Strategies for Implementing Successful IT
Security Systems in Small Businesses
Section 1: Foundation of the Study
Cyber security threats have increased since the rise of technological
advancements. Cyber attacks are a continuing threat, and when there is a breach of
sensitive data, both organizations and consumers are affected (Balan, Otto, Minasian, &
Aryal, 2017). Owners of small businesses have become more attractive targets because
they lack the financial resources and Internet technology (IT) personnel to commit to
cybersecurity like big companies (Selznick & Lamacchia, 2018). As data breaches
against small businesses have increased, it has become a growing source of concern for
consumers who rely on owners of small businesses to protect their data from data
breaches. Therefore, I sought to understand what strategies owners of small businesses
used to protect their business and customer information from cyber attacks.
Background of the Problem
Watad, Washah, and Perez (2018) noted that 79% of owners of small businesses
have no plans to respond to a cyber attack, while 40% do not believe their businesses
would be attacked. Owners of small businesses have been struggling to combat threats
and protect company and customer data (Goode, Hoehle, Venkatesh, & Brown, 2017).
Selznick and Lamacchia (2018) pointed out that 43% of cyber attacks in mid-2016 were
targeted at small businesses. Cybersecurity issues are becoming more prevalent, with an
increasing number of threats and vulnerabilities. Owners of small businesses lack
effective cybersecurity strategies to protect their business and customer information from
cyber attacks.
Problem Statement
The threat of cyber attacks to businesses in the United States is increasing as more
businesses become targets for trade secrets, sensitive corporate data, and customer
information (FBI, 2016a). The cost of data breaches to U.S. companies increased from
$800,000 in 2014 (FBI, 2014) to $1.3 billion in 2016 (FBI, 2016b). The general business
problem was that data breaches could damage a business brand reputation and cause
customers to lose confidence. The specific business problem was that some owners of
small businesses lack cyber defense strategies to protect business data from cyber attacks.
Purpose Statement
The purpose of this qualitative multiple case study was to explore strategies
owners of small businesses used to protect confidential company data from cyber attacks.
The target population for this study consisted of five successful owners of small
businesses in the Fort Lauderdale, Florida area who have implemented effective
cybersecurity strategies to protect their business data from cyber attacks. The implications
for positive social change include the potential to enhance sound cybersecurity policy to
reduce data breaches, and protect business and customer data, thereby increasing
customers’ confidence, increasing businesses’ economic growth, and stimulating the
socioeconomic lifecycle, resulting in potential employment gains for residents in
communities.
Nature of the Study
I used a qualitative research methodology for this study. Researchers use
qualitative methods to understand the underlying phenomena and motivation in real-life
situations and gain insight into research problems (Reinecke, Arnold, & Palazzo, 2016).
A qualitative methodology was appropriate to gain insights into the strategies
some owners of small businesses use to protect confidential company data from cyber
attacks. I reviewed other methodologies, such as quantitative and mixed methodologies.
A quantitative research methodology was not suitable for this study because I did not
intend to examine the relationships among variables. Researchers use the quantitative
methodology for predicting, describing, and categorizing groups to consistently identify
patterns (Elman, Gerring, & Mahoney, 2016). I rejected the mixed methods methodology
because this study does not include relationships among variables. The mixed
methodology involves collecting, analyzing, and integrating both qualitative and
quantitative methodologies to solve a research problem (Reinecke et al., 2016).
A qualitative multiple case study was an appropriate design choice for this study
because it was the process used to obtain data through semi structured interviews and
company documentation. Researchers used multiple case studies to analyze data across
different situations and build explanations from the collected information (Ridder, 2017).
I reviewed other qualitative designs, such as ethnographic, phenomenological, and
narrative designs. An ethnographic research design was unsuitable for this study because
the goal of this study was not to understand the cultural practices of a specific group
(Cardoso, Gontijo, & Ono, 2017). A phenomenological research design was inappropriate
for this study because the goal was not to observe the meaning of experiences lived by a
group or an individual that relates to a particular phenomenon (see Flynn & Korcuska,
2018). Using narrative research was not appropriate for this study because the
participants’ descriptions of stories from their personal experiences may not be relevant.
A narrative researcher provides a visual representation or written stories of the
participants’ personal experiences (Bruce, Beuthin, Sheilds, Molzahn, & Schick-
Makaroff, 2016).
Research Question
The research question for this study was: “What strategies do owners of small
businesses use to protect business data against cyber attacks?”
Interview Questions
The interview questions used to gather data for this study included the following:
1. Please describe the strategies and various security tools that your organizations
currently utilize to address or mitigate targeted cyber attacks successfully?
2. How, if at all, do you conduct a security system assessment to ensure basic security
practices are in place?
3. What successful processes have you implemented to implement your security
awareness program?
4. What, if any, successful employee training have you implemented for security
procedures to improve and enhance cyber attack detection capabilities?
5. How successful is your response plan for detecting, preventing and protecting both
business and consumers’ data?
6. What is your contingency plan in the event of a successful cyber–attack?
7. What successful data control techniques have you implemented?
8. What else can you tell me regarding how your business is protecting customers’ data
against cyber–attacks?
Conceptual Framework
I chose Von Bertalanffy’s (1972) general systems theory (GST) and Cohen and
Felson’s (1979) routine activity approach (RAA) as the conceptual framework of this
study. Von Bertalanffy (1972) developed the GST as an interdisciplinary theory to
analyze the nature of complex systems, and as a framework, it is a process used to
investigate any group of connected objects. The framework could serve as the basis for
understanding complex cybersecurity systems and implement strategies to change their
focus from defensive to offensive approaches (Stitilis, Pakutinskas, Kinis, &
Malinauskaite, 2016).
Cohen and Felson (1979) developed the RAA and noted that crime happens when
the following three elements are simultaneously present in any specified space and time:
(a) a motivated offender, (b) a suitable target, and (c) the absence of a guardian. Leukfeldt
and Yar (2016) noted that the RAA would be useful as an analytical framework to study
cybercrimes, identify vulnerable targets, and serve as a means for adopting and enforcing
cybersecurity policies.
Von Bertalanffy’s (1972) GST and Cohen and Felson’s (1979) RAA were both
synthesized frameworks used to formulate a comprehensive cybersecurity strategy. Both
theories aligned with this study. I integrated both theories into the conceptual framework
through which I reviewed strategies used by owners of small businesses to protect
business and customer data from cyber attacks.
Operational Definitions
The following terms were used throughout the study.
Cybercrime: A growing act that is directed at specific victim computers to
generate profit for the cybercriminals (Huang, Siegel, & Madnick, 2018).
Cyber defense mechanisms: This is a collection of tools and concepts used for
detecting and preventing attacks (Jones & Shashidhar, 2017).
Cybersecurity awareness: This is the combination of knowledge and techniques
used to protect and prevent cyber attacks (Onwubiko, 2017).
Data leakage: This is the transfer of sensitive or classified data from a secured
system to an unauthorized third party (Vavilis, Petkovic, & Zannone, 2016).
Information security threats: The various techniques hackers are using to
compromise the integrity of an information system (Young, 2016).
Insider threat: An insider threat occurs when an employee gains control to abuse
one or more rules outlined in the specified cybersecurity policy (Vlad-Mihai, 2017).
Online security breach: A deliberate and malicious act used to disrupt or breach
an information system to gain access to individual or organization data (Trappe
& Straub, 2018).
Security controls: These refer to any precautions or countermeasures that
organizations use to avoid or minimize cybersecurity risks (Trappe & Straub, 2018).
Small business: Small businesses include private corporations, partnerships, or
sole proprietorships with the size standard that ranges from 1 to 1,500 employees (SBA,
2018a).
Assumptions, Limitations, and Delimitations
Assumptions
Assumptions describe those elements that are out of the scope of the researcher
but are considered and accepted as relevant to the study (Feller, Mealli, & Miratrix,
2017). There were two assumptions related to this study. The first assumption was that
participants would answer the interview questions without fear of reprisal or harm to their
reputation and business. I presented participants with confidentiality agreements to ease
any fears of reprisal. The second assumption was that participants would honestly and
truthfully answer questions regarding their business cybersecurity.
Limitations
Limitations describe those elements that are outside the researcher’s control and
can potentially create weaknesses in a study (Roseveare, 2017). The first limitation of this
study was that owners of small businesses might unintentionally provide insufficient data
due to their limited knowledge of cyber security. The second limitation was the continued
growth of cyber security, which would limit the knowledge of participants.
Delimitations
Delimitations are the boundaries and limitations that the researcher sets to reduce
the scope of the study’s investigation (Park & Park, 2016). The delimitations of the study
were the size of the business, the sample size, and the location of the businesses. I limited
the study findings to specific small businesses located in the Fort Lauderdale, Florida
area.
Significance of the Study
One of the most significant issues facing owners of small businesses is the ability
to protect themselves against potential cyber attacks. When sensitive data is at risk, due to
cyber attacks, both organizations and their customers are affected (Goode et al., 2017). A
business’ reputation suffers when business owners fail to protect data, which could lead
to the loss of the business’ customers (Janakiraman, Lim, & Rishika, 2018). Some owners
of small businesses do not allocate budget items to mitigate and address cyber
vulnerabilities. Owners of small businesses have an urgent need to develop effective
cyber strategies to protect their company assets, intellectual property, and customer data
from cyber attacks. The results of this study may help owners of small businesses develop
cyber strategies to identify vulnerable targets and mitigate threats to protect companies’
confidential data.
The findings of this study may include information that might be useful in
formulating cyber security strategies that could help to predict and eliminate future
threats to customers’ information privacy problems. The implications for positive social
change include the potential to develop and stimulate economic growth and create
additional jobs to improve the social lifestyle of residents within communities.
A Review of the Professional and Academic Literature
I began my search of the literature by reviewing the conceptual framework of the
GST and RAA. I discussed both frameworks and developed a comprehensive analysis
and synthesis of sources from peer-reviewed journals, published dissertations, and
government data. My search efforts focused on accessing information through Walden
University library resources, including the following databases: Emerald Management,
Business Source Complete, ProQuest, Academic Search Complete, EBSCOhost,
ABI/INFORM Complete, ACM Digital Library, IEEE Source Library, and SAGE
Premier, a multi-discipline research database. I used the Ulrich web global serials
directory database engine and the journal articles’ homepages to validate the scholarly
reference and peer-reviewed listings.
The literature review search criteria included the following keywords: cyber
attacks, cybersecurity threat, data breaches, strategies for data breaches, ransomware
attack, cyber-crimes, internal and external breaches, cyber incidents, cyber fraud,
network security monitoring, cyber hacking, cyber loss, data theft, cyber warfare, data
loss, email phishing, hacking, fraud, network prevention, security prevention, risk
assessments, government regulations for cyber security, security detection, software theft,
and intrusion prevention and detection.
At least 85% of the citations were from peer-reviewed and academic journals that
were published within 5 years of the anticipated CAO approval date. Table 1 includes the
various citations used in the study.
Table 1
The Breakdown for Literature Review Publication
Total
sources
Year
published
(20162020)
Percentage
published
2016-2020
Peerreviewed
sources
Percentage
peerreviewed
Full document 233 208 85.30% 192 92.05%
Literature
review 136 145 95.34% 134 98.53%
The purpose of this qualitative multiple case study was to explore strategies used
by business owners to protect their business data from cyber attacks. Business and
consumer data breaches have become a significant business problem. The objective of
implementing cyber security strategies was to prevent unauthorized access and use of
business and consumer data (Janakiraman et al., 2018). Stitilis et al. (2016) stated that
cybersecurity breaches, intense cyber wars, and separate attacks are becoming more
common than the physical attacks; such cybersecurity violations might result in damage
to businesses’ reputations. Densham (2015) noted that organizations must respond with a
comprehensive plan to mitigate breaches and implement effective cybersecurity strategies
to prevent a potential disaster.
I discuss the following concepts and key sectors further in the next sections: (a)
evolution of theories, (b) theories supporting cybersecurity, (c) cybersecurity threats, (d)
holistic cybersecurity strategies, (e) system security strategy, (f) intrusion detection
strategy (g) cybersecurity awareness education and training, (h) outsourcing strategy, (i)
third-party vendors strategy, (j) holistic prevention strategy, (k) data protection strategy,
(l) data breach prevention strategy, and (m) data leak prevention strategy.
Evolution of General System Theory
Von Bertalanffy (1972) developed an outline of GST by considering (a) system
units, (b) collaborative exchange and continual relationships within the system, and (c)
the analysis of systems would provide a way of interpreting and viewing interconnected
units. Von Bertalanffy (1950) began by envisioning a theory and conceptual framework
that would be equally applicable to many fields of inquiry. Wang, Shi, Nevo, Li, and
Chen (2015) viewed an organization as a system that consists of subsystems working
together in an ever-changing environment to achieve a common goal; any form of change
or impact in one subsystem affects the overall system or organization. Von Bertalanffy
(1969) argued that the GST bridges the gap by dividing subject and object-oriented
disciplines. Rousseau (2015) added that the GST could be applied to support
interdisciplinary collaboration and enable scientific findings in disciplines that lack such
theories. The principle of systems theory is a process used to manage people and
processes within an organizational environment (Rousseau, 2015). Bohm and Kuhn
(1964) expanded the systems theory by suggesting that scientific progress is not a
straightforward evolution, but a systematic application of methods where knowledge
surges to the limits of the current model. Bohm and Kuhn concluded that one viewpoint
replaces another, resulting in a shift and leading to the development of subsystems with
dynamic and new characteristics.
Bennis, Katz, and Kahn (1966) developed an open-systems approach to repeated
cycles of input, output, and throughput. Systems receive input as a form of resources
from the environment; this input is processed into a system as throughput and produces
output to restore the balance (Bennis et al., 1966). The open systems use this process as a
means of interacting with the environment; this is a process used to define which
components of the system are not operational as designed, thereby affecting the system
(Anders, Schiendorfer, Siefert, Steghofer, & Reif, 2015). The fundamental premise of
GST is that different system units tend to share some basic organizing principles,
irrespective of their purposes, which contribute to system wholeness (Von Bertalanffy,
1972). Researchers can use GST to understand the wholeness of organization systems and
to discuss leadership, management, and related functions.
Von Bertalanffy (1969) noted the holistic approach of the GST by implying that
systems consist of interrelating parts; it is impossible to isolate the connections from the
rest of the system by reviewing a single component. The only exceptions to this are (a)
when the system interactions are weak and (b) when there is a linear relationship between
the system components. The holistic approach changes the method by using the analytical
tools to review network and security systems. The holistic system approach is a process
used to set boundaries to problems while understanding the relationships within natural
systems to avoid unwanted consequences (Monat & Gannon, 2018). Gajic, Palcic, and
Cosic (2015) evaluated the influence of this approach, as a process used to examine
systems as a complete functioning unit by depending on the following building blocks:
(a) the foundations of GST, (b) cybernetics, and (c) soft system method. With these
building blocks, it is possible to define, investigate, and explain security (Gajic et al.,
2015). In this study, I explored why a holistic system approach to cybersecurity is
essential, especially regarding the prevention or mitigation of data breaches.
Von Bertalanffy (1972) indicated that systems could self-correct and regulate; as
such, through this lens, we can understand complex problems and phenomena. GST
through the lens of interdisciplinary, cross-cutting meta-concept that can evaluate current
security and safety analysis techniques (Lei, Yang, Niu, Yang, & Hao, 2017). It is also
possible through the lens of GST to identify issues within the system and solve problems
related to identifying, restructuring, and optimizing security monitoring systems while
considering multiple objectives, constraints, resources, benefits, costs, and risks (Tisdale,
2015).
Evolution of Routine Activity Approach (RAA)
Cohen and Felson (1979) developed the RAA, which explains that crime occurs
during the instantaneous meeting of a motivated offender with an appropriate target that
lacks capable guardians. Cohen and Felson (1979) indicated that one must evaluate all
three components in a broader context before investigating them at a micro-level. The
importance of the findings at the macro level provided the motivation needed for scholars
and researchers to test the theory (Cohen & Felson, 1979). Many scholars and researchers
have investigated the micro and macro levels while trying to explain offender behavior
and criminal victimization (Savard, 2018).
Williams (2016) supported the argument that Internet governance is achievable
with a combination of macro and micro guardianship as the controlling effect of
cybersecurity strategies. Scholars have used the RAA to focus on criminals’ actions,
rather than the criminals themselves, which makes this approach salient to studies of
cybercrime (Williams, 2016). Argun and Daglar (2016) suggested that the RAA can be a
useful theory for preventing and reducing crime. Practitioners can use this approach to
evaluate and analyze criminal problems, as well as to recommend routine measures and
precautions to reduce criminal opportunities. This perspective can aid the understanding
of cyber attacks by focusing on specific cybercrime attacks and how such attacks affect
guardianship and suitable targets (Leukfeldt & Yar, 2016).
Williams, Levi, Burnap, and Gundur (2018) noted that the RAA could provide
potentially useful criminological insight into insider cyber victimization. The authors
further indicated that insider cybersecurity breaches are a function of routine activities.
Organizations, therefore, must be evaluated whether potential offenders are motivated
and determine by a suitable target in the absence of guardianship (Williams et al., 2018).
Theories Supporting Cybersecurity
Monat and Gannon (2018) noted that systems share common characteristics,
including a dynamic structure that can be defined by components and configuration.
Integrated systems consist of several interacting elements involving processing inputs and
producing outputs, interconnections between different functioning parts of the system,
and structured relationships (Monat & Gannon, 2018). In a modern system, each level of
information is related to a level of correspondent security risk. Each level must be
welldefined, including a proper measure to control the risks of data security (Anton &
Nedelcu, 2015). A systemic method is a process used to manage data security; the
process is based on understanding how a system’s processes can effectively be structured
to secure all components of the system (Anton & Nedelcu, 2015). A system mainly
consists of integrated objects, either logical or physical, qualities that describe the objects,
the objects’ relationship with other objects, and the system’s control environment
(Gutierrez-Martinez, Nunez-Gaona, & Aguirre-Meneses, 2015). Classic security and
safety problems, such as ensuring the reliability of hardware and protection from natural
phenomena, modern systems are so interconnected that security threats from malicious
adversaries must be carefully considered (Alves & Morris, 2018). Cybersecurity issues
are becoming more prevalent; as such, monitoring and securing systems from cyber
breaches, and malicious threats are increasingly critical and challenging (Kesan & Hayes,
2017). Organizations can use the RAA to provide a robust foundation that will potentially
serve as an integrated approach to cybersecurity (Leukfeldt & Yar, 2016). Onwubiko
(2017) suggested that businesses can implement a protective process by introducing data
security solutions to improve data security awareness while reducing cybersecurity
threats.
The holistic system approach can be applied when analyzing and implementing
cybersecurity strategies. By understanding the root of a breach, small business leaders can
support and tighten the disintegrated parts of the target system to prevent future data
breaches (King et al., 2018). A shared functionality formed the process used to identify
the different system functions. We can view systems through this lens as an interlinked
and nested with other systems. In such a method, the analysis may occur at multiple
levels about the externalities outside of the system. Chalvatzis, Karras, and
Papademetriou (2019) described small and medium-sized enterprises as systems that
consist of diverse components, of which one component is data security. Due to the rise
of cyber attacks, cybersecurity is a critical system component for all businesses.
Owners of small businesses can monitor their environment by collecting
information about environmental deviations to formulate it as input, which can also be a
form of feedback that formed the change or create a cybersecurity strategy (Rothrock,
Kaplan, & Van, 2018). The most critical information can formulate a negative input;
when there is a breach in the system, the analyzed information can alert the business that
a problem needs correction (Marti, 2015). Positive input alerts the business when
something is right and indicates the need to continue modifying the activity (Gajic et al.,
2015). Small business leaders should analyze and process this information in order to
formulate solutions to their cybersecurity needs (Bagschik, Stolte, & Maurer, 2017). An
open system is a process used to respond and adjust environmental changes through the
input of information. These adjustments can sometimes affect organizational processes
(Rothrock et al., 2018). These adjustments may reduce, increase, or support
environmental change deviations (Marti, 2015). The organization can analyze
information in the throughput to tailor their process to fit their goals (Rothrock et al.,
2018). When small businesses adapt to cybersecurity changes, their actions and messages
represent the output, and these outputs formed the process used to measure the
effectiveness (Jenab & Moslehpour, 2016).
In recent years, researchers have placed a vast amount of resources and effort
toward improving and expanding cybersecurity; however, there has been a lack of
significant progress in this field (Joo & Hovav, 2016). While technological improvements
resulting from developed security techniques are becoming outdated (Schabacker, Levy,
Evans, Fowler, & Dickey, 2019), practitioners created many security techniques years
ago when systems were mainly composed of electro-mechanical components and were
less complicated than today's intensive systems (Joo & Hovav, 2016). Marti (2015) found
that throughput feedback creates new changes in a system, but if the messages and
actions are not sufficient, the process repeats until it found a proper solution. If a small
business is unable to adopt a cybersecurity strategy variation, then it will ultimately cease
to exist. Jenab and Moslehpour (2016) noted that systems theory could be useful in
understanding the feedback derived from cyber breaches and creating consistent
cybersecurity strategies based on information from the throughput stage. When
investigating a breach in a system, it is necessary to understand the relationships between
the elements of the environment and the system, as well as the impact's effect on the
environment, in formulating the estimated effect of the impact on the system (Naudet,
Mayer, & Feltus, 2016).
Leukfeldt and Yar (2016) explained that the RAA could be used to reflect the
differences and similarities between offline and online behavior patterns involved in
cybercrimes. Researchers found that they could apply RAA to different online
cybercrimes by evaluating the patterns of data and crime victimization (Leukfeldt & Yar,
2016). Through a comparison, Reyns (2015) found that the core elements of RAA formed
the process used to review and test criminogenic terms in an online environment, with the
scheme of criminal behavior represented by motivated offenders and with a proper target
lacking capable guardians. Online-motivated offenders take the form of hackers,
fraudsters, stalkers, pirates, and other criminals (Reyns, 2015). Online targets that are
suitable for predation include proprietary business data, personal data, and online
payment systems, along with vulnerable computer systems that may be disrupted and
compromised by unauthorized interference and intrusion (Reyns, 2015). Capable
guardians include the various forms of cybersecurity, computerized protections,
management access systems, ID authentication, firewalls, virtual private networks, and
anti-intrusion and virus software (Van de Weijer & Leukfeldt, 2017).
The impact of inadequate cybersecurity on the possibility of insider victimization
could be analyzed using the RAA. Several applications point to the significant effect of
routine activity in analyzing cybercrimes (Leukfeldt & Yar, 2016). Balan et al. (2017)
observed that cybercriminals continue to probe and target businesses of all sizes with the
smallest possible flaws in their systems. These criminals are persistent, well-funded, and
sophisticated. Protecting customers and business data is an organizational problem, not
just an IT department issue. Tisdale (2015) suggested various viewpoints on a holistic
approach to cybersecurity. Owners of small businesses could consider that holistic
approaches have their foundation in systems theory. Thus, owners need to understand all
the potential entry points for cyber attackers in order to create a holistic cybersecurity
strategy that leaves no entry point (Tisdale, 2015).
A holistic cybersecurity approach must accommodate all facets of incident
preparedness, customer data security, legal counsel, and regulation for the future (Naudet
et al., 2016). Owners of small businesses who adopt an inclusive approach to
cybersecurity are readily able to successfully mitigate, prevent, and remediate cyber
attacks (Opitz, 2018). These inclusive approaches must incorporate technology, people,
and processes. Owners of small businesses adopting the inclusive approach would
consider not only technical factors, but also governance, social, human, and cultural
factors. This approach formed the process used to detect and prevent cyber-vulnerabilities
(King et al., 2018). It is possible to achieve a robust cybersecurity posture through a
combination of integrated security solutions, multi-layer protection, and end-user
education (Kafol & Bregar, 2017).
Cybersecurity Threats
Izuakor (2016) concluded that cybersecurity threats are a current reality, and
cybercriminals are employing a growing number of tactics to compromise and steal data.
Successful cyber attacks could negatively impact the wellbeing of business and economic
security (Izuakor, 2016). Janakiraman et al. (2018) concluded that cyberattacks could
occur to a business irrespective of the type or size of business. The cause of cyberattacks
can by directed through targeted attacks, malicious insiders, and benevolent insiders; as
such, owners of small businesses ought to integrate data security plans into their overall
processes to reduce the impact of cyberattacks (Janakiraman et al., 2018). Cyber threats
describe potential harm, which may come in many forms, including viruses, Trojan
horses, phishing attacks, malware, or ransomware network backdoors (Janakiraman et al.,
2018). The number of small businesses that are potentially affected, and the damage
resulting from these attacks, are at unprecedented levels (Trappe & Straub, 2018). Astani
and Ready (2016) cited various estimates of the cost of damages caused by cyber
breaches, which indicates that cyber breaches cost billions of dollars. Kesan and Hayes
(2017) found that cyber attacks on the global economy have resulted in losses of $445
billion per year. While cyber attacks on small businesses have increased, the average cost
to clean up after a single attack is about $690,000 (Watad et al., 2018).
Cybercriminals are becoming more sophisticated because they found new ways of
penetrating security measures, the most common cybersecurity threats facing owners of
small businesses are distributed denial of service attack (DDoS), vulnerabilities, spam,
phishing, and malware attacks. Malware attacks formulate a process used to steal
sensitive customer data when it takes over a website and spread more malware, which
could be a devastating effect on small business e-commerce. Iovan and Iovan (2016)
concluded that businesses are experiencing a continuous increase in malware threats
making it a dynamic continuous challenge.
Most phishing attacks are targeting small business employees; the process is when
an attacker impersonates a CEO, manager, a business partner, or a contractor by sending
an email with a malware attached when the employee opens the attachment, they would
unknowingly installed malware on their computer (Huang et al., 2018). Hennig (2018)
pointed out that new phishing sites created every month have increased to an average of
1.4 million. Attackers do this by creating fake web pages that mimic corporate web pages
(e.g., Google, Dropbox, Chase Bank, and PayPal). Williams, Bengert, and WardCaldwell
(2016) reported in their research that the 2014 breach at Sony started with a series of
phishing attacks targeting Sony employees. Sony incident proves how the nature of cyber
attack has permitted the attacker to leave obscure disinformation and problematic
attribute (Williams et al., 2016). The phishing emails are designed to persuade employees
to download the email with malicious attachments or visit counterfeit websites that would
install malware into their systems (Goode et al., 2017). The counterfeit websites created
by cybercriminals may last up to 8 hours before they create a different site, making it
difficult for automated security tools to mark the site as malicious (Hennig, 2018).
Attackers are becoming more experienced in hiding behind domains, obscuring their
exact URLs, importing more destructive payloads, and misleading users with fake
websites (Huang et al., 2018). Simultaneously, the volume of spam and malware attacks
has substantially increased in recent years. With the rising rate of small businesses
adopting web technology, more systems are vulnerable to malware infections that can
exploit and corrupt data. In addition to malware threats, ransomware is a new threat that
hackers use to encrypt data stored on the victims’ system and lockout users from their
system (Goldsborough, 2016).
In the last three years of 2018, the use of ransomware has become a leading
method by which hackers are targeting small businesses (Thomas & Galligher, 2018).
Brewer (2016) described ransomware software as a malicious attack that allowed hackers
to gain access to a company or an individual’s vital data. Hackers then hold these data
and demand payment before lifting the restriction. In 2016, the primary targets of
ransomware were hospitals and end-users (Goldsborough, 2016). The FBI estimated that
in 2016 the losses due to ransomware attacks totaled $1 billion (Brewer, 2016). The most
commonly used ransomware restriction is to encrypt essential data, thereby allowing the
attacker to hold the system or data hostage (Thomas & Galligher, 2018). Hackers then
demand payment before undoing the changes or returning the data. This ultimatum may
arrive through on the infected computer as pop-up windows with instructions (Ali, 2017;
Richardson & North, 2017).
Some owners of small businesses are less careful about security and controls than
end users, which makes even security-savvy customers easy targets. Owners of small
businesses often underestimate their risk level and fail to invest in cybersecurity
measures; as such, they have become a more frequent target (Goldsborough, 2016).
Sultan, Khalique, Alam, and Tanweer, (2018) stated that since the first ransomware
attacks occurred in the mid-2000s, there have been over 7,600 attacks (FBI, 2015). In
2015, the IC3 received over 2,453, complaints of ransomware that cost over $1.6 million
(FBI, 2015). In 2016, the IC3 received 2,673 complaints identified as ransomware,
represented a loss of over $2.4 million (FBI, 2016b).
Hackers that formerly focused on blanket attacks have increased their presence
(Sandberg, 2019). Their new method involves targeting specific businesses, consumers,
and hospitals with a critical need for data (Yaqoob et al., 2017). Consumers are becoming
the most likely victims of ransomware, as some businesses are unable to recover from the
loss of data because the cost of recovery is prohibitive (Ali, 2017). The use of mobile
devices and social media with relatively lax security has made organizations—
particularly especially those that utilize social media for recruitment and marketing are
vulnerable to attackers (Sandberg, 2019). Social media enables unprecedented access to
individual and business data, which is another weak access point that owners of small
businesses must learn to control (Kaushik, Kumar Jain, & Kumar Singh, 2018). Hackers
also exploit security weaknesses in the operating systems, firmware, encryption software,
and productivity software that are used by small businesses (Kesan & Hayes, 2017).
Various areas of technology are vulnerable to cybersecurity threats. Cyber threats to
small businesses have become a daunting problem because hackers are after business and
customer data. These businesses do not have multi-million-dollar security budgets, and
therefore are a much easier target (Krunal & Viral, 2017).
Other areas of interest to researchers are security weaknesses associated with
ecommerce systems, as well as the methods owners of small businesses used to protect
data (Burhan, Rehman, Khan, & Kim, 2018). In a small business survey, the researchers
found that most owners of small businesses outsource their electronic commerce websites
(Choras & Kozik, 2015). Although this may have a significant impact on solving the
physical problem after being outsourced, the IP address that the business server used to
host the site can remain visible through a basic search via Google (Sharma & Lijuan,
2015). Web application attacks are the most single predominant and devastating security
threat that most businesses are facing today (Sobitha Ahila & Shunmuganathan, 2016).
Owners of small businesses need to adopt a robust cybersecurity system with
multifaceted and integrated security solutions (Pan, White, & Sun, 2016). Owners of
small businesses need a comprehensive security plan that would address a wide variety of
vulnerabilities and Internet-based attacks. This comprehensive security plan could also be
modified to periodically tackle the constant changes in Internet-based attacks (Sabillon,
Cavaller, Cano, & Serra-Ruiz, 2016).
Holistic Cybersecurity Strategies
Cybersecurity is a proactive approach that could be used to protect Internet-linked
systems, including software, hardware, and data, from cyber attacks (Trappe & Straub,
2018). From this viewpoint, cybersecurity is connected to an organization's practices,
policies, and physical infrastructure (De Oliveira Albuquerque, Garcia Villalba, Sandoval
Orozco, De Sousa Junior, & Kim, 2016). Cybersecurity is considered a significant
challenge for any organization that must deal with cyber threats (De Oliveira
Albuquerque et al., 2016).
A holistic cybersecurity strategy covers the preparations and precautions against
cyber breaches (Ceric, 2016). Holistic cybersecurity strategies include corrective and
preventive measures that some owners of small businesses used to protect confidential
company data from cyber attacks (Allodi & Massacci, 2017). A cybersecurity strategy is
an essential technology element that organizations are using to protect their system from
an imminent attack. Good cybersecurity practice ensures the integrity, confidentiality,
and availability of data security (Elifoglu, Abel, & Tasseven, 2018). By becoming
proactive in cybersecurity issues, owners of small businesses are essentially safeguarding
their organization’s security system.
Watad et al. (2018) noted that adopting information security tools is not consistent
across all small businesses. These are due to inconsistency, lack of information security
awareness, and the lack of necessary skills and knowledge to select and implement
security solutions (Watad et al., 2018). These factors made it difficult for small
businesses to implement a consistent, proactive cybersecurity strategy. Small businesses’
information security strategies should be able to address the continual growth of cyber
threats and risks. However, to be effective, owners of small businesses must align
strategies closely with business goals (Nastasiu, 2016). Owners of small businesses need
to determine the level of their system vulnerability and develop a suitable holistic plan to
address vulnerabilities (Jones & Shashidhar, 2017). Some owners of small businesses
have incorporated holistic strategies that can detect, protect, and respond to current cyber
attacks.
The holistic approach incorporates human, technical, and physical factors relevant
to detecting, preventing, and correcting current cybersecurity vulnerabilities (Kafol &
Bregar, 2017). Some owners of small businesses are defending against cybersecurity
attacks by installing system security, security awareness, education, training employees,
and intrusion detection to prevent targeted attacks (Almeida, Carvalho, & Cruz, 2018).
System Security Strategy
Some owners of small businesses have installed computer protection like
firewalls, antivirus software, intrusion detection systems, two-factor authentication,
phishing filters, and many other security products to combat Internet-based attacks
(Huang et al., 2018). Firewalls are a vital strategy for small business network security, as
they are a set of related layers against threats and prevent outsiders from accessing data
on the business network as described by Elifoglu et al., 2018. Internal firewalls are being
used to fortify the computer system by some owners of small businesses. Firewalls could
be used to prevent pop-ups, cookies, malware, and e-mail viruses from infecting the
business network (Elifoglu et al., 2018).
Some small businesses are contacting security companies for antivirus,
antimalware, and anti-spyware software solutions that can protect their computer system
from cyber attacks (Huang et al., 2018). Some small businesses’ computers are secured
with antivirus, anti-malware, and anti-spyware software that have been configured to
receive the regular update.
Intrusion Detection Strategy
Some owners of small businesses that have the resources to implement intrusion
detection are adopting a defense-in-depth (DID) strategy to protect valuable data and
information (Rahman et al., 2019). The implementation of a DID strategy gives them the
ability to detect, defend, and mitigate various types of cyber attacks. This robust security
measure combines a series of different defensive mechanisms; such that, if one fails,
another is immediately in place to thwart the attack, For example, some businesses
include automated vulnerability testing of both the website and the system that supports it
(Burgess, 2016). Security testing is part of all stages of the system’s life cycle and is a
practical solution used to secure business data from attacks (Wolff, 2016).
DID strategy require that relationships between network resources and network
users be scalable so that controlling access could go beyond placing firewalls between
segments on the network. Wolff (2016) noted that DID strategy would require a tailored
strategic approach that could be applied to various levels of security to restrict setting and
protect critical assets, such as proprietary and confidential information. The DID strategy
also provides a series of defense that includes malware scanners, firewalls, intrusion
detection systems, and local storage encryption tools (Rahman et al., 2019). Owners of
small businesses could deploy these strategies to close gaps in their security system and
protect their businesses from an attack.
Cyber Security Awareness Education and Training
Hadlington (2017) noted that understanding what governs good cybersecurity
practices is the need to focus on awareness and employee training. Employee education
has gone a long way to helping some owners of small businesses to detect and ward off
cyber attacks. Employees are trained to understand cyber attacks warning signs, safety,
and the proper methods to respond to an attack, understanding their duties and
responsibilities, the procedures and processes needed to protect confidential company
data from cyber attacks (Hadlington, 2017). Some owners of small businesses are
educating their employees about the various online threats, including the safe use of
social networking sites (Elifoglu et al., 2018). The first line of defense against a data
breach is often the employees. Having employees who understand their responsibility in
handling data goes a long way towards preventing a breach before it begins.
Janakiraman et al. (2018) wrote that businesses are developing adequate security
awareness through employee training scenarios. Some owners of small businesses have
also implemented a cybersecurity awareness program that ensures employees are
cognizant of the significance of protecting sensitive information and the risks of
mishandling information (Williams et al., 2016). Conteh and Schmick (2016) noted that
new employees must be required to attend preliminary training during orientation. The
training would help to build awareness by exposing new employees to various
cyberthreats and the tactics and behaviors used by hackers. Some owners of small
businesses have cybersecurity policies on the importance of securing information,
defining risk management, listing the types of information that ought to be secured, and
identifying various threats using best practices (Rizov, 2018).
A culture of security awareness helps owners of small businesses prepare against
cyber-incidents. An atmosphere of this kind includes reporting, responsiveness, and
openness that allows quick responses to potential threats and mitigates the issue
(Tasevski, 2016). Information security awareness training is essential because it does not
merely educate employees on possible security threats and the steps to prevent them but
also focuses on organizational culture on security awareness (Muronga, Herselman,
Botha, & Da Veiga, 2019).
Outsourcing Strategy
Some owners of small businesses need to be able to defend against and limit cyber
attacks, when it comes to cybersecurity and defensive capabilities, the needs of small
businesses are similar to those of larger organizations. The main difference is that some
owners of small businesses are using standardized cloud services, for example, Microsoft
Office 365, SaaS, Cloud Infrastructure, and Google Docs instead of customized
applications and infrastructure (Mokwena & Hlebela, 2018). Also, they are outsourcing
their cybersecurity to the right technical partner or service provider that can handle their
day-to-day security processes and also secure critical assets, such as proprietary and
confidential information (Prince, 2018). Ogunshile (2018) concluded that having the right
cybersecurity partner to manage their security environment would take an enormous
burden from owners of small businesses. While working with vendors, some owners of
small businesses have developed some security measures to protect sensitive data. Some
owners of small businesses still lack adequate response to an attack because they do not
have the means and techniques to properly manage cyberattacks (Makridis & Dean,
2018).
Owners of small businesses must be able to manage and protect both business’
and customers’data by using multiple vendors to make data-driven decisions (Kim, Lee,
& Ryu, 2018). Some owners have taken proper steps to invest and implement defense
systems using different approaches, such as defending their system from a specific set of
attacks or limiting data access (Williams et al., 2016). These steps could ensure that they
can quickly detect and respond to them before data are stolen (Vlad-Mihai, 2017). Other
owners of small businesses prioritized what they protect. They plan to spend on
technological platforms because their needs are the same, even though the scale of their
expenditure is less than a larger organization (Kim et al., 2018). The problem facing
owners of small businesses is often intractable; unlike big organizations, small businesses
are not able to invest in the necessary resources and people to manage IT security
(Rothrock et al., 2018).
Those owners of small businesses who are not able to afford defensive
cybersecurity systems are moving their technology to the cloud system because of its
affordability and unmatched utility (Korte, 2017). A cloud service agreement is
accompanied by security services that include an understanding of how the business
collects data, usability, and ownership. These services have helped some owners of small
businesses to prevent data losses, which have the potential to jeopardize business
reputation with customers, suppliers, and partners (Mokwena & Hlebela, 2018).
The general trend is for owners of small businesses to depend on cloud vendors to
provide more and more e-commerce services. As technology improved, more and more
product is being delivered through the cloud system with the democratization of
cybersecurity (Pantangi, Xiong, & Makati, 2016).
Third-Party Vendors Strategy
Some owners of small businesses that are unable to invest in cybersecurity are
either retaining managed security services providers (MSSPs) or relying on specialized IT
vendors (Cezar, Cavusoglu, & Raghunathan, 2017). They developed an effective
cybersecurity strategy by outsourcing their information security to an MSSP that helped
them gain access to professionals who monitor and maintain their systems remotely to
ensure privacy and security best practices (Lopes & Oliveira, 2016).
Owners of small businesses face many IT challenges, but by outsourcing their
information security, everything from website functionality and cloud migration to
technology update and data backups (Njenga & Jordaan, 2016). Outsourcing services
include business continuity, operational efficiency, maximum return on technology
investments, cost reductions, as well as better protection for business and customer data
(Li, Liu, Belitski, Ghobadian, & O'Regan, 2016). These measures have supports and
resources that can handle current cybersecurity challenges and protect against cybercrime
as well as disaster recovery processing should an attack occur (Opitz, 2018).
A Holistic Prevention Strategy
Cyber-terrorism has become a more significant threat because owners of small
businesses who are government contractors often become the target of malicious attacks
(Wainwright, 2018). The alarming rise of such incidents has made cybersecurity a
significant concern, and researchers called for creating a cyber-terrorism framework
(Terzi, 2019). Besliu (2017) stated that the highest risk of cyber attacks is government
employees, followed by business employees with access to government networks. These
risks have become a significant concern to owners of small businesses because some
receive government and large corporate contracts. Without standardized preventive
methods capable of adapting to current threats, cyber-terrorism will increase as a threat to
small businesses (Albahar, 2017).
A holistic prevention strategy could be used to avoid the effects of cyberterrorism.
Kadir, Judhariksawan, and Maskun (2019) concluded that deterrent strategies are not
adequate to prevent cyber-terrorism because deterring all unwanted cyber-threats has
proven difficulties. Business leaders need a realistic expectation for deterrence that would
be able to minimize and mitigate the impact of cyber-terrorism (Wainwright, 2018). The
greatest danger to cybersecurity for small businesses comes from trusting providers,
strategic partners, and allies who have not been engaged in prevention and detection
(Nicola, 2018). As a result, some owners of small businesses are using a preventive
strategy that is not well-defined and may not defend against cyber-terrorism (Nicola,
2018). Gross, Canetti, and Vashdi (2017) noted that resilience efforts constitute securing
the bridge between the system that supports business operations, upgrading network
hardware, and Internet connectivity pathways to improve situations following a
widespread and potentially devastating cyber attack. Significant preparations would also
help improve cyber-resilience that can manage and control the aftereffects of a cyber
attack (Kadir et al., 2019).
Data Protection Strategy
Data storage is another growing concern for small businesses. The way that data is
shared and stored evolves with the advance of technology. The Internet of Things (IoT)
refers to Internet-connected devices that collect and share data (Riahi Sfar, Natalizio,
Challal, & Chtourou, 2018). The IoT is helping owners of small businesses streamline
their processes and compete with other businesses to reach millions of customers around
the globe (Janecek, 2018; Makridis & Dean, 2018); However, this also can lead to cyber
breaches. Owners of small businesses need to guarantee that IoT devices are connected
correctly and that there is no room for a data breach, as these devices are susceptible to
the same Internet-based attacks as businesses (Riahi Sfar et al., 2018).
The IoT shares data through Internet protocol with other communication devices
that are equipped with sensors, microchips, and actuators to help prevent a breach (Gil,
Ferrandez, Mora-Mora, & Peral, 2016). Some owners of small businesses use this
technology to improve their everyday work through advancements, such as free smart
office assistants (Ban, Choi, & Kang, 2016). Small businesses are prone to cyber attacks
through these connected devices because cybercriminals are aware of the different
Internet protocols (Stanciu, & Tinca, 2017). Guitton (2017) recommended three strategies
to secure against Internet-based attacks: (a) prevention before an attack, (b) detection
during an attack, and (c) response after an attack. Early detection and immediate
mitigation of cyber attacks are the hallmarks of managing Internet-based services and
having a proactive defense strategy against such threats (Anderson, Baskerville, & Kaul,
(2017).
Some owners of small businesses applied these strategies to secure Internet-based
systems: monitoring security against cyber attacks, studying the effects of cyber attacks
on their system by developing an attack tree by generating intrusion scenarios to explore
specific attack paths (Guitton, 2017). Financial organizations are more prepared to handle
a data breach attack because they developed a better monitoring system, as they could
detect and prevent breaches. Developing a monitoring system and data protection
strategies is essential to small business operations, regardless of the type of connection
the business is using to send data (Munier & Kemball-Cook, 2019).
Kesan and Hayes (2017) indicated that more than 63% of customer credit card
data are unencrypted when stored in the server, and 7% of businesses still keep records of
data contained in the card’s magnetic bar. These practices magnify the business’ security
vulnerabilities (Kesan & Hayes, 2017); there are alternative methods to safeguard
customer credit card information during transmission as some owners of small businesses
have strengthened their payment gateway with banks that issue cards; this has helped to
secure credit and debit card information during purchases (Greenacre, 2015). Banks that
issue a credit card to small businesses are supplying tools that the owners use to confirm
card payments and ensure that customers' data are safe (Greenacre, 2015). Some owners
of small businesses are practicing isolation, which is one of the best cybersecurity
practices for credit and debit cards (Greenacre, 2015). These are done by isolating
payment systems on a separate computer from the regular network, which has helped to
limit the risk and impact of attacks (Awrey & Van Zwieten, 2018).
Some owners of small businesses updated their payments processor and all
pointof-sale (POS) systems that include mPOS devices with updated cybersecurity
technologies (Awrey & Van Zwieten, 2018). Encrypted card data could be manipulated
so that each legible entry would be read-only as a string of obscure characters if an
unauthorized user accessed it (Cox & Pilbauer, 2018). By using tokenization, the
payment processor could securely store card data (Awrey & Van Zwieten, 2018). Some
owners of small businesses also took advantage of e-commerce websites that offer builtin
security systems with payment processing services that would protect their online
customers’ data (Holland & Gutierrez-Leefmans, 2018).
Owners of small businesses could also identify various potential internal and
external data security risks and develop a counter-attack strategy to protect against them
(Wadhwa & Arora, 2017). Some owners of small businesses have designed and
implemented security plans, data privacy, policies, and procedures that include incident
response and crisis management plans (Tisdale, 2015). These also include potential
shareholders, liability issues, regulatory interests, a data retention policy, and ways to
dispose of unwanted information (Almeida et al., 2018).
Data Breaches
Janakiraman et al. (2018) described data breach as the inadvertent or intentional
exposure of confidential data to unauthorized parties. Data breached occur when hackers
gain access to private data such as social security numbers, addresses, passwords, phone
numbers, and usernames from breached sites such as credit bureaus, retail stores, and
email providers. A data breach could occur for various reasons, including fraud, theft, and
human error (Janakiraman et al., 2018). Among the data breaches that have taken place in
the United States and globally included retail brands like Target lost over 40 million
customers data, Home Depot over 56 million customers data, Michaels over 2.6 million
customers data, Neiman Marcus over 1.1 million customers’ data, and Staples over 1.2
million customers were hacked (Kim, Johnson, & Park, 2017). These retailers are the
major suppliers to small businesses, and these massive data breaches are directly
affecting small businesses, which are resulting in millions of compromised consumer
accounts (Plachkinova & Maurer, 2018).
Selznick and Lamacchia (2018) concluded that during the past five years, the
number of cyber attacks on organizations with 250 or fewer employees increased
dramatically. In 2015, the average cost of a data breach was $6.53 million, making this a
significant problem for organizations (Selznick & Lamacchia, 2018). In 2017, the
Chipotle Mexican Grill restaurant chain was a target of cybersecurity attacks. The breach
affected 2,250 restaurants nationwide (Selznick & Lamacchia, 2018). The hack was due
to malware designed to access payment card data from cards used at POS devices in
certain restaurants (Selznick & Lamacchia, 2018). In 2016, Newkirk Products, a small
business service provider that issues insurance healthcare ID cards for Blue Cross and
Blue Shield, reported a breach on the server that holds member information, and some
data were stolen (Selznick & Lamacchia, 2018).
Data breaches could be a result of an accidental data breach or an attack;
objectives include competitive data used for corporate espionage purposes, employees’
social security numbers, financial, medical records, and customers’ records (Brown,
2016). The fallout of such breaches could persist for years, as was the case in the Equifax
attack (Moore, 2017). Bai, Jiang, and Flasher (2017) noted that in 2016, the medical and
healthcare sector experienced 34.4 % of the 185 data breaches to date. The number of
records exposed in these breaches totaled nearly 4.5 million, representing about 34.4 %
percent of the total as of July 2016 (Bai et al., 2017). 90% of small businesses that
experienced data breaches were unaware of the breach until informed by a third party, as
cybercriminals continue to adopt new techniques as their threat continues to advance
(Eddolls, 2016). Owners of small businesses must become proactive by being aware of
these changes and ensuring that their business process is adequately prepared and
protected.
Data Breach Prevention Strategy
Owners of small businesses could develop resilience in combating future cyber
attacks by creating a cyber-defense strategy that could position them to dynamically
respond to attacks through improved situational awareness, active command control, and
active defenses. These approaches would provide a proactive response to cyber attacks, as
recommended by Williams et al. (2016). Previous organizational methods of handling
data breaches include implementing an incident response plan after the breach (Fisher,
Norman, & Klett, 2017). Owners of small businesses generally employ reactive strategies
to combat data breaches rather than proactive approaches (Galinec, Moznik, & Guberina,
2017).
A proactive approach for data breaches would incorporate layered security
strategy to detect suspicious activity before a breach occurs and put a stop to a potential
breach as early as possible (Williams et al., 2016). Most scholars studying
cybersecurityfocused on the technical aspects of a data breach incident, which is useful in
helping organizations understand how a breach occurred (Parks & Adams, 2016). Owners
of small businesses could then create internal assessment procedures for determining
effective security control. Some owners of small businesses are creating a catalog of
security controls to meet current cybersecurity needs that could also apply to the future
(Brown, 2016). Allodi and Massacci (2017) provided steps that can be applied to specific
areas where businesses could improve their cybersecurity strategy. These can be done not
by investing in the latest technology but by improving internal organizational processes.
Data Leak Prevention Strategy
Data leakage is another issue that poses threats to organization operations,
financial losses, and reputational damage. Losing sensitive information could be
detrimental to the long-term growth and stability of small businesses (Cheng, Liu, & Yao,
2017). While data leaks could be considered a minor inconvenience, the reality is that the
worst data breaches occur over time by devious means, which have far-reaching
consequences when confidential data fall into the hands of an unauthorized user
(Alneyadi, Sithirasenan, & Muthukkumarasamy, 2016).
Data leakages can be caused either by malicious intent or an inadvertent mistake
by an insider. In either case, exposure of sensitive information can severely hurt an
organization (Angst, Block, D’Arcy, & Kelley, 2017). The potential damage and adverse
consequences of a data leak incident can be classified into the following two categories:
direct and indirect loss. Direct loss refers to physical damage that is easy to measure and
estimate quantitatively. The indirect loss is much harder to quantify and has a much
broader impact regarding cost, place, and time (Rothrock et al., 2018).
The scope for data leakage is pervasive and is not limited to just web and email;
data leakage includes the unauthorized transmission of data to an external destination
from within an organization, which can either be intentional or inadvertent (Vavilis et al.,
2016). A combination of factors like insider or outsider threats can cause a data breach;
from a targeted attack, which is often inadvertently allowed by well-meaning insiders
who do not follow data or security policies (Choi, Kim, & Jiang, 2016). Data leakage can
either be created intentional or unintentional; Intentional leaks occur when data are
purposely transmitted to someone outside the company, who does not have a legal right
to possess the information (Angst et al., 2017).
The potential damage and adverse consequences of a data leak incident can be
classified into two categories: direct or indirect loss. Direct loss refers to physical damage
that is easy to estimate, and indirect loss is much harder to quantify that has a
wideranging impact that includes cost, place, and time (Rothrock et al., 2018). The scope
for data leaks are pervasive and not limited to just the web and email; data leakage
includes the unauthorized transmission of data to an external destination from within an
organization, intentionally or inadvertently (Vavilis et al., 2016). A combination of
factors (such as insider or outsider threats) could cause a data breach. A targeted attack is
often inadvertently allowed by innocent insiders who do not follow security policies
(Choi et al., 2016).
In most cases, careless insiders without a motive or intent to cause harm could
leak data and cause a situation that can be just as bad as one caused by malicious
attackers (Dhawase, Chaudhari, Kolambe, & Masare, 2018). Employees are the most
common security threat to most organizations; when they abuse their access, they harm
security layers of the company and may cause considerable losses (Hennig, 2018). In
2014, eBay asked their 145 million users to change their account passwords due to a
breach that affected personal information and encrypted passwords (Williams et al.,
2016). Hackers gained access to an eBay account through stolen login credentials from
eBay employees. Organizations must perform consistent vulnerability assessments on
both internal and external network systems (Williams et al., 2016). Owners of small
businesses need a breach response plan that would trigger quick responses to data
breaches to decrease the impact. The plan could contain steps that involved notifying the
appropriate personnel and vendors who could contain the breach. Kim et al. (2017)
pointed out that in a crisis, businesses that are faced with data breaches should avoid legal
consequences by disclosing the nature of the breach to affected and potentially affected
customers whose data may have been compromised.
Data leakage requires protective measures to mitigate future threats. Data loss
prevention (DLP) is a strategy that ensures users are not able to send confidential
information outside a company’s network (Costante, Fauri, Etalle, den Hartog, &
Zannone, 2016). These strategies involve a combination of user security policies and
tools. Owners of small businesses need a data protection policy that includes information
security, privacy, and need that relate to the business. Kaur, Gupta, and Singh (2017)
noted that DLP could be used to reduce risk, improve data management practices, and
even lower compliance costs. DLP increases user awareness by alerting them when there
is a suspicious email; this has helped to increase business’ responsibility and used to
correct oversights to security policy before a leak happens (Ma, 2017). Owners of small
businesses can use DLP to improve processes, identify steps to uncover security flaws,
and implement remediation actions.
Summary and Transition
Summary
The literature supports the intent and problem statement of the current study.
Cybersecurity is a relatively new field, with a limited number of extensive studies and
models. As technology continues to evolve, cybersecurity will become a viable field of
study due to the pressing need to secure data in all settings. The growth of
cyberdominance makes cybersecurity a pressing need (Jia, Qi, Shang, Jiang, & Li, 2018).
While all businesses are vulnerable to cyber attacks, it is clear that small business
is more susceptible to cyber attacks than large organizations. However, it is also clear that
owners of small businesses do not have access to resources and techniques like large
organizations. Larger establishments typically have a robust defense system that is
difficult to compromise or breach. Many larger organizations’ systems are interconnected
with those of small ones. When hackers compromise the security system of small or
midsize businesses, they can then easily penetrate the defenses of even multinational
corporations. Hackers are aware of complacency among small businesses concerning
cybersecurity. Hackers understand that owners of small businesses invest relatively little
money to improve the state of their cybersecurity; this weakness is being exploited and
making small businesses vulnerable to attack. In short, existing researchers studying
cybersecurity breaches have predominantly focused on the impact of public disclosure of
such incidents on the affected organizations' market valuation. Chen (2019) examined the
impact of data breaches on consumers and ways at which owners of small businesses can
reduce the impact of data breached. The author further indicated that owners of small
businesses should be able to provide insights on how to prevent and manage data
breaches. The impact and cost associated with a single breach can be catastrophic to
small businesses. It is necessary to address the different factors that influence owners of
small businesses that lack cyber-defense strategies. In this literature review, I
substantiated the need for owners of small businesses to be aware of cybersecurity
threats, as well as develop preventative strategies to combat security threats and eliminate
privacy concerns.
Transition
In Section 1, I included information to support the research problem. Additionally,
I presented the background that supported the phenomenon that some owners of small
businesses lack the knowledge of cyber-defense strategies to protect business data from
cyber attacks. In the problem statement, I addressed both the general and specific
business problems, while the purpose statement contained the justification for the
research method, design, and participant size. Using a detailed literature review, I
supported the research problem. In Section 2 of this study, I deliberate on the research
framework components, which includes further details on the overall intent of the study,
participant enlistment, data collection, and analysis. In Section 3 of this study, I provide a
formal presentation of the findings of the study.
Section 2: The Project
Purpose Statement
The purpose of this qualitative multiple case study was to explore strategies
owners of small businesses use to protect confidential company data from cyber attacks.
The target population for this study consisted of five successful owners of small
businesses in the Fort Lauderdale, Florida area who have implemented effective
cybersecurity strategies to protect their business data from cyber attacks. The implications
for positive social change include the potential to enhance sound cyber policies that can
be used to protect business and customer data, thereby increasing customers’ confidence,
increasing businesses’ economic growth, and stimulating the socioeconomic lifecycle,
resulting in potential employment gains for residents in communities.
Role of the Researcher
My role as a researcher involved selecting participants, preparing the interview
questions, collecting and recording data in an accurate manner as it relates to the study
problem statement as described by Bansal, Smith, and Vaara (2018). Researchers who
use qualitative methodologies must develop sufficient knowledge to comprehend why it
is essential to interpret and understand the data needed to conduct the research study
(Cumyn, Ouellet, Cote, Francoeur, & St-Onge, 2018). Scholars who used qualitative
methodologies must successfully develop their skills with research instruments that could
be used to collect data (Yin, 2018). Researchers who used qualitative methods must
develop, conduct, and interpret comprehensive qualitative data analysis that could be
used to present study findings while following basic ethical standards (Bansal et al.,
2018). Researchers must adhere to basic guidelines and ethical principles that would
assist in resolving ethical problems. I enacted protocols to ensure that participants were
treated with the highest ethical standards, as described in the study conducted by Miracle
(2016). I reviewed and observed the basic ethical principles detailed in the Belmont
Report. To be able to follow this objective, I completed the Collaborative Institutional
Training (CITI) course training (Certification Number: 8042684). The Belmont Report
served as the ethical framework for this research because it outlines a framework that
guarantees respect, beneficence, and justice for participants (DHEW, 1979). Compliance
with these guiding values ensured that I conducted my research using an ethical
foundation. I adhered to ethical principles and guidelines by applying the three principles
to minimize risks and ensure benefits to participants (see Miracle, 2016). I maintained
ethical and professional relationships with participants, as described by Cypress (2018).
The selected owners of small businesses are not in my professional or social network. I
did not have a professional relationship with the study participants; this helped to ease the
concern of participants who were reluctant to participate or hesitate to reveal sensitive
information that benefited the study. Amankwaa (2016) pointed out that researchers who
plan to create a qualitative proposal should create a trustworthiness protocol. These
provided evidence of consistency and accuracy concerning the process of how data were
collected and the timeline directing the activity similar to the approach used by Cypress
(2018). I prepared my research protocols with a detailed process as to how I collected
data in the interview protocol (see Appendix B).
I found that there are no conflicts regarding the boundaries between practice and
research on how I collected data from owners of small businesses. Owners of small
businesses voluntary participants in this study and have the option to opt-out at any point
during the research process. I ensured that participants’ experience in cybersecurity
matches the goal of the study. I did not include those with too much or too little technical
knowledge; only those with the appropriate level of experience were included for the
research study. Participants were encouraged to speak openly during the interview
process to guarantee that their point-of-view was relevant. I was neutral, as such, avoided
impacting how participants are answering the research questions. To further protect
participants, I excluded the names of organizations and participants from the study. To
assist in maintaining consistency and structure between interviews and ensure that the
data collected are accurate and unbiased, I used the interview protocol similar to the
approach described by Van Hilten (2018).
I also used member checking to seek feedback from participants to mitigate bias.
Member checking is a technique that involves participants validating the interpreted data
after the interview, and which could establish credibility with participants (Birt, Scott,
Cavers, Campbell, & Walter, 2016). Thomas (2016) described member checking as a
method that could be used to obtain participant approval and reduce research bias.
Following each interview, I seek feedback from participants, which helped to improve the
credibility of the collected data. After participants validated the interpreted data, I used
the data to capture the themes for accuracy.
Participants
Recruiting participants is the foundation of an effective research study because
research results are only as useful as the participants’ involvement. As the researcher and
the primary data collection instrument for this study, I used the purposive snowball
sampling strategy similar to the approach described by Valerio et al. (2016). These are
based on a referral tactic in which I corresponded with some owners of small businesses
with specific characteristics that were used to recommend and recruit others with the
same characteristics. These tactics were beneficial in recruiting the five successful owners
of small businesses in Fort Lauderdale who have implemented effective cybersecurity
strategies.
Meyvis and Van Osselaer (2017) noted that recruiting participants in research
studies is an essential part of the study process. I also recruited participants using
business statistics publications provided by local government and state agencies. This
strategy helped to optimized participant recruitment and gained access to their
professional perspective, similar to the approach used by White and Hind (2015). The
first technique of population search consists of business listings from inquiries on the U.
S. Small Business Administration (SBA) website for the South Florida District–Miami
(SBA, 2018b). Using the SBA website links gave me access to small business datasets
that helped in my preliminary source for recruiting participants who met the sample
population criteria for this study. Another search technique that I used to recruit
participants from the City of Fort Lauderdale was using the city business resources guide,
which helped to develop my sample population (City of Fort Lauderdale, 2018; Greater
Fort Lauderdale, 2018). The next technique was accessing owners of small businesses
from the Broward County Small Business Assistance Council, whose main aim is to
encourage the growth of small businesses in Broward County (SBA, 2018b). Finally, I
attended a monthly meeting for the Broward County Economic Development
Commission, where I met some owners of small businesses, which help to provide
another means for recruiting participants.
Participants were required to meet the established small business size standard as
detailed in the North American Industry Classification System dated 2012 or later (SBA,
2018a). Peticca-Harris, DeGama, and Elias (2016) stated that researchers must comply
with academic institution requirements while organizing and planning their study; this
includes obtaining approval from an ethics board. I also contacted participants by phone
to establish a working relationship and introduce participants to the study, after I obtained
the IRB approval (No. 06-26-19-0490285) from Walden University. I also contacted
potential participants in person and in writing to maximize the time spent with each
participant, similar to the approach described by Griffith, Morris, and Thakar (2016).
After owners of small businesses have indicated their readiness to participate in this
research, I asked each one to sign a consent form, which was in the IRB requirements
spelled out in Walden University's ethical guidelines. Researchers must build and
establish a trusting relationship by keeping the information of participants confidential, as
described by Gonzalez-Saldivar et al. (2019). I used the participant consent form to
recognize and establish participant privacy and trust in this study.
Research Method and Design
Research Method
I chose to use a qualitative method for this study. Researchers use qualitative
methods to understand the underlying phenomena to gain experience (Jacobs &
Tschotschel, 2019). Qualitative methodology was appropriate because it was useful in
gaining insight into the strategies that owners of small businesses have used to protect
company data from cyber attacks. Bansal et al. (2018) indicated that qualitative
methodology is most appropriate for studying social phenomena that do not generate
sufficient data for quantitative studies. My intent was not to quantify why owners of
small businesses do not implement security control, but rather to learn the strategies that
owners have used to protect their company’s data from cyber attacks. A quantitative
research method was unsuitable because I was not examining relationships among
variables of cyber security data. Further, mixed methods were inappropriate for this study
because this approach involves integrating both qualitative and quantitative components.
I was not studying relationships and trends relating to cyber security variables. Also, I did
not have access to this type of data to add to the qualitative data from the interviews (see
Nelson, 2016). Mixed methodologies involve collecting, analyzing, and integrating both
qualitative and quantitative methodologies to solve a research problem (Park & Park,
2016).
Research Design
A multiple case study was the appropriate design choice for this study. Other
research designs that were considered included ethnographic, phenomenological,
narrative, and case study. Ethnographic research was unsuitable for this study because it
seeks to identify and understand the behaviors and cultural practices of a specific group
(Cardoso et al., 2017). The goal of phenomenological research is to provide the meaning
of the experiences of a group or an individual that relates to a particular phenomenon
(Flynn & Korcuska, 2018). Past experiences did not provide insights into the strategies
that were reviewed in this study; therefore, the phenomenological research design was not
appropriate. Narrative research provides a visual representation or written stories of
participants’ personal experiences (Bruce et al., 2016), but was not appropriate for this
study because analyzing strategies does not benefit from telling stories from past
experiences. The purpose of this study was to analyze strategies used by owners of small
businesses to protect confidential data from cyber attacks. The multiple case study design
was suitable for this study because it can be used to identify, describe, and understand
collected data, as noted by Heale and Twycross (2017).
A single case study set focuses on a specific case, while a multiple case study
focuses on multiple cases that allow for a more comprehensive exploration of the
research questions and their development (Wilson, 2016). A multiple case study was the
most suitable design choice because using multiple case studies allows the researcher to
explore phenomena and utilize multiple forms of data collection to gather information on
strategies owners of small businesses have used to protect their business data from cyber
attacks. I interviewed five successful owners of small businesses for this study to achieve
data saturation similar to the approach described by Boddy (2016). When I reached the
point in the interview process that the data collected offered no new information (or was
redundant), data saturation was attained as described by Benoot, Hannes, and Bilsen,
(2016).
Population and Sampling
The study population was five owners of small businesses in Fort Lauderdale,
Florida. Benoot et al. (2016) noted that a qualitative research purposeful sampling is a
non-probability sampling method that a researcher uses to identify and select a set of
features within a sample as it relates to the phenomenon of interest. Purposeful sampling
is beneficial when conducting interviews because it provides a set of recommendations
that can be used for multistage designs (Benoot et al., 2016). A purposeful sampling of
four participants was drawn from the population of those who have successfully
implemented cybersecurity strategies. The purposeful sample participants were derived
from face-to-face and semistructured interviews. These semi structured interviews took
place at a convenient location to avoid distractions. Benoot et al. (2016) noted that an
appropriate sample size for a qualitative study would depend upon the study context.
Purposeful sampling was suitable for this study because it allowed me to gain different
viewpoints and collect data from participants who were knowledgeable and had
implemented effective cybersecurity strategies. Data saturation is significant because it
indicates data accuracy, and this can occur when no further categories or themes can be
derived from the collected data (Benoot et al., 2016).
For a multiple case study design, I needed at least five interviews to achieve data
saturation similar to the approach used by Boddy (2016). If I did not reach data saturation
after interviewing the five successful owners of small businesses, I would further conduct
interviews until data saturation is achieved. When I reached the point in the interview
process that the data collected offered no new information, I attained data saturation
similar to the approach described by Benoot et al. (2016).
Ethical Research
Protecting participants’ privacy is a critical factor in this research study. My top
priority was maintaining the highest standards of ethics that focused on the highest
quality of research. I began the study after obtaining IRB approval (No. 06-26-
190490285) from Walden University. I avoided falsification, plagiarism, and misconduct,
as described by Burkholder and MacEntee (2016). To assist in maintaining moral
principles,
I observed the following research protocols:
•I only used participants who gave their consent in the data collection process.
Participants volunteered by agreeing to contribute to the study by replying “I
consent” to the informed consent form that was emailed to participants (see
Appendix A). This approach was found to be effective by Gallin, Ognibene, and
Johnson (2017).
•Participants had the liberty to withdraw at any point in the research process
without penalty by verbally communicating so during the interview, or by
contacting me by telephone or email. This approach was used by Soulier (2019).
Participants also had the right to express his or her concerns to withdraw from the
research process at any time.
•I established identity protection for participants’ personal information during their
involvement in the study. All personal data collected during the interview are
remaining confidential, following IRB standards.
•Participants were guaranteed protection on all data collected, including
individuals’ names and company information. A masking process was relevant to
preserve participants’ privacy and confidentiality. This approach was found to be
effective by Korstjens and Moser (2017). Participant names are labeled with a
random number, and a random letter was used to represent organization names.
•All original paper copies are scanned and stored in a private cloud account with a
protected password, after which copies of the originals paper will be mechanically
shredded. All data collected from the date of the interview are stored no longer
than 5 years. After 5 years, I will delete all electronic data of the research record
from the private cloud account.
Data Collection Instruments
This qualitative multiple case study involves face-to-face, semistructured
interviews to collect data. Oltmann (2016) noted that semistructured interviews involve a
list of open questions that allow participants to respond to the researcher's interests in a
focused way. DeJonckheere and Vaughn (2019) suggested that semistructured interviews
help to understand the dynamics of a situation by data collection. I used semistructured
interviews to explore strategies that owners of small businesses use to protect confidential
company data from cyber attacks. Also, has the primary investigator that conducted the
interviews and acted as the data collection instrument, I supplemented my data collection
with observational notes, which helped me to record specific details of the interviews.
Twycross and Shorten (2016) indicated that observation notes are useful for data
collection in qualitative studies. These may comprise additional information, such as
body language, detailed conversations with participants, and researcher reflection of
communication with the participant.
Englander (2019) noted that participants’ responses guide the interview, but
researchers used the interview guide to conduct qualitative semi structured interviews. I
started by scheduling the interviews in advance at a convenient location and time for each
participant. The open-ended questions were designed to capture data from participants by
their descriptions and analyses. I then integrated the interactions into my observation
notes and coded their views into common themes, similar to the approach described by
Mann (2016).
After I coordinated the interviews, I organized the thematic analysis of the
collected data and calculated each theme's frequency to determine specific factors as
described by Tai and Ajjawi (2016). Observational notes, member checking, and
interviews were used to achieve data triangulation. I also provided each participant with a
summary of their interview following the member checking process. Member checking is
used for exploring the credibility of results in qualitative research and allows participants
to validate the data collected after the interview (Birt et al., 2016). Data collected were
returned to participants to check for quality and accuracy. Participants reviewing the data
collected during member checking would ensure approval and allow the researcher to
capture participants’ honest responses (Thomas, 2016).
Data Collection Technique
The data collection technique used for this study was the interviewing of owners
of small businesses. The interview method was suitable for this research study because it
offers the opportunity to uncover data that cannot be accessible using other techniques
such as observations and questionnaires (Oltmann, 2016). Interviewing is not just a data
collection tool, but rather an interactive means used to gain information; as such, it has its
advantages and disadvantages. The advantage of using interviews includes controlling the
answering order, relatively flexible interaction, and a high return rate with the presence of
the interviewer (Hunter, 2017). The interview questions were simplified and rephrased to
ensure a shared understanding between the interviewer and interviewees. As a result,
more appropriate answers can subsequently produce accurate data (Hunter, 2017).
Furthermore, the interview method is inexpensive compared to other data
collection techniques; these advantages have made interviewing an attractive method for
my study data collection. However, like any other data collection technique, interviews
have disadvantages; although interviewing is among the most used data collection
technique, it can only be useful in small-scale study research and can be deceptively
difficult because the perceptions can change over time pending on the circumstances and
responses that might be considered biased and potentially inconsistent (Hunter, 2017).
More so, the interview process is time-consuming with both data collection and analysis
that need to be transcribed, coded, and translated. After IRB approval, I began to conduct
face-to-face, semistructured interviews as stipulated in the interview protocol (see
Appendix B). I used an audio recorder to capture conversations and record interviews,
which is an acceptable process for collecting data through an interview; this was a similar
process used by Clark and Veale (2018). I conducted the interviews personally rather than
through the phone, in which the interview process assisted me in analyzing participants’
body language, which was a similar process used by Oltmann (2016).
In the first interview question, I considered strategies used by owners of small
businesses to protect their business data against cyber attacks, and the interview question
was further developed. The interviews were face-to-face, and I used open-end,
semistructured questions, which permitted me to collect data while trying to understand
the dynamics of the interview (Weis & Willems, 2017). I also observed the interview
protocol and conducted a follow-up question for clarity, which is a similar process
described by Clark and Veale (2018). I followed a detailed workflow to support
consistency with all the interviews. This workflow includes a list of thorough questions
for the participant, a summary statement, and a member-checking follow-up with a
reminder to participants similar to the process used by Van de Wiel (2017). It is
imperative in qualitative data interpretation for the researcher to guarantee reliability and
validity. I used member checking for data interpretation by summarizing and restating the
information and asked the participant to determine the similar validation process
described by Birt et al. (2016). Some of the participants either disagreed or agreed that
the summarized information reflected their experiences or views and when completeness
and accuracy were assured, this step provided the necessary accuracy and credibility.
Data Organization Technique
I recorded the interviews using an audio recorder similar to the approach used by
Castillo-Montoya (2016). I later transcribed all recordings into a Word document. Weis
and Willems (2017) recommended a process for organizing and securing data. I
organized and secured both the transcribed documents and audio recordings and backing
them up to a private cloud account. During the interview process, I wrote down notes that
detailed my observations. I used thematic analysis process to analyze the transcripts; this
helped me to identify common themes and calculating the themes’ frequencies, as
described by Maguire and Delahunt (2017). I used Nvivo to note and calculate the
thematic analysis and also backed up all documents in the private cloud account. All files
were stored in the private cloud account for five years, after which, will be securely
deleted from the private cloud account.
Data Analysis
I collected data through semistructured interviews. I supported participant
responses by reviewing and analyzing business archival documents on IT security
procedures that were obtained from participants. The process of data analysis involved
investigating and transcribing digital audio recordings, semistructured interview
transcripts, member checking notes, and reviewing other field notes and comments to
help simplify the data analysis. Qualitative researchers typically employ software to
collect, organize, and examine data from interviews, review documentation, and field
notes (Yin, 2018).
Using software for data analysis is very helpful when conducting a semistructured
qualitative study, and selecting the correct software will help to increase research
accuracy. NVivo is a user-friendly product that provides qualitative data analysis and
enables researchers to generate projects and manage data based on various study designs
(Zamawe, 2015). NVivo supports data retrieving, sorting, categorizing, browsing, coding,
interpreting, and synthesizing researcher qualitative data (Zamawe, 2015). I used the
program because it offered features that allowed me to analyze and automate data that
were generated from the selected inputs, as described by Paulus, Woods, Atkins, and
Macklin (2017); Phillippi and Lauderdale (2017). I used Nvivo to analyzed the transcript
based on the interview transcripts and further subcategorize the data based on their
parameters. Nvivo was very helpful in organizing, analyzing, and classifying
nonnumerical data from a similar process described by Zamawe (2015). I analyzed and
transcribed the interview transcripts and observational field notes from participants’
responses, similar to the approach described by Boddy (2016). I used NVivo to code
participants’ responses into themes by using a thematic analysis technique, as described
by Zamawe (2015). After entering the data into NVivo, I used the coded data to generate
multiple data sets as it relates to how owners of small businesses are protecting
confidential company data from cyber attacks. I was able to remove unrelated data and
evaluate the remainder with an unbiased approach while maintaining the original data set.
Analyzed results included descriptions, themes, and the factors that influence owners of
small businesses' decisions as it relates to protecting confidential company data from
cyber attacks.
After analyzing the data, I described the interpreted data and presented the
findings in section 3 of the research study. Alongside thematic analysis, I also utilized
observational notes to ensure that I captured all related and essential data. Alongside
thematic analysis, I also utilized observational notes to ensure that I captured all related
and essential data. The observational notes were used as a supplement to the interview
responses and archival documents on IT security procedure response plans, as discussed
by Phillippi and Lauderdale (2017). Member checking was a process used to increase
validity, while data triangulation was used to ensure and test the validity of the findings
as described by Tibben (2015). I correlated the key themes from the data to address the
research question, I used the primary components emerging from interviews to connect
current literature and conceptual frameworks as a means of evaluating, interpreting, and
organizing the collected data.
The search terms from the literature review that was used to capture data are
cybersecurity strategy, system security strategy, outsourcing strategy, implementing
security procedures, cybersecurity awareness education and training, and I then analyzed
the data using GST and RAA. Researchers use GST as a framework for understanding
complex cybersecurity systems and implement strategies to change their focus from
defensive to offensive approaches (Stitilis et al., 2016). Leukfeldt and Yar (2016) noted
that the RAA would be a useful analytical framework to study cybercrimes, identify
vulnerable targets, and serve as a means for adopting and enforcing cybersecurity
policies.
Reliability and Validity
Reliability and validity are crucial in this study. To establish and obtain accurate
data measurement, I concentrated on data triangulation and dependability, similar to the
approach used by Motoyama and Mayer (2017). To establish and obtain validity, I used
the concepts of conformability and transferability. Trustworthiness in qualitative research
studies consists of dependability, credibility, transferability, and confirmability
(Korstjens & Moser, 2017). I will further discuss how I obtained reliability and validity in
the following section.
Reliability
Renz, Carrington, and Badger (2018) pointed out that reliability could be achieved
through triangulation and dependability. I used dependability to seek reliability because it
defines the degree to which the research findings produce consistent and stable results.
Birt et al. (2016) concluded that participants’ validation is an essential component in
qualitative research that helps researchers to check for resonance and accuracy in
participants’ responses. To improve dependability, I used several data sources: (a) review
and conduct semistructured interviews; (b) used interview protocol in Appendix B to
administer all interviews; (c) applied member checking, and (d) used observational notes
to examine the collected data for consistency. Interview questions were not focused on
specific organizational initiatives, but rather the findings were based on participants’
responses. I took accurate notes while actively observing responses to replicate the
interviews that helped to established research study dependability, similar to the process
used by Collingridge and Gantt (2019). To ensure the mutual reliability and legitimacy of
the findings, I established research quality. Amankwaa (2016) noted that research study
trustworthiness is essential in creating the value of a study.
Validity
Validation and verification of data help to improve the validity and credibility of
research findings. Participants could validate the data collected from the interview
through member checking to determine the data credibility. I seek participants’
perspectives, which helped to maintain validity and credibility. Participants were able to
verify the interview data and provide their opinion; this helped to validate the collected
data and improve its credibility. Qualitative research data verification and validation use
corroboration from participants through member checking (Birt et al., 2016).
As I collect data, I considered all repetitive behaviors or actions as a way of
maintaining the credibility process, as described by Nelson (2016). Davidson, Paulus, and
Jackson (2016) noted that interviews are a standard method used to collect data in
qualitative research. I collected data through face-to-face, semi structured interviews
using an interview protocol. Renz et al. (2018) further described that transferability is
synonymous with external validity or generalizability. Transferability could be
recognized when readers are provided with evidence that the research findings could
apply to other situations, contexts, and populations. To ensure applicability and
transferability to other situations, I maintained a thorough note and documentation, along
with geographic limitations, as it relates to the interviews in order to ensure that
transferability applies to findings from similar projects. A transferability limitation in this
study would be geographic because the research was conducted only in Fort Lauderdale,
Florida. Confirmability signifies the extent to which other researchers can confirm or
corroborate the research study results. These helped determine the level of objectivity
related to the study (Renz et al., 2018). I developed a review trail, and this was a unique
way to adopt confirmability, which allowed me to remain in the background during the
study (Connelly, 2016). I ensured validity by taking several precautions. First, as
described, I never had initial contact with participants before IRB approval. Second, I
listen to the viewpoints of participants without bias, which assists in preserving the
integrity of the interview process. Third, I followed the data analysis procedure outlined
in the previous section, which ensures that I maintained the standard used in prior studies
to validity data (Connelly, 2016). Data saturation is significant because it indicates data
accuracy, and this can occur when no further categories or themes are derived from the
collected data (Benoot et al., 2016). In a multiple case study design, the pool size of four
interviewees, and the qualitative interview technique are essential requirements for
achieving data saturation (Boddy, 2016). Because the study did not reach data saturation
after four interviews, I conducted more interviews after no new information was received,
I attained data saturation, which was a similar approach described by Benoot et al.
(2016). The research study consists of various methods for comparing, associating, and
cross-checking data that helped to increase the study’s reliability and validity.
Summary and Transition
In Section 2, I described the research purpose statement, the role of the researcher,
and I addressed how participants were selected and detailed the research methodology
and design. I further defined the sampling tactics and how I used these. I detailed the data
collection instruments, techniques, organization, and analysis. Section 2 ended with
ensuring study reliability and validity. I begin Section 3 by presenting the overview
findings, professional practice, the implications’ social change, recommended action,
further research recommendations, my reflection and experience during the process, and
conclusion.
Section 3: Application to Professional Practice and Implications for Change
Introduction
The purpose of this qualitative multiple case study was to explore strategies
used by owners of small businesses to protect confidential company data from cyber
attacks. All participants that were interviewed concluded that proactive security
strategies were essential in mitigating data breaches. Through the combination of the
interview data, literature review, and conceptual framework, I discovered the strategies
participants used to protect their business against cyberattacks, which include four
themes: (a) security information management strategy, (b) organizational strategy, (c)
consistent security policy, and (d) cybersecurity risk management strategy.
Additionally, the study findings support Von Bertalanffy’s (1972) GST and Cohen and
Felson’s (1979) RAA. In the following section of this study, I confirm the connection
between the themes identified and derived from the collected data and the conceptual
frameworks.
Presentation of the Findings
The findings address the overarching study question, “What strategies do owners
of small businesses use to protect business data against cyber attacks?” I applied a
practical working framework, such as grouping the codes into categories using the NVivo
software tool to help me identify themes that emerged, such as security information
management strategy, organizational strategy, consistent security policy, and
cybersecurity risk management strategy. I also categorized the themes and created
descriptions to identify the themes and noted the frequency as they occurred from the data
set.
In Section 1 of this study, I was unable to find specific and current information for
the literature reviewed, that directly related to the research question; this created a gap for
further study. These research findings were consistent with evidence from the related
concept of Von Bertalanffy’s (1972) GST and Cohen and Felson’s (1979) RAA, which
were both conceptual frameworks for this study. The GST theory is a process used to
explore data that correspond with: (a) system units, (b) collaborative exchange and
continual relationships within the system, and (c) analysis of systems. The GST theory
provides a way of interpreting and viewing internally connected units, as suggested by
Aydiner, Tatoglu, Bayraktar, and Zaim, (2019), of the cybersecurity strategies used by
owners of small businesses. Owners of small businesses use internally connected units to
reach various parts of their systems, such as information security (Chalvatzis et al., 2019).
All participants agreed that protecting business data was a critical component to the
success of their organization, and implementing cybersecurity is crucial to their growth.
Managing information security strategy and organizational strategy were both
predominant prevention coding nodes during the analysis of the interview data and
archival documents.
The study findings support the concept of interconnectivity in GST, as
demonstrated in the themes and subthemes; each theme was based on evolving and
growing changes in cybersecurity. The GST was essential in understanding the
interconnectivity of the system, which was a process used to explore strategies that
participants were using to protect confidential company data from cyber attacks. Instead
of treating each theme and subtheme separately, owners of small businesses could
consider collectively using the themes and subthemes to implement a holistic strategy to
protect business data from cyber attacks.
The RAA was also useful in determining the potential motivation behind
cybersecurity attacks and possible means for preventing and reducing cybercrime on
small business systems, as proposed by Argun and Daglar (2016). The RAA outlined
criminal behavior as motivated offenders with a proper target lacking capable guardians.
Online-motivated offenders include hackers, fraudsters, stalkers, pirates, and other
criminals (Reyns, 2015). An online target that is suitable for predation includes
proprietary data, personal data, and online payment systems, along with vulnerable
computer systems that may be disrupted and compromised by unauthorized interference
and intrusion (Reyns, 2015). Capable guardians involve the various forms of
cybersecurity, system protections, management access systems, ID authentication,
firewalls, virtual private networks, and anti-intrusion. These are considered strategies
employed by owners of small businesses to protect their business data against cyber
attacks (Van de Weijer & Leukfeldt, 2017).
The consistent security policy and organizational strategy themes served as the
coding nodes for creating a security plan, that demonstrated the presence of a capable
guardian in place. The cybersecurity risk management strategy served as a prevention
measure that reflects a coding node for a secured provider that also illustrated the
presence of an intelligent guardian in place.
The four emergent themes regarding strategies used by owners of small businesses
to protect business data against cyber attacks are (a) security information management
strategy, (b) organizational strategy (c) consistent security policy, and (d) cybersecurity
risk management strategy. A total of 254 collected references were counted from the
coded contents. From the four emergent themes, managing information security strategy
has approximately 79 references count with a total of 30.12%, the organizational strategy
has approximately 66 references count with a total of 26.23% consistent security policy
has approximately 56 references count with a total of 23.35%, and cybersecurity risk
management strategy has approximately 53 references count with a total of 20.30%.
Theme 1: Security Information Management Strategy
Security information management strategy emerged as a major theme. Data were
collected from five participant’s responses and through reviewing IT security procedure
documents from the five participants. The participants responded with the emerging
subthemes for cloud storage implementation, access control, information strategy,
security practice strategies, policy strategy. Information security refers to the protection
of business and consumers’ data from cyber attacks; this process could be used to protect
data confidentiality, integrity, and availability by preventing unauthorized access,
malicious intentions, disruption, modification and the destruction of data (Wang, Shan,
Gupta, & Rao, 2019). Owners of small businesses could implement an information
security strategy that can protect data confidentiality, integrity, and availability while
maintaining effective productivity (Paliszkiewicz, 2019). The pseudonyms SB1, SB2,
SB3, SB4, and SB5, are used to maintain participant confidentiality in this study. All five
participants stressed the importance of managing an information security strategy. SB1
stated:
We integrated our strategy for protecting information into our core business
process by publishing a well-defined security standard and information security
policy. We also have a designated cybersecurity point person that is implementing
all our IT solutions. Even without a dedicated IT staff, our designated
cybersecurity point person is knowledgeable about cybersecurity. We have also
established a security perimeter around our critical systems using multifactor
authentication. To mitigate data risks, we adopted a single cloud security platform
that controls users' device and network access, which is used to detect and
mitigate threats in real-time. We managed access to data; our data are
passwordprotected, and we demand an additional form of authentication. We
configured the authentication to issue a one-time PIN before the individual can
have access to the data.
In agreement with SB1, SB2 mentioned:
We have established a successful way of managing our information security
program; the program begins from upper-level management. The program
consists of building data protection in layers; we setup appropriate access rules to
information management, thereby reducing vulnerability. As part of managing our
information security, we doubled our firewall to add redundancy. We also used
email filtering in addition to continuous threat protection to scan inbound emails
to avoid any potential threats from both links and email attachments to prevent
malware attacks from entering our network system. We also compartmentalizing
our network to enforce network separation and use commercial software to
monitor network traffic and identify unauthorized attempts they may want to
change, delete, or cause damage information. Also, we backed up all user
workstations and company servers to a cloud server at a different geographical
location. The average cost of cloud storage is less expensive but very helpful in
protecting our business data against ransomware and phishing attacks.
SB3 noted:
We practice protecting login credentials for network hosts, which is also crucial in
defending business data against cyber intruders. We also implemented and installed some
system security tools like firewalls, antivirus, encryption, a virtual private network
(VPN), passwords, and biometrics software. We have also implemented a business
continuity plan that frequently back-up our business data in the cloud. We also conduct
regular information security testing on our systems. We currently use a third-party
cybersecurity company for penetration testing to ensure compliance and protection
procedures against any possible cyber breach. SB4 acknowledged that “our strategy
involves basic system security practices, which require the implementation of strong
passwords, secured web applications with firewalls, and we also use an automated
malware scanner to scan our system regularly. We easily sync files and folders from our
computers and mobile devices to our backup cloud system.” SB5 indicated that “my
organizational data are automatically backed up to the cloud regularly. Our operating
system's firewall is enabled and set to prevent outsiders from accessing data on our
network.”
Managing information security is to minimize risk and guarantee business
continuity by actively limiting cybersecurity risk (Tu, Yuan, Archer, & Connelly, 2018).
Owners of small businesses must improve their information security strategy to ensure
capabilities provided aligns with their business goals by implementing an effective way to
identify and address potential threats and vulnerabilities (You, Oh, Kim, & Lee, 2018).
Sensitive data should be adequately secured; no individual should have access to
information beyond their access privilege. Owners of small businesses could avoid
granting classified access, as superiority within the organization, does not permit greater
access. Likewise, compartmentalization access controls on a network to limit
communication between systems can be used to identify unexpected and unauthorized
attempts on the network (Sabitha & Rajasree, 2017). Lateral compartmentalization
protects systems from unintentional interference by unqualified or unauthorized persons,
which is a process used to reduce potential threats and vulnerabilities.
Owners of small businesses could enforce access control policies based on
compartmentalizing how sensitive data can be accessed (Sabitha & Rajasree, 2017).
Compartmentalization of business data is a process used to mitigate an insider and
external risks, by segmenting access to a network, the goal is to reduce the scope of data
compromise. Cloud storage implementation emerged as a sub-theme; the coded contents
have approximately 47 references count with a total of 49 %.
Cloud storage implementation. The subtheme from the security information
management strategy was cloud storage implementation. The cloud storage
implementation subtheme emerged from five participants’ responses and through
reviewing IT security procedure documents from the five participants. Cloud storage is a
computing model that allows businesses to store data in the cloud using the Internet
(Yuhuan, 2017). Cloud storage vendors maintain the capacity, security, and durability
that makes cloud storage data accessible and secured, thereby allowing owners of small
businesses a means of protecting their business data against cyber attacks. Kalaiprasath,
Elankavi, and Udayakumar (2017) noted that cloud storage implementation is adhering to
privacy and security policies that guarantee users' data are fully secured. Participants had
different responses concerning appropriate data protection with cloud vendors.
Senarathna, Yeoh, Warren, and Salzman (2016) discovered that security and privacy
features have less influence on why owners of small businesses are adopting cloud
computing. Participants who rely on cloud storage for their business benefit from the
security services; they are also using the services for allocation, distribution of access
control, monitoring, and protecting their business data against cyber attacks. They back
up their files in cloud storage, which is an essential source for business continuity in the
event of a system crash, cyber breached, or data loss. Owners of small businesses can
implement cloud computing at a reasonable price that can guarantee access to data and
applications from anywhere. Implementing cloud computing also gives businesses access
to previously out of reach technologies, which is helping them develop and improve
operational processes (Henry & Ali, 2017).
Cloud storage can also assist in verifying and protecting business and consumers’
data at rest, in motion, or use in the cloud or on business premises with services that
include unified sharing of computing resources. One of the most comfortable and most
efficient ways for owners of small businesses to tackle cybersecurity needs is to backup
critical business data and applications in the cloud. The organization can securely
synchronize business data from the cloud to workstations and other work-related devices
without losing any data or data ever leaving the server. The organization can also store
data in a secure location that can also capture cloud backup.
Kalaiprasath et al. (2017) concluded that security controls and compliance models
could be used to manage the risk associated with potential cloud storage threats. The
study developed a semantically rich ontology that could be used to model threats,
controls, and cloud security policies. Owners of small businesses could formulate their
cloud storage security policies to include security controls and compliance models to
protect business data in the cloud.
Theme 2: Organizational Strategy
The second major theme is the concept of organizational strategy, which emerged
after analyzing participant responses and reviewing IT security procedure documents
from the five participants. James (2018) researched supported this study by affirming that
an organization's security strategy must align with its business strategy and should be an
integral component of the top management decision-making process. I reviewed
participant interviews and archival documents. All five participants stressed the
importance of implementing an effective organizational strategy. Carias, Labaka,
Sarriegi, and Hernantes (2019) acknowledged organizational strategy as cybersecurity
preparedness that integrates employee training and technical security to measure and
manage cyber attacks while effectively continuing its business operation. Boiko,
Shendryk, and Boiko (2019) described an effective organizational cybersecurity strategy
as a technique used by business leaders to align risk associated with cybersecurity and
their critical operations. The study findings below described the emerging subthemes
which are (a) awareness education has approximately 40 references count with a total of
35.54%, (b) employee training has approximately 39 references count with a total of
33.27%, and (c) people’s management has approximately 37 references count with a total
of 31.19%.
Awareness education. The first subtheme to emerge from analyzing data from
the organizational strategy was awareness education. Awareness education is one of the
resources that businesses depend on to prevent and protect confidential company data
from cyber attacks (Irons, 2019). Owners of small businesses should be aware of the
constant increase in data breaches, phishing, and ransomware attacks. Awareness
education involves knowing how to protect organizational data and how to take practical
steps to prevent data breaches.
SB1 stated, “our team performs awareness education to keep our organization
updated with the latest threats and making sure that our systems are safe from hackers or
any form of breach attempts. By instituting awareness education, owners of small
businesses could understand the current security vulnerabilities and heighten the chances
of catching an attack before it is fully enacted, thereby minimizing the damage and
reducing the cost of data breach recovery (Bhardwaj & Goundar, 2019).” SB2 replied that
“we conduct repetitive training and ongoing awareness; sometimes we even conduct
random testing to analyze security vulnerabilities within our system and areas of
exploitation and educate our employees on how to prevent vulnerabilities. The most
prevalent IT security threat that owners of small businesses are facing is the fact that they
lack the awareness of security vulnerabilities (Bhardwaj & Goundar, 2019). Owners of
small businesses could promote cybersecurity awareness education to prevent and
overcome potential threats.” SB3 stipulated that “we created and instilled security
awareness culture within our organization in a modified manner, by working with the IT
manager to interpret security verbiage into simple procedures that every employee could
easily understand and follow. Based on these guidelines, we provide constant training to
all employees on how to access and safeguard critical business systems, and we guarantee
that they understand and apply this concept to help us mitigate possible risk exposure to
our system.”
SB4 also stipulated that “we have developed a risk management strategy that
consists of situational awareness and an acute awareness of customers' personal
information, limits access, and monitors network system.” SB5 replied that “we hired a
security company to educate our staff on the current threats; they also evaluate our system
and perform cybersecurity awareness. Every three months, we perform risk assessment,
which is helping us to identify risks and vulnerabilities in our network. Our security
awareness program is a process used to rate severe vulnerabilities, determine the
effectiveness of our current security resources, and the cause of action.”
The data revealed that participants recognized and implemented awareness
education and provided employees with the essential understanding of imminent and
ongoing cyber threats, and also prepare them to be the first line of defense and be vigilant
against frequent cyber attacks and threats. All employees with access to a work-related
mobile device and computer undergo a thorough awareness education, which includes
maintaining physical security, password management, online security, and how to detect
system vulnerabilities, phishing, and malware defense simulations (George & Thampi,
2019). By implementing cybersecurity awareness and training, owners of small
businesses could heighten the chances of mitigating an attack before it is fully enacted,
minimize the damage to the business brand, and reduce recovery costs (Irons, 2019).
Awareness education should be implemented on three levels: creating, delivering,
and evaluating the program. Over time, the program can have steadfast quarterly and
annual goals that would become increasingly directed towards the occurrence and
severity of actual incidents that arise within the organization. Cybercriminals are
continually seeking new and sophisticated ways of exploiting security weaknesses;
security awareness education is a means in which organizations are equipping their
employees to react to the latest successful exploit of the organization. Effective
cybersecurity awareness education should integrate organizational, legal, and best
practices of security technologies, this can progress the information assurance of small
businesses (Dai, 2018). An essential and affordable action is for owners of small
businesses to continually conduct a security assessment to identify vulnerabilities. Once
vulnerabilities are recognized, owners of small businesses can create a response plan on
how to mitigate threats and losses in the event of an attack.
Awareness training activities should include details of employee preparedness in
the event of a breach. The security awareness should provide every employee with the
fundamental understanding that there are imminent and ongoing cyber threats, preparing
employees through constant cybersecurity training for common cyber attacks and threats.
Due to the rapidly changing technological environment and the extensive vulnerabilities,
the effectiveness of the awareness education cannot be measured based on past security
assessments. Instead, to ensure its success, awareness education must be tested
continuously and update regularly. Cybersecurity awareness education must be efficient,
repetitive, and continuously tested to safeguard and protect organizational data (Irons,
2019).
Employee training. The second subtheme to emerge from analyzing data from
the organizational strategy was employee training. Training involves teaching employees
the strategies that would help guarantee preparedness and optimized defensive responses
to cybersecurity threats. Howell (2016) pointed out that employee training could best be
implemented in the simplest terms of providing employees with the necessary knowledge
and skills that can prepare them on how they can protect the business system from all
forms of attacks. Participants’ responses and review of their security procedures revealed
that all participants had some form of employee training. SB1 stated that “we conduct
cross-section training for all store managers. While the manager is in charge of training
employees based on safeguarding operating systems, reporting system outages, and
reduced email scams and identified social phishing.” SB2 also indicated that “we
provided and scheduled multiple cybersecurity training sessions for our employees based
on their availability, but for new features in our software, our reliability is on our vendors
to provide those training.” SB3 stated that “we provide constant training to all employees
on understanding and accessing systems and to ensure they comprehend the proper use of
the business system(s), which has ultimately helped in lowering our potential risk
exposure to security issues.” SB4 emphasized that “managers understand their security
requirements and are responsible for conducting quarterly employee training, and
employees understanding how to spot suspicious attempts by becoming the first line of
defense, thereby assuming the role of protecting business and customer data.”
SB5 also indicated that “as part of our business policies, we are educating and
training every new employee on security measures. We also are conducting quarterly
training for all our employees on the latest security measures, and how they can help keep
our system safe.” The findings showed that each participant implemented education
awareness and training as a way of defending against cyber attacks. Data security is
paramount to organizational success; as such, it is paramount for small businesses to
develop employee training that would address how data can be handled and how to
identify and mitigate threats to data security. Proper employee training should include
these elements: current threat assessment, red flag attack, preventive procedures, and
mitigating plans. Network security and awareness education training should be based on
cyber attack simulations that are consistent with current trends. Cyber attacks evolve in
their technologies and approach; as such, owners of small businesses must upgrade
defensive training to keep system vulnerabilities low (Meyers, Hansen, Giboney, &
Rowe, 2018).
Owners of small businesses could also create cybersecurity awareness and
employee training protocols as a countermeasure against attacks and protect the
confidentiality of business and customer data (Rocha Flores & Ekstedt, 2016). Employees
are becoming the most critical aspect of cybersecurity preparation were eliminating
human error seems impossible. However, owners of small businesses can minimize
cybersecurity risk by continuously and consistently testing and educating employees to
become defenders against cybersecurity threats by developing their knowledge of
cybersecurity, thereby improving employee behaviors toward cybersecurity preparation.
Employee cybersecurity training should include ways of identifying all kinds of threats,
how to respond to phishing emails, how to avoid visiting malware-infected web pages,
and also how to implement a two-step verification and access confidential information
(Howell, 2016).
Peoples management. The third subtheme to emerge from analyzing data from
the organizational strategy was people's management. Owners of small businesses could
no longer overlook the concept of managing people's cybersecurity behavior. They would
have to implement cybersecurity policies that would manage and guide employees’
cybersecurity behavior. Although technology solutions play a vital role in protecting
business assets, users are often the weakest link in information security. A new challenge
for owners of small businesses is the ability to manage and guide employees’ information
security behaviors. Budzak (2016) concluded that users’ behavior is becoming a threat to
information security. Gangwar and Date (2016) noted that people are the primary source
of information security incidents. People’s management subtheme emerged after
reviewing the participants’ responses and through reviewing IT security procedure
documents, in which all participants agreed that managing and guiding employees’
cybersecurity behavior is vital to protecting information security. Udroiu (2018) noted
that without employees who are dedicated and steadfast in doing their part to ensure that
significant business systems and information assets are safe, good security practices
would be impossible to carry out. Owners of small businesses could develop strategies on
how to manage and guide employees’ information security behaviors, by evaluating the
effectiveness of their information security behavior, and determine ways to improve
employees’ behavior. Owners of small businesses should focus on improving information
security strategies to find ways to manage and motivate employees to protect
organizational information assets. Owners of small businesses should not minimize the
significance of human factors in information security because users could intentionally or
negligently pose a substantial threat to organizational information security (Sollars,
2016). Owners of small businesses should recruit and motivate staff to follow their
security policy guidelines and encourage them to be vigilant in protecting organization
information security (Sollars, 2016).
Theme 3: Consistent Security Policy
The third major theme that emerged in this study was a consistent security policy.
The theme emerged from five participant’s responses and through reviewing IT security
procedure documents from the five participants. Information security policy is defined by
San Nicolas-Rocca and Burkhard (2019) as a document that identifies rules and
procedures that guides how the organization's IT resources and assets are accessed.
Schulz (2019) noted that effective and consistent IT security policy is a model of the
organizational culture in which procedures and rules are driven from its employees'
approach to organizational information security. Almeida et al. (2018) further described
that information security policy must reflect the support and commitment that owners of
small businesses have for information security and demonstrate the role it plays in the
overall organizational strategy. A small business information security policy should offer
guidelines to employees on how to handle everyday information security tasks. The
participant interviews and through reviewing IT security procedure documents from SB1,
SB2, SB3, SB4, and SB5 showed that all participants are maintaining IT security policy.
The reviewed documents provided details on how these owners of small businesses are
defending their business data from a cyber breach. Based on this analysis, participants are
continuously improving their IT security policy to protect business data against cyber
attacks. SB1 indicated that “we implemented security policies and procedures that we
directed towards enhancing our internal network security tools. Our current policies and
procedures are efficiently guiding the flow of data and protect our businesses from
cyberattacks.” One of the issues facing owners of small businesses is the nonexistence of
consistent IT security policies, which is a process used to respond to cyber attacks and
also protect against unforeseen threats. SB1 also noted that “we configured our systems to
track data distribution as part of our data protection regulations.” SB2 stated that “we
regularly update our IT security policy to preserve the confidentiality, integrity, and
availability of our information systems and how members of our organizations access
information.” After reviewing the IT security policy document from SB2, the policy
describes how the responsibilities and functions of each individual in the organization as
it relates to protecting business data from a cyber breach. The IT security policy also
categorizes how authority is granting security personnel and identify and detail data is
transmitted in their network. The IT security policy of an organization is a set of rules
that prescribed the organizational network structure and also ensured how users could
access data within the boundaries of the organization network.
SB3 stated that “we also practice internal system control, such as creating unique
login information, a valid password to access business systems, and we instituted a policy
that requires a password change between 45 and 90 days contingent on the sensitivity of
the access data.” SB4 stated that “we also have a cybersecurity policy that governs
Internet usage and the penalties for violating the policy. Our policy also describes how
we handle and protect business and customer data.” SB5 stated that “we have a policy in
place that ensures all employees that work from home are firewall-protected and
encourage the use of VPN to connect to our central system.” Owners of small businesses
must continue to invest in a proactive approach to protect confidential data. I reviewed
participants’ IT security policy documents to ensure that a consistent security policy is in
place. I included some extracts from SB4’s IT security policy documents as a means of
triangulating and validating the data collected from the interview: The security policy
objective is to protect our business and customer data from illegal access. The security
policy entails how data and applications are accessible and used for essential and
continued operations of the business. There shall be no alteration or deletion as a result of
intentional or accidental attempts to gain or compromise access to business computer
systems. The security policy is related to all users who have access to our system and
network administrator that is responsible for operating workstations and data backup. The
business process must adhere to the organization's security measures, as it is essential to
our business continuity. This security policy articulates the complexity of information
security. If there is a need for change at any level of this policy, the changes must be
evaluated by our legal counsel. Mermigas and Pirounias (2018) noted that organizations
should accept that security policy is an essential cost, and the best way to improve and
manage the cost associated with security policy is by developing procedures around a
robust security framework. The continuous increase in cybersecurity attacks has led to
businesses investing and maintaining a consistent security policy. A consistent security
policy is a process that uses no-compromise protection against cybersecurity attacks, with
consistent implementation of policy at every level. All-inclusive protection is directed to
stop cybersecurity attacks. A security policy offers guidelines that make it different from
security procedures and processes. Security policy provides both specific and high-level
guidelines on how the organization is protecting its data but will not stipulate the precise
implementation. These provide the scope to choose which type of security methods and
devices that would best fit the organizational budget. A consistent security policy must
maintain a standard, enforced, and communicated throughout the organization. Owners of
small businesses can now create a consistency security policy across what were
substantially different security policies and implementations. This consistency method
will help owners of small businesses avoid conflicts in policy that add misperception, run
up costs, and increase vulnerabilities.
Theme 4: Cybersecurity Risk Management Strategy
Cybersecurity risk management strategy was the fourth main theme in this
research. The theme developed from five participants’ responses and through reviewing
IT security procedure documents. The emerging subthemes are adopting a 3rd-party
vendor, consulting IT experts, and limited liabilities. The findings correlate with that of
Kure, Islam, and Razzaque (2018), who described cybersecurity risk management as a
fundamental and essential process for managing risks associated with data breaches.
Owners of small businesses would be able to identify, evaluate, and mitigate the risk
associated with the availability, confidentiality, integrity of their business, and customers’
data. Governments are implementing regulation that may impact businesses that do not
have the proper process of handling business and customers’ data. For example, the
general data protection regulation (GDPR) is an EU regulation that governs the
processing of personal data. The policy requires that all businesses protect data from
attacks, but primarily to protect consumer data from transactions that arise within and
outside EU member states (Denley, Foulsham, & Hitchen, 2019). GDPR applies to all
business selling to and storing personal data of EU citizens, including the business
organization from other countries. The GDPR affects all types of companies that collect
and process personal data (Munier & Kemball-Cook, 2019). Examples of data include
names, telephone numbers, customer data, e-mail addresses, or any form of identifiable
data (Denley et al., 2019). The GDPR policy applies to all businesses irrespective of
where the business process took place; as such, failure to comply with this policy would
incur penalties. Owners of small businesses would need to implement a cybersecurity risk
management strategy with security procedures and invest in security technology and IT
experts to protect their business data against cyber attacks. Also, it is vital to note that
protecting organization data would require implementing robust and comprehensive
business solutions. Owners of small businesses can hire IT expert consultants as a
costeffective way to bridge the gap in skill, knowledge, and IT solutions is a process used
to avoid vulnerabilities, minimize and mitigate cybersecurity risk (Drechsler, &
Weibschadel, 2018). Owners of small businesses can also invest in a third-party vendor
that can provide cybersecurity preventive procedures and business services that would
allow them to remain compliant with PCI DSS regulations. The study findings below
described the emerging subthemes which are (a) adopting a 3rd part vendor has
approximately 47 references count with a total of 34.44%, (b) consulting IT experts have
approximately 45 references count with a total of 33.27%, and (c) limited liabilities has
approximately 42 references count with a total of 32.29%.
Adopting 3rd party vendor IT. The concept of adopting 3rd party vendor IT was
the first subtheme created from cybersecurity risk management strategy. All participants
stated that they depend on 3rd party vendor IT services to avoid the risk associated with
payment processing to protect their business data against cyber attacks. Reviewing the
participants’ security and procedure documents showed that they observed: “Payment
Industry Data Security Standards (PCI-DSS), is a process used to safeguard and regulate
data for cardholder payment.” SB1 emphasized that “I rely on a third-party vendor for
payment processing to avoid risk.” SB2 said that “I depend entirely on a third-party
vendor for payment services; they absorb all burden and risks while limiting our liability
against losses should there be any.” Also, SB3 indicated that “our third-party vendor
handles all our payments, thereby limiting our liability by protecting our business and
customer data against a cyber breach.” SB4 stated that “part of our strategy was to invest
in a third-party vendor that is using SSL technology to optimize security for debit and
credit transactions, thereby protecting cardholders against the misuse of data.” Participant
SB5 established a similar reliance on a third-party payment system: As stated, “We
invested in a third-party payment system because it is safe and allows us to comply with
financial regulation. It is difficult for our company to observe all the financial regulations;
as such, we expand the scope of our third-party agreement to include how they handle our
customers' data.” New regulation compliance adds responsibilities and costs to owners of
small businesses; the benefit of outsourcing payment systems compensates the liability
and risks of having an internal payment system. Cybersecurity risk management strategy
is to provide information and tools necessary to tackle data theft. Data theft has become a
significant threat facing owners of small businesses. Owners of small businesses could
use these tools to make better business decisions to help reduce data risk and protect
business data against cyber attacks. Owners of small businesses also must understand the
regulatory risks and identify steps that they can use to mitigate the risk. Owners of small
businesses must adopt and integrate a cybersecurity risk management framework to
assess and manage consumers’ data in a proactive manner. Cyber risk management
services do not only reduce the risk associated with cyber attacks but actively include
compliance with payment system regulation (Talesh, 2018). The strategy can also
identify and quantify data risk and provide a cost-benefit analysis of potential mitigation.
The cybersecurity risk management strategy would provide a risk-weighted analysis that
owners of small businesses can use to base risk retention, reduction, sharing, transferring,
and decision avoidance.
Consulting IT experts. The concept of consulting IT experts emerged from four
participant’s responses and after reviewing their security and procedure documents.
Owners of small businesses can consult with IT experts to identify areas where their
business system is vulnerable to cyber attacks and obtain recommendations that can be
useful to protect business data against cyber attacks. Consulting IT experts’ services
include having a full assessment, implementation, and maintenance of the security
systems. SB1 stated that “we consulted with IT experts, before creating our
comprehensive incident response plan and monitoring tool that we are using to ping an IP
address that tries to breach our security.” An IT expert who specializes in anticipating and
mitigating threats can provide an extra layer of protection that can prevent and minimize
risks and quickly resolve any form of security issues. SB2 stated that “we use
cybersecurity IT experts to develop and install patches in our network to protect our
system from an attack.” SB3 also indicated that “every year, we consult with an IT expert
to conduct system penetration and testing to evaluate our system weakness and provide
security controls that are adequately mitigating any perceived data risk.” SB4 emphasized
that “we consult with IT experts to conduct system checks to identify vulnerabilities,
assess its immunity to attacks and provide recommendations to secure our system; we
were able to prevent further vulnerabilities in our systems.” After reviewing SB1’s IT
security award, which indicates that they received commendations for relying on IT
experts to provide secured services, these commendations were in their business bulletin.
Cybersecurity IT experts are likely to have encountered virtually all forms of cyber attack
and have found ways of dealing with the issues. As they are very familiar with the
techniques that hackers are employing, they move faster when dealing with security
issues. Cybersecurity has become a significant priority for small businesses looking to
protect their business against the massive cost of data breaches. Cybersecurity IT experts
are likely to find solutions quicker before any damage can occur since cybersecurity has
become a significant priority for small businesses that are looking to protect their
business against the massive cost of data breaches (Heller, Toregas, & Hoffman, 2019).
Limited liabilities. The third subtheme that emerged from analyzing data from
participants demonstrates the implemented measure used to protect business and
customers’ data against cyber attacks. Participants responded by indicating their
responsibilities and liabilities in the occurrence of a data breach; each participant agreed
that adopting a 3rd party vendor helped limit their liability in the event of a data breach.
SB1 replied that “the contract we have with our third-party vendor includes a limited
liability provision.” Owners of small businesses who utilized third-party vendors to
secure business and customers’ data tend to limit their cybersecurity liabilities, to prevent
any form of losses in the event of a cyber breach. SB4 stated, “our vendor provides and
maintains the confidentiality of our business and customers’ data and are liable for any
data loss.” All participants indicated that their third-party vendor agreement also
stipulated that they have unlimited liability on their payment services. Participants’
contract documentation with third-party payment providers indicates that if the business
reports an account data or data breach. The business must retain a forensic investigator
(PFI) to investigate the business processing system that the breached occurred; and if the
evidence proves that the breach indeed occurred (Brown, 2016). The PFIs will give a
detailed report to the card associations, on all the card data that is at risk and whether the
business complied with PCI guidelines during the breach period. Owners of small
businesses would then be required to provide all processed card numbers throughout the
risk period. If the small business owner were not compliant during the risk period that led
to the breach, they would incur the fine of noncompliance.
Applications to Professional Practice
Strategies used for protecting business data vary from small businesses to larger
firms. The appropriate strategy may differ due to organizational size, but the factor
remains that protecting business data is crucial to the survival of the business.
Ronchi (2019) concluded that technical countermeasures alone are not enough to
protect against cyber attack; there is a need to uphold cyber defensive and preventive
methods that can foster cybersecurity culture. The findings of this study might contribute
significant strategies that could be useful to formulate cybersecurity strategies that
owners of small businesses can use to protect their business data against cyber attacks.
The findings might be significant to positive professional implications for implementing
successful IT security systems in small businesses. Owners of small businesses might
apply a cybersecurity strategy towards guiding their efforts and expenditures toward
structuring more secured business processes (Terlizzi, Meirelles, & Viegas Cortez da
Cunha, 2017). Owners of small businesses could apply the identified themes in this study,
which are (a) security information management strategy, (b) organizational strategy, (c)
consistent security policy, and (d) cybersecurity risk management strategy. After an
extensive review of current research, Campbell (2019) offered the opinion that for
businesses to practice good cybersecurity, it would have to focus on counter actions that
would include awareness, policies, processes, and continuous employee training towards
cybersecurity compliance. These study findings include awareness, employee training,
and people's management, which tends to increase owners of small businesses' resilience
to cyber threats; and also provide their employees with the fundamental understanding
toward cybersecurity compliance. All the described strategies, if implemented, can
benefit owners of small businesses who want to protect their business data against cyber
attacks. The findings of this study may also be used to create employees' knowledge base
that can include cyber defensive and preventive methods used to reinforce employee
cybersecurity awareness, to provide relevant training and consistent policy across all
processes. The findings of this study align with evidence from the reviewed literature and
might be relevant to extend knowledge gained from previous studies. The findings could
provide owners of small businesses with appropriate strategies to further minimize
cybersecurity risk. The application to professional practice consists of communicating the
successful strategies that owners of small businesses are using to protect business data
from cyber attacks. The results of my research showed that the application of active
cybersecurity strategies, such as (a) security information management strategy, (b)
organizational strategy, (c) consistent security policy, and (d) cybersecurity risk
management strategy, might be able to provide a foundational guide to other owners of
small businesses who would like to develop and apply practical strategies to identify
vulnerable targets and mitigate threats to protect confidential business data.
Implications for Social Change
The results of this study have the potential to generate positive social change that
would increase customers’ confidence, businesses’ economic growth, and stimulate the
socioeconomic lifecycle, resulting in potential employment gains for residents within the
communities. Positive social change can be obtained through the implementation of this
study findings to create a robust threat and vulnerability management program that can
reduce consumers’ exposure to security breaches and improve community engagement.
Owners of small businesses could integrate a holistic cybersecurity approach that would
enhance their cybersecurity to address all facets of incident preparedness, customer data
security, legal counsel, and regulation that is tailored towards their business.
Findings from this study could provide owners of small businesses with four
effective strategies that successful owners of small businesses have used to protect their
business data against cyber attacks, which are (a) security information management
strategy, (b) organizational strategy, (c) consistent security policy, and (d) cybersecurity
risk management strategy. Owners of small businesses could implement and improve
their cybersecurity strategies to eliminate future threats to their business and customers’
data. The implications for positive social change might include applying and
implementing this study to increase consumer confidence and ensure better economic
prosperity.
Recommendations for Action
The findings of this study are examples of strategies that some owners of small
businesses used to protect confidential company data from cyber attacks. The
recommended strategies are courses of action for owners of small businesses in the
industry. The first recommendation is that owners of small businesses should develop an
organizational strategy that will fully engage in active cybersecurity practices. Such a
strategy should consist of policies and procedures that can be used to protect both
business and customer data against cyber attacks. The second recommendation is that
owners of small businesses could progressively link their business processes with
cybersecurity policy to create a consistent security policy across their organization. The
third recommendation is that owners of small businesses could also implement an
effective strategy that they can use to address preparedness, data privacy, and response to
data breaches in the event of a breach, which can have a positive impact on mitigating the
effects of data breaches and protect confidential company data.
The findings and recommendations will be shared directly with the study
participants. I intend to submit this study for publication and also seek opportunities to
present the results at business workshops and conferences.
Recommendations for Further Research
The study findings might result in bridging the knowledge gaps on how owners of
small businesses can protect their business and customer data from cyber attacks. Current
and future owners of small businesses might use the results of this study to cultivate
consistent cyber security policy. Since this study was limited to Florida, there is a need
for more research to be conducted, which should include other geographic locations. The
findings may be different or similar based on the sample size and geographic data.
Replicating this research study at a later time may yield different results as cybersecurity
strategies may change over time.
A limitation that I mentioned in Section 1 was how participants could
unintentionally provide insufficient data due to their limited knowledge of cyber security.
However, participants supported their experiences with archived documents, which
yielded the results of this research study. Participants were candid in their responses
during the interviews, and they provided sufficient data for this study. My
recommendation would be that future study researchers increase the sample size and
geographic locations and compare the results to see if they are different or similar based
on the increased sample size and geographic locations.
Reflections
I came to understand the types of successful strategies that owners of small
businesses have used to protect both their business and customer data from cyber attacks,
through the reviewed literature studies, completion of interviews and reviewing of
archival security procedures documents. The DBA journey challenged me personally,
academically, and increased my knowledge far beyond what I anticipated. Through the
literature review and the interview process, my perspective was developed significantly
on strategies that owners of small businesses can use to protect their businesses from
cyber attack. My perspective on the topic was developed because I had no preconceived
notions about the research topic; I remained optimistic and kept a neutral view all through
the research process. I relied on pre-existing research on the subject, and the data
collected from interviewing participants and supporting documents. It was interesting to
learn about new themes in cybersecurity strategies; my defined notion changed after
completing the research study on cybersecurity strategies. This exercise has helped me to
broaden my understanding, validate the purpose, and reason for researching strategies for
implementing successful IT security systems in small businesses.
Conclusion
Past data protection studies have focused only on the technical aspect of a data
breach incident, which is useful in helping organizations understand how a security
breach occurred. The holistic cybersecurity approach that was included in this study
finding incorporates process control, technical, and human aspects, which are the
essential components for protecting data. Owners of small businesses can begin by taking
the responsibility of protecting company data from cyber attacks by applying a holistic
cybersecurity approach. My findings supported this approach by including (a) security
information management strategy, (b) organizational strategy, (c) consistent security
policy, and (d) cybersecurity risk management strategy to protect confidential company
data from cyber attacks. Owners of small businesses could use these findings to formulate
a cybersecurity strategy that could help to predict and eliminate future threats to
customers’ information.