows for a reduction of risk.
Researchers have applied GST studies in different technology and business
disciplines to study complex systems. Baioa and Carreira (2023) proposed the bridge
between mathematical modeling and scientific inquiry, highlighting one of Von
Bertalanffy’s core principles that all systems are elements or components of a larger
whole and that those elements have similarities in structures and functions independent of
their respective scientific domain (Von Bertalanffy, 1968). Amadi-Echendu (2023) used
GST and found that the property supply chain process crosses organizational boundaries
and system thinking is necessary for a holistic view of this process is needed when
managing property transactions and the end-to-end process. Further, Majukwa et al.,
(2020) used GST as the conceptual framework to explore sustainability strategies for
small medium enterprises [SMEs] in Zimbabwe, finding that dedication and passion,
quality product and services, customer satisfaction, and employing staff with the right
skills are all key parts of a sustainability strategy needed for an SME [small and midsize
enterprises] to be successful in Zimbabwe. This research highlighted the elements that
can directly affect a company’s culture, relationship, and success in this region, stating
that no one single element is the strategy but that all must be included to some degree to
keep the SME [small and midsize enterprises] functioning.
Supporting Theories
Multiple theories were evaluated to research strategies that security professionals
use to mitigate cybersecurity threats in small business. First, however, the researcher
must determine if this theory helps in providing an answer to the research question.
Therefore, the GST was chosen as a conceptual framework for this study due to its
nature, which helps to understand the phenomenon. There are other supporting theories
that were dismissed that are used to study complex systems.
Complex Systems Theory
Complex systems theory (CST) is a multidisciplinary framework that aims to
study and understand the behavior and properties of complex systems (Rapuano &
Valickas, 2021). These systems are characterized by their large number of interacting
components, nonlinearity, emergence, and the ability to adapt and self-organize. While
Complex systems theory shares some principles with GST, it introduces specific concepts
to address the dynamics of highly complex and nonlinear systems. Complex systems
theory emerged in response to the limitations of reductionist approaches in understanding
and explaining complex phenomena. It draws from various fields, including physics,
mathematics, biology, computer science, and social sciences. Pioneers of Complex
systems theory include researchers like Murray Gell-Mann, Ilya Prigogine, and Stuart
Kauffman, who contributed to the development of the theory by studying complex and
nonlinear systems (Jain & Wadia, 2019; Ramage & Shipp, 2020). Complexity theory has
been applied to reveal and analyze career management challenges (Rapuano & Valickas,
2021, p. 48).
Principles of Complex Systems Theory (CST). Complex systems theory
emphasizes that the behaviors and properties of complex systems emerge from the
interactions and relationships among their components (Rosenhead et al., 2019).
Emergent properties cannot be easily predicted by analyzing individual parts in isolation.
Complex systems often exhibit nonlinear behaviors, where small changes in initial
conditions can lead to disproportionate and unpredictable outcomes (Rosenhead et al.,
2019). Complex systems have the capacity to adapt and self-organize in response to
changes in their environment (Eppel & Rhodes, 2018). Many complex systems exhibit
hierarchical and misaligned structures, where components are organized into levels, with
interactions occurring both within and between levels. Feedback mechanisms play a
crucial role in complex systems, affecting stability, amplification, and regulation of
behaviors (Eppel & Rhodes, 2018; Ruijer et al., 2023). Complex systems adapt to
positive and negative feedback loops contribute to system dynamics (Ruijer et al., 2023).
Complex systems theory often focuses on the network structure of interactions between
components, emphasizing the importance of interconnectivity in shaping system behavior
(Morçöl & Wachhaus, 2009). Complex systems can undergo phase transitions, where
sudden and qualitative changes occur in system behaviors often represented by agents
that learn and react in response to other agents (Rosenhead et al., 2019).
Influence of General System Theory. Complex Systems Theory builds upon the
principles of General System Theory (GST) while introducing specific concepts to
address the complexities of highly nonlinear and adaptive systems (Turner & Baker,
2019). Both GST and Complex systems theory emphasize a holistic approach to
understanding systems, considering the interactions and interdependencies among
components applying principles from various scientific disciplines to study nonlinear
behaviors in phenomena.
Complex Systems Theory is influenced by General System Theory, but it extends
and refines its concepts to address the intricacies of highly complex, nonlinear, and
adaptive systems. Complexity theory also argues against strategic planning’s
effectiveness in complex systems, networks, and organizations (Bovaird, 2008; George et
al., 2019; Ortman et al., 2020). This study is not a longitudinal study; therefore, I did not
research or utilize the feedback loop elements or the adaptability of cybersecurity
strategies. These elements allow the researcher to study these complex interactions,
feedback loops, hierarchical structures, and the interactions between components. This
was not part of this research project and therefore I did not select Complex Systems for
this research.
Complex Adaptive Systems Theory
Cybersecurity strategies have many different elements, such as specific strategies,
security tools, processes, and teams of people, that need to work together to protect
businesses and data from cybercriminals, leading to a very complex open system that
could mature over time. John Holland proposed Complex Adaptive System Theory by
combining systematology and reductionism (Holland, 2014). Complex Adaptive Systems
Theory is one of the theories applied to complex system science; it links the macro and
micro elements of a system to study the mechanisms and system that emerge in complex
cases (Suo et al., 2023).
Complex Adaptive Systems Theory is an approach to modeling complex real life
adaptive systems encompassing structural, temporal, and developing environments
(Burke & Morley, 2023). Complex adaptive systems are open systems, as defined by
GST, with permeable boundaries through which energy, information, and matter are
exchanged between the system and its environment” (Burke & Morley, p. 38, 2023).
These complex adaptive systems can share boundaries, be interconnected, or be nested
together (Burke & Morley, 2023). Researching cybersecurity strategies, this framework
would allow the researcher to show how agents interact as well as systems and
subsystems of the holistic cyber strategy.
Complex adaptive systems are also defined by the interactions and relations
among elements and between the system as well as the wider environment (Riaz et al.,
2023). Burke and Morley (2023) suggest that the actors or agents are not a focal point in
Complex adaptive systems when trying to study a complex phenomenon but to view
actors, elements, objects, and entities are continuously produced and reproduced in the
actions, interactions, and practices of the system (Burke & Morley, 2023). This suggests
the complex adaptive system is not only adaptive but dynamic and characterized by
nonlinear interactions. Levin (2002) defines complex adaptive systems (CAS) by three
properties “diversity and individuality of components; localized interactions among those
components, and; an autonomous process that uses the outcomes of those interactions to
select a subset of those components for replication or enhancement” (Levin, p. 4, 2002).
Researchers have used Complex adaptive systems to study energy systems
(Pearson & Bardsley, 2022; Suo et al., 2023), information system development and
engineering (Kautz et al., 2020), and organization planning of hospitals, environments,
and enterprises (Burke & Morley, 2023; Harvey & Jones, 2022; Wang & Liu, 2021). I
chose not to use Complex adaptive systems due to the limited focus on actors, the
adaptive and replication wilderness other researchers specify. Cybersecurity strategies
need to adapt but do not replicate through autonomous processes.
Proponents of GST
Proponents of GST claim that the theory lacks substantive concepts to support
systems practices and create conceptual frameworks and methodologies effectively.
Checkland (1994), states that GST is too broad and abstract to provide a sound
foundation for developing a conceptual framework (Checkland, 1994). Zexian and Xuhui
(2010), state that general system thinking is greatly dependent on an abstract
mathematical model far from the practice of the natural world and cannot get adequate
support from substantive materials, nor does GST develop methodologies to solve all
kinds of specific problems in cross-disciplinary applications and GST is not capable of
coordinating mutually exclusive status between holism and reductionism.
Contrasting Theories
Although the General System Theory was appropriate for this study, there were
other contrasting theories that were reviewed but were found not to be suitable for this
study. Those theories are Routine Activity Theory, Protective Motivation Theory, and
Game Theory.
Routine Activities Theory
Cybercriminals use various tools, technologies, and capabilities to commit crimes;
this growing threat to public safety and security has put added pressure on law
enforcement and cybersecurity professionals. I considered Routine Activity Theory as a
potential framework for this study due to the number of cases affecting small businesses
involving cyber criminals but ultimately dismissed this theory.
Routine Activities Theory has been used to study cyber security and other
criminal activities. Routine Activities Theory (RAT) theorizes that crime occurs when
there is the convergence of 3 elements: a motivated offender, a suitable victim or target
victim, and the absence of a capable guardian (Guerra & Ingram, 2020). A motivated
offender is the criminal element, i.e., the hacker with the capacity and capability to act on
the criminal inclination. A suitable victim or target is a person, place, business, or object
with a need for a capable guardian.
Due to the lack of capable guardians within cyberspace, there is an increased
opportunity for motivated criminal elements to converge on suitable victim or victims
with the proliferation of and increased use of malware, phishing, and ransomware. Choi,
Kruis, and Choo (2021), suggests that the virtual nature of cyberspace allows for
victimization in an asynchronous manner where the criminal element and the victim do
not have to cross paths at a specific time. An example is the victim’s use of social media,
online websites, or programs to access free media files such as movies or music. The
criminal need to only infect the media and upload it to the location and wait for a victim
that lacks the necessary computer security programs (capable guardian) to prevent the
malware infection of the victim's system allowing for an asynchronous convergence of
the victim and the criminal element (Choi, Cho, & Lee, 2019; Choi, Kruis, & Choo,
2021).
Choi, Cho, and Lee (2019) showed that exposure to cyberspace changes the
requirements of proximity to the victim and the motivated criminal element. They
propose that the idea of virtual proximity presents situations where victims will encounter
motivated offenders through virtual proximity through phishing emails, calls, or text
messages (Choi, Cho, & Lee, 2019). Further research has been done by Kemp et al.,
(2020), Showing the growth, extent, and widespread fraud being orchestrated by criminal
elements affecting Europe and suggesting the need to reevaluate policing and crime
prevention in the context of cybercrimes (Kemp et al., 2020).
Researchers use Routine Activities Theory to demonstrate and account for the
victimization of the target by the criminal element (Holt et al., 2020). Routine Activities
Theory is not used to research the internal complexities of a small business and how the
cyber professionals, “Capable Guardians,” use strategies to mitigate cyber security threats
to small businesses. Routine Activities Theory is also used to analyze a company’s online
activities in relation to a company being targeted or having a cyber security breach (Buil-
Gil et al., 2021). Therefore, Routine Activities Theory is not appropriate for this study.
The Protective Motivation Theory
Protection Motivation Theory and General System Theory are used to study cyber
security. Both theories offer ideas, exploration, and experiments around organizational
structures or societies. Recent studies have used Protection Motivation Theory or GST to
apply and develop risk mitigation policies, governance, and disaster recovery
(Buchtmann et al., 2023; Wong et al., 2022).
Protection Motivation Theory suggests that people process the event in two ways
when exposed to a threatening event: one focuses on the threat itself, and the second is to
act against the threat (Threat appraisal and coping appraisal) Rogers (1975). Protective
Motivation Theory focuses on threat appraisal. This may lead to negative behaviors such
as denial or avoidance and the coping appraisal people analyze, such as the likelihood of
that threat occurring and whether people will assess and take a recommended course of
action to remove the threat (Burns et al., 2017). I considered but discarded Protective
Motivation Theory to research the motivations and techniques cyber professionals use to
protect small businesses. I focused on the idea that holistic cybersecurity strategies should
include human interactions, information sharing, risk analysis, and resiliency or coping
mechanisms in the event of a cyber incident.
Other studies indicate that when it comes to human behavior in cybersecurity
protection of business data, systems, and the organization relies on actions rather than
intentions (Shillair et al., 2015; Sulaiman et al., 2022; van Bavel et al., 2019). Awareness
of threats, vulnerabilities, and risks may result in a better overall cyber security posture
for an organization or small business. Van Bavel et al. (2019) suggest that Protection
Motivation Theory can be used to assess an organization's risk posture. Based on this
study, the participants exposed to a coping message behaved more securely (van Bavel et
al., 2019). Understanding employee behavior and the importance of security awareness
and preventive measures to address risk is part of a holistic cyber strategy.
When researching cybersecurity, Protection Motivation Theory focuses on the
behaviors, motivations, and human elements. A study by Wong et al. (2022), shows the
positive impact on behavior, motivation to engage in protective measures, and compliant
attitudes in enhancing the security of supply chain activities (Wong et al., 2022). van
Bavel et al. (2019), shows that participants in their study took protective interventions
when told what effective action to take to mitigate cyber risks, while threat elements or
punitive measures did not predict secure behavior (van Bavel et al., 2019). Protection
Motivation Theory has been used to show how humans cope with cyber incidents and
react to cyber risk, as well as cyber security policies with punitive clauses. I ultimately
found Protection Motivation Theory unsuitable for this study because it is used to study
cybersecurity professionals and employees' behavior, attitudes, and motivations.
Game Theory
In researching cyber security strategies and mitigation techniques, I found
research utilizing Game Theory to understand cybersecurity's attack and defense nature. I
considered Game theory due to cyber security's attack and defense nature. However,
when researching strategies cyber professionals use to mitigate threats in small
businesses, I dismissed this theory when studying the defense nature of cyber security
strategies in the context of a whole system or system of systems.
Game Theory analyzes cooperation and competing branches of interdependent
decision theory (Gomes et al., 2023). The five elements in a Game Theory model are 1) a
group of players, 2) strategies, 3) personal gain, 4) an outcome of every action, and 5)
optimal solutions (Salagnac & Wakeley, 2021). The strategy for each player or opponent
is to maximize their individual payoff with the decisions that they choose (Šůcha et al.,
2021). Game Theory involves decision-making where opponents must consider the
thinking of the other players before making an action or reaction to collect the most
significant payoff before reaching a point of equilibrium (Einy et al., 2022).
Game Theory has been recently used to gain more understanding of different
strategic phenomena in cybersecurity due to the attack defense nature of the phenomena.
The organization implements strategies to defend data, resources, implement barriers and
mitigate cyber-attacks while the attacker attempts to bypass security controls, barriers and
gain access to the protected data. Zhang et al. (2022) suggest that Game Theory can
provide scholars research models and methodological guidance for analyzing
cybersecurity problems and attack-defense behavior (Zhang et al., 2022). Game Theory
can be used to evaluate and comprehend decisions and outcomes based on payouts and
consequences.
In cybersecurity, this would be the hacker vs. the target (business, person, or
entity). The attacker then must make decisions. In Game Theory, the focus is on the
players utilizing strategy in order to achieve outcomes that serve their interest and
provide personal gains as opposed to those of others (Kamenjarka et al., 2020). I did not
select this theory because the phenomena of strategies used by cyber security
professionals to mitigate cyber security threats in small businesses are more than how
cyber professionals and hackers attempt to protect and bypass the security controls used
to protect a business.
Small Businesses
According to the Small Business Administration (SBA), there are over 32 million
small businesses in the United States that create over 60% of new jobs annually (SBA,
2023). Small businesses are often independent businesses with fewer than 100
employees. According to the World Bank, 90% of business and 50% of employment
worldwide is represented by small businesses (World Bank, 2023). Despite the
importance of small businesses, research in cyber security is significant and while limited
cyber strategy research is primarily focused on larger corporations and government
organizations.
Research specifically on small business cyber security strategies is very limited
(Falch et al., 2023). Research suggests that small businesses are also not self-reporting
cybersecurity breaches because they are not aware of the attack being cyber in nature and
or the requirements of reporting a cybersecurity incident or data breach (Chidukwani et
al., 2022; Kemp et al., 2023; Sangari et al., 2022; Tam et al., 2021). Failing to report
cyber incidents hinders the ability of researchers and organizations to understand the
depth and breadth of cyber-attacks on small businesses.
Small businesses have limited resources, lacking the knowledge, time, and
investment to protect themselves compared to larger organizations (Gafni & Pavel, 2019).
Most small businesses utilize internal financing (personal, family, friends) as the primary
source of funding to start and operate their business, and over 80% of small businesses
are non-employee businesses or businesses that have no employees conducting business
as an individual (SBA, 2021). Owners and managers lack of knowledge and awareness of
cybersecurity issues, threats, regulation and the ability to cope with cyber threats (Gafni
& Pavel, 2019; Tam et al., 2021). Gafni and Pavel (2019) found that small businesses
have a variety of possible vulnerabilities, such as:
The [small and midsize businesses] SMB’s owners, managers, and decision-
makers are not aware of cybersecurity threats; The SMB’s owners, managers, and
decision-makers might not have enough budget to cope with cybersecurity threats.
Generally, SMBs have less technological, financial, and human resources to
respond to cyber-attacks, less sophisticated security infrastructure, less organized
processes to manage threats, and thus, they are found by hackers as more
vulnerable (Gafni & Pavel, p. 16, 2019).
Cyber Strategies
Businesses today are more connected than ever before, creating a larger attack
surface for cybercriminals to operate. As a businesses’ information technology and
interconnectivity improve operational efficacies, so does the number of vulnerabilities,
attack surface, threat landscape, and operational risk (Borca, 2022; Li & Walton, 2023;
Papakonstantinou, 2022; Tsiodra et al., 2023). Recent security breaches show that cyber
risk exposures have reputational, legal, financial, and operational costs. The FBI’s
Internet Crime Complaint Center (IC3) received over 800,000 complaints with a potential
loss of over more than 10.2 billion USD in 2022 (IC3, 2022).
Since 1990 and the early days of E-commerce, researchers have warned of the
risks and need for a cybersecurity strategy to protect businesses from fraud, theft, risks
associated with outsourcing, DDoS, phishing, viruses, ransomware, malware, and hackers
(Aldauiji et al., 2022; Densham, 2015; Haapaniemi, 1996; Hu et al., 2021; Jacobs, 1999;
Wang & Liu, 2021). Cybersecurity is essential to protect systems, data, and people from
cyber-attacks (Samonek, 2020).
According to Li and Walton (2023), cybersecurity strategies are essential to a
business’s operational strategy. A holistic cybersecurity strategy is more than the
adoption of information security tools. The terms “Cyber Strategies” and “Cyber Security
Strategies” are widely used to describe the concept of risks, prevention, detection, and
response to cyber threats and attacks (Carías et al., 2019; Samonek, 2020).
Strategic leadership and strategies are broad and can be studied in multiple ways
that are often competing, inconsistent, and often lacking explanations (Boyd et al., 2011;
Bromiley & Rau, 2016; Liu, Fisher, & Chen, 2018). Strategic leaders direct the
organization or business, providing a vision, maintaining flexibility, and creating a future
for the organization. Hernandez, et al. (2011), states that individuals at the top of an
organization have the responsibility to make strategic decisions and create an overall
purpose and direction for the organization, which ultimately guides strategy formulation
and implementation. Businesses’ strategies could reflect significant efforts from
leadership to guide and change the direction and vision of an organization (Samimi et al.,
2022).
Cyber Security Threats
Cyber threats do not discriminate by business size since businesses rely on
networks, computers, software, and their data to function. Without sufficient security,
these business assets become vulnerable to cyber threats (Mkuzangwe & Khan, 2020).
Malware (malicious software) is one of the biggest threats to computers, phones, tablets,
networks, and other devices. Motivated criminal elements use malware to steal sensitive
information, hold data assets for ransom (Ransomware), and illicitly use your IT
resources for mining cryptocurrencies, financial fraud, intellectual property theft, identity
theft, and more.
Cyber-physical systems are a new generation of Internet of Things (IoT) and
Industrial Internet of Things (IIoT) devices that produce a new target for cybercriminals.
These devices are built with a field, communications, and computation layer (Karbasi &
Farhadi, 2021). The field layer has distributed sensors, actuators and other networked
devices. The communication layer consists of low-cost machine-to-machine IoT wireless
communication modules and the computation module is the computer or server that is
connected (Karbasi & Farhadi, 2021). Research by Liu, Zhang, et al., 2021 shows how an
attacker might access a cyber physical network and attack these industrial,
manufacturing, environmental controls such as heating, ventilation, and air conditioning
(HVAC) or other cyber physical systems highlighting the need for more protections
around the computation or critical nodes. Their research suggests that these systems are
more vulnerable and easier to exploit and should have a higher layer of protection (Liu,
Zhang, et al., 2021).
Distributed Denial of Service (DDoS) and Denial of Service (DoS) attacks
prevent authorized users from accessing a service or system. The attacker starts
immersing the target computers with various messages and blocking the legal flow of
data (Li & Liu, 2021). In a DDoS or Widespread Denial of Service attack the attacker
launches the same type of attack from different distributed sources at the same time.
According to Li and Liu (2021), this is often done using worms or bot nets. This type of
attack prevents any user, system, or service from using the internet or communicating
with other systems (Topping et al., 2021).
Malware is one of the most dangerous and major security threats facing the
internet (Al-Sofyani et al., 2023; Maniriho et al., 2022). Trojan horses, viruses, worms
and ransomware are types of malware that can infect individual systems or whole
organizations. Viruses utilize a host file that needs to be run to start the infection and the
impacts can be stealing data, loading and installing unwanted applications, sending
documents via e-mail, or even crippling a computer’s operating system (Akinde et al.,
2021; Nursidiq & lim, 2023). Computer worms spread across the internet by replicating
themselves on computers via the networks or internet without the use of a host file
(Maniriho et al., 2022).
Trojan Horses and root kits are dangerous pieces of software that appear to be
benign or helpful (Maniriho et al., 2022). Trojans and root kits are used to cause the loss
of or steal data and create bot nets used for DDoS attacks (Li & Liu, 2021). Root kits
conceal another user and allow for the enabling and continued access to a computer as a
privileged user, granting admin rights to the system (Al-Sofyani et al., 2023; Maniriho et
al., 2022). Cyber criminals utilize root kits and exploit kits to gain access to a system
through and exploitable vulnerability in a piece of software prior to the application being
patched (Hart et al., 2020).
The biggest cyber security threat to small businesses is ransomware extortion,
which is when malicious software is introduced to the business information systems,
encrypts data and holds it hostage under threat of deletion until the business owner
pays(Kshetri & Voas, 2022; Farion-Melnyk et al., 2021; Comeau et al., 2021; Connolly
& Wall, 2019; Gonzalez & Hayajneh, 2017). The average ransomware payment was
170,000 USD in 2020, and the average downtime due to ransomware is 21 days, with an
average cost of 3.2 million in employee productivity loss (Kshetri & Voas, 2022).
Ransomware is often spread through phishing emails and social media downloads
where a recipient clicks a link and downloads the malicious code (Kshetri & Voas, 2022).
Small businesses are more vulnerable to these types of attacks due to the lack of security
awareness and protections in place to prevent this type of attack (Farion-Melnyk et al.,
2021). Ransomware has some of the most severe business implications, including
business closure. According to research by Cyberreason (2022), ransomware has caused
more than 25% of survey participants reported that a ransomware attack forced their
business to close (Cyberreason, p.14, 2022).
According to research done by Humayun, et al., (2021), there are several ways to
protect individuals and businesses from ransomware attacks. This research recommended
having an offline backup since attackers often target online or connected backup systems,
training employees regarding trusted websites, restricting user access rights to protect the
security of data, and limiting user privileges (Humayun et al., 2021). Prevention is the
first method to protect businesses from cybersecurity threats. Farion-Melnyk, et al.
(2021), state that (cyber) security programs and investment in (Cyber) security
knowledge can prevent serious damages and financial losses and that it is easier to
prevent (cyber-attacks) than to return the computer systems to a working condition
(Farion-Melnyk et al., 2021). Some small businesses lack security policies, tending to
reuse passwords, mix business operations Wi-Fi with guest Wi-Fi, and fail to implement
security best practices (Bekkers et al., 2023). This leaves them vulnerable to security
threats and could lead to financial liabilities and catastrophic damages.
Holistic Cyber Strategy
Cybersecurity is a consistent challenge for any business or organization due to the
increasing activities and sophistication of hackers, malware, and the regulations around
data loss, privacy, and customer protection (Falch et al., 2023; Dekel et al., 2023; Kemp
et al., 2023; Gafni & Pavel, 2019). During this literature review, I found no studies that
suggested cyber threats and attacks will decrease.
Cybersecurity strategies are the vision, guidelines, and plans for the future of
cybersecurity programs in an organization. Every business has some form of business
plan and strategy to stay in business and grow (Samimi et al., 2022). Cybersecurity and
IT strategies support these business strategies by aligning tools and systems to product
streams and internal processes and monitoring key performance indicators used for the
success of a business.
A holistic cybersecurity strategy aligns with these other strategic documents and
outlines how to control changes in the information technology baseline, manage cyber
risks, incident management, vulnerability management, IT governance, and train
employees in security procedures and awareness (Limna et al., 2023; Oruj, 2023; Medoh
& Telukdarie, 2022). Analysis of the literature shows that small businesses do not think
cyber security is essential, small business owners do not understand how to protect their
business, and common cyber security hygiene is missing (Gafni & Pavel, 2019; Tam et
al., 2021). Common core components of cybersecurity management are missing from
many small businesses, and business owners do not have a cybersecurity strategy.
A holistic cybersecurity strategy for businesses includes proactive preventative
and corrective measures covering IT baseline management, risk, and vulnerability
management, incident management, IT governance, and security training. These elements
are essential to protect systems, data, and people from cyber-attacks (Daricili & Celik,
2022; Ajmal et al., 2021; Falch et al., 2023; Medoh & Telukdarie, 2022).
Cybersecurity helps protect business systems against cyber-attacks and detects
abnormal activities in systems and services. Cybersecurity strategies must include an
information security component if information security is not part of the larger IT
strategy. Information security is needed to protect customer data, projects, and
intellectual property (Mutalib et al., 2021). Security policies, plans, practices, and
procedures are necessary to utilize security technology to protect businesses and
customers. The organization’s cybersecurity capabilities and response should be verified
by independent experts (external auditors). According to the literature, intrusion
detection, prevention, and vulnerability management are some of the common core
systems that are missing from many small businesses (Abbas et al., 2023; Bokan &
Santos, 2022; Pérez et al., 2023)
Strategies for Cybersecurity Risks
Cybersecurity risks refer to an organization, business, or individual’s vulnerability
to losses due to a cyber-attacks or data breaches. ISC2, an industry leader in
cybersecurity education and certification, defines risk as “the possibility of damage or
harm and the likelihood that damage or harm will be realized” (ISC2, p. 15, 2023).
Effective cybersecurity management includes cybersecurity risk management.
Cybersecurity professionals manage risks associated with information systems, data, and
access based on the preventive methods applied to maintain confidentiality, integrity, and
availability, known as the CIA triad (Todorov & Lutfiu, 2022).
Information system security (ISS) is a layered approach based on the CIA triad
used to protect information systems. These security layers are people – managers, system
and network administrators, system operators, and end users; procedures – procedures
and governance are the organizations’ security policies that govern a business or
organization; and products – these are the physical and digital components of system or
security system (Bucşă & Fotache, 2021).
Strategies around risk management assess the level of acceptable risk a business is
willing to assume and the negative impact, reputational, and financial consequences to
the business in the event of a failure, breach, or malware event. Several different
frameworks can be employed to assess and manage risks, such as International
Organization for Standards documentation (ISO) 3100, ISO 31000:2018, ISO
27005:2022; National Institute of Standards and Technology (NIST), NIST 80-171, NIST
800-37, NIST 800-53, and Control Objectives for Information and Related Technologies
COBIT 5. These frameworks have similar strategies that start with understanding
business, data, and system assets and prioritizing the importance of each asset.
There is limited scholarly research available that focuses on small business
strategies to manage IT and security risks. Small businesses are just as dependent on
technology to operate their businesses and more exposed to cyber risks with smaller
budgets and fewer resources (Falch et al., 2023; Kemp et al., 2023; Bada & Nurse, 2019).
Cyber risk management and cyber risk strategies are important to maintain a growing and
competitive business (Benz & Chatterjee, 2020; Lloyd, 2020)
Literature on effective risk mitigation of cyber risks shows that business need a
risk management process in general, business continuity plans that detail the functions or
systems that are critical to the business to operate with clearly defined roles, actions, or
task and responsibilities and incident response capabilities to respond to hacks and
attacks in a timely manner (Hoppe et al., 2021; Lloyd, 2020; Benz & Chatterjee, 2020).
To combat today’s cyber threats, businesses require disciplined, coordinated, and
consistent risk management. Testing and evaluation of new software tools and technology
prior to being introduced (Tam et al., 2021). Research by Shreeve, et al., (2023) on cyber
security decision making found that risk perception is a key part of cyber security
decision making and managers need to preform asset audits in order to identify additional
vulnerabilities and do proper threat assessments (Shreeve, et al., 2023).
As businesses grow and mature, the vulnerabilities multiply by introducing new
technologies, methodologies, and services. A robust cyber risk strategy must include
auditing for risk assessments, enforcement of security controls, and continuous
monitoring.
Strategies for Intrusion Prevention & Incident Response
Data breaches have grown exponentially, exceeding the previous 14 years
combined in 2020, with over 30 billion records exposed (Glenny, 2021). This has created
severe consequences for organizations, such as reputation, revenue loss, and adverse
reactions from customers and investors (D’Arcy et al., 2020; Gwebu et al., 2018;
Hamilton, 2019). Research by Fang, et al. (2023), suggests that customer and public
negative rhetoric and adverse effects are mitigated with information transparency when
an event occurs, previous investment in information security and cyber security
protections, and the information is legally obtained and used while doing business (Fang
et al., 2023).
Research by Nikkhah and Grover (2022) found that customers and investors were
influenced by response times, and corrective action with an apology mitigated negative
impacts on the company (Nikkhah & Grover, 2022). To have a quick response time to
data breach events, a business needs to have a functional incident response strategy that
includes processes, policies, and tools.
Strategies for IT Governance and Security Awareness
IT governance is a process of increasing technical value to the business or
organization through managing and controlling IT capability decisions, IT processes, and
IT policies, ensuring compliance with any regulation body, and providing processes that
control the technology baseline (Chau et al., 2020). The literature suggests that critical
elements of IT governance cover risk management, information security, system quality,
IT resource management, IT use policies, and business-to-IT alignment (Ilmudeen, 2022;
Mikalef et al., 2021). This relationship between IT and the business takes a formal
structure with governance policies allowing IT to support business decisions. IT
governance must contain the policies required by IT security to prevent cyber incidents.
New emergent risks occur when additional industry regulations or laws are enacted that
affect your industry or business type. This has a significant impact the business,
development of policies and assessments of third-party vendors, and documentation of
risk management processes, policies internal controls and security testing procedures.
Governance policies set the expectations of the business stakeholders, system
users, IT managers, and IT professionals (Rawindaran et al., 2023; Upadhyay & Panwar,
2022). The IT use policy generally covers users' acceptable behaviors on business
equipment and networks. This includes using strong, complex passwords, not tampering
with antivirus and security software, not altering the system to bypass security gateways
and internet traffic filters, and the principles of least privilege (Rawindaran et al., 2023).
This allows the organization to set the standards for the management of all IT resources
and security across the business IT baseline. Information security awareness programs
address the people security layer of many approaches to information system security.
Evidence suggests that a developed information security awareness program (ISA) in
conjunction with information system security (ISS) and a risk assessment model reduces
security breaches, especially those caused by employees (Alkhazi et al., 2022).
Information security awareness programs address the people security layer of many
approaches to information system security. Evidence suggests that a developed
information security awareness program (ISA) in conjunction with information system
security (ISS) and a risk assessment model reduces security breaches, especially those
caused by employees (Alkhazi et al., 2022).
Transition and Summary
Section 1 provided the background of the issue, problem statement, purpose
statement and introduced the research topic. The literature review takes a cyber security
strategy perspective emphasizing the economic need for small businesses and the
challenges small businesses face from a resource, knowledge, and capabilities
perspective. I demonstrated through the literature, the need for cybersecurity strategies
and the complex nature of cybersecurity for a small business. I explained the definitions
that are referenced in the literature for this study and the limitations, delimitations and
assumptions that are applicable to this study.
I provided a contextual lens of Ludwig von Bertalanffy’s General System Theory
to view cybersecurity strategies as more than just the sum of the parts but an
interconnected system of systems that needs to function together in order to protect a
business from cyber threats. The detailed specific IT problem facing small business is
that cybersecurity professionals in some small businesses lack strategies to mitigate
cybersecurity threats.
Section 2, identifies the methods and protocols used in executing the study and
includes the researcher’s role, participants, ethical consideration. Section 2 also outlines
data collection, data analysis and additional critical elements regarding data collection,
management and the ethical treatment of participants in this study.
Section 2: The Project
In Section 1, I provided the purpose of the study, background of the IT problem,
and a review of the literature associated with the research question. The detailed specific
IT problem facing small business is that cybersecurity professionals in some small
businesses lack strategies to mitigate cybersecurity threats. This is important because a
business without a cybersecurity strategy is more vulnerable to cybersecurity threats
without appropriate strategies, small businesses are at a higher risk of experiencing data
breaches, financial losses, and reputational damage. I framed the research within the
conceptual framework of GST and the importance of using general system theory when
researching a complex series of systems and the elements they contain.
Section 2 outlines the role of the researcher and the research decisions I made as
the researcher for this document. I provide the rationale used and criteria for participation
in this research study. I include the methodology that my research is based on prior to the
collection of data. The methodology frames the research into a specific structure, as I
applied qualitative research methods and qualitative pragmatic methodology. Data were
collected through semi-structured interviews, allowing the participants to provide their
real-world experiences, perspectives, and the outcomes of different discussions related to
cyber security in a strategic context. I also provide the rationale for ethical research
considerations with human participants, the techniques I used to collect data, the
organization and analysis of the data I collect, and the strategies to ensure the reliability
and validity of the research. Next, Section 3 will provide the findings of the research,
implications for social change, suggestions, and recommendations for further research. I
will include a summary of the effective strategies small businesses could use based on
what cybersecurity professionals use to mitigate cybersecurity threats in small businesses.
Purpose Statement
The purpose of this qualitative pragmatic study was to explore strategies some
cybersecurity professionals use to mitigate cybersecurity threats in small businesses. In
2020, small businesses were targeted due to the remote workforce and the Covid -19
pandemic (Kumar et al., 2022). Thirteen security professionals sourced from LinkedIn
shared their experiences, perspectives, and knowledge about cybersecurity strategies and
how they have mitigated recent cybersecurity threats. The cyber security professionals
were vetted to ensure their backgrounds are proficient to inform viable cyber security
strategies through a series of qualifying questions. The intent of the research question and
interview process was to identify strategies that can be used by small businesses to
mitigate network security threats.
Role of the Researcher
The role of the researcher in qualitative research is to act as the primary data
collection instrument. It is the researcher’s responsibility to collect data from multiple
lines of inquiry through interviews, evidence, literature reviews and existing records
(Yin, 2018). I performed this qualitative pragmatic research study exploring
cybersecurity strategies that cyber professionals use to mitigate threats to small business
using skills gained from formal education through academia and working in cybersecurity
since 2006. I have experience as a business owner, manager, employee, and contractor for
local businesses, Fortune 500 companies, U.S. Federal government, and international
organizations. As the researcher and data collection instrument, I considered ethical
concerns applicable to my study and data collection method. I did not include participants
from former or current business clients, nor did I utilize employees or staff I manage as
participants. I selected participants based on their experience with implementing
cybersecurity strategies regardless of the outcomes of their efforts. Security professionals
who have dealt with security breaches, malware attacks, or other incidents have insights
that are different than security professionals who have not had to remediate a security
event. The insights of failed strategies provide a valuable dimension to the data collected
and helps identify different trends within the research pool.
I followed the principles of the Belmont Report to ensure I adhered to acceptable
standard research ethics while working with human subjects. Use of the Belmont Report
ensures that the three core principles of beneficence, respect for persons, and justice are
met while the study was being conducted (U.S. Department of Health and Human
Services, 1979; Pearce et al., 2018). The Belmont Report forms the normative basis for
protection of research subjects and the framework for the regulations governing research
with humans (Redman & Caplan, 2021).
Semi-structured interviews allow for open ended questions to be asked giving the
participant and researcher a degree of freedom and adaptability that allows themes and
new ideas to emerge (Roberts et al., 2023). Interview questions are used to confirm or
disprove the information, concepts, and validity of the existing literature and possibly
additional information or influential factors (Roztocki et al., 2023). Respondents’
decision to participate in research is made by reading the invitation letter, which includes
the intent of the research (Pederson et al., 2021). I conducted virtual interviews; in-person
interviews were declined due to the schedules, locations, and preference. To assist in
removing any personal bias, I recorded the interviews and use the transcribing service
built into Microsoft Office 365 software to transcribe the interviews without interjecting
any personal views into the data. I interviewed 14 participants when data saturation was
achieved, and the data presented themes that are used to organize the research.
Participants
The population for this qualitative pragmatic inquiry consisted of participants
selected from LinkedIn who have advertised management experience, at least 2 years’
experience in cybersecurity, and have experience in another IT discipline. Online
recruitment is convenient and wide reaching and has issues related to the perceived value
of the research study (Tamlyn et al., 2023). I utilized purposive sampling, which is done
deliberately to match a key informants to the objective of the study in order to obtain
answers (Moser & Korstjens, 2018). I contacted cybersecurity professionals and IT
managers via LinkedIn messaging with an introduction letter asking them if they are
interested in the study outlining the prerequisite of at least 2 years of cybersecurity
experience and experience in another IT function. IT function is defined as but not
limited to (network/system engineer, systems analyst, system(s)/network/firewall
administrator, support staff, and developer). It is important for the participants to have
this experience in the cybersecurity field and other IT positions for this qualitative study
so that they can share their own experiences with the phenomenon (see Yin, 2018).
Participants who showed interest received a letter via email outlining the goal of
the study, the structure of the semi-structured interviews, and an overview of the data
protection and participant confidentiality agreement. I utilized this opportunity to build
rapport with the participants and to establish trust with each participant to gather an
authentic experience from the participant during the future semi structured interviews
(see Brown & Danaher, 2019). After identifying the eligibility criteria for each
participant and the intent to participate in this study, I sent each participant the
questionnaire, confidentiality, and data protect agreement outlined in the ethical research
section in accordance with Walden University IRB practices.
Research Method and Design
I selected qualitative research method after considering mixed method and
quantitative methodologies. Qualitative pragmatic inquiry research method allows the
researcher to explore participants’ perceptions, experiences, and knowledge of a practical
issue (Goldkuhl, 2012). This approach allowed me to focus on discovering trends and
approaches in an unbiased and unconstrained manner to effectively determine potential
cyber strategies for small businesses.
Research Method
The selection of the research methods is one of the most important processes
during a study; researchers select a method based on the research objectives and the
rational for the study. The purpose of qualitative studies is to understand the why of a
phenomenon. In qualitative research, the researcher is a research instrument used for data
collection and analysis (Denzin et al., 2017). The qualitative method is used to explore
research that is not well defined, with complex problems that require description. This
research is exploring what cybersecurity strategies cyber professional use to mitigate
cyber-attacks is a complex problem that is different based on the risk assessment and
threats an individual business has. Qualitative method was selected to understand the
thoughts, choices, experiences of the participants of this complex phenomenon.
In contrast, quantitative studies provide numbers in terms of percentages,
averages, and statistical information. Quantitative research methods use a controlled
strategy to measure an occurrence (Rutberg & Bouikidis, 2018). The data are used to test
a hypnosis using statistical data. This type of methodology would not get to the root
cause of phenomenological issues regarding strategies cybersecurity professionals use to
mitigate cybersecurity threats in small businesses, so it was not selected for this research.
Due to the complexity of researching strategy and the complexity of decision-making
involved in cybersecurity strategies, I dismissed the option of using quantitative research
methods. It would be too difficult to illustrate the complexities of decision making within
a survey and numerical scale (Abulela & Harwell, 2020).
Mixed method research uses both quantitative and qualitative research to
understand a phenomenon. Mixed methods research is more complex and a lengthy
procedure due to the need to collect both quantitative and qualitative data (Taguchi,
2018). Collecting quantitative data based on what strategies cyber professional use to
mitigate cyber-attacks could be difficult and assimilating the data types in a meaningful
way increases that difficulty (Dagnino et al., 2020). I did not choose mixed methods
because of the difficulty with quantitative research for this subject and the fundamental
challenges of managing the two different data types and the length of time it takes to
complete a mixed methodology.
Research Design
Pragmatic inquiry is a research approach that emphasizes the practical application
of the research findings (Kelly & Cordeiro, 2020; Morgan, 2014). This approach is
particularly valuable in qualitative research, where researchers seek to understand
complex phenomena in real-world settings. Pragmatism can serve as the philosophical
design for research in qualitative, quantitative, or mixed methods and the fundamentals of
pragmatism are well suited for the analysis of problem solving (Morgan, 2014).
Pragmatism inspires researchers to base choice on relevance of methods and
methodologies from the world of theory to the world of practice and vice versa (Kelemen
& Rumens, 2012; Kelly & Cordeiro, 2020). Researchers use pragmatism principles to
anchor the research in practical and actionable knowledge (Kelly & Cordeiro, 2020; Kissi
et al., 2023). Instead of framing research in an abstract philosophical structure,
pragmatism concentrates on ideas and beliefs that are more actionable and directly
connected to real world outcomes (Kelly & Cordeiro, 2020; Kissi et al., 2023; Morgan,
2014; Simpson & den Hond, 2022). My research focused on the exploration of successful
strategies some cybersecurity professionals use to mitigate cybersecurity threats in
businesses and the possible practical application of these strategies to a small business.
Pragmatic inquiry aligns with my research goals and the real-world application of the
research.
Grounded theory was written in the 1960s by Barney Glaser and Anselm Strauss
with the goal to close the gap between theory and method (Glaser, 2016; Glaser &
Strauss, 2017). Grounded theory methodology is used for theory building on current
theories or generate new theories that are grounded in observations or empirical data
(Glaser, 2016; Niasse, 2023; Nathaniel, 2022; Wiesche et al., 2017). The theory is created
through constant comparison, theoretical sampling, data collection, initial encoding and
abductive reasoning (Niasse, 2023; Thornberg, 2012).Grounded theory methodology
encompasses four main components. First, it breaks from the more traditional qualitative
inquiries by relying on its own data collection and analysis of constant comparative
analysis and theoretical saturation (Glaser, 2016; Niasse, 2023). Second, grounded theory
methodology allows for both qualitative and quantitative data to build on to or expand a
theory (Walsh et al., 2015). Third, data analysis used both qualitative and quantitative
techniques in the study (Walsh et al., 2015). Fourth, the specific purpose is to generate
theory that is fully grounded in the data (Glaser, 2016; Niasse, 2023). Grounded theory
was not appropriate for my study because the goal of this study was not to further a
theory or author a new theory based on the relevant data.
Edmund Husserl, a German philosopher, is often cited as the father of
phenomenology. Husserl described phenomenology as the uninterrupted basic experience
and the essence of all things; paying careful attention to describe things as they appear
and the way they appear (Koch, 2020; Monk, 2014). Phenomenological design allows
researchers to study the lived in experiences of humans (Creely, 2018; Flynn &
Korcuska, 2018) and provide new insights (Attard et al.., 2022, p. 2). Phenomenology
emphasizes the need for empathy and provides a structured account for descriptions of
empathy as part of a study (Ekdahl, 2023). Phenomenological design is about the
experience of the research subject during a specific event, time, and or phenomena and
collecting the lived in experiences such as feelings, thoughts, worries to provide a
narrative perspective (Byrne, 2001; Creely, 2018). My research was not based on the
lived in experiences, feeling, and thoughts about cyber security strategies from cyber
security professionals. My research is about the practical application of cybersecurity
practices to small business cyber strategies. Therefore, phenomenological design was not
appropriate for this study.
Ethnographic design is used to explore the representation of a socio-culture and
individuals through the analysis of practices, people, and ideas (Neubert & Trischler,
2021). Researchers using the ethnographic approach create detailed accounts and
comprehensive descriptions of the culture under study that can be used by academic and
non-academic audiences (Nichols & Guay, 2022). Ethnographic design allows the
researcher to have firsthand accounts of the cultural practices through immersion into the
society or culture being studied. Dumont (202), suggests that total immersion in the
culture is a practical, intellectual, and emotional exercise required to achieve the social
competency required to capture what people think, do, and believe resulting in
descriptions and analysis of the different aspects of organizational life (Dumont, 2023).
The advantage of this design is the direct access to the culture or group being researched.
The primary disadvantage of ethnographic design is the amount of time the researcher is
immersed in the culture which could span months or years running the risk of biases due
to the amount of interpretation, time immersed in the culture and the emotional
involvement with some research topics (Bechky, 2020; Dumont, 2023; McMurray, 2022).
According to Kellezi (2023), ethnographic research is focused on in-depth detailed
understanding of a social culture in the environment over the course of month or years
(Kellezi, 2023). Ethnographic design was not appropriate for this research study because
I am not studying the culture of cybersecurity experts and their customs, practices and
ideas as a social structure ethnographic design is not appropriate for this study.
Data saturation occurs when the researcher no longer receives information that
adds to the theory that has been developed (Malterud et al., 2016). Morse (2020),
suggests that data saturation occurs when the researcher no longer is receiving new data;
however, Morse suggests more participants for more complex topics.
Population and Sampling
The population for this qualitative pragmatic inquiry consisted of participants
selected from LinkedIn that have advertised at least 2 years’ experience in cybersecurity
and management experience with at least 2 years of cybersecurity experience and
experience in another information technology function. Information technology function
is defined as but not limited to (network/system engineer, systems analyst, system(s) /
network/firewall administrator, support staff, and developer). Cybersecurity professionals
need a crosscut of concepts to be successful and the ability to use a range of disciplines
and systems to solve the cyber security and privacy issues in business today (Armstrong
et al., 2020). Therefore, selecting participants with a range of disciplines was vital to this
research. Having participants with a breadth and depth of information technology
experience and leadership experience with a minimum of 2 years cyber security provided
a holistic view of what strategies cyber professionals use to mitigate cyber-attacks.
Interviews were scheduled and conducted in virtual environments using Zoom. If
the participant was available for an in person interview I would have held in person
interviews in a private meeting space in Northern Virginia or Washington DC. This
would have allowed me to provide for the ethical considerations, participant safety,
respect for autonomy, and requirements expected when preforming qualitative research
study (Pataki, et al., 2021). Participants declined the in person meeting options in favor of
the virtual Zoom meeting due to location, flexibility in scheduling and personal comfort.
Sampling
Sampling size relies on the on the concept of “data saturation”. This research
started with a sample size of 10 participants and continued until data saturation was
reached with 14 total interviews. Fusch and Ness (2015), state “there is no one-size-
fitsall method to reach data saturation, because study designs are not universal” (Fusch &
Ness, p.1409, 2015). Researchers agree on some general principles and concepts to reach
data saturation such as no new data are being discovered, no new themes are emerging,
no new coding and the ability to replicate the study (Chitac, 2022; Morse, 2020; Fusch &
Ness, 2015; Young & Casey, 2018).
Researchers plan the sampling process in two general ways: Probability and
nonprobability sampling. In probability sampling method, the researcher or community
doesn’t select the participants as done in random sampling of a population (Naderifar et
al., 2017). In non-probability sampling the participants are chosen based on their
availability to the researcher (Naderifar et al., 2017). I performed non-probability
sampling to select participants that meet the knowledge and time in cyber security
requirements to collect relevant data to this research.
The selection of these participants was based on purposive sampling and snowball
sampling techniques were used gather additional participants for this research. Purposive
sampling is defined as the matching of a selected sample to obtain answers that match the
objective of the study (Campbell et al., 2020; Moser & Korstjens, 2018). I selected
participants based on the years of experience in the IT field that meet the criteria listed. I
attempted to target participants that have some experience working in or managing a
small business. I purposefully selected LinkedIn to provide a diverse participant pool.
Each participant was the result of a personal solicitation based on their background and
experience in cybersecurity.
To recruit hard to reach participants or participants with specialized skills or
characteristics researchers have used agencies and snowball sampling approaches to gain
access to these populations (Abrams, 2010; Naderifar et al., 2017). The intent is that after
each interview, the participant recommends the study to colleagues. This snowball
sampling through word of mouth or email would allow participation from a broader
participant population.
These participants are not current federal or state government officials or federal
employees, employees of my business or one of my partner’s, and are not current military
or law enforcement members. Participants from government, military and law
enforcement have different requirements, governance, and oversight than those of
businesses. Using these participants could change the data and alter the results in a way
that is not conducive to the study goal of exposing cyber security strategies for small
businesses.
Ethical Research
I received IRB approval from Walden’s IRB prior to conducting interviews. I
conducted interviews to collect the information used to make connections between
different system elements. I targeted individuals that meet the selection criteria of at least
2 years’ experience in cybersecurity and management experience. These cyber security
professionals and IT managers with at least 2 years of cybersecurity experience and
experience in another information technology function. I inquired via Linkedin about
their interest in the study and provide contact details. Those professionals that responded
were sent a welcome email that includes the goal of the study, an informed consent form
to ascertain intent to engage in this study, participation criteria, and the withdrawal
process.
Participation was voluntary in this research study as outlined in Appendix C, and
this ethics section. Kelly et al. (2017), suggests that incentives averaging $48 USD
increase participation and would make participants more willing to engage in research
studies. This research is self-funded by the author and despite previous research on
incentives for participation in studies there were no incentives offered for participation in
this study. For participants that are not in the local area, I offered virtual interviews and
did not pay for any travel, meals, entertainment, internet access or communication
devices. All participation was at will and in the interest of the study with no
reimbursements or pay for time as stated in Appendix C Letter of invitation. Any
respondent or participant that didn’t agree to these terms had the freedom to leave the
study at any time under their own free will with no reprisal. This study adhered to the
informed consent preceding voluntary participation, the highest research standards
outlined by the university’s ethical guidelines and academic research practices.
The participant had the right to withdraw at any time by sending an email
notifying the researcher of their decision to be excluded from the study. The
documentation focused on the participant’s free will, and willingness to participate in the
study with an understanding of the data collection and ethical guidelines (Klykken,
2022). This allowed the researcher to ensure the participant understood and was capable
of giving full consent to be part of the study.
Participants of this study who chose to participate via virtual means (Zoom or
Microsoft Teams) had anonymity achieved by using an undisclosed location of their
choice, as outlined in the consent form, adhering their individual rights to privacy.
Participants who wished to engage in a face-to-face interview had the right to withdraw
and leave the venue at any time. Although there were no in-person interviews, had there
been, they would have been scheduled under the researcher’s name without releasing the
intent of the room reservation, name of the study, name of any participants nor any other
information pertaining to the research study. Participants were required to abstain from
discussing the interview information, questions, personal information, names, locations
and or professional standings of any participant of this study with any outside parties.
This allowed each participant a level of confidentiality while the study was being
conducted. All information collected was encoded to help protect the participant and
provide me the information’s origin. This is further outlined in data collection section
below.
I followed Walden Universities IRB’s ethical and legal requirements to avoid
harming the research participants. This allowed the researcher to balance the participant
interaction and uphold all of the ethical considerations, participant safety, dignity, respect
for autonomy, and requirements expected that is essential the guaranteeing ethical
adherence when performing qualitative research study (Pataki et al., 2021).
In accordance with standard research processes, all data from this research study
has been and will continue to be protected through encrypted removable USB storage and
stored in a locked fire retardant safe for 5 years after publication date. After a period no
less than 5 years, I will destroy the data associated with this study.
Data Collection
Data Collection Instruments
The data collection technique for this study was performed using interviews.
Researchers use interviews to capture the experiences of participants for qualitative
studies (Moser & Korstjens, 2018). The purpose of the individual interviews was to
capture each participant’s unique experiences. A pilot study was not conducted for this
research. Pilot studies are done as feasibility studies, studies where there is not previous
research, and or used to test a particular research instrument (Malmqvist et al., 2019;
Krogh et al., 2023).
The data was collected using semi-structured interviews with open-ended
questions. The use of open-ended questions will be framed to gather short or long
answers that will be used to identify correlations between data sets and the phenomena of
cybersecurity strategies (Weller et al., 2018). According to Brown and Danaher (2019),
semi-structured interviews have been used to highlight diverse and complex research
across multiple disciplines (Brown & Danaher, 2019).
I was the primary data collection instrument. As the interviewer, I asked open
ended questions that elicited conversational answers vs one-word responses. I used
prearranged questions to gather the information provided during these interviews.
Siedlecki (2022), suggests that broader open-ended questions are preferable to specific
questions allowing the participant to share their personal stories about the phenomena.
Malshe and Al-Khatib (2023) found that it is best to interview participants, especially
those in executive or managerial positions, away from the office finding that professional
commitments may come up and pull the participant away from the interview (Malshe &
Al-Khatib, 2023). Jiménez and Orozco (2021), suggest that using prompts that pose as
questions will allow the respondent to think through and discuss the topic leading to
deeper responses for interpretation verse short straight forward answers.
I used the interview protocol (Appendix B) to obtain qualitative data and
facilitate the interviews in a constant manner while following the data collection protocol
and the University of Walden’s IRB and ethical research standards. Qualitative data
validity was also checked by providing the interview transcript to the participant to
perform member checking. This allowed participants with the opportunity to validate the
accuracy of researcher’s interpretations and their responses before data analysis and
triangulation with industry and government documentation (Burke et al., 2022; Eberman
et al., 2023).
Data Collection Technique
The data collection consisted of semi-structured interviews online, relevant
documentation, and additional industry standard publications about cybersecurity
strategies. I asked open-ended questions and collected field notes and observations during
each session. Observations and key points were collected using a physical notebook.
These observations and notes are used during the analysis process and are also used to
provide guidance on the point of saturation (O’Byrne et al., 2023; Wallwey & Kajfez,
2023). An advantage to field note collection based on observations during the interview
event is the allowance for a different dynamic to the non-verbal commentary and could
expose biases the interviewee is unaware of (James et al., 2022; Wallwey & Kajfez,
2023).
I conducted interviews via a virtual meeting space using the system Zoom at the
participant’s convenience specifying a preference for evenings after working hours.
These virtual interviews were recorded with the participant’s full knowledge and then
transcribed from the audio of the interview using Microsoft Word transcription
capability. Although there were no in-person participants, if a participant had been
available for a face-to-face interview in my locality, I would have used a digital recording
device to record the audio of the interview. The use of audio recording for the purpose of
transcription was necessary as it allowed for accurate transcription of the interview to be
used later for data analysis (McMullin, 2023). Thelwall and Nevill (2021), state that
online focus groups are save on time and cost compared to traditional face to face or
conference calls.
Researchers use additional data sources such as observations, government
documents, industry publications, and available secondary sources to do data
triangulation (Odiri, 2019; Moon, 2019; Vogler, 2023). In this study, I used quality
secondary sources such as NIST documents, government documentation and if possible, a
focus group. Focus groups involve a discussion with a group of people through their
interaction and conversation that the participants will provide more useful information
(Thelwall & Nevill, 2021). According to Surawy-Stepney et al., (2023) focus groups are a
researcher-led conversation and data are collected in both individual and group responses;
however, this research also notes that individuals have a hesitancy in discussing particular
or sensitive themes and the social or communal dynamic can result in suppression of
minority points of view.
Research by Erden-basaran et al., (2023), observed that during focus groups at
least one person drifted away from the discussion and that some participants became
distracted and found participants talking over each other and “gender-related existential
fights affected conversation” (p.202). Based on the literature and research findings
additional consideration and moderation will need to take place if data is collected from a
focus group of 3 or more people.
The nature and sensitivity of cybersecurity practices meant that I needed to use
LinkedIn to explore this research topic and I expected participants to be in different
geographic locations than the interviewer. I attempted to do face-to-face interviews when
possible since research from Schwartzman and Kennedy (2023), found that in-person
interviews allowed participants to connect better compared to virtual interviews and that
respondents preferred in-person interviews.
Additionally, Schwartzman and Kennedy (2023), found that virtual interviews
served a great purpose despite the preference for face-to-face in person interviews
(Schwartzman & Kennedy, 2023). In a study, by Rhoades et al., 2022 of resident
matching programs and the impact of virtual interviews; they found there was no
difference between fellows meeting expectations in candidates interviewing on person vs
candidates interviewed virtually and found the virtual interview process to be effective.
Virtual interviews have additional value over face-to-face interviews when
researching difficult or sensitive topics. Research on abuse by Matthew and Barron
(2023), found that interviewees provided more in-depth information through online
interviews, named more than a single theme, and allowed them to remain anonymous and
feel safe. Research by Sah et al., (2020), suggests that research participants were excited,
felt safe and virtual interviews were more convenient. Sah et al., (2020) also experienced
challenges such as lack of internet connectivity and skills to use technology could limit a
wider participation cohort.
I proposed interviewing 10 participants and increasing the participant number to
12, 14, 16 then 20 if saturation has not been reached. Data saturation is performed for
thematic analysis of different categories of data. Thematic analysis requires researchers to
capture data until themes become present and no additional data is provided (Braun &
Clarke, 2021). It has previously been recommended that qualitative studies require
between 7 and 10 interviews to reach data saturation (Young & Casey, 2018).
After the conclusion of the semi-structured interviews, I performed member
checking which involved sharing the research findings or interpretations with participants
to validate or clarify the accuracy of their representation. This process helped ensure that
participants' perspectives are accurately reflected and enhances the validity of the study
(Burke et al., 2022). Member checking doesn’t find a universal truth but the truthfulness
of the interview, referring to the participants’ perspective, and understanding of the
research and confirming that the participants meaning was not missed and confirm the
accuracy of the interpretation (Sahakyan, 2023).
The interview protocol for semi-structured face-to-face and virtual interviews was
to introduce the research topic as stated in the informed consent form(s) and provide a
copy of the form, present the recording device and explain that the interview will be
recorded and how it will be used, assure the participant of personal and professional
confidentiality, confirm the length of the interview to be respectful of the participant’s
time and not create a rushed atmosphere, encourage participant to answer questions with
in-depth answers and restate questions and answers as applicable. As the researcher, I
noted observations and any expanding questions for future participants to maintain
reliability of the collection data. I thanked the participant for their time. I provided the
transcripts of the interview to the participant for member checking prior to analysis and
scheduled follow-up or future interviews as needed.
Data Organization Techniques
The collection of data for this research study is the primary focal point. Thus, the
organization of data that is collected is important to this study. The data I collected
consisted of electronic notes, recorded interviews, and any other data. The data collected
has been and will be stored on a secure encrypted device or in the case of physical notes
in a locked safe that only I have access to for a minimum of 5 years. The encryption will
be controlled by an encryption key that will be password protected and stored on a
separate device that only I have access to.
The information collected was encoded to help protect the participant and provide
me the information origin. An example included 4-2023-I-P1 as the date of the interview
by month only, I for initial or F for follow up and the participant number.
Different qualitative data analysis software is available to qualitative researchers
such as Qatlas, Nvivo or the use of spread sheets to keep track of data and do thematic
analysis. Paulus et al., (2019) reported that scholars across disciplines and researchers
have used software Qualitative Data Analysis Software (QDAS) to organize data,
perform data coding and analyze themes. Vignato et al., (2022), found that Qualitative
Data Analysis Software specifically NVivo software was helpful and recommend
incorporating software into the data organization and analysis of a research study.
Research suggests that the use of software to organize and analyze data for qualitative
research is helpful and saves time over the labor-intensive manual organization and
coding (Nason et al., 2023; Vignato et al., 2022; Paulus et al., 2019). I used Nvivo
version 14 by Lumivero for organization of my data and analysis.
Data Analysis Technique
In qualitative studies, reliability is performed by establishing trustworthiness and
credibility rather than the use of statistical measures. Reliability and validity can be
performed through several data analysis techniques. Triangulation is one of the ways to
ensure quality in qualitative research and adds to the depth of research (Fusch et al.,
2018) Triangulation involves using multiple sources of data, such as interviews,
observations, and documents, to cross-validate and corroborate findings (Odiri, 2019;
Fusch et al., 2018; Vogler, 2023). By analyzing data from different approaches,
researchers can enhance the reliability and validity of their interpretations and limit bias.
Triangulation is proposed to achieve reliability or forms of consensus between coders
(Vogler, 2023). Maintaining an audit trail involves documenting and transparently
reporting the research process, including decisions, data collection, analysis, and
interpretations. This documentation allowed for the traceability and replication of the
research, enhancing validity.
Reliability and Validity
Reliability and validity are required for every form of qualitative research to
establish trustworthiness of the study. Reliability refers to the instruments or interviews
that are used to collect data and validity represents the accuracy of the data collected
(Yin, 2018). The accuracy of data documentation is essential to the credibility of the
research study. The criteria for establishing trustworthiness in a qualitative study is
confirmability, transferability, credibility, and dependability (Forero et al., 2018).
Reliability
After performing the interviews and collecting data, I assessed the trustworthiness
of the information to ensure the truthfulness of this study’s findings by assessing the
reliability and validity of those future findings. The reliability and validity of a study are
an integral part of the study to prove the data adequacy and data appropriateness of the
study (Spiers et al., 2018). Reliability is based on the ethic standard, method and
instrument used to collect data. According to Pham (2022), researchers should follow
institutional procedures to conduct research. To do this. I followed the data collection
protocol and the University of Walden’s IRB and ethical research standards.
To do this, I provided the participants with the questions for the semi-structured
interviews ahead of time. After the interview, I tested the reliability of the data by
providing the transcript of the interview to the participant to preform member checking.
Member checking allows participants the opportunity to check the researcher’s
interpretations and validate their responses. The member checking process helps ensure
the perspectives captured during the data collection process are accurately reflected and
enhances the validity of the study (Burke et al., 2022). Member checking refers to the
participants’ perspective, and understanding of the research and confirming that the
participants meaning of the participant was not missed and confirms the accuracy of the
data collected from the participant (Sahakyan, 2023). This allows the researcher to follow
an ethical research process with integrity, transparency, and research reliability (Pham,
2022).
Validity
Validity occurs by the achievement of dependability, confirmability,
transferability and credibility. To ensure a study has dependability, the study has to be
repeatable and based on ethical research standards (Pham, 2022). Leung (2015) states
several methods were adopted to enhance validity including 1st tier triangulation (of
researchers) and 2nd tier triangulation (of resources and theories), well-documented audit
trail of materials and processes, multidimensional analysis as concept- or case-orientated,
and respondent verification (Leung, p. 325, 2015).
Researchers can create audit trails in the data collection process and study
methods to ensure repeatability (Forero et al., 2018). Frechette et al., (2020) states that
participants can be called to validate interpretations through follow-up interviews. I
documented the entire data collection process and gave the participants the ability to
review the transcripts and the researcher’s interpretations to validate my understanding
and participants meaning and intent to validate the findings. I performed member
checking by sending the transcript to the participant to validate their responses and
schedule a follow-up interview if needed of asked for by the participant.
Dependability
Dependability in qualitative research is the ability to show the analyses are consistent and
the study could be repeated (Rose & Johnson, 2020). Nassaji (2020), states
“reported in such a way that others could arrive at similar interpretations if they review
the data” (p. 428).
Dependability can be enriched by consistently documenting all the research
activities such as audit logs, research protocols, research collection methods and any
changes that occur during the research (Nassaji, 2020; Rose & Johnson, 2020; Bleiker et
al., 2019). This allows outside researchers to examine the accuracy of the conclusions
that are made based on the collected data.
I documented any changes or additions to the data collection protocol, questions,
research collection instruments, note taking methods. I engaged in member checking with
each participant in this research to show the data collection, conclusions and findings are
accurate and based on the data collected. Adhering to the protocols for data collection and
analysis will allow another researcher to follow and replicate this study to further enhance
dependability (Coleman, 2021).
Credibility
Credibility is a form of internal validity and is established through the ethical
treatment of the research participants and the integrity of the data collection, analysis and
presentation (Abdalla et al., 2018). To establish credibility, I adhered to the research
method, design, data collection and analysis stated in this study. I asked the participants
the same questions stated in this study and the agreements with study participants.
Credibility is also demonstrated by showing the inquiry is performed in a way that
ensures the research topic is assuredly identified and described (Pham, 2022). Rose and
Johnson (2020), suggests member checking with study participants on others within the
culture further increases the credibility of research. Rose and Johnson also state that
“Member checking has limitations, including that research participants may not
necessarily recognize their own perspectives reflected in themes analyzed by the
researcher(s)” (Rose & Johnson, p. 441, 2020).
Coleman (2021) suggests tools can be used to reduce the threats to validity and
increase credibility such as recordings, the use of contradictory evidence, member
checking, respondent validation, triangulation and ethical treatment (Coleman, 2021). I
recorded the semi-structured interviews, providing the transcripts to the participants for
member checking, using research and federal documentation such as NIST and or focus
groups for triangulation, and following the ethical requirements and IRB of Walden
University to reduce risks to the validity of this study.
Transferability
Transferability is a form of external validity and in qualitative research is the
ability to transfer the data results to other settings or context (Rose & Johnson, 2020).
Rose and Johnson suggest that this can be achieved through consistent documentation
and methodical procedures aided by a detailed study protocol “so that others can follow
similar procedure” (Rose & Johnson, p. 439, 2020). Bleiker et al. (2019) states “the aim
in transferability is to utilize the rich detail produced in qualitative research so that others
can evaluate its potential for application of the findings in other spheres” (Bleiker et al.,
p. S7, 2019).
Maxwell, (2021) suggests that transferability is the readers’ issue, and that the
researcher must provide enough information on contexts and meanings and processes or
population that the reader can judge the trustworthiness of the research (Maxwell, 2021).
Levitt (2021) suggests that readers need to see both consistency and variation within the
research and transfer data from the study into a personal context (Levitt, 2021). The
researcher has limited to no control over transferability. To allow this pragmatic study to
be useful to the reader, I provided accurate descriptions of the research participants’
responses and clear interpretations of the data so that the reader may use this research to
make informed decisions or further study to determine the applicability of my study to
their environment or situation.
Confirmability
Confirmability is the ability to confirm the research data and interpretations are
clearly derived from the analysis of the data collected (Rose & Johnson, 2020). Rose and
Johnson (2020) suggest this can be performed by inspecting recordings and transcripts to
account for possible mistakes and that themes and or codes that are developed should be
clearly defined for consistency.
Coleman (2021), states that reliability in qualitative studies is harder than
quantitative studies because there are no statistical tests, however “triangulation provides
compelling arguments to the reliability of findings” (Coleman, p.3, 2021). Triangulation
compares results from two or more different methods of data collection and two or more
data sources allowing researchers to formulate an interpretation of findings (Vogler,
2023; Coleman, 2021; Leung, 2015). This allows others to confirm the interpretations and
findings of a research study.
Data Saturation
Data saturation is achieved by interviewing participants until all information about
the research question is exhausted, and no need data is presented by the participants. This
will be achieved when analyzing the participant’s responses during the interviews when
enough participants to no longer discover new information, patters or themes using the
collection method (Hayashi et al., 2019). I performed member checking with participants
to ensure the validity of their answers and my observations.
Transition and Summary
Section 2 explained the purpose of this study and provided information on how
research would be conducted ethically, and describes the population and sampling for this
study. It explained the research design and how the research analysis aligns to the
research and purpose of the study. I showed evidence of how pragmatic inquiry is
appropriate method for this research study to answer the research question “What
successful strategies do some cybersecurity professionals use to mitigate cybersecurity
threats in small businesses?” I explained how data saturation would be achieved. This
section outlined the role of the researcher, methodology, approaches used for research
collection, how data saturation would be achieved, and how validity and reliability will
be addressed through member checking, follow-up interviews as necessary, and
triangulation.
Section 3 will be the presentation of findings for this study, recommendations for
future research, and the themes and subthemes that the collected data presents. Section 3
also contains the author’s reflections and applicability to social change.
.
Section 3: Application to Professional Practice and Implications for Change
Overview of Study
The purpose of this qualitative pragmatic study was to explore strategies some
cybersecurity professionals use to mitigate cybersecurity threats in small businesses. The
population for this qualitative pragmatic inquiry consists of participants selected from
LinkedIn that have advertised at least 2 years’ experience in cybersecurity, management
experience, and experience in another IT function (e.g., network/system engineer,
systems analyst, system(s)/network/firewall administrator, support staff, and developer).
All 14 participants had multiple years of cybersecurity experience, management
experience, and experience in different IT fields such as network administration,
developers, system administration, and worked for or ran small businesses in the United
States during their careers. I followed the study protocols outlined in Appendices A, B,
and C to collect and analyze interview data and documentation.
Data were imported into NVivo 14 to organize and analyze the data into themes.
There were six major themes discovered: cyber security strategy based on business needs,
risk management, security controls, foundational security and cyber hygiene, proactive
security and incident response, and continuous monitoring. Analysis of the major themes
allowed me to connect themes and subthemes to the literature review and related research
question.
Presentation of the Findings
I preformed this study to answer the question: “What strategies do some
cybersecurity professionals use to mitigate cybersecurity threats in small businesses?” In
this section I present the findings from the research I collected. In this study I collected
data from 14 cyber security professionals who had worked in the field of cyber security
for a minimum of 2 years, had management experience, and or had experience in some
other IT discipline. Demographics of these participants are listed in Table 1. Each
participant was contacted via LinkedIn and emailed the informed consent form and
agreed to an audio recorded virtual interviews. I performed semi-structured interviews
using Zoom virtual conferencing. I utilized the triangulation method reviewing relevant
industry documentation from National Institute of Standards and Technology (NIST),
International Organization for Standardization (ISO), and Cybersecurity and
Infrastructure Security Agency (CISA).
Table 1
Participant Demographics
Participants Geographic location Years of Cybersecurity Experience Total Years of IT experience
1 Southeastern USA 5 25
2 Western USA 15 22
3 Southeastern USA 27 32
4 Southeastern USA 15 26
5 Southeastern USA 20 22
6 Western USA 6 15
7 Southeastern USA 11 19
8 Southeastern USA 26 41
9 Western USA 5 14
10 Southeastern USA 15 27
11 Southeastern USA 14 19
12 Southeastern USA 12 13
13 Southeastern USA 23 31 14 Southeastern USA
7 20
To derive themes, I did a top word search query and based on key words and
phrases from my semi structured interviews. Data were uploaded into a qualitative data
analysis software (QDAS) by Lumivero called NVivo 14 for data organization, coding,
and analysis of the interview transcripts. From the data analysis six major themes were
discovered (see Table 2). Analysis of the major themes allowed me to connect themes
and subthemes to the literature review and related research question.
Table 2
Themes
Themes Participants Count Document count
Cyber Security Strategy based in Business
Needs
348 1361
Risk Management 257 919
Security Controls 265 1153
Foundational Security & Cyber Hygiene 181 1046
Proactive security and Incident Response 174 218
Continuous Monitoring. 134 414
Theme 1: Cyber Security Strategy Based in Business Needs
Cyber security professionals cannot address threats, analyze risks, or protect an
organization or business without understanding the core business functions. This entails
prioritization and valuation of data and assets, applying industry frameworks that are
tailored to the specific business context, analyzing the governance processes and needs,
and recommend training for staff. A full understanding of the business needs is critical to
allowing cybersecurity managers, cyber analyst, ISSOs, risk auditors, security operations
center professionals, and other cyber professionals the understanding to tailor
frameworks, processes, procedure, security standards to protect the business or
organization from cyber threats and mitigate or transfer risks to the organization. P1, P2,
P3, P4, P5, P8, P9, P12, P13, and P14 mentioned that knowing the business and the core
functions are key to securing the systems, networks, and key assets from cyber threats.
Participants stressed that knowing what is important to the business or organization and
the business processes is necessary to securing business functions from malware, cyber
criminals, and recovering from disasters.
Many of these themes are interdependent and have fundamental functions that are
highlighted as a major theme that have relationships to other themes and subthemes in
this study. GST as the framework explains a holistic cyber security strategy is an open
system with a hierarchy of different capabilities, concepts and practices with relationships
and interdependencies that work together to protect a business or organization from cyber
security incidents and malware, indicating a cyber security strategy is more than just the
sum of its parts but a series of relationships and interactions between each part that makes
up the whole. This theme, cyber security strategy based in business needs, includes four
common sub themes: prioritize and valuation of assets, tailoring frameworks, industry
governance and security training. I organize these finding based on the analysis of each
subtheme (see Table 3). Table 3
Theme 1 Subthemes
Participant Count Document Count
Prioritize and Valuation of Asset: 68 114
Tailoring Frameworks 64 57
Industry Governance: policies, procedures, accountability 142 912
Training and Continuous learning 74 229
Subtheme: Prioritize and Valuation of Asset
Prioritizing assets and assigning a value to business assets based on the
capabilities and core functions of the business is required to inform cybersecurity
professionals as well as IT professionals about what the critical business processes are
and the critical data that needs to be protected. The term “assets,” according to all
participants, could be intellectual property for a research firm, the systems that control
manufacturing robots, temperature and pressure controls in oil refining, customer health
and PII (personal identifiable information) in a doctor’s office, client data and systems for
Subtheme
an engineering product, or customer data for an advertising firm. Understanding the
critical business assets and processes allows the cybersecurity strategy to align with the
business strategy and goals. All participants in this study stated that cybersecurity teams
need to work with the business and IT stakeholders to set expectations for a cybersecurity
program.
According to industry documentation from NIST, ISO and Security Controls
Framework Council (SCF), organizations depend on systems to conduct routine,
important, and critical business functions, so it is necessary that the protection of the
underlying systems and environments of these operations is vital to the success of the
business (ISO 2022; NIST, 2020; NIST, 2012; SCF, 2023). According to the Security
Controls Framework Council (SCF), cyber security needs comes down to “a need by
businesses, regardless of size or industry, for solutions that can help fix those common
frustrations that exist in most cybersecurity and data privacy programs” (SCF, 2023, p.
3). P1, P2, P3, P4, P6, P8, P9, P10, P12, P13, and P14 of this study expressed the
importance of valuation of assets to allow cybersecurity to better support the critical
businesses and operations of the organization. For example, P6 expressed the importance
of the value of assets and the relationship between how security can apply controls to
those assets based on the value to the organization. P6 explained how some organizations
protect high value assets:
We have high value assets that need to be heavily scrutinized from a security
and controls perspective. These assets are heavily locked down so only certain
ports are going through only certain individual networks. The activities, traffic,
ports and protocols are monitored and only certain IP addresses are even
allowed to connect to that particular VLAN.
This level of security is for the most critical business assets or business data.
Many SMEs undervalue their information and do not perform standard risk calculations
(Benz & Chatterjee, 2020). All participants associated the criticality of assets with their
risk profile in a bottom-up approach for a particular system. P2 stated, there are certain
networks and devices and instances of systems that are used that are very, very focused
on their function and their function has a much higher risk, so establishing a risk profile
for that particular service and for that network to make it as secure as possible.
The literature reinforces these ideas from the participants and industry showing IT and
security strategies have a relationship to the organization. The effects of these
relationships are reflected in how IT managers implement the technical infrastructure and
organization of process functions to sustain the business processes and functions (Mikalef
et al., 2021).
All participants mentioned engaging stakeholders from across the organization
ensures that technology assessments are aligned with business objectives and that the
results are properly communicated and acted upon. P14 highlighted,
Establishing what are on the critical asset list. What are the key mission and
business essential functions that need to be secured and then applying CSF [Cyber
Security Framework]. CSF is the governance function being added, but utilizing
that to establish those and prioritize the key functions to those most impactful
services, and ensuring that the correct corresponding security tool is applied to
satisfy the risk to these critical systems, services, and functions.
NIST documentation backs this up from a cyber security perspective in the NIST SP 800-
53Ar5 (2022): “Obtaining a general understanding of the organization’s operations
(including mission, functions, and business processes) and how the system or common
control that is the subject of the particular assessment supports those organizational
operations” (p. 21). P1, P4, P8, P9, P10, P11, P12, P13, P14 stated that from a cyber
perspective it is important to know the business, business model, business impact
assessment, business continuity plan, understand what is most important to the business
in order to keep producing certain services, data, or products. To do this effectively the
business and cybersecurity strategy needs to understand the impact of cyber threats to
quantify potential financial loss as part of the asset and risk assessment. By understanding
the potential financial impact on the business assets organizations can prioritize their
protection efforts and allocate resources more effectively.
This is specifically important to [small and medium business] SMB based on the
research small businesses have far less resources available to them to protect key assets
from cyber events (Rawindaran et al., 2023; Tam et al., 2021; Upadhyay & Panwar,
2022). NIST documentation backs this up from a cyber security perspective in the NIST
SP 800-53Ar5: “Obtaining a general understanding of the organization’s operations
(including mission, functions, and business processes) and how the system or common
control that is the subject of the particular assessment supports those organizational
operations” (NIST, 2022, p. 21).
This collaboration between business leaders, leaders of IT and leaders of
cybersecurity is also supported by the concepts of GST which asserts that the whole is
greater than the sum of its parts. The NIST SP 800-53Ar5 explains this dependency
stating,
The degree to which organizations have come to depend upon systems to conduct
routine, important, and critical mission and business functions means that the
protection of the underlying systems and environments of operation is paramount
to the success of the organization. (p. 1)
The business and IT stakeholder engagements applies to the valuation and prioritization
of assets showing how cybersecurity needs input from the business to prioritize and
assess what is key to the continued functions of the business and support the overall
business strategy. Using GST as the conceptual framework highlights the existence of an
ecosystem that included IT, cybersecurity, data privacy, business leaders, business
strategy and cybersecurity strategy as key components to the continued success and
protection of this ecosystem. Participants in this study, academic and industry
documentation expose the understanding of these interactions between business systems,
business processes, procedures during operations is necessary to protect these crucial
functions (NIST, 2022; SCF, 2024; Tarafdar & Bose, 2019).
Subtheme: Tailoring Frameworks
Strategically, using an existing industry vetted framework then tailoring methods
based on these frameworks is a good basis for the development of a holistic strategy.
These frameworks give a cohesive foundation that cyber security professionals use to
protect organizations of all sizes. P1 specifically called out the NIST documentation and
the NIST CSF [Cyber Security Framework] stating, “NIST, the National Institute of
Standards and Technology cyber security framework is like, or almost like the Bible. It
has a very high-level strategic framework for how to manage risks”. However, these are
frameworks, not guides and care needs to be taken based on the risk posture, asset
valuation and criticality when applying frameworks. All participants talked about
tailoring frameworks such as NIST Cybersecurity Framework (CSF), Zero trust
Architecture (ZTA), Risk Management Framework (RMF), and HITRUST Framework.
Participants spoke about how these frameworks need to be tailored and how a strategy
can implement portions of different frameworks based on the business needs. P1
specifically stated, “risk management frameworks like NIST, ISO, and COBIT etc. are
general frameworks helping you identify your assets and prioritize the various risks from
a strategy perspective. So, you identify your assets, and prioritize the various risks.”
Participants mentioned how several of the frameworks have different overlapping or
similar capabilities highlighting the need for tailoring and or selecting a framework based
on the business needs. P2 stated, “PCI DSS, like HIPAA (Health Insurance Portability
and Accountability Act), and high trust basically all cover roughly 80% of the same
thing”. P1, P2, P3, P5, P7, P8, P10, P11, P12, P14 all mentioned the need for different
frameworks and tailoring those frameworks based on the type of business, regulations,
and data types such as PII (Personal Identifiable Information) and medical data covered
under HIPAA (Health Insurance Portability and Accountability Act). These frameworks
also need to be tailored based on state privacy regulations and General Data Protection
Regulation (GDPR). P3 shared
There's no one-size-fits-all framework. There's not even a one size fits most. It
starts off as a generic framework, but then as they (business leader or
cybersecurity leader) gain a better understanding of the framework and the
technology, they slowly begin to improve and implement more stringent risk
management and security controls.
P7 also talked about very specific frameworks for different aspects of cybersecurity such
as threat hunting. P7 stated,
The main framework we use for threat hunting is the MITRE Attack Framework.
It's built around the concepts of malicious actors and their tactics, techniques and
procedures, and the things that are difficult to change as an actor become the area
of focus for the defenders.
Both participants and the academic research show that great care should be taken
when implementing a framework. Cybersecurity professionals and stakeholders need to
understand what is being implemented, how the framework is tailored to the specific
business processes, how the cyber security strategy interacts with and what the expected
outcome will bring value to the business. Falch, et al. (2023) states, “It is necessary to
make a distinction between different types and sizes of SMEs (Small and Medium
Enterprises) and for role in the digital ecosystem in order to make sure that solutions are
tailored to them” (p.742).
All participants stated that depending on the organization, the parts of this Zero
trust architecture (ZTA) that are implemented can cause communication issues. P3, P5
and P9 mentioned how different workloads can be negatively affected by the isolation of
the zero-trust framework. P3 specifically mentioned, “cloud workloads may be more
integrated, and other systems be more isolated in nature the way zero-trust is
implemented. These types of systems need to be tailored to reduce the attack surfaces of
the cloud workloads without communication failures.” P9 shared their experience as a
user, zero-trust architectures are implemented to reduce the risk of inappropriate access,
but also to reduce the risk of data leakage. We further control our environments through
VPN access, however, even scheduling a conference room within our facilities, you have
to be on the VPN or be on the network. In order to book and reserve rooms, employees
must be logged into the network. We put that same level of security control around the
financial information and some very specific intellectual property.
P14 specifically called out the need for IT Service Management (ITSM) before
implementing the zero-trust framework and some of the challenges this participant has
experienced in implementing the zero-trust framework. P14 stated, “I would say without
an associated enterprise governance or a governance of the necessary workflows and
management strategies of ISTM Zero-trust is incomplete at best and provides a facade
that it's increasing or improving security.” P7 stated that in their experience, “Zero-trust is
still sort of in its infancy for implementation. It's a big cultural change for a lot of
organizations because more of a foundation needs to be established before you can just
run with zero-trust”. Reviewing the industry documentation from NIST, the NIST SP
800-207 (2024) shows that zero trust architecture (ZTA) may have a negative impact on
users and organizations through security fatigue. According to NIST SP 800-207 (2024),
“Security fatigue is the phenomenon wherein end users are confronted with so many
security policies and challenges that it begins to impact their productivity in a negative
way” (p. 49). P9 mentioned how this can be frustrating as a user when the integration and
communications are too restrictive. There is no one single provider of all the tenants of
ZTA. There is a need for several different processes, services and tools which can lead to
specific dependencies on different systems, tools and providers. NIST SP 800-207
(2024), also cautions that because of this “If one vital component is disrupted or
unreachable, there could be a cascade of failures that impact one or multiple business
processes” (p. 49).
A framework is important for to use for a cybersecurity strategy. Through the
conceptual framework of GST, the selection and use of a cyber security framework is
complex due to the interdependencies between cyber security and IT. The use of defense
in depth, ZTA, or any other industry framework utilizes systems that are often nested and
share services that are not just a single resource that can be isolated but that there are
agents that interact between these systems (Burke & Morley, 2023). GST states that a
system is greater than the sum of its individual, isolated parts. The interactions,
relationships and interdependencies between systems and subsystems are what makes a
cyber security strategy complex open system that interacts with the outside environment.
Subtheme: Industry Governance: Policies, Procedures, Accountability
Effective cybersecurity strategies include governance that allows synergies
between business, IT, and cybersecurity through collaboration of stakeholders on
cybersecurity strategy, business strategy, business vision, organizational culture and legal
/ regulatory compliance (Ilmudeen, 2022; Mikalef et al., 2021, Chau et al., 2020). P14
pointed out that most of the frameworks above, have a pillar or a portion dedicated to
governance. According to P14, the zero-trust framework or the graphic depiction of the
seven pillars of zero-trust has an implied governance that interconnects all of the pillars.
That governance aspect is required to integrate data flows, user requirements, micro
segmentation, and the core functionalities. Without the integration of governance across
the 7 pillars there is no realized benefits to implementing the Zero-trust framework.
All participants and industry documentation state that there are several statutory
obligations or “Laws” that are in effect that have cyber security and data privacy
compliance requirements that a business must adhere to if they are doing business in the
United States and or one of the states with specific state statutory obligations. Table 4
shows a subset of examples that could be required in 2024 (Secure Controls Framework
Integrated controls Management [SCF ICM], 2024). This list will change as different
states and localities pass privacy laws and customer data handling laws. Regulatory
obligations are issued by a regulatory body typically by industry or specific customers
such as state and federal governments, financial services and certifying bodies.
Table 4
Statutory, Regulatory and Contractual Obligations
STATUTORY
OBLIGATIONS
REGULATORY OBLIGATIONS CONTRACTUAL
OBLIGATIONS
Fair and Accurate Credit
Transactions Act (FACTA)
Defense Federal Acquisition
Regulation Supplement (DFARS)
Center for Internet Security
Critical Security Controls (CIS
CSC)
Family Education Rights
and Privacy Act (FERPA)
Federal Risk and Authorization
Management Program (FedRAMP)
Cloud Security Alliance Cloud
Controls Matrix (CSA CCM)
Federal Information National Industrial Security Payment Card Industry Data
Security Management Act
(FISMA)
Program Operating Manual
(NISPOM)
Security Standard (PCI DSS)
Federal Trade Commission
(FTC) Act
Financial Industry Regulatory
Authority (FINRA)
ISO 27001 certification
Gramm-Leach-Bliley Act
(GLBA)
New York Department of Financial
Services (NY DFS) 23 NYCRR
500
Service Organization Control
(SOC) audits
Health Insurance Portability
and Accountability Act
(HIPAA)
UK - Data Protection Act
(DPA)
California - SB 1386 /
CCPA / CPRA
Massachusetts - 201 CMR
17.00
Oregon - ORS 646A.622
European Union General Data
Protection Regulation (EU GDPR)
Participants talked about compliance of some of these obligations and regulations
from a pragmatic perspective. One participant looked at governance and compliance from
a customer viewpoint. P1 stated the challenges with doing business with all the different
statutory and regulatory obligations,
Within this company we had challenges working with different laws. We had to
comply with General Data Protection Regulation (GDPR) of European Union
when working in Great Britain, the California Cyber Protection in California, and
now we are also finding out that many states in the US as well as many countries
in the world are coming up with their own laws regulating compliance (P1).
All participants stated governance is required and should be more than a
compliance activity. P1, P2, P4, P8, P9, P10, P14 mentioned that governance is more than
just compliance, it is the starting point for governance and more effort is needed to secure
a business. P10 shared their experience,
PCI compliance, for example some people take it very seriously while others may
look at it as a huge burden and only do the bare minimum per quarter to get away with a
compliance sign off. I know which individuals who are serious about PCI compliance and
those are the individuals I would like to do business with. P1 mentioned the challenges
when using outside vendors and the need to understand where your customer data
specifically PII is going. P1 shared
If you have servers with services that transmit data across countries, not only can
this slow down your data rate, but also open up more regulation and a lot more
legalities and difficulties when traversing multiple companies, within different
countries.
Participants stated that knowing your systems, especially cloud and SaaS (Software as a
Service) vendors is necessary to prevent liabilities due to statutory regulations around
data.
Governance is needed to align cybersecurity to the statutory, regulatory
obligations, the overall IT and business strategy to build on procedural and relational
governance mechanism within the business ecosystem (SCF, 2024; Chau et al., 2020).
NIST (2022), also shows that governance is what assessors can use to audit technical
policies against written policies and procedures (NIST SP 800-52r5, 2022). Governance
needs to be easy to understand due to the significant impact and the importance of
governance in IT and business strategy (Ilmudeen, 2022; Mikalef et al., 2021). P1
highlighted this need and how it related to the larger business context. P1 stated “the
Cyber security strategy needs to align with our business goals. So, our policies directly
support our organization security objectives as well as our risk tolerance, and they are
written for clarity, and conciseness”. P1, P8, P9, P10, P11, P13 mentioned that employees
at all levels and all capabilities need to be able to read and understand governance
policies and their significance to the organization as well as their impacts and liabilities
when breached.
P11 also highlighted that policies and processes need to work together and not
cause additional confusion. P11 stated, “Combining a security controls to implement a
rule based on the computer use policy that would prevent users from going to specific
sites. Implementing those types of rules work well with computer use policies.” P11
suggested that the users need to understand the impact to the business when breaking a
policy. P3 talked about policies being backup by training and setting expectations on the
users. P3 stated, “Employees are expected to know every security policy”. It is critical
that the business provide employee training, and explain why security is important to the
business the literature and industry documentation both show that IT governance and
cyber security governance are concerned with guidance, compliance and decision rights
(Ilmudeen, 2022; Mikalef et al., 2021).
The GST framework states that a complex system has interdependencies,
relationships and different components can create reaction in the greater system. GST is
relevant to cyber security strategies because any individual component can affect the
interactions of other components. GST relates to policies and governance in a cyber
security strategy by showing that governance is an open system with input coming from
statutory and regulatory obligations that can change the way data is protected, used and
transmitted. As a complex system of interdependent parts and relationships, the
governance portion of a cyber security strategy can affect the risk posture of an
organization based on the interactions between policies, the business strategy and end
user behaviors. A cyber security strategy is not a single concept but a complex system of
interdependences, relationships and components. Cybersecurity strategy governance has
implications on the business, innovation and customers. For example, objects of the
governance polices can dictate what behaviors are allowed with business networks,
computers and who may install software. This can include the use of personal email,
social media and personal devices on the business network. The governance component
may rely on HR (Human Resources) and cybersecurity monitoring to enforce the policy
and the users’ behaviors. Training maybe implemented to explain why the policy is in
place and how it is important to secure the business IT equipment and communications.
This interaction combines all the attributes and defines the relationships between these
components creating a greater whole than the individual parts.
Subtheme: Training and Continuous learning:
Where governance sets the overall policies and procedures for an organization, the
trainings apply these aspects of the cyber security strategy to the end users.
Continuous education gives IT and cyber professionals updated skills to protect the
business operations from new and future threats. According to the academic literature,
ransomware is one of the biggest threats to businesses, especially small businesses
(Kshetri & Voas, 2022). IoT devices, email, java scripts and social media are some of the
largest proliferators of these threats (Humayun et al., 2021, Wang & Liu, 2021, Karbasi
& Farhadi, 2021). P9 stated, "We use the term cyber army within our organization. The
idea that everybody is part of cyber and has a cyber responsibility. To accomplish this
effectively we've got to have the training aspects to teach people what to look for and
how to report (anomalies).”
This idea is backed up in the industry documentation NIST lists current awareness
and training policies, training procedures, training of system users, security literacy
training at all level from user to executive as assessment objectives that can be measures
and audited. ISO 27001:2022 lists “information security awareness education and training
as one of the people controls in section 6 subsection 6.3” (ISO, 2022, p43).
According to NIST SP 800-53B
In a small organization, more frequent auditing, targeted role-based training, or
stronger personnel screening may be implemented in lieu of separation of duties.
Well-defined procedures, targeted role-based training, and more frequent auditing
may be implemented in lieu of automated mechanisms (NIST, 2020, p.12).
All participants in this study reinforced the literature and industry documentation
that recommends implementing comprehensive training programs and suggests
promoting a culture of continuous learning are essential components of a cybersecurity
strategy. All participants emphasized the importance of providing regular trainings to
employees at all levels, staying informed about the latest threats and technologies, and
encouraging ongoing skill development to maintain a strong cybersecurity posture. P7
talked about how under trained or untrained users become victims of social engineering.
P7 stated,
If there's a lack of training for your users, it's not uncommon for them to fall prey
to those social engineering attacks which is going to lead to malicious software that
establishes persistence in your network for the adversary (Cyber Criminal). P1, P3, P5,
P6, P7, P8, P9, P10, P11, P14 highlighted that user training is part of the overall cyber
security strategy. Participants also stressed that the users need to understand why it is
important so that they become vested in the cybersecurity program and the cyber strategy
as a whole. P3 highlighted, "User training is important and it complements every cyber
security policy that is out there. Users have to know this training, and why it is
important.” All participants stated specific training and validation of that training, such as
phishing campaigns, work well together. P9 stressed the importance of this by stating,
train for phishing! We probably let zero things in through firewalls, open ports and or
applications, but phishing emails and random sales emails still get into your inbox. So,
you've got to be able to be aware of what that looks like as part of the training.
P1, P2, P3, P9, P11, and P14 called out that trainings are more effective when the
end users or audience of the training understands the impacts of not following security
trainings. P14 stated, “The training and explaining to people the impact of not following
proper security policies. By showing the actual impact of it helps people understand the
important that this is not just another annual training.” P2 suggested that users who are
untrained are a weak link and the industry and academic documentation stating security
awareness training is necessary is correct. P2 stated this when talking about security
training for users to protect against malware and phishing, highlighting, “Computer
training is important. The weak link is the user. That piece has been well-documented.
Well-trained users are less likely to touch on something.” P9 mentioned more detailed
trainings to protect intellectual property, research and key operations, commenting,
“Trainings that relate directly to security, so insider threat, phishing type of constructs as
well as the standard compliance training that we have to do.”
P10 and P11 shared other experiences and perspectives about user training. P10
highlighted,
Well, I wish I could say user training was useful. I think users find it annoying.
Why is my password so long? You teach them what secure pass phrases are
instead of passwords, and they don't want to use them. I know, education is by far
a best tool, however, if your end users don't see the value, they won’t change.
P11 also had concerns about the end user security trainings, stating,
The human vulnerabilities are more difficult to combat because most of the time
they're subjective. You end up training all your workforce or most of your
workforce, showing if you receive an e-mail from somebody who is unknown to
you and they offer a link. Don't click it. Well, as many times as you say that,
they're still going to click it. Unfortunately, even if you repeat the message most
of the time it gets ignored.
GST states that all systems have objects and attributes that are components of the
system. The combination of these components their dependences and relationships enable
the different parts to be greater than the sum of each individual component. Through the
lens of GST, we see the relationships between training and other aspects of a cyber
security strategy are interdependent, and creating a cyber strategy that integrated users as
the first level of defense is key to protecting the business. The academic research,
participants and industry documentation also stressed that training can be used to inform
users about policy changes, new threats and techniques that can help protect the
organization or business. Training is integral to protecting the organization as it can
enable end users to properly report anomalous computer or application behaviors and
informing the organization about the expectations, policies and use of technology. This
theme, through the use of the GST framework, shows how the business strategy, IT
strategy and cyber security strategies are interrelated and interdependent. That
stakeholder involvement in the cybersecurity strategy can add value to the business,
implement governance and have training inform users and keep cyber professionals up to
date on the latest techniques.
Theme 2: Risk Management
Risk management was a major theme in the research. All participants talked about
how risks need to be assessed based on how critical systems are to the business functions.
These business functions could be different capabilities, data types, assets and processes
that are key to the business operations. By focusing on the most significant risks,
organizations can allocate resources effectively and minimize the potential impact of
cyber incidents. Cybersecurity professionals stressed the need to understand this
valuation to secure sensitive systems, data and processes. Theme 2 risk management is
broken into 3 sub-themes risk and threat assessments, threat mitigations and risk
management, and disaster recovery (see Table 5).
Table 5
Theme 2 Subthemes
Subtheme Participant Count Document Count
Risk and Threat Assessments 62 635
Threat mitigations & Risk
management
124 128
Disaster Recovery 71 156
Subtheme: Risk and Threat Assessments:
Risk assessments are a key part of a holistic cybersecurity strategy. According to
all the participants in this study, conducting regular risk assessments allows an
organization to identify, evaluate and prioritize potential threats and vulnerabilities within
the applications, technical systems, and communication networks. Several participants
highlighted the need for a comprehensive approach that considers both technical and
nontechnical factors, such as people, processes and external threats. P1, P3, P2, P4, P5,
P8, P9, P11, P14, P14 stressed the significance of a holistic approach to risk assessments,
stating that understanding the assets, creating a threat assessment, and understanding the
attack surface of the business or organization is key. P1 stated, "I have written threat
assessments, vulnerability analysis, information mitigation strategies, patch management,
access control, and security awareness using the risk management framework and NIST
CSF." This highlights the need for organizations to consider a wide range of factors when
assessing their risk posture, determining threats and assessing risk mitigation techniques
as part of a broader cybersecurity strategy. P8 stated, “strategies predominantly followed
the risk management framework because it's well documented, well understood by
decision makers who drive corporate policies.”
P1, P2, P4, P5, P7, P8, P9, P12, P13, P14 mentioned assets being systems, key
processes and data that is critical to the function to the business. They stated that these
assets need to be categorized or prioritized based on how key they are to the core
business function. These assets would cause the most harm to the business if
compromised or unavailable. According to the industry documentations, specifically SCP
ICM, 2024; NIST 80-37, 2018; NIST 800-30, 2012 this is typically referenced highest to
lowest criticality, concentrating on the most critical or high value assets (HVA) first. P1
described their experience with this type of risk assessment approach, "I identify assess,
prioritize the various risks. Then you see what kind of vulnerabilities and risks exist and
can develop a risk-based security strategy and assign the roles and responsibilities (of
each security and IT team)."
P1, P3, P4, P7, P8, P9, P11, P12, P13, P14 talked about risks as a judgement call
and the use of layers of protection based on how critical the technology or data is to the
core business. P4 stated, “Part of that assessment is acknowledgement that if I'm a
smaller company and I don’t have state or government level threats, I have to make a
judgment call about how much protection I use and what my budget is”. P12 stated this
determination of risk in this way,
Risk management is at the forefront of a cyber strategy. Strategy starts at the top.
What is the business risk appetite? What's the risk tolerance? How do you identify
risk and threats? Then determine what tools are available to monitor these assets
and mitigate, reduce or transfer the risks to the organization.
P1 stated that the risk tolerance is like a bet,
Risk tolerance is how much risk a company is willing to accept regardless of the
cyber threat. Threats are always going to exist, but what are you willing to risk
what is your bet that the threat will not occur. To build backup sites and a cyber
team is going to have a financial cost.
The risk tolerance is the readiness of an organization to bear the risk after treatments have
been applied (NIST, 2011). Providing an asset valuation allows you to accept a certain
level of risk to some business components but not others. P4 stated,
If I am a big media company and if people want to deface my website a little bit,
I'm way less concerned about that than if they get into my film archive. I would
put more effort in to protecting high value assets and other assets will get funded
and secured differently.
The experiences of the participants reinforces the information from the literature.
The use of different technologies brings a certain amount of risk and threat to an
organization and there are ways to control or mitigate the risk with information security
risk assessments (Rawindaran et al., 2023, Alkhazi et al., 2022, Ilmudeen, 2022; Mikalef
et al., 2021). NIST offers several publications as guides, such as the NIST SP 800-30
Guide for conducting risk assessments. All participants in this study mentioned NIST
Risk Management Framework or (RMF) for risk assessments, controls and as a starting
point for a cybersecurity strategy and as a guide to doing risk assessments.
Threat assessments are part of a risk assessment. NIST SP 1800-5 states “risk is a
measure of the extent to which an entity is threatened by a potential circumstance or
event” (Stone et al., 2018, p. 10). Threat assessments analyze the intentions of entities
that could pose a threat to the organizations. Small businesses may not realize they are
specifically targeted by different entities. However, their innovations, intellectual
property, customer data, customer credit card information and potential vulnerabilities
make them targets for malware and hackers (Shreeve, et al., 2023, Tam et al., 2021,
Kemp et al., 2023; Sangari et al., 2022). Research also suggests that small businesses do
not perform threat and risk assessments or have other knowledge necessary to protect
themselves from threats (Kemp et al., 2023; Sangari et al., 2022). Participants talked
about different threats that target businesses such as insider threats, phishing attacks,
mobile devices being lost, and social engineering attacks. P9 stated that to protect data,
external storage is being limited “seeing implementations around no USB drives, either
through policy or through configuration controls within the end user devices, reduces the
risk of data leakage by loss of USB drives”.
P7 talked about the threats from phishing emails and that they can cause
ransomware attacks,
A popular social engineering techniques that adversaries like to use are phishing
emails. Phishing is when an adversary crafts an e-mail to try and trick a user into
either giving away sensitive information like a user account or password, or in
even greater malicious situations trying to get them to click on a web link that will
redirect the user. When they redirect the user, it can be to the malicious actor’s
own server, where it downloads malware such as viruses or ransomware. As
stated by the academic research, ransomware is one of the biggest threats to small
business today and should be part of a risk assessment. Participants cautioned that
downloads from social media, links and files from unknown senders received via
email can contain malware and ransomware.
The GST framework states that a system is a complex structure that is greater than
the sum of its individual components. That each part of the system has dependencies and
relationships between other components. Risk assessments rely heavy on threats
assessments, asset valuation, and the relationship between Cyber security, IT and the
business. Risk assessments are used for the mitigations of threats, can influence policies
such as computer use policies. Using GST as the framework to study cyber strategies risk
assessments according to the participants, academic research and industry documentation
are part of the top level hierarchy of the complex system that is a cyber security strategy.
Risk assessment are used to influence the amount of security resources (financial and
personal) implemented based on the value of the asset and the amount of risk that asset
possess if ever compromised. Participants and industry documentation shows how
complex and interrelated these components are to the larger cyber security policy and as a
company updates the risk assessment the overall cyber security strategy is impacted and
will need to update and evolve.
Subtheme: Threat Mitigations & Risk Management
The participants agreed with industry and academic research documentation.
Outlining the need for a business to understand possible threats to the organization in
order to manage risk and mitigate threats with appropriate controls. The industry
documentation specifically the NIST SP 800-30r1 Guide for Conducting Risk
Assessments has four components. The first step to identify threats to the organization
(assets, operations or individuals) or threats detected through other organizations (NISTt,
2012, p. 5). Participants stressed the need for business owners, cyber leaders and
executives to understand the impact of cyber threats on the business. All participants
stated that business leaders need to understand the role security plays in protecting,
monitoring and mitigating threats to the business these could be cyber or even
environmental. P2 stated, “a business leader needs to understand the impact of security,
the value of security to their organization and that it’s worth the crown jewels. If a cyber
disaster happens, can my business still function?”
A threat is any circumstance or event with the potential to adversely impact
organizational operations and assets, or to individuals through unauthorized access,
destruction, disclosure, or modification of information, and/or denial of service.
According to NIST SP 800-30r1 (2012),
Threat events are caused by threat sources and categorized as: (i) the intent and
method targeted at the exploitation of a vulnerability; (i) hostile cyber or physical
attacks; (ii) human errors of omission or commission; (iii) structural failures of
organization-controlled resources (e.g., hardware, software, environmental
controls); and (iv) natural and man-made disasters, accidents, and failures beyond
the control of the organization (p. 8).
When threat events are identified with great specificity, threat scenarios can be
modeled, developed, and analyzed. A threat scenario is a set of discrete threat events,
attributed to a specific threat source or multiple threat sources, ordered in time, that result
in adverse effects. Creation of threat scenarios is useful so an organization can understand
that some risks have a cascading effects. Some risks are found only after another
vulnerability is exploited. These are often very disruptive and have high threat impacts on
the business or organization. P1, P2, P3, P5, P7, P8, P11, P12, P14 talked about threats
and how they are always present. P1 specifically mentioned threats and the relationship to
organizational risk, the overall impact of cyber threats analysis are to assess the risk
tolerance and understand how much risk a company is willing to accept regardless of the
threat.
Threats are always going to be there, some are higher risk, and some lower.
NIST explains threat impact based on a hierarchy or levels of magnitude the NIST
800-30r1 states,
The level of impact from a threat event is the magnitude of harm that can be
expected to result from the consequences of unauthorized disclosure of
information, unauthorized modification of information, unauthorized destruction
of information, or loss of information or information system availability (NIST,
2012, P.11).
Threats are often divided into sources such as environmental, accidental, structural and
adversarial. P1, P2, P3, P4, P5, P6, P7, P8, P10. P11, P12, P13, P14 talked about the
impact of threats to the business and the criticality of securing data or transactions. P7
highlighted the importance of risk management regarding threats and the classification
of systems based on the threat assessment specifically stating, “assets are categorized
depending on the criticality of the system, or data and its impact on business if the
systems were to be compromised and or brought down.” Industry documents reinforced
the participants’ views and experiences.
NIST 800-30 states this well “the level of impact from a threat event is the
magnitude of harm that can be expected to result from the consequences of
unauthorized disclosure of information, unauthorized modification of information,
unauthorized destruction of information, or loss of information or information
system availability.” (NIST, 2012, p. 11)
Many academic journals state the importance of threat analysis in regard to doing
risk assessments and protecting organizations from external and internal threats such as
hackers, malware, ransomware, environmental and natural disasters, and
misconfigurations, human errors, and hardware failures across the threat landscape (Oruj,
2023, Medoh & Telukdarie 2022, Kshetri & Voss 2022, Humayum et al. 2021).
The threats that have previously been assessed need to be prioritized based on
how critical the threat is to the organization, the importance of the asset that is threatened
to the business, the likelihood that the threat can occur and the vulnerability that exists in
the system, and organization. As an example, analyzing an external risk of a business that
exists and operates in a flood zone indicates that the threat of flood cannot be fully
mitigated or eliminated without moving the location. However, it can be managed or
treated through flood insurance, proper drainage around the buildings and putting more
expensive equipment on higher floors if possible to prevent damage if the flood occurs.
IT risk management of a digital environment or ecosystem works in a similar way based
on the business’ appetite for risk. If the business cannot return to operations after a flood
then the risk needs to be eliminated. This works for the cybersecurity strategy as well. If
the business is hacked, what are the remediation actions? How does the business protect
those critical assets from being hacked? What does the business tell its customers,
partners and what is the processes to identify the risks manage them and if they do occur
mitigate the amount of damage caused is all part of risk management? Participants talked
about the NIST Risk Management Framework RMF (NIST SP 800-37r2) and the ability
to put systems into the technical ecosystem via an authorization to operate or ATO
process. P12 stated,
I've also seen organizations, especially as relates to energy and utilities
implementing, NIST cybersecurity framework with the goal of reducing and
managing risk. In my experience, NIST is kind of like the main body of
knowledge, whether it's the risk management framework or whether it's the cyber
security framework that organizations are implementing.
Participants talked about different processes as part of the overall risk
management strategy. P12 stated, “Patch management, configuration management,
change management, project management, supply chain, risk management, are all areas
I've seen businesses leverage in order to reduce their risk and their footprint”. The
academic research suggests that risk management is important for continued business
growth and the ability to be competitive in the marketplace (Benz & Chatterjee, 2020;
Lloyd, 2020). The literature and participants provided several risk management
techniques such as business continuity plans, documentation that details the functions of
systems (system architecture), clearly defined roles and responsibilities for cyber
security, incident response and management, specific processes and policies also detailed
in Theme 1 (Benz & Chatterjee, 2020; Hoppe et al., 2021; Lloyd, 2020). P14 talked about
the strategic importance of risk management by stating, we ensured that we did a proper
tracing of those of the pertinent controls against what were the key assets across the
enterprise and pretty much summarize 1200 assets. We assessed and determined the key
controls and key functions that need to be addressed in that and implementing through
our workflow management system, which is also the system of record to handle the risk
management framework implementation with automation of liens and POAMs (Plan of
Action
Milestone).
A POAM is “A plan of action and milestones detailing remediation plans for
unacceptable risks identified in security and privacy assessment reports is developed”
(NIST SP 800-37r2, p. 61). With the participants’ perspectives and the threats based on
industry, the GST framework demonstrates there are many relationships between
different aspects of a cyber security strategy and how the different parts, processes and
policies need to interact regarding the internal and external threats to an organization or
business. The organization needs to understand what the functions and assets including
data, industrial control mechanisms in manufacturing, code repos for development of
software or customer order data that contains valuable PII and financial information, are
critical for the business to function.
Subtheme: Disaster Recovery
Disaster recovery can be seen as contingency planning for the realization of
threats. The participating cybersecurity professionals emphasized the importance of
having a well-defined and tested disaster recovery plan as part of an organization's overall
risk management strategy. They highlighted the need for a comprehensive approach that
addresses both technical and non-technical aspects of disaster recovery, ensuring that
critical systems and data can be restored quickly in the event of a cyber incident or other
disruption. Every participant in this study mentioned a continuity of operations plan or
(COOP) as a way of keeping the business or organization functional during or
immediately after a disaster. P7 talked about a geographically dispersed COOP,
For my customers and the organizations I’ve been in, one of the most common
features is the continuity of operations plans which usually involves having two
geographically separated sites. They conduct business and on a regular basis, both
sides are up and running, but there are policies and procedures in place for the
unthinkable event of a natural disaster.
Natural disasters occur and should be part of the risk and threat assessment mentioned
above, each geographical location across the USA, there are different disaster types prone
to the area. These might include hurricanes, earthquakes, flooding, and tornadoes. P1
highlighted these types of natural disasters and the need for possible geographically
diversifying backup, “not just for someone hacking, but also from the aspect of, if there's
a natural disaster, hurricane or earthquake. Things can and still do happen.”
Participants mentioned doing disaster recovery in the cloud as being more cost
effective. P14 stated “the cloud environment builds are relatively inexpensive compared
to the cost of not having restoration or mitigations”. Participants talked about the way
cloud services could be used and how some services have native backups based on their
advertised 99.99% availability. P7 stated,
There are some advantages to cloud such as a lot of cloud infrastructures are
already innately set up with that kind of redundancy in mind. They'll have multiple data
centers within a single area. When you create or save something within the cloud, a
backup copy is sent to each of those data centers so that if the incident were to happen,
you'd have multiple places you could recover from. Participants also warned that
business owners may need some additional support from experts when looking at cloud
options. According to P7,
Cloud services education and consulting the appropriate experts is recommended
to build a cloud transition plan when moving a business to cloud. Because there's
a different mindset when selecting cloud services. The cloud offers a lot of
services and many cloud service providers have hidden costs.
Buchtmann et al., (2023) states, “the consequences of disruption or destruction –
will continue to grow as social, economic, technological, and infrastructural systems
become increasingly hyper-connected and interdependent” (p. 54). Participants reinforced
the research and academic literature regarding risk and disaster recovery. All participants
stressed the need for a disaster recovery plan as a way to respond to a serious cyberattack,
environmental, or other disaster that causes an outage.
P1, P2, P3, P4, P5, P7, P8, P9, P11, P12, P13, P14 explained that the critical and
high value systems, services and assets from the risk assessment need to be the basis for
the disaster recovery plan in order to continue business operations. P10 stated,
When critical systems go down, you are losing money. That is a disaster.
Businesses need to have a plan to get the administrators, security engineers and
managers involved that know how to restore services and get the business
functional quickly.
P11 agreed and suggested, “A disaster recovery plan should work if there is any type of
outage, including environmental or hacks. It should have communication plans and
delineated roles and responsibilities for teams. Cyber-attacks are much more of a when
than if.” According to P10,
If you're providing something that's critical and you're dealing with customer
information or information that changes frequently. Transactional backup of your
DR (disaster recovery) is important because the system can be restored and
maintain an up-to-the-minute data before the cyber incident.
In the context of GST, disaster recovery cannot function on its own. Disaster
recovery highlights the interdependencies of systems, processes and procedures as well as
the intersection with what the business views as critical. In the event of a disaster, these
systems can be brought back up in order of criticality. Cyber security strategies have
many components that are coupled with how the business operates, communicates, and
how it can be resilient in the event of a cyber-attack, natural disaster, or other catastrophic
event. Organizations must prioritize the development, testing, and maintenance of robust
disaster recovery plans to ensure they can quickly and effectively respond to and recover
from potential cyber incidents or other disruptions. A comprehensive approach requires
regular testing and rehearsal, clear communication and coordination, backup facilities and
redundant systems, and regular reviews and updates emerge as key factors in effective
disaster recovery practices. The GST framework states that a system is the combination
of all the components, their attributes and the complex relationships between these
components. That the system is not just the individual components but that the
relationships, dependencies and attributes is greater than the sum of the parts. Disaster
recovery is key for a business to continue operations after a cyber, environmental or
localized disaster. Risk assessments, backups, asset valuation, asset management all have
interdependencies with disaster recovery. The dependencies of risk assessment with asset
valuation inform the disaster recovery plans identifying high value assets and critical data
to backup and or maintain in a fail over site. Processes and policies are updated as
disaster recovery is validated and tested to ensure in the event of a disaster the different
parts of the organization know what their roles are and how to respond.
Theme 3: Security Controls
Security controls are used to prevent security breaches and incidents where
applications and services can be degraded, data is stolen, exfiltrated, or held ransom
through the use of malware known as ransomware. Participants talked about the use of
different security controls and how they relate to the risk management framework.
According to P8, “typically in the application of the security controls, organizations that
are just consuming basic off the shelf applications often fail to apply the appropriate
controls for their infrastructures, leaving opportunities for adversaries to take advantage
of them.” This section includes the subthemes Administrative Security Controls, Data
Governance and Access Control, and Vulnerability Management (see Table 6).
Table 6
Theme 3 Subthemes
Subtheme Participant Count Document Count
Administrative Security
Controls
136 668
Data Governance and access
control
129 241
Vulnerability management 62 244
Subtheme: Administrative and Technical Security Controls
Participants’ and industry documentation validated the academic research and
need for administrative security controls. All participants highlighted the need to use
security controls and policies to secure the organization, not just from a compliance
approach but to do security in a way that protects the organizations reputation, customers
and assets. Reaching compliance for compliance’s sake is not enough. P1 expressed this
need through the use of different framework,
Compliance is not enough if you're just compliant. In doing so, you’re just saying
you’re OK with security and pass all minimum checks and balances. Having a
good cyber strategy includes defense in depth, the risk management framework,
the CMC (Cyber Monitoring Center).
P8 stressed the significance of going beyond compliance-driven assessments, stated, the
least effective strategies, though commonly implemented, are those that are
compliance driven. The compliance strategies, which are the most pervasive ones
we find that they don't necessarily work because they certainly don't address
zeroday attacks, advanced persistent threats (APTs), or cyber-attacks that have
never been seen before.
Conducting thorough technology assessments that go beyond basic compliance
requirements can help organizations identify potential vulnerabilities and areas for
improvement.
All participants mentioned the NIST 800-53and, NIST 800-171 as the basis for
controls that can be used to secure networks and applications. P12 specifically mentioned
this,
I've seen quite a few organizations adhere to the NIST Risk Management
Framework. As it relates to identifying categorizing systems, prescribing the set
of controls, implementing those controls and then verifying the implementation of
those controls, creating security documentation packages, documenting
configuration settings, and performing everything that's recommended for the
initial risk management framework.
NIST recommends selecting a control baseline from the NIST 800-53B, “A control
baseline is a collection of controls from [SP 800-53] assembled to address the protection
needs of a group, organization, or community of interest” (p. 5). NIST and the SCP both
suggest tailored controls based on the risk profile of an organization or business. Tsiodra
et al., (2023) states “(discussion makers) understand their risks and prioritize the
implementation of security controls based on their risk profile, budget constraint and
security objectives” (p. 44469). Several of the researched journals mention the need to
tailor controls to meet the risk profile of the organization. The research suggests that
controls and security configurations can protect against security threats (Zhang et al.,
2022, Shreeve, et al., 2023, Rawindaran et al., 2023; Upadhyay & Panwar, 2022).
Participants reinforced the research and stressed the need to audit security controls
that are in place. P2 explained the difference between an ATO compliant network and a
secure network,
NIST secured standard network is going to be more secure. But not necessarily an
ATO network. I make this distinction between technical implementation of
security controls (NIST) and paperwork security for compliance. A paperwork
secured network is not a technically secure network.
P6 stated,
I've been in organizations that asked other organizations to come in and audit
their systems or paid for a third party come in audit the systems. These audits not
only look at the systems themselves but look at all the security controls. They
look at all the documentation and make assessments. They report on strengths and
weaknesses so we can mature and better secure the organization moving forward.
P1, P2, P3, P4, P5, P6, P8, P12, P14 mentioned the use of vulnerability scanners and
SEIM tools mixed with red team assessments to test the controls once they are in place.
P1 stated, “Cyber security needs the state of the ecosystem at the technical level, where
the vulnerabilities and threats reside. Doing bug bounty or pen testing (red teaming)
exercises can help validate the security controls that are implemented”. Administrative
controls are an integral part of a cyber security strategy. Security controls prevent
unauthorized access, can trigger detection of security incidents and minimize potential
damage to the business.
Participants have mentioned how administrative security controls have
relationships with risk management, vulnerability management and governance. Policies
and procedures ensure that security controls are applied and monitored. Validating these
controls though an audit or penetration testing (red team) exercise can show how teams
respond and provide real world insights into the controls ability to protect systems at the
appropriate risk level.
The GST framework states that a system is the combination of all the components,
their attributes and the complex relationships between these components. That the system
is not just the individual components but that the relationships, dependencies and
attributes is greater than the sum of the parts. Administrative controls are part of the
threat mitigations and dependent on the risk assessments to identify high value assets.
The level of administrative controls depends on the risk acceptance of the organization
and the resources applied to protect specific systems and data. These relationships and
interdependencies are much greater than the individual components or parts of a cyber
security strategy.
Subtheme: Data Governance and Access Control
Data governance and access controls are necessary for cybersecurity strategies in
order to protect specific types of data, systems and services from unauthorized access,
theft, damage and security incidents. Participants shared that data governance is a crucial
aspect of an organization's security controls, focusing on the management, protection, and
proper handling of sensitive information throughout the data lifecycle. The participants
emphasized that data governance needs to be part of the cyber security strategy and the
overall security baseline by establishing clear policies and procedures for data. According
to P1, P2 P5, P8, P9, P13, P14, data governance involves securing data through data
classification, access controls, and ensuring the data is accurate and available to business
teams. P5 stated,
Data governance can be performed in part by a data governance board that has
members of the IT teams, business and cyber security teams this internal
organization makes decisions on how data is encrypted, ingested into systems and
what processing is allowed to be shared. Data governance policies are managed,
written and enforced by this board.
The management of the data types used in core business systems are key to the business
protecting customer data privacy and continuing core functions. P1, P5, P14 mentioned
data tagging so that the organization knows where the PII, HIPAA (Health Insurance
Portability and Accountability Act) or other regulated data is stored and who has access.
P5 stated,
Organizations must prioritize the data in some way, so that everyone knows what
it is. PII is an easy one and if an organization isn't tagging their PII data, then it
makes it more difficult to know where that data is and how it is secured. This is
important especially when different privacy laws are beginning to come into
effect.
Participants validated the industry and academic research about the importance of
data protection standards and data governance. The research suggested that data loss is
one of the biggest issues in cyber security. That customer data, financial data and
intellectual property in business is often targeted and not always properly protected.
(Chidukwani et al., 2022; D’Arcy et al., 2020; Kemp et al., 2023; Sangari et al., 2022;
Tam et al., 2021). Participants highlighted the importance of implementing strong access
controls and monitoring mechanisms to ensure that only authorized individuals can
access sensitive data. This includes enforcing the principle of least privilege, regularly
reviewing and updating access permissions, and maintaining audit trails of data access
and modifications. All participants recommended the use of multi-factor authentication
(MFA). P1, P3, P4, P7, P8, P12 shared how some organizations use geo-blocking to
prevent traffic and cyber traffic from different countries from affecting their
organizations. P12 stated,
One thing you want to do is have a strong form of authentication, multi-factor
authentication and if you have the ability, do some type of conditional access
based on Active Directory. Conditional access allows the organization to limit the
footprint to known users are only in the US. You limit people from only being
able to access that system in the US, or you can narrow it down to a particular
state.
All participants recommended the use of strong passwords and following best
practices for passwords in NIST CSF, NIST SP 800-63B and ISO27001 that all states a
password length of more than 8 characters with uppercase, lowercase, special characters
and numbers. P6 explained how they have seen password resets and accounts locked. P6
suggested,
Another strategy that we use is forcing password resets, forcing more complex
passwords to be used, and limiting the number of attempts by setting timeouts. If
a person attempted to log in too many times they'd have to wait a period of time
before they can try to log in again.
Participants talked about data loss protection strategies and some of the policies
that are in use to protect data. P9 stated,
We are seeing implementations around not allowing USB drives either through
policy or through configuration controls within the end user devices to reduce the
risk of data leakage by loss of USB drives. We are also seeing restrictions on the
ability of employees to use outside mass cloud storage drives. Private Onedrives,
drop box technology, and other cloud environments like Google Drive are not
allowed.
P14 also stated data loss protection is being implemented in different organizations,
“We’re seeing that greater implementation of all the HBSS (host based security system)
modules to include the application control and the data loss prevention are now being
utilized”.
P1, P2, P6, P7, P11 mentioned access control on the networks and different technologies
that can reroute traffic to protect core assets or prevent unauthorized access.
P7 mentioned,
As a network engineer, we would implement traffic restrictions. Routers and
switches would have access control lists and black holes. A black hole is
essentially a routed interface that goes to nothing that you can set up quickly to
redirect malicious traffic. These were setup in tandem with internal firewall
configurations.
P6 explained how they have used network isolation technology to separate traffic,
Traffic can be isolated to specific VLANs so if you're not part of certain VLANs
when private data is processed, monitored and audited you will not access that
data. If you're not part of that VLAN you can't get to these resources.
P12 highlighted the need to have an access control policy and identity and access
management. P12 stated “the access control policy and identity and access management
seem to be tightly coupled and work well together from a policy perspective. And I think
there's a lot of synergy between those policies”. Participants talked about the need to
audit access control and authentication systems. P10 highlighted, "It's been my
experience a lot of companies have a lot of people are grandfathered with a lot of rights
they shouldn't have and they don't go back and really reexamine that.”
Participants also talked about how cloud native tools can be used for access
controls. P3 stated, a specific example where I work includes Azure’s conditional access.
Conditional access is a rules engine that will allow or deny access requests to cloud
services for their users or service principals. It has AI behind it and so it starts off very
broad and pretty permissive, but organizations can get very granular with their
access needs.
P1, P2, P6, P8, P10, P11, P13 stressed that access control should be easy for users
to navigate and use as well. P10 gives an example of a difficult access control
environment. P10 stated,
I've seen in some environments where it was incredibly locked down like you
couldn't remote from one system to another without going into a third party
access control, authenticating there, then getting a onetime password to
authenticate to that particular server. Then you have to do it over again for any
other tasks. It was incredibly painful, it took what should have been a 15 minute
job and it took two hours just because of the access control.
Participants stressed when applying access policies and access control an organization
has to keep the system administrators, IT support and end users in mind. Making a system
too secure can limit access to the resources making it cumbersome to use and less useful
for the business as a result.
GST states that the whole is greater than the sum of the parts. When looking at
this portion of a cyber security strategy the industry, participants and academic literature
show the complex interdependent relationships between all of the data and who can
access it interacts with every system and subsystem in the cyber and IT ecosystem. The
management of these security practices as part of the larger cyber strategy is key and has
impacts across a wide range of other security systems, controls, and business functions.
As P10 stated that if it is not done properly, it can have a negative impact of the user
experience and productivity.
Subtheme: Vulnerability Management
According to the research, cyber criminals and hackers use exploitable
vulnerabilities to gain access to networks and systems (Hart et al., 2020; Al-Sofyani et
al., 2023; Maniriho et al., 2022). Participants in this study and industry documents
validated these claims. All participants mentioned systems are easily exploitable due to
unmanaged vulnerabilities. P14 stated, “Fairly advanced actors who have exploited
systems very simply, due to poorly implemented security and vulnerability management.”
All participants mentioned patching and patch management as a way to mitigate
vulnerabilities in software and hardware. P7 stated the reason patches are needed for
software and hardware. P7 points out, “if there's a patch, it's because the vulnerability has
already been exploited and released. It is known about in the security and criminal
community. That's why we have the patch. Patching closes these vulnerabilities and must
be done” P1 stated the IT perspective on patching, “IT people look at patch management
as patch Tuesday. If you're patched, then you know you're not going to be hacked, or
you're less likely to be.”
Participants talked about how to automate patches and used different tools to
validate patching based on criticality. P1 stated, “but there are certain things that you can
mitigate risk and you can look at how you can automate certain patch processes, but
you're also going to have to still do the checks and balances”. P7 talked about automation
of security logging and patching “automate the boring stuff, but essentially add in that
level of automation so that your service level agreements are being hit and generating the
appropriate logging and auditing for the accountability for the cybersecurity
professionals”. P12 mentioned automation of security scanning tools, “implementing
automating some of those automatic tools that can go out and do vulnerability scanning
and things of that nature and also you know just aligning the top-level policy with all of
the cybersecurity control”.
Participants talked about patching hardware and the efficiencies of patching and
monitoring vulnerabilities in cloud providers. P12 shared their experience, stating, "I
would say a lot of companies seem to only focus on the infrastructure and the network. A
lot of people, don’t focus on the application or databases when it comes to vulnerability
testing and vulnerability assessments. People think that if they do some net scans or
quality scans of the infrastructure, then they're secure." P14 shared their experience with
automated patching, “We're actually using automated systems that help probe the system
or those assets on a recurring basis. And the fact that people know it's happening and
we've got automated applications for the patches”. P1 shared their perspective, “From a
tactical perspective of making sure your systems are locked down and not exposed,
configuration management includes the patching cycle”. P3 talked about this from a
cloud perspective, they're going to give you patch management. It's easy to turn on
Windows, update the built-in Windows Update integration if you’re using the
Azure cloud. Or it's easy to turn on the security logging and change drift
management using some of the automation inside of a cloud, like Azure.
P1, P2, P3, P4, P5, P10, P12, and P14 talked about knowing where software and
patches are coming from and removing legacy systems that are no longer supported. P2
stated,
It is important to know the source of your patches and software. Do regular
security checks into these items and incorporate the patch management into their
trusted sites and containers. This is how you can talk about baking security in.
P6 stated,
You should have patch management for the workstations. To help with patch
management for other devices, whether they are virtual or physical is to limit the
number of operating systems that would be allowed. As operating systems come
to end of life and no longer supported, we would work as an organization to
eliminate those operating systems.
NIST 800-53B has several families of controls that manage patching and
vulnerability management. System Information and integrity (SI-2) gives guidance on
patch managements, automated hardware and software updates, and scanning and
remediation of software flaws. This is carried through the maintenance family of controls
(MA-3) restricted tool use, and software updates and patches. Risk assessment family
(RA-5) covers vulnerability scanning, discoverable information, privileged access and
correlation of scanning information. Vulnerability analysis is also part of the system
acquisition family (SA-15), and developer testing and evaluation (SA-11). Participants
and industry documentation backup the academic research showing that vulnerability
management is necessary in a cyber security strategy to protect businesses and
organizations from being exploited and hacked by cyber criminals.
GST states that the whole is greater than the sum of the parts. When looking at
this portion of a cyber security strategy the industry, participants and academic literature
show the complex interdependent relationships between all of the data and who can
access it interacts with every system and subsystem in the cyber and IT ecosystem. Using
the GST framework and the participants’ views, vulnerability management has
relationships with security controls, security tools, incident management and cyber
hygiene / attack surface management. Vulnerability management is highly interdependent
on asset management, risk assessments and security controls. These relationships and
interdependencies are required to know what the vulnerabilities are, inform scanning
decisions and patch level decisions. Vulnerable system that are legacy and or EOL also
will affect and inform the risk assessment process that could change the security controls,
security baseline and alter the attack surface of the business. This shows that the system
is greater than the sum of individual components and the complexity of a cyber security
strategy will evolve to address changes in threats and vulnerabilities.
Theme 4: Foundational Security Practices & Cyber Hygiene
According to all the participants in this study, foundational security practices and
basic cyber hygiene such as antivirus, firewalls or perimeter security, access controls, and
basic backup of critical systems is fundamental to protecting business from cyber events.
Based on the literature, small businesses do not think cyber security is essential, and
common cyber security hygiene is missing (Gafni & Pavel, 2019; Tam et al., 2021).
Participants emphasized the importance of basic security measures, such as patch
management and access control in reducing an organization's attack surface. P10
highlighted this point, stating, "Reducing the attack surface is extremely important. I
think this is often overlooked by companies. Companies need to look at their exposure
(surface area) and old devices and decide why they have this and does this need to be on
the internet?" Participants also stated the need to tie technology to the business.
Rawindaran et al. (2023) states “SMEs may be particularly vulnerable to cyber
threats due to limited resources and expertise in cyber security” (p. 204). P11 stated,
“There's a large misconception when people say cyber, because it isn't a single discipline.
It can’t be taught without knowing the other parts of the IT puzzle.” This section includes
the subthemes Asset management, Backup capabilities, processes and procedures, Cyber
Hygiene and attack surface, Secure Baseline, and Technology Assessments (see Table 7).
Table 7
Theme 4 Subthemes
Subtheme Participant Count Document Count
Asset management: 42 282
Backup capabilities, processes and procedures 78 82
Cyber Hygiene and attack surface 39 64
Secure Baseline 30 570
Technology Assessments 32 48
Subtheme: Asset Management
Cybersecurity strategies should include some form of asset management in a
partnership with IT teams in order to do risk assessments, manage vulnerabilities and
assign controls to critical assets. IT asset management (ITAM) provides a means of
managing and monitoring the asset inventory. This is achieved through discovery,
inventory, and monitoring of the organizations assets. NIST SP 1800-5 provides several
benefits to IT as a whole and cybersecurity specifically. The NIST SP 1800-5a in
conjunction with the NIST 800-53r5 documents how different interfaces communicate
with security devices and systems, allows a record and tracking of attributed assets to the
organization, and audit software allowed on the network by the organization. The
academic research suggests that asset audits and an asset inventory help with threat
assessments, risk assessments, incident response (Shreeve, et al., 2023). All participants
in this study suggested that asset management is key to resolving cyber security issues.
P5, P13 and P14 stressed the significance of asset management, specifically, the
relationship between incident response, IT service management and asset management to
track assets and issues associated with infrastructure and applications. According to P5,
A real good IT Service Management system (ITSM) allows IT and Security to learn from
issues that happened and have it documented. The incident will be cataloged and the
solutions implemented. If the incident happens again in the environment we know what
do and how to build the defenses prior to the next attack.
P13 mentioned asset inventory and the classification or value to the business of these
assets. P13 stated, "Businesses need a good inventory of assets including classifying them
by business processes and ensuring a good understanding of the architectural and
infrastructural landscape." P14 stated, “A key component of applying security controls
was ensuring that we did proper tracing of the pertinent controls against the key assets
across the enterprise. To do this, we needed a good asset management system.” P1
explained how asset management is key in the process hierarchy of assessing risk and
assigning controls. P1 also stressed the relationship between assets and the ability to do
risk assessments, stating, "To assess and prioritize the various risks and see what kind of
vulnerabilities there are, you need to have your assets assessed." P9 showed the
relationship between policies, asset management and security risk assessments. P9 stated,
We have a lot of policies that mandate and require asset inventory to happen on a
quarterly basis right now. Then we've got the continual reviews and the PMRS where the
project managers must come and do a monthly report on some of our higher risk.
Asset management is a major part of a cybersecurity strategy and enables risk
management, risk assessments, is critical to vulnerability management. The GST
framework stated that a system is more than just the sum of the individual components.
The relationships and interdependencies of these components are part of the overall
interactions within a system. Through the GST framework, participants showed how
these are complex relationships with inputs and output of other larger processes within a
holistic cybersecurity strategy. Asset management is used to inform risk assessments and
risk management decisions, track inventory of physical and software assets for
vulnerability management and the relationships between assets is used for incident
management isolations and scanning tools.
Subtheme: Backup Capabilities, Processes, and Procedures
Participants reinforced the academic literature and industry documentation when it
comes to backup, recover and contingency plans. NIST 800-53r5 refers to backups as a
major part of contingency planning. As the participants have stated, exposure to a cyber
event is not a matter of “if but when” a cyber incident will affect a business. A cyber
event or misconfiguration could result in a system outage degrading critical system
components or core business functionality. All participants mentioned the need for testing
the backup procedures and having them well documented. P1, P4, P7, P8, P13, P14
mentioned how involved a backup or contingency plan should be, so that a recovery can
take place. P8 stated, “I have been involved with financial institutions where the cost of
an outage far outweighed the cost of an adaptive response including processes,
procedures and restorative operations that were automated and could sustain business
operations”. P4 indicated multiple times how their customers were saved by having a
good backup system, specifically an offsite backup to protect the data from ransomware.
P4 described a company hit with a phishing scam that had people inside their network,
messing with their billing. If they had already been managing backups on and off
site, then they wouldn’t need to try to rebuild systems and services. If they had it
just instantly cloned everything at the end of the day as a full backup and store a
copy somewhere, they could have been quickly operational again.
All participants stated that when something disastrous happens such as a cyber incident,
malware infection, ransomware or just a mistake that deleted data, businesses can utilize
the backup to get up and operational again.
All participants talked about the need to validate backup procedures, processes
and backups. P1, P2, P4, P5, P6, P7, P8, P9 P10, P14 specifically talked about drilling
procedures, processes and validating the backup during a live test. These participants
called them drills or fire drills. P7 explained this concept stating,
Practice like you fight. Lots of organizations have backups and processes on
paper. If they don’t run drills, do fail over testing to hand over operations to
another site and practice the procedures for every role and responsibility, then
when something happens people don’t know how to respond or who to call. This
has additional impacts on the business.
P10 talked about the need to test these processes and remove single points of failure that
exists either through access, knowledge or capabilities because if the recovery process
fails and an outage can become a larger threat or possible disaster. P10 suggested,
You’re in a restore scenario, the critical systems are down and now it's costing the
company money. You can't even fix it because you don't have access rights. The
process was not tested to restore the system and the people that can are on
vacation. Now you’re in a disaster scenario with major impacts the business.
P1, P3, P4, P8 talked about the value of a distributed backup system to mitigate
some of the risk associated with ransomware attacks and responding to ransomware
events. P4 stated, “the biggest thing that I've seen recently is the rise of all the
ransomware. Having a good, distributed backup system is invaluable to maintain business
operations.” P4 went into details about how the use of simple backup techniques can
allow a company to return to operations after a security incident involving phishing that
led to a ransomware attack. P4 described, “I've seen a company get hit with a couple
different ransomware attacks. They just need to get up and operational again. Having the
backup there enabled them to restore right away.” This backs up the research by
Humayun et al., (2021), that recommended having offline backups since attackers’ target
network connect backup systems. P10 highlighted the importance of backups of
applications, configurations and data in relation to a disaster or cyber event. P10 indicated
that to protect against ransomware, “A good backups of all the data is key. Without a
good backup you will either be forced to pay the ransom or lose all of the businesses
data.”
P1, P2, P3, P5, P7, P12, P14 mentioned the use of cloud services for backups. P2
mentioned using a cloud vendor for a multi-site data center. P2 stated,
Cloud technology is based on regional availability zones (AZ) these are different
physical locations managed by the cloud vendors. This is done as a form of
redundancy so that if one AZ goes down, communication can flow from another
AZ. When you talk about disaster recovery, you're dealing with backups of data
or warm/cold sites. This is based on the risk assessment and the response time
required to return to operations. This hot, warm or cold site can be provided by
mirroring existing cloud environments in another AZ, and or region.
P1, P2, P3, P7, P8, P12, P14 went further, describing setting up a global resiliency system
using cloud technologies. P3 stated,
Cloud infrastructure has a lot of benefits that comes with the cost. One of those
benefits is global resiliency and backups. This is incredibly important. I
recommend not running your business out of only one region. Businesses should
have either offsite or second tiered backups, and break glass accounts (emergency
management accounts for when normal administrator accounts cannot be used)
for logging in in case a disaster occurs.
Participants provided a few methods of securing backups to prevent ransomware from
affecting the backup. P11 stated,
The only real way to prevent a ransomware attack costing the company money is
a backup that has no direct access to your network. You're probably going to have
network attached storage for files or people sharing and collaborating. But if
you're doing either a nightly backup or a stage backup with that particular thing,
there should be a place that you're putting that particular backup that isn't directly
accessible or only accessible during specific times.
P4 stated the importance again stating having a good distributed backup system is
“absolutely awesome.” Participants talked about the full recovery plan as well. P7
highlights this in a strategic perspective, stating,
It is really important for an organization setting up a recovery plan to have the
means of reconvening data in an off-site facility and more importantly
offnetwork. Backups should not be on the network, because if the production
network is compromised, then your backups are compromised, too. Then you just
wasted all that time and money to store these backups.
This is especially important with ransomware that will encrypt backups that are network
connected.
P1, P2, P4, P6, P9, P11, P13 also talked about using backups and restore
procedures as part of a cyber tabletop exercise. According to P6,
Take periodic backups. And take them offline, encrypt them, and put them in a
safe space. Run a tabletop scenario. This is done by picking a network or system
and running the exercise assuming this system going to be affected by malware.
What are the roles and responsibilities? Walk through the procedure, and get
management involved so they know how long it can take.
During a tabletop exercise, P1, P2, P4, P6, P9, P11, P13 stated the need for executives
and business leaders to be involved as stakeholders and the technical teams and business
teams should be able to answer these questions during the tabletop scenario: What do we
do (roles and responsibilities)? What is documented and where is it? Is there a restore
procedure written down that includes configurations? Are you taking your backups
offline, where are they? Do you have a documentation of all your systems? How long
will it take you to sanitize your systems and bring them bring them back to speed?
The need for a backup strategy as part of the large cyber security strategy
demonstrates how interconnected backups, policies and procedures are to the function of
an organization or business as represented by GST. The ransomware threat and use of
tabletop exercise highlights the complex relationships between backup systems, policies,
procedures, team roles, business stakeholders, incident response, and security controls.
Participants and academic documentation highlights the need for offsite backups as part
of a larger holistic cyber security strategy.
Subtheme: Cyber Hygiene and Attack Surface: Legacy Systems, Unnecessary Ports/
Protocols and Connections
Cyber security strategies need to implement the idea of cyber hygiene.
Implementing strong security practices and maintaining good cyber hygiene are essential
components of a cybersecurity strategy aligned with business needs. The participants
emphasized the importance of basic security measures, such as patch management, strong
passwords, access control, and reducing the organization's attack surface. Patch
management was covered in more detail in theme 3. All participants stated that
unnecessary communications should be removed from ports, protocols and technology to
reduce the attack surface. P2 mentioned the reason this is important and why this is an
issue. P2 stated, the Internet is meant to be the interchange of open and free ideas. It was
designed for the ability to talk to anyone on these different services in these ports.
Obviously this became a big concern when they exposed (need for cyber security).
P1, P2, P5, P10, P14 mentioned the removal of legacy systems and an end-of-life
systems (EOL) that are no longer patched by vendors. P2 stated,
If an EOL (end of life) systems functionality can be absorbed into a new system
that provided better capabilities, do that. Replace the systems with things that
have patches and support. Old hardware and software that is EOL has no support
and is very vulnerable to being exploited by hackers and malware.
P14 suggested,
If you can’t replace legacy or EOL systems, because it is not cost effective or the
capability doesn’t exist, then you need to limit the access to these systems or
devices. Secure them and make it super restrictive. Add additional firewalls and
make sure they can’t access the internet.
P10 stated,
As a cyber professional, having old stuff in the network is scary especially if it is
critical or high priority systems. Some automated monitoring tools don’t work
with these old systems. A lot of time and resources are spent protecting old gear.
Participants mentioned closing ports and protocols that are unnecessary and
reducing the attack surface of a business. NIST SP 800-53r5 refers to the attack surface
as “Attack surface reduction is a means of reducing risk to organizations by giving
attackers less opportunity to exploit weaknesses or deficiencies”(NIST, 2020, p. 282). P1,
P2, P3, P4, P6 reiterated the academic and industry documents emphasizing that
businesses should turn off unused ports and protocols, removing unnecessary remote
communication, and limiting exposure of systems to the internet. P3 stated, “We use tools
that provided recommendations to prevent cyber incidents. These tools scan for open
ports and protocol. I need to turn off these services or I need to turn off these ports to
prevent cyber incidents.” P2 stated, limiting that attack surface and the only systems that
should be talking are allowed to talk through the firewall. Audit the ACLs on the routers
and firewalls, and block ports that are not being used from incoming traffic.
P6 talked about limiting access to system through networking best practices, limiting
network protocols at the VLAN, ”We could limit the VLAN to only allow certain traffic.
(You should) only allow certain activity to go through certain ports, and (be) really
stringent on high value assets”. P2 suggested,
Limiting the attack surface so that the systems that need to communicate through
the internet are the only things that should be allowed to communicate. Because if
it doesn't need to talk to something, it shouldn't be talking to something and that
way you limit the attack surface. Organizations that have a very focused, or
narrowly focused type of communication, manage the type of interactions
between systems that they want. So we've been able to lock them down and
reduce the attack surface this way fairly easily.
P1, P2, P3, P6, P7, 10, P11 discussed how to limit the attack surface to protect
organizations using network devices. P10 stated, "Monitor the network traffic use IDS
(intrusion detection system) and IPS (intrusion protection system)". P6 mentioned, "a
business needs intrusion detection systems, multiple firewalls, and technical policies to
take a layers approach to network monitoring and security." A multi-layered approach to
technical controls can help prevent and detect potential threats. P6 also mentioned the use
of honey pots and the ability to report cyber-criminal activity. P6 stated,
I would implement firewalls, strict firewall rules, monitoring tools, and honey
pots. I think organizations do themselves with disservice by not sticking honey
pots out there and being able to catch traffic. Once something happens to the
honeypot you can update your threats, recovery strategy, and cyber strategy. You
also have some information that you can give to the authorities so that they can go
and track these individuals down.
Honey pots are decoy systems that can be used to attract attackers to gather information
about threats and notify defenders of attackers attempt access honey pots by unauthorized
users (NIST, 2016; NIST, 2020).
P1, P10, P12, P14 mentioned limiting access of systems based on job functions to
protect the organization. P10 stated, "I am very big on restricting access. I need
justification for why someone needs access to things. I strongly recommend separation of
duties." Granting access based on the principle of least privilege and regularly reviewing
and adjusting access rights helps minimize the potential impact of a security breach. This
also prevents users or exploited accounts from accessing data or systems they do not
need, such as HR (Human Resources) systems and payroll (NIST, 2017).
P1, P4, P10, P14 talked about setting up test environments for development and
new software to check for open ports and the needs of a specific system. P4 found that
software was often tested on the operational or business network leaving the businesses
vulnerable. According to P4,
During an audit, I noticed that all these ports and services were opened. Even if
there's nothing listening. You don't have a minimum set of ports and protocols,
instead they have the most permissive set so that you could just push whatever
changes you want. This violates security controls. These system tests need to be
managed in a test environment.
P4 talked about how these issues happen in development environments. P4 stated, what
I've found is developers often times will develop permissively. When you don't
have good security procedures and testing in place as part of CI CD creates an
issue. Developers will sit down and make this service talk to that service and try
to open up something. It doesn't quite work so they end up just opening a whole
bunch of stuff.
Limiting the attack surface is key for a business to reduce risks and address
threats. By removing unused ports and protocols, limiting the amount of internet facing
systems, and closely monitoring development environments as part of the overall cyber
strategy a business can reduce the number of vulnerabilities and address risks from the
risk assessments. Cyber hygiene is the minimum expectation of security a business
should have and according to participants this could reduce cyber-attacks.
Cyber hygiene and limiting the attack surface are used to address risks found
during the risk assessments, inform monitoring operations, reduce threats, and have a
basic level of data protection. Reducing the attack surface is dependent on vulnerability
scanning, administrative and technical security controls, and governance. As explained by
interconnectivity of systems according to GST, governance policies have a strong
interdependency with cyber hygiene because they enforce user privileges, inform
developers how to operate in testing environments.
Subtheme: Secure Baseline Configurations
All participants mentioned securing the baseline of the systems, network and
endpoints through the use of Security Technical Implementation Guides (STIGs),
different cloud technologies and network technologies. Participants talked about the
importance of maintaining a baseline of network and systems as it relates to security
functions and detecting incidents.
P1, P4, P6, P7, P8, P11, P13 talked about the need for a baseline the network
traffic and using a logging perspective to identify anomalous activities in a network for
incident response and protecting from zero-day exploits by hackers. P4 stated,
Very small changes in behavior where normally doesn’t just add up. It can
multiply. With a bit of canned traffic, and a controller monitoring the pipe that is
what gives you the baseline. And I think this illuminates that that baseline
information, that baseline information based on ground truth is just so important.
P3 mentioned the importance of a network baseline and understanding traffic
from a network management perspective. P3 stated,
Look at the expected communication, for example, the traffic, the ports, the
protocols, the IP addresses, for a month. Then look at another month. You can
compare months or it can go week to week or minute. You can see if you have a
shifting baseline or have a fairly stacked baseline. It depends on how advanced
organization is. But basically, looking for differences in the network traffic.
P3 talked about the baseline and documentation for cloud providers. P3 mentioned
some of the native tools in cloud providers that can help with controlling the secure
baseline if a business’s operations are cloud based. According to P3,
The cloud services native functionality is to secure my workloads as securely as
possible. Luckily a lot of the cloud providers publish these secure baselines or
best practices on how they recommend customers configure the workloads in the
most secure manner possible. What we find though, is that is a 75-80% solution
and customers and organizations generally want to go a little bit further and put
their own mix or their own flavor of cybersecurity.
Participants mentioned a secure library or templates for virtual and cloud systems
that are hardened by security professionals to maintain a security baseline. P14 “If you
are going to build an AMI (Amazon Machine Image) and image any instance like that,
you have to pull that baseline from our catalog that has already been hardened, it's built
for the major specific uses.”
Several participants mentioned controlling the baseline through change
management practices. P5 gave their view and need for change management, stating “A
real change management system would be nice. You know an actual rollback plan”. P11
explained the need for change management policies, stating, “change management policy,
I guess policy is the best word for that. That would be in place to make sure that random
patches or unimproved patches aren't being pushed out.” P11 also stated aspects of the
change management policy, “So your change management should happen anytime a
change to the system happens, period.” P3 talked about the importance of change
management as a multi-part process, change management is massive. It is so easy for
workloads, especially when you know you have something so accessible like a cloud for
things to just kind of drift and not be documented. So there's two parts, one is change
management from the process level. I have a change management process from my
workload. I'm following that. I have change management process from the security risk
assessment process.
P6 mentioned using software to control the baseline and configuration and as a
validation mechanism of security controls for the minimum secure baseline. P6
mentioned documented baselines for server and end point operating systems, stating,
“Operating systems have baselines and that those baselines are documented. The
baselines are also upgrade consecutively throughout the year. It maybe that some years
would be twice a year, some years would be quarterly to reduce any potential attack.” P2
stated,
I really like configuration management tools that are enforcing a baseline. These
tools prevent system configurations from deviating from a standardized baseline
without an exception without and a check and balance from the source repository.
You have authorship and a reason to understand why there's a variation in a
baseline, or why the variation in the baseline is required due to a ticketing
process.
P1, P6, P9, P12 mentioned STIGs as part of securing the system baseline. P1
stated, “implement some of these STIGs or, you know, security implementations to
harden their network and so forth.” P12 stated, “I've been utilizing STIGS, the security
technical implementation guides as it relates to the hardening, standards and how you hire
infrastructure.” P6 suggested that controlling the baseline also enables vulnerability
management to be more efficient. P6 stated, “look at what versions and STIGs that are
out there. Look at the CVE's (Common Vulnerabilities and Exposures) that are out there,
and determine what you want to implement. Then work and collaborate with the
administrative teams”. P9 suggested STIGs as a validation of the servers configuration
based on customer needs, stating, “We use just the STIGS to ensure the servers are set up
properly. We determine if we are up to date on all the configuration controls that that
customer requires and that's done through the CISO doing an inventory.”
Participants showed the relationship between maintaining the baseline
configurations also to maintain the patching of system vulnerabilities and the relationship
between these 2 sub themes as well as operational support from the system admins. This
ties to the General Systems Theory Framework showing how these 2 themes of cyber
strategy are not sole functioning as unique parts but are intertwined to function together
as part of the larger security posture. P6 indicated,
Good support systems that is well documented that are collaborated on by not
only the admin community but also the security community so that both can use it
do an intermittent scans and using those tools those scanning tools to scan
baseline systems. Come up with collaborative effort to not only implement
baselines but implement patching.
P1 stated,
Sustaining a security posture is not just setting something up once and walking
away. But it's having that regular assessment and the vulnerability scans. It is
good to see what your network looks like, including the highs and even more
importantly, what it looked like last time you did a big scan.
The GST framework states that a system is the combination of all the components,
their attributes and the complex relationships between these components. That the system
is not just the individual components but that the relationships, dependencies and
attributes is greater than the sum of the parts. Securing the baseline of a business requires
security controls, monitoring and vulnerability management. To maintain the baseline
over time and not let entropy take over. The interdependencies between updating security
controls based on an updated risk assessment and new threats in the cyber land scape is
used to manage the security baseline. Vulnerability
management is needed to patch the baseline and close vulnerabilities in new and updated
software and hardware. Having polices and processes that support cyber hygiene
strengthen the security baseline my mitigating unnecessary traffic from the business to
the internet and enforcing policies such as strong passwords. This shows that secure
baseline is a complex interdependent system of systems that is part of the overall holistic
cyber security strategy.
Subtheme: Technology Assessments
New tech is not always good tech. Technology that is not core business function
or a capability based on the core business needs increases the attack surface and
management of technical teams. P1, P2, P4 and P9 highlighted their concerns with new
technologies, pointing out the issues with IoT devices. P4 stated, “If your business is a
grocery store, don't use a bunch of insecure protocols and IoT devices. The core business
doesn't need that. Just reduce your footprint.” P1, P2 and P4 also stated concerns they
have found and experienced with IoT devices. P2 stated,
If this IoT device doesn't have the ability to log events, and it doesn't have the
ability to be secured because of the number of threats and vulnerabilities going on
in the world. We're going to lock it down so that IoT devices can only talk to it's
set its controllers and do its specific job.
P1 and P4 suggested that there is a shift to attacking IoT devices and industrial controls to
disrupt energy systems, HVAC [Heating, Ventilation, and Air Conditioning], logistics,
oil, gas and water services. These devices need extra security and in most cases should
not be on the internet. P1 and P9 suggested the use of an enterprise steering committee
around new technologies specifically mentioning guidelines of use and the restricted use
of sensitive data such as PII and generative AI technologies. P9 recommended, Going
through a board approval for all new technology. Showing what data, a system uses, what
technologies and how the system is expected to work so that security can test and audit
the functionality and business executives understand and accept the risk.
Small businesses may have a very simple ATO process for bringing in new systems and
equipment but these should be assessed under the risk management for the organization.
As P4 mentioned this when talking about managing risk through risk transference, “Until
you reach a level of security capability or a size of an organization where you really can
control everything on your own, your whole goal should be to offload as much risk as
possible to other people”.
P1, P2, P4, P6, P8, P9, P14 mentioned authority to operate or ATO as part for the
accreditation process for a system to be put into production. P14 talked about how his
organization is combining ATO as part of the security assessments into the contracting
assessments. According to P14,
Systems are going to be graded on not just the functionality or how well things
are delivered, but also the security status and the risk report. This will be part of
the CISO risk heat map score of your system. Communicating these activities
created a shared responsibility model with projects being very proactive and
gaining a much greater understanding of what the risk management framework
entails.
P2 had a different experience with the ATO process “the implementation of the ATO
process itself was just ineffective because it didn't do anything to guarantee the security
posture it was just a compliance process”. P8 shared their concerns that ATO was not
enough, stating,
Product teams implement the security controls and they may or may not
document it, and it's done explicitly just to get an ATO (authority to operate).
Those systems are still vulnerable, even though they're scanned they're vulnerable
because of 0 days.
According to NIST 800-37 (2018), ATO is part of the risk management framework,
Authorizing official issuing an authorization to operate or a common
control authorization. The risk acceptance statement indicates the explicit
acceptance of the security and privacy risk incurred from the use of a shared
system, service, or application with respect to the customer organization
information processed, stored, or transmitted by or through the shared or
cloud system, service, or application. (p.
148).
Technology assessments have relationships with the security baseline and risk
management of an organization. Participants recommended new technologies be tested
for vulnerabilities and old technologies be removed or secured with additional controls to
reduce the risk to the organization. Participants also recommended that new systems are
vetted through a process to validate security controls through an organizational
accreditation process.
As described by GST, relationships, dependencies and attributes creates a systems
that is greater than the sum of the parts. Technology assessments allow the business to
understand additional risk using new technology such as IoT devices, this can limit the
attack surface by not using insecure devices. Risk management is part of the overall ATO
process and the dependencies of technical and administrative security controls being
applied and tested as part of the overall technology assessment. The interdependencies
between updating security controls based on an updated risk assessment and new threats
in the cyber land scape is used to manage the security baseline and are applied as part of
the ATO process. The technical assessments are then used to update asset management as
systems are retired and new system are integrated into the business. The relationships,
and dependencies between these security tenants shows that a cybersecurity strategy is
more than the sum of the parts but that there are complex relationships that change and
evolve over the lifecycle of a cyber security strategy.
Theme 5: Proactive Security and Incident Response
According to all participants proactive security and incident response are key
components of a cyber security strategy. These are the practices used to monitor and test
the cyber security strategy for effectiveness. Proactive security is the preparation for a
cyber event to take place. Incident response is how the organization will respond to the
cyber event or security incident. Based on the literature, small businesses need detailed
security plans, the ability to validate security processes and procedures, and incent
response capabilities to respond to hacks and cyber-attacks in a timely manner (Hoppe et
al., 2021; Lloyd, 2020; Benz & Chatterjee, 2020). This is broken down into three
subthemes incident response, threat hunting and phishing campaigns (see Table 8). The
literature suggests that continuous monitoring is part of proactive security. This was a
major theme during data collection and is theme 6 of this study due to the amount of
information participants provided.
Table 8
Theme 5 Subthemes
Subtheme Participant Count Document Count
Incident response 96 95
Threat hunting & Penetration
Testing
41 71
Phishing Campaigns 37 52
Subtheme: Incident Response
The research shows how SMEs may not have the resources, knowledge or
investment to appropriately protect data, customers and core business functions
(Chidukwani et al., 2022; Gafni & Pavel, 2019; Kemp et al., 2023; Sangari et al., 2022).
Participants in this study stress the importance of incident response as part of a cyber
security strategy. Participants reinforced the academic and industry documentation which
shows increasing levels of sophistication by hackers, the use of zero-day exploits and
malware to infect and damage business capabilities (Limna et al., 2023; Oruj, 2023;
Medoh & Telukdarie, 2022. P1, P3, P4, P8, P13, P14 mentioned the access a hacker or
adversary has once they get into the network. P1 mentioned, “Someone breaks into my
network. They probably have access to our Slack. They probably have access to our
servers. Probably have access to a lot of things.” Hackers that get access to a business
network can disrupt core business processes, steal data, steal money from corporate
accounts, and delete files.
Industry documentation has several approaches to incident management and
response. NIST 800-53B has a whole family of controls and recommendations for
incident response. NIST also published a guide for contingency planning that details
incident response activities recommended for the US Federal Government titled
Contingency Planning Guide for Federal Information Systems. NIST SP 800-34r states
“Cyber Incident Response Planning is a type of plan that normally focuses on detection,
response, and recovery to a computer security incident or event” (NIST, 2010, p.7). The
incident response plan has procedures that can address cyber-attacks against and
organization information systems (Benz & Chatterjee, 2020; Hoppe et al., 2021; Lloyd,
2020; NIST 800-34r1).
P1, P6, P7, P8, P9, P10, P11, P14 talked about the processes for incident
management and remediation. P9 stated,
We have remediation processes that we would go through if there's an incident.
We bring together cyber security professionals, project managers, and technical
leads to do a deep dive and then establish rapid remediation steps. The run books
or processes established state: instantly cut off the network. Isolate the incident
and then figure out what happened before you do anything else.
P1 indicated why incident response plans need to include root cause analysis, stating
“doing that root cause analysis after an incident or hack, is crucial to recovering and
ensuring that something like that doesn't happen again.”
P1, P2, P7, P8, P9, P11, P13, P14 stressed the importance of these types of plans
and the communication of cyber incidents. P8 talked about their experiences with cyber
strategies and incident response stating,
I see a big gap in a lot of the strategies or deficiencies in the strategies which are
to implement the controls and not necessarily focus on what happens when you
have an incident. It is important to know how to respond and how to have
sustained operations if they're critical. Few organizations go that far to implement
those kinds of response options and they are critical.
All participants talked about communication of plans with business and IT
partners is key. P3 stressed that these are key relationships and very important during a
cyber incident, stating,
If there is a hack or something else coming up they can get ahead of it, but if
organizations aren't partnered and are playing the blame game, these things
become very hostile and an incident can sometimes be a death sentence to an
organization or a business. Transparency and communication are probably the
biggest two tools for properly trained security teams. Transparent
communications are very important. (during a cyber incident).
P4 talked about their experience with communication plans and transparency as part of an
incident response plan. P4 stated,
The solution is to not get hacked but if you are, immediate disclosure with good
solid follow-up with business partners and customers. If something has happened,
the faster your organization can move and the faster you can speak to the people
who are concerned about what might be happening, and the more transparent you
appear, the more they are going to trust you and trust your work in the future.
This validates the research about disclosures by Fang et al., (2023) that suggests
customers have a negative rhetoric about an organization that are not transparent
about their cyber response during a security or cyber incident.
Participants and industry documentation validated that incident response cannot
exist alone in the organization. The literature, industry guides, and participants state how
incident response leverages communication plans, risk managements techniques, relays
on security controls and tools to protect the baseline of the organization. This also
highlights what GST assertion that the sum of a complex system is greater than the
individual parts. This research highlights some of the complex, relationships, and
interdependencies that exist between incident response and a holist cyber security
strategy. Participants and academic research suggests this is especially complex when
dealing with customer data loss and public disclosures.
Subtheme: Threat Hunting & Penetration Testing
Threat hunting is part of the proactive preventative and corrective measures that
researchers suggest to protect businesses (Daricili & Celik, 2022; Falch et al., 2023;
Medoh & Telukdarie, 2022). The research suggests that organizations use proactive
security measures to protect their data and IT resources such as penetration testing where
skilled red team members attempt to exploit a vulnerability and threat hunting that uses
indicators of compromise to determine if a compromise has already occurred (Aldauiji, et
al., 2022; Ajmal et al., 2021; Dekel et al., 2023; Nursidiq & Lim, 2023). All participants
reinforced the research stating red teaming is a way to test the cyber protections and
search for vulnerabilities and that threat hunting can look for compromises that have
occurred to better inform incident response of potential security issues. P7 stated, "Threat
hunting is a proactive approach to security. You address the environment with a mindset
that an incident isn't going to happen. As threat hunters, the whole process is based on the
idea that it’s very likely a cyber incident has already happened.” P4 also talked about
their experience with threat hunting, stating,
Come from shops with active, very active threat hunting. There are groups that all
they do, all day long, is pull through alerts and threat data and try to see what they
can find. In a few of these incidents, they come across something unusual the day
that it happens.
P1 shared their thoughts about compliance and that threat hunting can be part of
continuous monitoring, stating,
Pretty much all companies and organizations out there that have been hacked in
general have been compliant, but they haven't really strengthened their hardened
their networks and the machines to the point where their strategy is continuously
monitoring, improving and threat hunting.
NIST SP 800-53Ar5 has a full section dedicated to the assessment and maturity of
threat hunting (RA-10) and penetration testing (SA-11). P1 spoke about the validation
aspect of penetration testing. P8 shared an experience where controls were not validated
through a proactive pen testing, “there's a great big hope and prayer that the controls
actually work, which personally I find very ineffective. Every time I've seen a security
incident and there's business loss, it's because the security controls were insufficient to
deal with the cyber activity that occurred.”
P1, P3, P4, P7, P8, P10, P12, P13, P14 shared their experiences and the value of
doing proactive cyber security and validation as part of a cyber strategy. P1 “doing bug
bounty or pen testing, red teaming this different type of exercises can help validate the
security controls, overall continuous monitoring practices, and your incident response.”
P1, P3, P7, P8 P12, P14 spoke about the validation of systems resiliency and the
validation of incident response through penetration testing. P8 stated, what really matters
is how systems perform under the real stresses of a purple or a red team using modern
penetration techniques. Speed becomes a critical factor in executing, detecting, and then
engaging response options. These drills are best performed when the blue team or
defenders are not aware of the assessment. P3 stated, “Some of the best organizations
will do their own pest testing, pen testing, or external auditing assessments, either black
box or white box.” These participants talked about using penetration testing or red team
exercise validation methods as part of the testing of incident response processes,
procedures, tools and techniques.
Based on the literature, participants in this study, and industry documentation, the
GST framework shows how different aspects or pillars of a cybersecurity strategy can be
used to validate other pillars, such as penetration testing (pen testing) validating, security
controls and incident response. The different components or sub systems of a cyber
security strategy and a cyber strategy when in operation inform, validate and strengthen
each other through these relationships.
Subtheme: Phishing Campaigns
The literature stated that small to medium business (SMEs) are the most
victimized group by ransomware and this type of cyber-attack is often proliferated
through phishing emails (Kshetri & Voas, 2022, Farion-Melnyk et al., 2021, Connolly &
Wall, 2019; Gonzalez & Hayajneh, 2017). Participants in this study validated the
literature stating that phishing is one of the biggest issues they see as cyber professionals
because it targets the end users through a form of social engineering that they often fall
victim to. P1 had a scenario that was shared about how hackers had stolen money from
several executives using targeted social engineering attacks. P1 stated,
A lot of the executives and board members would get a text message, supposedly
from the President or CEO. The supposed President and CEO of the company was
messaging a board member or an executive to send them a gift card of like 50
bucks. And you will be surprised at how many of these executives actually sent a
gift card of 50 bucks to some random hacker, and then later called me as a cyber
guy. It was interesting because he was on his personal cell phone and outside my
parameters, but I recommended that he never do that again. I pointed out that as
an executive, they should have the CEO/President should already be programmed
in his phone. If you get a message from a number you don’t know. Don’t respond.
P1, P3, P4, P7, P9, P10, P11, P13 talked about phishing campaigns and the need
to educate users of all levels of phishing emails. P7 mentioned the amount of malware
that can come in through emails and attachments, stating, “Training users in social
engineering techniques specifically looking out for phishing emails is important. I have
seen malicious code transmitted through phishing emails, web links, and adversaries have
moved to using documents”.
P1, P3, P4, P7, P9, P10, P11, P13 stated there are several ways companies can
train and validate the users’ ability to spot phishing emails internally by adding phishing
campaigns to their proactive security strategies. P4 stated, “There are plenty of ways to
identify potential phishing and email scams that an organization can implement
internally. Training the users and running phishing simulations.” P1 stated,
Security needs to make sure that education and information gets out to others and
providing that material on either a weekly, monthly, or quarterly basis. Send out e-mail
test to see if people know how to catch spear phishing (attempts) P13 reiterated the
importance of phishing campaigns and education, stating “Educating their own users
around phishing attacks or receiving e-mail or uploading into your environment that can
have that can have malware attached is important”.
P1, P4, and P9 also stated importance and the reasoning behind phishing
campaigns and this level of training and education. P9 stated this very well,
Training for phishing is super important, because we probably let 0 things in
(malware), but phishing emails and random sales emails still get into your inbox.
So, you have got to be aware of what phishing emails look like as part of the end
user training.
The scale of this type of cyber threat is so prolific that industry leader NIST has a single
document that is only about phishing called the NIST Phish Scale User Guide or NIST
TN 2276 by Jacob Dawkins. This document validates the responses of participants with
detailed explanations of the indicators of a phishing email such as attachments,
misspellings of words, the use of hyperlinks (Dawkins, 2023). The need for a phishing
policy as part of a cyber security strategy is tied to education of the user base, and
technical controls to block or filter emails that could contain malicious attachments.
Participants, industry and academic research shows that a cyber security strategy
needs to have training validations for end users such as a phishing campaign. GST states
that the sum of a system is greater than the individual parts due to the complexity of the
system. Effective phishing campaigns are used to validate user trainings and need
technical controls to support and strengthen its functions to be effective as part of a cyber
security strategy. The relationships between these techniques, tools and capabilities are
why a cyber security strategy is a complex open system with many interdependencies.
Theme 6: Continuous Monitoring
According to all participants in this study, continuous monitoring and continuous
assessments of current cyber security tools, processes policies and practices are
fundamental to maturing the cyber security practice. A cyber security strategy must have
continuous monitoring, and assessment to ensure that it is protecting the business and
assets from current threats and mitigating the most recent risks.
All participants backup the literature stating continuous monitoring is one of the
most effective ways to maintaining a strong security posture and detecting potential
threats in a timely manner. According to Tam et al. (2020), “Many attacks have no
obvious symptoms. Active monitoring is required for subtle attacks such as data
exfiltration, man in the middle, spyware, etc.” Organizations must continuously adapt and
update their monitoring strategies to keep pace with the evolving threat landscape and
ensure the protection of their networks, systems, and data. This section includes the
subthemes Assessments of cyber strategies, policies and procedures, and Continuous
Assessments & Continuous monitoring (see Table 9).
Table 9
Theme 6 Subthemes
Subtheme Participant Count Document Count
Assessments of cyber strategies, policies and
procedures
36 49
Continuous Assessments & Continuous
monitoring
98 365
Subtheme: Assessments of Cyber Strategies, Policies and Procedures
Employing a multi-faceted approach to technology assessments can help
organizations identify potential risks and vulnerabilities that may be missed by a single
assessment technique. The research suggests that dynamic strategies and governance
allows companies and organizations to adapt their capabilities to changes in the industry
markets and threats to the business (Ilmudeen, 2022; Mikalef et al., 2021; Liu, Fisher, &
Chen, 2018). Participants backed up the academic research sharing opinions and
experiences that show how continuous assessment of the cyber strategy policies and
processes reduces risk and improves cyber capabilities. P9 highlighted, “You have to
make sure that there's some process in place that you are continually monitoring what's
going on and continually assessing strategies and techniques because the threat landscape
hasn't slowed down, it's actually amplified.” P1 suggests doing assessments can
illuminate changes that could impact customers. P1, P8, P9, P10, P13 and P14 stated they
either have experience as executive or working directly with executives and suggested
that risk assessments, policies and procedures be reviewed at least annually to see it they
need to evolve based on the new threats in the cyber landscape. P1 suggested validating
the performance of cyber security teams and the strategy by doing a full assessment and
pen test, pointing out, even more beneficial is looking at where are you now and what
changed since the last time you did a big scan or an assessment? Is the organization
improving since the last assessment a year ago or the last pen test? Do you have a more
secure security posture or having a less secure posture as you're adding and changing and
taking away assets or maybe things that are EOL? How is it that the overall strategy is
ensuring that you're protecting your customers?
P1, P2, P3, P5, P6, P8, P9, P10, P12, P13 and P14 stated that auditing procedures,
processes and the overall strategy could show new threats, additional risks or gaps in the
current security baseline. P13 suggested using 3rd party resources to audit policies and
review the strategy to make sure it is still relevant to the business needs and any new
threats the industry is experiencing. P1, P6, P12, P13 suggested using 3rd parties for
auditing to avoid internal biases. P6 stated, “Auditing all the documentation, security
controls and assess the strength and weaknesses by a third party partner organization can
avoid any biases.” P12 shared their experience,
I see in order to maintain your security posture, if you really want a non-biased
perspective, I say yearly you should have a third party to assess your systems,
processes, and security controls. The audit should include interviews and
evidence like screenshots. Providing the auditors all policies, your procedures
while the organization is showing them areas where you adhere to all of your risk
and security controls. The best way is a yearly review by third party and in
addition to that I would also recommend that organizations have a third party pen
test.
P1, P2, P3, P6, P8, P12, and P13 suggested testing the new and existing processes
through tabletop exercises. These participants mentioned using this to validate the new
process works as expected or that the existing process is still relevant with the changes
and evolution of the IT and cyber ecosystem. P13 stated,
The processes you're putting in place really are aimed at doing periodic
assessments how are these things behaving and are they continuously behaving in
the way they are expected? Are the processes keeping up with changes to your
landscape in terms of your infrastructure and part of that is also doing iteration
around the documentation and strategies as the environment changes and evolves.
P8 recommended both tabletop exercise and drilling processes,
Tabletop exercises are good to a point where they serve to inform, and refine
process. But there's no substitute for actual practice and most organizations don't
have or won't take spend the resources to do an actual rehearsal. At the end of the
day, rehearsals are the most effective.
The industry documentation, specifically NIST 800-30r1, NIST 800-53, and NIST
800-37, mention assessing capabilities. NIST 800-30r1 states “it is also important to
allow for the possibility of emergent vulnerabilities that can arise naturally over time as
organizational missions/business functions evolve, environments of operation change,
new technologies proliferate, and new threats emerge” (NIST, 2012, p. 9). NIST
documentation gives different reasons to do a reassessment such as a risk response step,
changes in the security baseline, risk monitoring step or after an incident has occurred
(NIST 2022, NIST 2012. NIST recommends using the lifecycle approach to RMF and
during the monitoring cycle changes in the baseline can occur that need to start the cycle
again from a planning and categorizing systems due to changes. NIST 800-100
Information Security Handbook: A Guide for Managers states, information security
strategy in an information security strategic plan or another document, if
appropriate. Regardless of how the information security strategy is documented,
its contents should be aligned with the overall strategic planning activities. The
document should be revisited when a major change in the agency information
security environment occurs (NIST, 2006, p.7).
Participants, industry documentation, and the academic literature suggest that
cyber security strategies are part of the business strategic life cycle and need to be
reassessed for completeness, efficiencies, and that they support the overall business or
organizational strategy. This shows direct relationships between IT, Cyber security and
the overall business function as a single unifying system of systems that support each part
of a larger whole system as described by the GST framework. Analyzing a cyber security
strategy using the GST framework shows that a cyber security strategy needs to evolve
and change as the parts change and evolve to threats and risks. The previous themes show
how there are many interdependent relationships between techniques, concepts, tools and
practices that comprise a cyber security strategy. This study shows that a cyber security
strategy needs to be continuously monitored and validated to ensure it still meets the
business needs and protects core business functions and data.
Subtheme: Continuous Assessments & Continuous Monitoring
All participants strongly suggested using continuous monitoring as the process for
persistently observing, logging and analysis of the network and systems to address
evolving security vulnerabilities, risk and threats. This backs up the research and industry
papers from NIST and ISO. All participants stressed the need for continuous monitoring
to spot abnormalities in system functions and network traffic. These abnormalities could
show the potential for a zero-day attack or the exploit of an unknown vulnerability. P4
stated that ground truth of what is going on in the network or system is very important
and the only way to see abnormalities is through a baseline of information. P4 mentioned
how an attack can obfuscate their actions and what to look for, stating “changes and the
differences can be really small, so don't be afraid to get false positives, you can't afford to
miss the false negative”. Participants explained that continuous monitoring is part of a
risk management life cycle. P13 highlighted,
The controls follow a life cycle, just like any kind of other application and you
need to treat them as such. The cycles requires monitoring on a continuous basis
for effectiveness and measurements of new vulnerabilities that pop up. Ultimately
what you're doing is life cycle analysis of your security posture itself, analyzing
whether it changes and where your business suddenly has a different risk profile
that can change your risk and security posture.
P12 mentioned some basics of a continuous monitoring plan, stating, one thing you
want to do is have a continuous monitoring plan and that's really
going to give you. You are basically reviewing all of your controls, or at least the
subset of those controls, in the high risk and high value areas. If not and incident
can really be catastrophic if they're compromised.
This aligns with the academic journals suggesting the monitoring of all security process,
the baseline, incident management and governance to evolve the overall security posture
of an organization (Limna et al., 2023; Oruj, 2023; Medoh & Telukdarie, 2022). P5
described how to use a continuous monitoring plan with different software vendors to
provide real time tools
Continuous monitoring has been the best way to assess and monitor what's going
on in the enterprise network. It needs to have a real time dynamic dashboard that
everybody who has access to and also access what they need to from the data
from the UI.
All participants stated that continuous monitoring is one of the most important aspects of
a cyber security strategy. P1 explains their own experience stating,
Pretty much all the companies and organizations out there that have been hacked,
in general have been compliant, but they haven't really strengthened or hardened
their networks and the machines to the point where their strategy is on a plan for
continuous monitoring, continuous improving, and continuous threat hunting.
You want to find and prevent the bad actors that would want their information or
access to their resources, such as PII, credit card information, or other sensitive
information.
Participants spoke about different tools and cloud capabilities that make continuous
monitoring less labor intensive. P6 highlighted,
We'd also have monitoring systems use different monitoring products to make
sure our systems are being reviewed. These include collection strategies such as
reviewing logs, storing logs, and then also running queries against our log
collection. Doing this would tell us if any trends were emerging.
P3 highlighted,
Native cloud tooling or like security tools to manage to manage and monitor the
workloads that are in that cloud. So if I'm in in a specific cloud, I'm going to use
that vendor’s specific security tooling to do the monitoring and maintenance and
securing of the workflows. There are a lot of bells and buzzers that can be
configured with every cloud service out there. Leveraging these can help you feel
secure.
Participants suggested that the concept of continuous monitoring is both a cybersecurity
and IT concept. P6 stated,
You would have to have monitoring tools and you have to have a monitoring tool
that only not only is well-documented, but it has to have a small learning curve.
There are some monitoring tools out there that can get super complex and my fear
from a cyber security perspective is the more complexity that you give individuals
and the longer for them to be proficient. Those that have an ease of use and a
good support system are better to use. I look for tools that are collaborated on by
not only the admin community but also the security community so that both can
use it do an intermittent scans and using those tools those scanning tools to scan
baseline systems.
Reassessing controls due to cloud providers or configuration drift is very important
according to participants and can change the exposure of different assets. P3 stated, the
actual workloads are super important to make sure that you may have access, you may
have accessed a control once, but to make sure that these controls don't change now
some of the cloud providers have built-in like rules engines that will assess the security
controls or whatever configurations that you've put in play.
P2 stated,
Regular configuration checks or assessments are essential to ensure that you're
not doing something ill-advised and increasing risk or adding vulnerabilities to
the baseline. You want to ensure configurations that are meant to be private stay
that way and don’t become publicly available. You want to do regular checks to
ensure you aren’t a target.
Participants talked about continuous assessments of processes and security
controls to limit risk and address new vulnerabilities and threats. P1states, “your regular
assessment might find irregularities and you might not have all the answers, but you have
somebody who can help and foster that and focus on it”. P3 added,
I have experience with organizations that do periodic reassessments or they do
drift analysis and workloads. As examples, they may look to see if VMS or IPs
have changed. They look to see what is anticipated and what is out of the norm.
P4 highlighted, “There needs to be a periodic assessments to respond quicker and you're
going to need to have people that can address the issues.”
Participants talked about using red team activities and drills to assess and validate
security controls, incident management and security response to a threat as part of the
continuous assessment of a business or cyber security strategy. P8 stressed this using the
following scenario, a typical attacker would execute much, much more slowly than an
automated attack, particularly where the protection teams and defense teams are unaware
of the activity. This is a true red team. It is very effective to train the detection and
mitigate and adaptive responses. You evaluate to see if they're effective in noticing the
activity and then engaging in whatever courses of actions are documented to contain,
mitigate or sustain business operations.
Participants stated how doing drills as part of the assessment process is more important
than just the compliance aspects. P8 highlighted,
The processes that I've seen to support the periodic assessments are really
compliance driven. Predominantly, the more effective execution is the rehearsal
of cybersecurity events and the surprise red and purple teaming. Those are the
most effective to maintain the security posture. Looking good on a dashboard is
not a true measure of whether or not an organization can actually withstand an
event.
Participants mentioned finding outdated systems and legacy software during
periodic assessments. P1 stated this when talking about finding different issues on the
network during an assessment, “Updating and getting current with some of the legacy
systems is oftentimes incredibly complex.”
Participants shared their experiences with external statutory and regulatory groups
that audit based on these obligations. P3 stated, “I use something like PCSS and have
annual assessments that are required prior to an external regulatory agency. Internal
audits occur ahead of time to ensure we can address issues.”
Using General Systems Theory, the participants, industry documentation and the
academic research show how complex the relationships are between different
cybersecurity concepts forming a system of systems. The combinations of technology,
processes, and procedures build a holistic cyber security strategy. These relationships are
interdependent and need to be monitored as part of the larger system of cyber security
and the much larger system of systems comprising the business or organizational
strategy. Each of these parts influences and is dependent on other aspects of the
organization or business.
Applications to Professional Practice
This pragmatic study explored what strategies some cybersecurity professionals
use to mitigate cybersecurity threats in small businesses. This study analyzed the strategic
techniques and trade craft used by accomplished cyber professionals to protect
businesses, customers and reputations along with multiple scholarly literature research
documents, the best practices and industry documentation available on the internet
through NIST, ISO, and Security Controls Framework Council (SCF). Based on the
triangulation of this data, 6 major themes materialized: Cyber Security Strategy based in
Business Needs, Risk Management, Security Controls, Foundational Security & Cyber
Hygiene, Proactive security and Incident Response, Continuous Monitoring. The results
of this study provided the perspective of industry and some cybersecurity professionals
that can be used by small businesses to create a cybersecurity strategy or understand the
applicability of cybersecurity strategies to small businesses when hiring 3rd parties or
supporting small businesses.
By leveraging the General System theory (GST) framework, this study has shown
how complex a cyber security strategy can be and that it is part of the larger business
strategy used to mitigate risks to the organization, manage statutory and regulatory
obligations and support the broader IT strategy. This shows how the complex
relationships between security, IT and business are important for small businesses. These
ecosystems act as a system of systems that are not independent and are interdependent on
each other to function and continue the operation of the business. The outcome of this
study highlighted the threats that small businesses are under and just how vulnerable their
systems are to these threats. The findings of this research highlighted some of the
processes, procedures, tools and capabilities small businesses need to protect themselves,
their reputations and customers.
Implications for Social Change
Small businesses are among the most targeted and vulnerable organizations in the
world to cyber threats. Small businesses make up large portions of the world’s economy
and creation of new jobs annually. Malware and data breaches are critical threats to these
businesses and local economic communities. Implementing a holistic cyber security
strategy to protect data from malware and security breaches, Small business leaders can
implement a strategy that encompasses policies, procedures, techniques, tools, and a
security-focused business culture to ensure the protection of business data, customer data
and business operations continue to function in a secure manner. Providing resources and
tools that small businesses can use ensures greater stability and allows them to explore
innovations in their business industry or sector while protecting critical intellectual
property. Implications for positive social change may include growth and innovation in
different industries. Enhancing the maturity of cybersecurity in small businesses may also
have the effect of reducing the number of compromises to customer PII and financial
data. The additional creation of communities of practice where business leaders can talk
about the challenges associated with cyber security, share resources, knowledge may aid
in the proliferation of successful secure small businesses. Allowing small businesses to
better use resources and enhance the cyber maturity level benefits the entire community
of practice.
Recommendations for Action
The outcome of these findings provide insight into some key-points cyber security
strategies should address to protect their customers, reputations and business from cyber
security threats. The strategies used by small business must be reviewed by cybersecurity
professionals as a single security breach or ransomware incident can cause a small
business to close its doors permanently. Combining the concepts of cybersecurity
strategies should be use to protect and support the overall business strategy and support
the IT strategy of an organization. This study suggests effective cyber security strategies
should include the following:
Asset and process prioritization and valuation. This allow the business to
classify processes, procedures and the systems that support core
business capabilities (What makes money and why the business exists) o
Document all assets and their use.
o Use and IT Management System for inventory and IT management
(trouble tickets, cyber events, software inventory)
•Utilize a cyber security framework as a basis for a cyber security strategy.
•Risk management techniques based on the systems and functions that support
core business capabilities o Use of risk assessments that prioritize core
business capabilities for security funding and mitigation techniques.
oThreat assessments that can show how bad an incident could be if not
mitigated (table top activities with executives)
•Backup of business data and disaster recovery plans.
oTest backups to see if they work o Test all aspects of the disaster recovery
plan as a fire drill. Practice so when the event happens teams know what
to do, what the responsibilities are and are prepared.
•Proactive (Threat Hunting) and reactive (incident response) Security
capabilities o Tools and capabilities that support the “ground truth” of the
traffic on networks, interactions and operations of applications and systems
that are used to conduct business actives. Participants suggest some SIEM
tools
and network taps can provide these capabilities.
oResearch or utilize cloud capabilities as alternatives.
•Importance should be placed on security controls for all applications,
operating systems and infrastructure based on the risk tolerance of the
organization.
oUse firewalls and network technique to segregate network traffic and
prevent malware and hackers from accessing everything.
oBlacklist and tar pit known bad actors and infectious websites.
oEncrypt communication and data
•Vulnerability testing and patching of all infrastructure, applications and
systems.
•Access control and data governance o Limit user access to job functions –
not everyone needs access to HR data, financial data and administrative
access to systems.
•Foundational security and cyber hygiene o Multifactor authentication o Limit
the attack surface by limiting traffic, unused ports and remote access o
Computer use policies and policies about connecting personal devices to the
network o Antivirus software o Strong passwords over 8 characters o Limit
admin access and created specific individual admin accounts.
o Remove legacy or EOL systems to prevent increased risk and exploitation
of vulnerabilities leading to cyber incidents.
•Continuous monitoring and assessments o Document all cyber processes and
procedures, then test and audit these procedures.
o Manage all technology changes and reassess controls often o
Monitor all security controls, accounts and scan for vulnerabilities o
Assess processes, backups, tools and security capabilities through a
validation mechanism such as Penetration testing or red team.
•Training and education of all users at every level in basic cyber security. o
Cyber security is everyone responsibility
This study suggest the value of a cyber army of all users that can
freely bring anomalous system and application behaviors to the
cyber security teams.
oPhishing campaigns and training to prevent ransomware, financial
fraud and theft from individuals and the business.
oEducation on policies and procedures o Educate IT and Cyber
professionals on new trend and capabilities.
Policies, procedures and training are required to govern the holistic cyber security
strategy. Utilizing general system theory (GST), these governing documents need to work
in tandem with the development of software or products, core business practices, data
classification, staff training, IT standards, change management, and culture of the
organization making cybersecurity a shared responsibility. These should be easily
understood and policies should be de-conflicted and reviewed cyclically to avoid
confusion, identify gaps due to market and industry changes, and be updated to mitigate
future threats. Special consideration must be taken when instituting accountability into
policies. The findings suggest a business and security culture of “see something say
something.” Identifying false positives is a better scenario than users and cyber
professionals concerned about reprisal or penalties when IT systems and infrastructure act
in an abnormal manner. IT was recommended by several cyber participants to join or
build a community of practice where businesses can talk about their cyber security
strategies, threats to their industry or market, and share challenges, and observations.
Recommendations for Further Study
The findings in this study analyzed what strategies cyber security professionals
use to mitigate cyber threats in small business. Based on the limitations in section 1,
further study with a broader range of participants that are in executive roles would
mitigate the limitations around creating and enacting cyber strategies that some
professionals expressed. Further study in a specific industry or case study could show
new insights on how strategies are different for small business in banking vs
manufacturing, for instance.
I recommend that further study be conducted on leadership and security culture.
While not in scope for this study, many participants talked about the need for
psychological safety when discussing cyber security incidents with leadership. This was
acknowledged at all management levels, including discussions with company board
members. My second recommendation is for further research be done on the security
posture of companies and the business culture as a multidisciplinary study between IT
and business researchers. Through the lens of General System Theory, the leadership
environment whether collaborative, collegial or toxic could have significant impact on
the security and ability to secure a business. The ability for cyber professionals and end
users to report anomalous behavior could be hindered or emphasized by the way
leadership receives and acts during plausible cyber events.
My second recommendation is further study be performed on the impact of
security guard rails vs. rigid policies and standards on innovation. Some participants
mentioned that strict policies and policies from different parts of organizations often do
not align with the IT goals and hinder innovation in IT. The sharing of outcomes of either
of these studies could have significant impact on the future of cybersecurity in businesses
of any size.
Reflections
I started my doctoral journey during 2020 and COVID as a way to stay motivated
during lock down and have something positive I could focus on during this time of
instability. This has been a humbling experience and more of a marathon than a race with
many personal obstacles along the way. This is one of the most rewarding and
challenging accomplishments of my academic and professional career. I understand the
dedication and personal fortitude it takes to complete a doctoral degree.
As an IT and security professional with more than 25 years of experience, I had to
come into this process with no preconceived notions. I had several different ideas on
what I wanted to research as the field is very large, but after a brief conversation with a
friend and small business owner over a cyber incident, I realized that there is a need for
education and support of small business owners on how to even start talking about IT
security and cyber security.
When I selected my topic and going through the approval of my prospectus, I was
faced with a bigger challenge of narrowing my focus to specific topic within the cyber
security landscape. The literature available for risk and audit, governance, accountability,
threats and mitigation techniques is significant. I kept going back to the conversation I
had and asking myself what would this person need to know to have prevented this issue.
I was asked what would I have done which led to the research question, “What strategies
do cybersecurity professionals use to mitigate cybersecurity threats in small businesses?”
After approval from the Walden University IRB, I found it difficult to get research
participants. Few professionals were interested in the study and had concerns about
repercussions when talking about a topic such as cyber security. I had to build a
relationship with these strangers over LinkedIn sharing my own experiences in cyber and
discussions of the challenges in the industry. After communicating through LinkedIn with
over 80 different professionals, 24 agreed to join the study. After receiving the formal
invite only 15 scheduled interview times and 14 proceeded with the interviews.
I had to let the research and data tell the narrative, leaving my own preconceived
ideas, opinions and biases at the door. The process of doing research at this level (inquiry,
research, analysis) provided a strong foundation and gates to check for bias and make
sure that the academic rigor was followed as intended. This rigor in my experience
checks the personal ego and puts the researcher in a frame of mind allowing for academic
inquiry to take place.