1 / 69100%
Successful Operational Cyber Security
Strategies for Small Businesses
Section 1: Foundation of the Study
Cyberattacks against small businesses continue to paralyze company growth due
to the invasion into private business and personal data. Small to medium-sized business
owners are under pressure to prevent, rather than respond to cyberattacks. Cyberattacks
are increasingly detrimental to networks, systems, and users, and are increasing in
number and severity globally (King et al., 2018). The ways that small and medium-sized
enterprises (SME) share knowledge and conduct electronic business make them a popular
target for cyberattacks. SME owners often lack the necessary resources to implement
emerging cybersecurity methods and exploit business opportunities (Henschel & Heinze,
2018). Furthermore, SME owners typically lack a cyber-security infrastructure capable of
keeping up with cyber-security threats. SME owners face cybersecurity challenges
different than those confronting large enterprises. Small business owners use computer
systems and the Internet to compete in the technology-infused global e-commerce
markets. The purpose of the study was to explore operational strategies chief information
security officers (CISOs) of small high-technology companies use to protect their
businesses from cyberattacks.
Background of the Problem
Criminals infiltrate businesses through information system hacking behavior
(Sieber & Neubert, 2017). However, due to the reach of the Internet, crime committed on
the Internet has no geographic bounds (Low, 2017). Cybercriminals continue to target
businesses because they have valuable exploitable information. Small businesses store
large amounts of sensitive data electronically using outdated and ineffective security
systems, placing the company at risk of cyberattacks. Keeping customers and financial
information secure is a constant battle for all organizations (Locke, 2017). With the
increased convergence of technologies whereby a user can access, store, and transmit data
across different devices in real-time, risks will arise from a lack of appropriate security
measures, users not having requisite levels of security awareness, and users not fully
understanding how security measures are useful (D’Orazio, Lu, Choo, & Vasilakos,
2017). Small-scale information technology users (SSITUs) remain ill-served by archaic
or obsolete cybersecurity practices (Osborn & Simpson, 2017). Therefore, my objective
in this study was to explore strategies CISOs of high-technology companies use to protect
their businesses from cyberattacks.
Problem Statement
Cyberattacks pose a significant problem for business owners who struggle to
protect business and customer private information (Bendovschi, 2015). In 2017,
cyberattacks cost the global economy approximately $445 billion (Samtani, Chinn, Chen,
& Nunamaker, 2017). The general business problem is organizational leaders place their
profitability at risk if they do not have adequate protection from cyberattacks. The
specific business problem is CISOs of high-technology companies lack strategies to
protect their businesses from cyberattacks.
Purpose Statement
The purpose of this qualitative multiple case study was to explore strategies
CISOs of high-technology companies used to protect their businesses from cyberattacks.
The target population consisted of CISOs from three small businesses operating in
Florida who successfully protected their business from cyberattacks. The CISOs were
appropriate participants for this study due to their knowledge and expertise in preventing
cyberattacks. The implications for positive social change could provide customers with a
safe and secure environment for communicating and conducting electronic transactions.
Nature of the Study
I conducted a qualitative multiple case study to explore strategies CISOs of
hightechnology companies use to protect their businesses from cyberattacks. I considered
quantitative, qualitative, and mixed method approaches for this study. Researchers use
quantitative inquiry to test hypotheses using variables and considering relationships or
comparisons (Boersma et al., 2016). I did not select the quantitative approach because I
was not seeking to explain phenomenon based on a hypothesis. A qualitative researcher
conducts interviews using open-ended questions to learn about participant perspectives,
decision making processes, and experiences (Yin, 2014). I selected the qualitative method
as a means of interviewing participants and gaining detailed information by asking how
and what questions. Mixed method researchers apply a combination of quantitative and
qualitative methods (Sim, 2017). The mixed method approach was not appropriate
because it includes the quantitative method.
The three qualitative research designs I considered for this study were
phenomenological, ethnographic, and case study designs. Phenomenological researchers
explore subjective perceptions of lived experiences of an individual or group of people
connected to a single phenomenon (Johnston, Wallis, Oprescu, & Gray, 2017). The
phenomenological design was not appropriate for this study because I sought to explore
beyond the scope of lived experiences and included additional data to understand the
phenomenon. Ethnographic researchers explore human behaviors within a culture or
group (Puttick, 2017). Ethnographic research was not appropriate for this study because I
did not explore human culture or behaviors within a specific group. A case study
researcher investigates a phenomenon within a specific context to address the research
questions (Yin, 2014). A case study researcher uses triangulation to investigate a
phenomenon. My approach included interviews, a review of existing company
documents, and a review social media sites. A multiple case study researcher investigates
multiple businesses to understand business leader behaviors. A qualitative multiple case
study design was appropriate for this study because I conducted semistructured
interviews, explored company websites, and reviewed social media portals to gain a
thorough understanding of cyberattack prevention.
Research Question
The overarching research question for this study was: What strategies do CISOs of
high-technology companies use to protect their businesses from cyberattacks?
Interview Questions
1. What strategies are you using to secure your business from cyberattacks?
2. What are the key challenges to implementing your operational strategies for
preventing cyberattacks?
3. How do you address the key challenges to implementing your successful
strategies to mitigate cyberattacks?
4. How do you assess the effectiveness of the strategies you implemented to
achieve the desired outcomes?
5. How long has your business been in existence?
6. What type of training do you have in place for your employees about
cyberattacks?
7. What type of cyberattacks strategies would you like to implement but have not
implemented?
8. What additional information on cybersecurity strategies would you like to
provide?
Conceptual Framework
The conceptual framework for this study was the organizational learning theory
developed by Chris Argyris in 1974. Argyris (1976) explored the concept of
organizational learning and its impact on a company’s growth. Argyris focused on
singleloop and double-loop learning. Single-loop learning encourages participants to
learn to perform, as long as the learning does not question the fundamental design, goals,
and activities of their organization (Argyris, 1976). Double-loop learning encourages
participants to ask questions about changing fundamental aspects of the organization
(Argyris, 1976). The tenets of organizational learning theory include (a) systems thinking,
(b) personal mastery, (c) mental models, (d) building shared vision, and (e) team learning.
Argyris (1993) promoted the concept of integrated problem-solving drawing on
individual contributions that add unique talent and ingenuity into decisionmaking
processes. The focus on collaboration provides a useful model from which to understand
how to integrate ideas to understand applied business concepts, fostering improved
business performance. As applied to my study, organizational learning theory provided
for a deeper understanding of operational strategies within the cybersecurity industry.
Operational Definitions
Badware: Badware is a software installed on a computer which can be harmful in
one’s system but totally harmless in another without knowledge or control (Han, Liu,
Han, Jia, & Lei, 2018).
Chief information security officer (CISO): The CISO is an individual who is
responsible in an organization to identify the information security concerns in
information technology (IT) outsourcing (Dhillon, Syed, & de Sá-Soares, 2017).
Cyberattacks: Cyberattacks are an attempt by hackers to damage or destroy a
computer network (Page, Kaur, & Waters, 2017).
Cybercrimes: Cybercrimes are crimes committed using malware and badware
with no viable mechanism (Rahman, 2017).
Data security: Data security is the provision of real-time security petabytes of data
which is important for cloud computing (Chang, & Ramachandran, 2016).
Data security breach: Data security breach is a privacy and security breach which
occurs from within a cloud service provider (CSP) as well as data states: data at rest,
while transferring data, enquiring data, and processing the data (Chakraborty, Sharma, &
Ranjan, 2016).
Organizational learning: Organizational learning which is a predictor of
knowledge transfer in an operational environment (Liu, 2018).
Risk management: Risk management is the forecasting and evaluation of financial
risks together with the identification of procedures to avoid or minimize their impact
(Rostamzadeh, Ghorabaee, Govindan, Esmaeili, & Nobar, 2018).
Assumptions, Limitations, and Delimitations
Assumptions
Assumptions in research help improve the quality of data (Xie, Hong, Laing, &
Kang, 2017). In this doctoral study, I made two assumptions. The first assumption was
that the data collection process would provide ample information to support a thorough
investigation of the phenomenon. The second assumption was that through the interview
process, participants would recall significant information to ensure the quality of the
investigation. In both cases, these assumptions proved true through diligent data
collection processes and the use of probing questions.
Limitations
Limitations represent potential weaknesses of the study (Eaton & Millar, 2017).
The one limitation in this study was the lack of generalizability of the findings to all
populations in all industries. While the information gathered in my research may be the
experiences of few, the findings may prove appropriate and applicable to similar
businesses in the cybersecurity industry.
Delimitations
According to Sheperis, Young, and Daniels (2016), delimitations are the
boundaries of the research study. First, I delimited this study to small business owners
located in the southern United States. Second, I delimited the study to CISOs of
hightechnology companies who were available for face-to-face interviews.
Significance of the Study
Contribution to Business Practice
Technology can help SME owners provide greater efficiency. SME owners utilize
technological innovations to streamline business process and implement effective
policies. CISOs are senior-level executives responsible for developing and implementing
an information security program, which contains policies and procedures intended to
protect enterprise communications, systems, and assets from both internal and external
threats of cyberattacks (Bauer & Bernroider, 2017). Small businesses are not only a target
of cybercrimes, but also main targets through which cybercriminals place the privacy of
consumers at risk of identity theft (Qabajeh, Thabtah, & Chiclana, 2018). Organizations
need to implement appropriate defensive measures to safeguard their business operations
from any attacks. Systems security is essential for the efficient operation of all
organizations (Baldwin, Gheyas, Ioannidis, Pym, & Williams, 2017). Security, trust, and
privacy are unending challenges for organizations that adopt cloud computing and big
data (Chang, Kuo, & Ramachandran, 2016). Findings from my study may have a
significance for small business leaders looking to prevent and mitigate costs from
cyberattacks. The findings may also provide small businesses with operative strategies to
protect their business against a cyberattack that might decrease derivate costs and
increase consumer confidence.
Implications for Social Change
Information and communications technology are expected to become ever-more
embedded in the economy and society, bringing both benefits and risk-related costs
(Hughes, Bohl, Irfan, Margolese-Malin, & Solorzano, 2016). This study’s implications
for positive social change include increasing the sustainability of information technology
in businesses. The findings in this study may help SME owners understand cybersecurity
strategies and invest in security to protect customers’ personal information. The public
may experience greater trust in the safety of transactions, leading to improving the use of
Internet services to conduct daily business and activities without having to incur the costs
from cyberattacks.
A Review of the Professional and Academic Literature
The purpose of this qualitative multiple case study was to explore the operational
strategies CISOs of high-technology companies use to protect their businesses from
cyberattacks. The specific target population consisted of high-technology companies
operating in Florida who have successfully protected their businesses from cyberattacks.
The literature review consisted of 236 sources of which 185 (95%) were current
peer-reviewed journal articles published no earlier than 2015. The following topics
appear in the literature review: cyberattacks, Chief Information Security Officers,
information security risk, cyber impact, and privacy and protection. The databases and
journals I used to develop the literature review include Google Scholar, IEEE Xplore
Digital Library, Science Direct, International Journal of Robust Security, The Journal of
Applied Behavioral Science, Organizational Dynamics, Information Management and
Computer Security, European Journal of Economics, Journal of Cleaner Production,
Production and Operations Management, International Affairs, Computers and Security,
The Learning Organization, and Nonlinear Control, Human Resource Management
Journal, Neurocomputing, Information Resources Management Journal, Information and
Computer Security, World Review of Entrepreneurship, Management and Sustainable,
Development, Strategic Management Journal, and Journal of Technology Transfer. A
review of the literature enhanced my understanding of the strategies CISOs of
hightechnology companies use to protect their businesses from cyberattacks and the
overall impact of cyberattacks on businesses.
Organizational Learning Theory
Organizational learning theory served as the theory comprising my study’s
framework. Organizational learning theory is a concept of everyday practical coping
guided by internalized sensitivities and predispositions (Rezaei, Allameh, & Ansari,
2018). Single-loop learning and double-loop learning are two essential tenets of
organizational learning. Argyris and Schon (1978) developed these two concepts and
emphasized that interaction often goes well beyond defined organizational rules and
procedures. Argyris and Schon has made a significant contribution to the development of
the organizational learning theory. Rezaei et al. (2018) found that knowledge creation had
a positive effect on organizational learning. Ideally, the effective organization should
have a two-loop model of training and function in the business.
The single-loop and double-loop model provides a basic understanding of change
management as a behavior change tool. Argyris (1976) argued the single-loop learning
encourages participants to learn to perform as long as the learning does not question the
fundamental design, goals, and activities of the organization. Wang et al. (2018) argued
that an efficient single-loop strategy is design in the presence of uncertainty. Single-loop
learning theorists have suggested that organizations avoid mistakes and double-loop
learning, and that they correct or change the underlying cause of the business problem
(McClory, Read, & Labib, 2017). Single-loop occurs when a process changes because of
a known deficiency (Argyris, 1996). The goal of single-loop learning is to provide
feedback to enhance the efficiency of the process change. Individuals will only be
creative and reflexive to avoid being singled out in the organization (Argyris, 1976). The
problem with using single-loop learning is that the method does not provide the feedback
which could help the efficiency of the process.
Leaders can use double-loop learning theory to reexamine problems organizations
face to add efficiency to the process. Double-loop learning occurs by changing the
fundamental principles of the actions in the process change (Argyris, 1976). Argyris
argued that double-loop learning encourages participants to ask questions about changing
fundamental aspects of the organization. Matthies and Coners (2018) argued that
organizations learn from past failures and successes. The implementation of double-loop
learning also enhances the communication between management and the employee
(Argyris, 1976). In contrast to double-loop learning, single-loop learning is used to solve
problems symptomatically (Argyris, 1976). Perhaps the impact of double-loop learning
and the process of interchange may justify the complexity and dynamics of changes in
policies and strategies for learning. Double-loop learning is an educational concept and
process that involves teaching people to think differently about their own assumptions
and beliefs. The double-loop theory may help individuals develop new skills, and it
allows the educator to create opportunities for individuals to understand and rethink why
they lead and how they lead individuals in businesses. The implantation of double-loop
learning increases the communication between management and the employees learning
to correct errors in a process (Argyris, 1993). The results of double-loop learning could
increase the effectiveness of the monitoring of decisions by business leaders.
The vision of an organization’s leadership permeates the workplace and is
manifested in the values and goals of the business leaders. The development of this vision
will start with the business leaders’ knowledge of how to deploy strategic alliances
(Simonin, 2017). Once business leaders obtain information, assistance, and qualities, the
managers will have the necessary information to interact and allow business leaders to get
the best out of their people from a single view to an organizational view (Kuo, Lin, & Lu,
2017). Having a clear vision allows business leaders to provide their firms with
competitive advantage, but longitudinal results in some studies have indicated that some
types of obvious content provide more enduring advantage than others do (Harrigan &
DiGuardo, 2017). Business leaders should offer motivation and opportunities to build an
effective long-term financial incentive and not just focus on the money (Delery &
Roumpi, 2017). Businesses can tap their insubstantial assets to grow their cost in the
business help business leaders transition from their present way of working to the desired
way of working.
Organizational learning theory highlights the intricacies of personal experience
and the influence of experience on workplace behaviors. Organizational learning theorists
are motivated by the observation that organizational leaders learn by making inferences
from experience (Greve & Seidel, 2014). Organizational learning involves gathering
information, analyzing the information, and learning from failure (Dahlin, Chuang, &
Roulet, 2018). Zhai et al. (2018) conducted research showing 324 SMEs discussed the
relationship between entrepreneurial orientation, absorptive capacity, environmental
dynamism, and corporate technological innovation performance. Zhai et al. suggested
that the relationship between entrepreneurial orientation and innovation performance is
significantly positive based on the moderation model.
The driving force of business theory is in the application of theoretical tenets.
Organizational learning theory has five main contextual dimensions (a) organizational
context and role, (b) geographical and spatial context, (c) social context and teams, (d)
institutional cultural norms, and (e) temporal dynamics (Wright et al., 2018). According
to the knowledge-based view of organizational learning theory, knowledge is embedded
in individuals and combined with organizational routines to generate innovative activities
(Grant, 1996). Argyris (1976) explored the concept of organizational learning and its
impact on a company’s growth. Argyris found no alignment between the dynamic
theories of organizational knowledge when learning involves various forms of employee
and entrepreneurial movement through a change in ownership. The disruption in
leadership poses challenges to reaping benefits from consistent management approaches.
Organizational learning is a product of organizational inquiry. Organizational
learning is how organizational leaders create and organize knowledge related to their
functions and culture. Organizational learning occurs in all the organizational leaders’
activities. The organizational learning theory involves developing, retaining, and
transferring knowledge within an organization (Qi & Chau, 2018). The goal of
organizational learning practitioners is to recreate changes or interventions (Pisano,
2017). Organizational leaders who are capable of maintaining the ability to self-adapt can
flourish. When business leaders process organizational learning, the cybersecurity
professional will interact with other members of the organization and productive learning
takes place.
Communication within an organization, generally considered an asset, can hinder
progress based on defensiveness and refusal to examine one’s own attitudes and
contributions toward a problem. Organizational learning theorists use the approach to
moderate the relationship between managerial ties and capturing opportunities (Li, Chen,
Liu, & Peng, 2014). Baumgartner and Rauter (2017) connected three distinct but
complementary dimensions of strategic management, as viewed from the perspective of
sustainability, to encourage the integration of sustainability issues into corporate activities
and strategies. Capacity development is particularly relevant in dealing with issues such
as cybersecurity.
The competitive advantage of learning. The organizational learning theory
applies when a company adopts new principles and paradigms that create a competitive
advantage. The goal of organizational learning theorists is to effectively change the work
environment (Nordin, Kork, & Koskela, 2017). The real world is costly for
experimentation, failing market-facing tests might jeopardize the organizational brand
and reputation (García-Sánchez, García-Morales, & Martín-Rojas, 2018). Increasing
innovation may allow organizations to gain a competitive edge and adapt organizational
designs to apply organization knowledge to emerging business problems.
Organizational learning theory was appropriate for this study primarily because
my intent was to understand behaviors within an organization that support developing and
sustaining competitive advantage. Pawlak and Barmpaliou (2017) presented the theory as
an underpinning of cybersecurity capacity building, the emergence of a principle-based
approach to capacity building in cyberspace with a sustainable outlook towards closing
the cyber capacity gap. To ensure the sustainability of efforts, organizations could
establish methods and instruments focused specifically on closing gaps. CISOs could
encourage higher-order learning during advanced system development. Organizations
would improve their chances of success in a changing and competitive world by
integrating appropriate methods and goals.
Theories Considered but Not Used
Transformational leadership. I considered using transformational leadership
(Burns, 1978) as a guiding concept, but did not use it given my intent to look beyond
leadership style alone as a factor in reducing cybercrimes in organizations.
Transformational leadership is defined as a social process in which members of a group
or organization influence the understanding of internal and external events, the choice of
goals or desired outcomes, the organization of work activities, and the individual
motivation and abilities (Frieder, Wang, & Oh, 2018). Transformational leaders moderate
the indirect effect of employees’ personality traits on their job performance via enhanced
perceptions of meaningfulness at work (Frieder et al., 2018). Additionally,
transformational leaders moderate the relationship between proactive personality and
work engagement, but only when employees have a growth mindset (Caniëls, Semeijn, &
Renders, 2018). Transformational leaders often work toward changing the organizational
culture through the implementation of new ideas (Northouse, 2016). Transformational
leaders establish behaviors that develop trust and organizational views.
Transformational leaders seek to influence relationships within an organization.
The transformational leader mediates mechanisms that could exist in the relationship
between transformational leadership and organizational performance (Para-González,
Jimenez-Jimenez, & Martínez-Lorente, 2018). Transformational leaders show integrity
and demonstrate how to develop a robust and inspiring vision of the future (Ashford,
Wellman, Sully de Luque, De Stobbeleir, & Wollan, 2018). Transformational leadership
was not an appropriate framework for this study because I did not explore the influence
of leadership style on cyber attack prevention; rather, the tenets of organizational learning
provided a strong foundation to explain business stakeholders’ behaviors in promoting a
safe and secure work environment.
Situational leadership. Business leaders may have a flexible approach to resolve
situational problems arising at work to build an effective organization. Hersey and
Blanchard (1969) argued the effective leadership rests in the appropriate balance of task
and relationship behaviors. Situational leadership is a very influential leadership model
that enables leaders of all kinds. Situational leadership refers to when the business leader
of an organization must adjust to the interaction between person-centered leadership by
professional leaders (Lynch, McCance, McCormack, & Brown, 2018). Leadership
depends on each situation and no single leadership style may be the best (Finkelstein,
Costanza, & Goodwin, 2018). A good business leader will be able to adapt themselves
from the leadership to the goals or objectives accomplished (Trotter, Salmon, Goode, &
Lenné, 2018). The situational leadership theory was expressed to overcome the
weaknesses of traditional leadership that were not suitable for some situations that
business leaders faced in the organization (Müller et al., 2018). Situational leadership
theory was not an appropriate framework for this study because the process of learning is
accumulative and not situational; thus, organizational learning theory was appropriate for
the study.
Contingency theory. Effective business leaders know how to frame their ideas
and provide direction to employees on how to satisfy the organization’s mission.
Effective business leaders also form relationships based on mutual trust. Fiedler (1958)
argued that there is a direct correlation between the traits of a leader and the effectiveness
of a leader. A business leader is a person who directs and coordinates the work of group
members (Fiedler, 1967). According to Fiedler, leadership traits helped in a certain crisis
and so the leadership would need to change given the new set of circumstances.
Fiedler’s contingency theory stated that effective leadership depends not only on
the style of leading but on the control over a situation. Contingency theorists claim that
there is no best way to organize a corporation, to lead a company, or to make decisions
that trace megaproject performance to variation (Gil & Pinto, 2018; Northouse, 2018).
Fiedler’s contingency theory is valuable for helping a company foresee the value of a
business leader within a given situation before assigning the employee on the job.
Contingency theory was not an appropriate framework for this study because I did not
seek contingent relationships to explain behavior. Rather, I sought to understand behavior
in terms of organizational learning strategies.
Cyberattacks
Networks are vulnerable to interruption by hackers and cybercriminals. The
definition of a cyberattack is an attempt by hackers to damage or destroy a computer
network or system connected to the Internet (Škrjanc, Ozawa, Ban, & Dovžan, 2018). A
cyberattack is considered mistreatment of computer systems, technology-dependent
enterprises, and network systems (Zhang, Wang, Liu, Ding, & Alsaadi, 2018). For
example, cyberattacks have challenged existing electric utility cybersecurity standards to
protect critical assets, their integrated dependents, and public safety from cyber threats
(Smith et al., 2016). Cybercrime is a growing and insidious problem for small business
owners, and owner efforts to encourage universal access to information technologies fail
because some business leaders lack cybercrime or IT knowledge to prevent related
problems (Jayakar, 2018). Cybercrimes are a phenomenon that, if ignored, could have
unlimited damage potential for business privacy, finances, and integrity. Cyberattackers
use malicious code to modify computer code and data, causing disruptions that can
compromise data and lead to cybercrimes, such as data and identity theft (Burnap,
French, Turner, & Jones, 2018). Cyberattacks continue to plague businesses, requiring
business owners to have well-crafted security strategies in place to prevent security
breaches.
Cybercrimes can cost businesses billions of dollars. For example, a serious
cyberattack caused confirmed physical damage to Sony. Sony suffered an estimated loss
of $20 million in revenue, and a $32 billion loss was incurred as a result of losing control
of customer data (Hou, Gao, & Nicholson, 2018). After this incident, cyber security at
Sony began a process of preventing another attack (Zetter, 2014). Sony implemented a
moving target defense to mitigate cyberattacks. Moving target defense is a type of
security technology involving the IT infrastructure changing its form actively to prevent
various cyberattacks (Park, Woo, Moon, & Choi, 2018). Preventing cyberattacks,
especially repeated attacks, is important to all businesses. Business owners try to keep
their data secure, but hackers find ways to intercept private, personal data which involves
investments of millions of dollars on behalf of customers, creating vulnerabilities to
customer personal accounts.
Business owners cannot afford cyberattacks. Cybersecurity professionals need to
have a well-crafted security strategy in place to prevent future attacks. The Internet
represents one of the most important drivers of innovation, growth, and competitive
advantage for national and international economies. Cyberattacks play an increasingly
important role in critical infrastructure manipulation, for government security, and
consumer privacy (Ding, Han, Xiang, Ge, & Zhang, 2018).
Access to business funding is one of the most effective ways to enhance the
resilience of SMEs. The SMEs are an important part of the nation’s economy, but their
owners often do not view themselves as targets for cyberattacks, creating a significant
weakness to the security of the business (Small Business Association, 2017). The rising
costs of cybersecurity render businesses ill equipped to sustain operability, and these
costs are estimated to climb rapidly.
Every government is reliant on independent countries to appropriately manage
their own cybersecurity issues. The U.S. government recognizes risk management
information systems in the developing world; and is needed to improve performance and
to impact users of information systems (Kaban & Legowo, 2018). The global business
environment must promote online involvement while ensuring the system is not creating
undue risks to patrons around the world.
Collecting and assembling data is financially taxing; and increasing data
collection efforts could carry the risk of reducing the available resource program an
organization has in place. Some companies are creating dynamic methods to secure their
organizations. Digital Defense’s innovative and leading-edge information security
technology helps businesses with a protection-sensitive data and eases the problems
associated with information security. Digital Defense, Inc. provides security assessments,
coupled with a deep background in security training for governmental and
nongovernmental organizations (Cabaj, Domingos, Kotulski, & Respício, 2018). The
Ponemon Institute (2015) is also a well-known resource for CISOs and other security
experts. SecrED is an industry-recognized training program that Ponemon Institute uses
to help organizations create a culture of security across the United States. The Ponemon
blog provides up-to-date information affecting CISOs government issues, and insider
threats. In 2015, the Ponemon Institute reported its analysis of the cost of all cybercrime
for a variety of 58 U.S. organizations, both public and private. Ponemon reported that
annual costs of cybercrime doubled since 2010, which averaged $6.5 million (Ifinedo,
2018). One method used by business owners is to develop a strong security policy. Each
business requires a policy and procedure to align with the assets of the business.
Implementing a policy and procedure could create a safe and welcoming environment for
the individuals in the business.
Social media use within the workplace is a common entry point for cyberattacks,
and organizations know little about how to actually manage social media risk. A survey
data from 98 risk-management, audit, and finance professionals, showed that the extent of
organizations’ social media use increases the actual risk of social media use (Demek,
Raschke, Janvrin, & Dilla, 2018). Organizational information protection initiatives could
increase over time as professionals become more comfortable with information
management strategies (Felo, Kim, & Lim, 2018). Organizations with a more widespread
social media policy could have more extensive training and technical controls. Few
organizations are adopting social media policies as opposed to operating a formalized risk
management process. This limitation accentuates the potential consequences associated
with cybercrime.
Chief Information Security Officers (CISOs)
The CISOs are increasingly finding information security strategies and functions
that are no longer adequate when dealing with a progressively more dynamic cyber risk
environment. The CISOs could provide craft training and learning principles to clearly
influence positive change. The CISOs in the organization should update and create some
risk-based choices rather than applying control in a sensitive manner. The CISO directs
the planning and implementation of the enterprise’s IT system, business operation, and
protections against security breaches and vulnerability issues that occur in the business
(Hasbini, Eldabi, & Aldall, 2018). The CISOs perform and oversee the functions and
activities that occur in the organization and do not focus only on unauthorized access to
the organization. The CISOs are also responsible for auditing the existing system while
guiding the management of security policies and procedures, activities, and standards. A
CISO must have exemplary interpersonal and written communication skills, solid
knowledge of electronic and site security issues, and an understanding of the business
environment, stakeholders, and working networks.
Cybersecurity professionals must lead in task accomplishment and lead with
integrity. Cybersecurity professionals need to have a clear understanding of their
cybersecurity human capital skills and abilities to ensure protection against threats to
information systems. Cybersecurity professionals need to focus on the importance,
difficulty, and timelessness that connect cybersecurity knowledge in the discipline
(Parekh et al., 2018). The CISOs must keep abreast of any new developments to avoid
costly mistakes and determine what actions they should carry out for the business
infrastructure at the given time. In a competitive organization, a set of skills are needed
for CISOs (Whitten, 2018). The CISOs must understand the effect attacks have on society
and the environment as vital to realizing sustainability. The CISOs should protect their
organization against cyberattacks to potentially increase the confidence resulting in
economic wealth.
The CISOs should partner with other organizations to understand their needs and
different strategies to prevent future attacks. Organizations are growing more dependent
on digital innovation and require individuals who work within the organization to meet
different challenges (Gustafsson & Jarvenpaa, 2018). One of the biggest challenges
facing leaders is to position the company securely and enable organization adaptability in
the face of increasingly dynamic, demanding, and high-risk environments. Cybersecurity
professionals need to distinguish various forms of cyberattacks.
The use of the Internet has changed the decision-making process through changes
in communication patterns in some businesses. According to Bashir, Wee, and Guo
(2017), Cybersecurity Awareness Week is a competition with measures of personality,
interests, culture, decision-making, and attachment styles. Bashir et al. examined
individuals, from self-proclaimed hackers to non-hackers and cybersecurity employees
versus students, in an exploratory study designed to identify the personalities of
cybersecurity competition members. The increase of hacking behavior has sparked a
debate about how online communication affects social relationships. The Internet releases
us from geographic bounds and brings us together to discuss topics, and what binds the
public in this domain is the access to the Internet (Bashir et al., 2017). The Internet is the
tool we use to interact with one another and to engage in new challenges. The internet is
not only affecting our lives but also mentally altering our brains which heightens
conflicting interest in the workplace.
Company leaders apply various strategies to approach cyber breaches. According
to Attaran and Woods (2018), personal demonstrations from business owners help
cybersecurity professionals focus on leadership development programs for coaching
leadership skills and practices. Communication is fundamental for leadership to function
more efficiently, but the communication skills and other skills could help leaders change
over time because of the infrastructure necessary for Internet connectivity.
Security Awareness Training
Security awareness training focuses on communicating and enforcing security
policies. Security awareness training is an effective way to prevent a cyberattacks against
small business (Fellnhofer, 2018). Information security policies should include training to
protect the integrity of the organization. Fellnhofer indicated that the majority of threats
arrive at the staff inbox through phishing scams and other social engineering attacks.
Training business leaders to defend against phishing, ransomware, and malicious
websites is a necessary component of a business digital security strategy. Training
business leaders on how to defend against phishing can help businesses reduce the risk of
cyberattacks (Fellnhofer, 2018). Businesses of any size require sufficient cybersecurity
measures, and appropriate training to inform employees of cybersecurity risks and best
practices.
Business leaders could find a way to protect critical information to gain a
competitive advantage in the workplace. According to Tadesse and Murthy (2018), 71%
of all data breaches affected companies with fewer than 100 people on the payroll.
Ransomware is the fastest growing malware threat and accounts for the majority of
extortion based malware causing billions of dollars in losses for organizations around the
world (Thomas & Galligher, 2018). Small business attacks are increasing because they
present cybercriminals with a way to access the business leader’s information and
personal data. Small business tends to have insufficient online security (Carr, 2016).
Also, small businesses are doing more online transactions and interactions through cloud
services.
Cloud computing is one of the latest strategies in computing. Understanding
malicious websites is a necessary component of a business digital security strategy
because cloud computing experiences increased popularity, but may pose significant
challenges to cybersecurity (Kumar, Raj, & Jelciana, 2018). Cloud computing is used
directly and indirectly by businesses and if any breach occurs in cloud computing, a
company may experience mounting and lasting ill-effects.
According to the Symantec Corporation, small or medium-sized businesses that
experienced cyberattacks, lost an average of over $180,000. Symantec is recognized as
one of the largest civilian threat collection networks in the world. Symantec Corporation
tracks over 700,000 global adversaries and records from 98 million attack sensors around
the world (Symantec Corporation, 2017). The utilization of innovative technology makes
collaboration easier for businesses, and business owners should create financial and
operational strategies for future impact with data analytics (Wang, Kung, & Byrd, 2018).
Implementing and using a business continuity plan (BCP) helps cybersecurity
professionals in the organization understand the risks associated with IT systems and
provides solutions to potential security problems. A more efficient business continuity
input process, immediate situational awareness for use of progressive planning, and
streamlined analyses for generation of reports for cybersecurity professionals may
significantly protect the integrity of organizations (Clark & Guiffault, 2018). By using a
consistent process, business continuity management may provide a supportive framework
for IT systems. In essence, the organizational structure for business continuity
management includes covering the roles of the leaders, identifying the tasks and
responsibilities of internal resources, and creating structures to document, test and
execute disaster recovery and employ IT contingency plans.
The Security and Exchange Commission (SEC) protects investors worldwide. The
US SEC has sanctioned broker-dealers (BDs) and registered investment advisers (RIAs)
to officially address issues when security breaches occur, also to determine whether the
SEC is imposing a strict liability approach. The SEC agreed to establish the required
cybersecurity policies and procedures in advance of a breach that compromised the
personally identifiable information (PII) of approximately 100,000 individuals and
thousands of organizations (Rubin & Xu, 2016). Cybersecurity attacks against the SEC
led to the implementation of strategies designed to block possible future cyberattacks on
businesses. Information security has increased public consciousness due to the universal
nature of data breaches, spanning from attacks on small business companies to individual
losses on a personal computer. According to Rubin and Xu (2016), strategic cyber
intelligence can substantially reduce risk to companies’ valued assets and supports due
diligence. The SEC goal is to collect information on the state of cyberattacks among
small businesses, understand cybersecurity risks, and expose the challenges faced by
smaller businesses that could undermine company security.
Information Systems Security Risk
Operating information systems is a critical part of any business that wants to
compete in the business world. Some businesses use information systems at all levels of
operation to collect, process, and store data. Management gathers and distributes data in
the form of information required to carry out the daily operations of the business. The
concept of a project-oriented business consists of three segments (a) values, (b)
structures, and (c) people (Gemünden, Lehner, & Kock, 2018). The above three segments
are ideally based on a range of management disciplines such as (a) the orientations in the
value segment developed in strategic management and innovation management; (b) the
foundations for the design of the sociotechnical artifacts in the structure segment of
organizational design, planning and controlling, the systems theory; and (c) the
foundations for the elements of the human side come from organizational behavior,
human resource management, and knowledge management theories (Gemünden et al.,
2018). Organizations need to understand the value of organizational behavior, human
resource management, and knowledge management theories.
Compliance by cybersecurity professionals could provide organizations with
confidence to focus on mitigating external threats. The goal of each business owner
should be to function in the organizing stage of the maturity cycle. There are many
reasons for a business to flourish or close. Organizational disappointment is inevitable as
a business leader experiences business failure due to harmful cyberattacks. However,
organizational disappointment may be within the control of the business leaders.
Malicious attackers frequently breach information systems by exploiting disclosed
software vulnerabilities (Biswas & Mukhopadhyay, 2018). The cybercrime prevention
and response process must start with the human factors that contribute to cybersecurity
vulnerabilities and risk (King et al., 2018). Vulnerability analysis is a vital part of
effective industrial risk evaluation (Abdo, Kaouk, Flaus, & Masse, 2018). Organizations
should create and check incident management plans to respond to security breaches
immediately. Cybercriminals are professional at hijacking identities. In some cases, the
attackers can upsurge a hacked user’s access within a system, leading to the identification
and inappropriate exposure of sensitive information. The integration of computing and
communication capabilities with the power grid has led to numerous vulnerabilities in the
cyber-physical system (Sun, Hahn, & Liu, 2018). Organizational leaders should create
and check incident management plans to respond to security breaches.
Secure organizations create security framework standards. The framework
development process initiated with Executive Order 13636, was released on February 12,
2013 (Schwartz et al., 2018). The development of methods and standards addressed
cybersecurity assurance in supply chains to increase societal expectations of sustainable
business practices, challenging organizations with a host of emerging risk factors (Zhu,
Song, Hazen, Lee, & Cegielski, 2018). Business owners are engaging in technological
transformation because of the advancements in cloud computing, analytics, mobile
devices, and social media (Sandor, Fulton, Engel-Cox, Peck, & Peterson, 2018). Some
organizational owners choose Information Security Management Systems (ISMS)
standards to create a set of credentials known as ISO 27001:2013. The ISO management
system standards demonstrate that the organization has the capability to manage
information systems successfully.
Cyber Risk Management Framework
A cyber risk management framework also helps organizations protect critical
infrastructures. The cyber risk management framework is designed to mitigate common
challenges that organizations face when developing analytic models, identifying
appropriate annalistic opportunities, and protecting analytic assets (Grossman, 2018). The
CISOs need to develop a model to capture the vulnerabilities of cyber capabilities during
hazards and propose novel ways to address the vulnerabilities (Zhao, Miers, Green &
Mitrani-Reiser, 2018). The NIST MEP Cybersecurity Assessment Tool allows small
business owners to self-evaluate the level of cyber risk to their business (Jaruga, Coskun,
Johnson, & Kimbrough, 2017). Increasing connectivity, use of digital computation, and
off-site data storage provide the potential dramatic improvements in manufacturing
productivity, quality, and cost (Hutchins et al., 2015). As threats to information security
gain attention in the organization, increasingly interested in asset management gives the
organization the ability to defend against cyberattacks.
Cybersecurity breaches make headlines as businesses around the world fall victim
to network intrusion and data theft. A comprehensive inventory of all security incidents
and breaches, uncovers the security risk organizations face when sharing sensitive
information (Yeh, 2018). Security of information is costly; and causes some
organizations to invest what is required to protect sensitive information (Luna, Rhine,
Myhra, Sullivan, & Kruse, 2016). Some organizations are still hesitant about spending
thousands of dollars to upgrade their security systems and improving data protection
policies and practices. Business owners cannot escape the huge financial costs of a data
breach, and organizations around the world must prevent business integrity losses as this
impacts all industries and processes involving stakeholder private information.
Cyber Impact
Cybercrimes are responsible for the disconnection of computer functions and
cause the downfall of many companies. The creation and improvement of technological
products and services depend on the exchange of data between people and companies
(Olano, 2018). Internet users may be unaware of the different cybercrimes and therefore,
may become victims of cyberattacks. Cybercrimes might happen to any business once an
entry point, or vulnerability, leads to their information hacking by an unlawful user
(Wadhwa, & Arora, 2017). The connectivity between computers through the Internet has
made cybercrime a public security issue.
Data breaches have been occurring for as long as businesses kept confidential
information and stored private data. Dodel and Mesch (2016) noted cyber-victimization
has extensive economic and personal consequences for Internet users as well as negative
consequences for economies and the entire cyberinfrastructure (Marti, 2018). The goal of
risk managers is to support assertions that the identified risk is manageable to secure and
satisfy business owners and stakeholders (Choudhary, 2018). Information security efforts
focus mainly on how to improve security and safety technologies (Nishigaki, 2018).
Business leaders must work closely to develop appropriate technical controls that
minimize the risks that occur in a business.
Business leaders who apply ICT strategies and plans can help cybersecurity
professionals to protect organizations. Organizational personnel who use computers can
describe their needs for information security and strive to trust in systems that ensure
confidentiality, integrity, and availability (Kakucha & Buya, 2018). With the increase in
data breaches that occur in the business world, success now hinges on the effectiveness of
data protection solutions (Kisekka & Giboney, 2018). Cyber-security systems, which
protect networks and computers against cyberattacks, are becoming common due to
increasing threats and government regulation (Toch et al., 2018). Cyberattacks affect the
way organizations plan and implement information systems.
Cybersecurity
Cybersecurity threats continue to rise and continually take on new forms in
response to new protection attempts that flood the cybersecurity market. The definition of
cybersecurity is the protection of information from unauthorized access or attacks that are
aimed at exploitation (von Solms & van Solms, 2018). Hacking has evolved from a
oneperson crime of opportunity to an open market of money laundering (Stergiou,
Psannis, Kim, & Gupta, 2018). Cybersecurity professionals strive to reduce, filter, and
organize large amounts of networks to help reduce the workload of the world’s most
damaging attacks. Computational models of cognitive processes are employable in cyber
security tools, experiments, and simulations to address the organizations and effective
decisionmaking in keeping computational networks secure (Veksler et al., 2018).
Cybersecurity tools are designed to categorize and structure network activity to diminish
the damage that an attack can cause to the organization.
Cybersecurity is a priority in all businesses. Information is one of the most
valuable assets in any market (Aishwarya, Pratiksha, Hule, & Sayli, 2018). According to
Paul (2017), SMEs employ 15.7 million people, which is 63% of all private sector jobs.
Investment in cybersecurity is critical to small business and medium-size enterprises
(Gordon, Loeb, Lucyshyn, & Zhou, 2018). Data breaches rose by a substantial 40% in
2016 (Timms, 2017). Cybersecurity professionals should reduce endpoint complexity and
improve internal stakeholder alignment, which would help cybersecurity professionals to
pursue more resources.
Cybersecurity Strategies
Cybersecurity threats continue to evolve strategies to mitigate and frustrate
cybersecurity professionals. An attacker can launch multiple attacks against a target with
a termination strategy indicating that an attacker will stop after observing a number of
attacks or when the attacker exhausts resources (Hu, Xu, Xu, & Zhao, 2017). A strategy
determines the direction in which an organization needs to move to fulfil the company’s
mission. As businesses move more, and the business functions of the public network,
they must take security measures to ensure that the data cannot be compromised.
Some SMEs encounter multiple cyberattacks daily; many remain undetected. The
loss of control over user data has become a very serious challenge, making it difficult to
protect privacy, boost innovation, and guarantee data sovereignty (Yin et al., 2018). Since
2017, human-centered cyber research has provided valuable insights into the cognitive
and collaborative work within cyber operations but ignored how the genesis, intentions,
methods, and outcomes of cyberattacks impact human-related outcomes (Chen, Herrera,
& Hwang, 2018). The SMEs business owners suffer from a lack of access to resources
that can increase security with less cost. Companies with inadequate security
instrumentation fail to protect their stakeholders, placing legal risks on the business
owner.
Remedies. Digital technology tools drive many changes in the business world.
Digital technologies have transformed innovation in many industries and sectors
(Nambisan, 2018). With many online tools, business leaders have a better insight into
customer preferences and form lasting interactions with other businesses. In the
contemporary business world, many users expect to engage with businesses through
online channels. Using digital technology tools as an online and e-commerce marketing
methods benefit small business.
Small and medium businesses are in a necessity for cybersecurity professionals.
The SME business leaders should have strategic goals and alternative innovation path in
terms of big data and analytics (BDA) (Heikkilä, Bouwman, & Heikkilä, 2018). Big data
is a new technology to improve existing business and create new business opportunities.
The big data on management control systems influences the way organizations provide
empirical evidence regarding control. The big data technology might help businesses
address various challenges and provide insights on real-time decision-making. Most
literature on big data and analytics focuses on how business leaders can enhance tactical
organizational capabilities, but very few studies examine its impact on organizational
value (Grover, Chiang, Liang, & Zhang, 2018). The advancement of information
technologies changes the way business operates.
Smart power networks in key areas of vulnerability could increase overall
cybersecurity. Smart power networks are exposed to an increasing number of cyberattack
events, due to the high integration of information techniques (Liu, Li, Shuai, & Wen,
2017). An effective cybersecurity strategy must work across business security platforms
(Cuganesan, Steele, & Hart, 2018). The SMEs can integrate a cyber risk management
strategy, comprising obtained cyber insurance into their business to defend themselves
from cyberattacks.
Insurance is essential to protecting a business from liability issues related to cyber
breaches. The adequacy of insurance for managing cyber risk is to extract cases of cyber
losses from an operational risk database and analyze their statistical properties (Biener,
Eling, & Wirfs, 2015). Cyber insurance may be a good investment for small businesses
that are affected by a cyberattack and do not have the funds to have IT risk audits to
prevent a cyber-intrusion.
A performance measurement database must begin by recognizing outcome goals
and then using those goals to guide the selection of suitable measures and relate the
process and capacity. Once the organization completes the steps, the cybersecurity
professional should begin operationalizing performance measures required to access the
appropriate data and well-organized resources (Kaban & Legowo, 2018). Cybersecurity
professionals should build on existing data systems for purposes of performance
measurement and to improve their value for other applications in place.
Business owners are charged with implementing strategies to mitigate the costs of
cybercrimes through preventative software and safe online practices for all stakeholders.
Business owners must invest in state-of-the-art technology to make business exchanges
safe and confidential for business owners and patrons. Business owners must adapt the
growth of organizations’ networks to remain competitive. The size and value of the
information hacked, damaged, and leaked are increasingly vulnerable for customers and
business owners. When business owners build tough systems that deliver interoperable
and reliable capabilities, they should establish and adhere to operational cyber styles; this
includes the ability to detect different styles and supply innovative solutions that allow
conclusive operational benefits.
Privacy and Protection
Maintaining privacy and keeping data secure has always been a very challenging
issue for the IT industry. A cyberattack could leave the mass populations vulnerable to
unprecedented personal and financial loss. The risk of targeted cyberattackers and the
vulnerability posed affects everyone in business and society. Dodel and Mesch (2016)
noted cyber-victimization has extensive economic and personal consequences for the
Internet users, as well as negative consequences for economies and the
cyberinfrastructure. Cybercrimes will impact individuals, businesses, and the economy.
The CISOs professionals are responsible for implementing an information security
program, which includes procedures and policies designed to protect initiative
infrastructures, systems, and assets from organizations (Georgiou & Lambrinoudakis,
2017). According to Irwin et al. (2018), SMEs constitute most businesses in the United
States and the issues impacting their performance is significant for many stakeholders.
The open environment of the Internet creates a vital opportunity for businesses to
consider the security of their networks. In addition, the business must ensure that the data
is not manageable to someone who is not certified to see it. Unauthorized network access
by an external hacker can cause serious damage to copyrighted data, affect the
companies’ productivity, and hinder the ability to compete.
Privacy protection is more difficult than providing security. Yet, federal law
recognizes no difference in the levels of protection expected for physical and electronic
data (Casini, 2018). A privacy strategy dictates who should recognize what. The law is
too often viewed as an impenetrable barrier to the use of administrative data to create and
evaluate evidence-based policy (Petrila, 2018). Policies and procedures reinforced by
system developments are addressable through the protection of sensitive data recognized
by federal laws. Business and governments around the world are committed to
sustainable development as a global policy on Internet protections. Cybercriminals use
businesses and governments to sell personal and private data to upset critical
infrastructures.
Data serve as a vital resource for entry into new markets, strategic partnerships
play a critical role in capturing the value created through the exploitation of data
resources (Mamonov, & Triantoro, 2018). With the rapid growth in technology, cloud
computing has become increasingly popular among individual users and businesses
around the world (Changchit & Chuchuen, 2018). Organizations can capture value from
new technology by incorporating the technology in their current businesses.
Communication privacy management (CPM) provides a framework for
understanding how small and medium business should maintain privacy parameters.
When a cybersecurity professional discloses information to a third party, the third party
becomes a co-owner of all the information and in some cases, that co-owner could
disclose personal information to a hacker. All cybersecurity professionals should have a
degree of control over the information. Connectivity and information flow represent the
two key enabling factors for a successful operation of the digital world (West, 2018).
Connectivity within the business process is not new.
In summary, cybercrime poses an increased risk to businesses, customers, global
entities, consumers, families, and society by infiltrating and stealing vital and confidential
information, for the purpose of personal and illegal gain (Hu et al. 2017). The costs to
businesses are far-reaching, but the personal costs, including the loss of trust in secured
interactions and transactions is detrimental to business security and reliance on secure
exchanges. The insidious nature of theft against the public, and the methods used to
infiltrate accounts and personal information is unfathomable. The alarming extent of the
problem highlights concerns about using the Internet at all as the Internet may pose
extreme risks to individuals, particularly those exchanging money for merchandise
online. Hackers face limited challenges in accessing personal account information, using
personal accounts for illegitimate purposes, and creating significant debt for unsuspecting
Internet users.
Business owners are responsible for the safe delegation of services to all
stakeholders who use the business online services. There is an expectation upon
businesses that, with the private customer information stored within the business’
database, that the information is secure and inaccessible to others. This remains an
assumption, and reports of entire systems under siege remains commonplace within the
business environment. Business owners must become knowledgeable about the risks of
cyberattacks directed at their company, and work to prevent cybercrime. This may
involve working with employees to promote safe Internet practices, ensuring encrypted
and secure transactions as a standard business practice, and most importantly, protecting
the integrity of the company through the protection of consumer data, business unethical
practices, and business reputation (Yeh, 2018). While companies provide some solutions
to these issues, a thorough exploration into what strategies CISOs of high-technology
companies use to protect their businesses from cyberattacks may aid in protecting the
growing number of businesses who may not have strategies, or the capabilities to prevent
cyberattacks.
Transition
Section 1 contained an introduction to the study regarding what operational
strategies CISOs of small high-technology companies use to protect their businesses from
cyberattacks. Section 1 included the background of the problem, problem statement,
purpose statement, nature of the study, research question, interview question, conceptual
framework, operational definition, and significance of the study. In addition, section 1
included a discussion of the assumptions, limitations, and delimitations of the study. The
conclusion of section 1 included a literature review of the professional and academic
literature. Section 2 included the discussion of the role of the researcher, participants of
the study, research method, and design, population and sampling, ethical consideration in
the research, data collection, organization techniques, and data analysis technique. In
Section 3, I included an overview of the study, presentation of the findings, the
application to professional practice, the implications for social change, recommendations
for action, recommendations for further research, reflections of my experience conducting
this study, and a research conclusion of this study.
Section 2: The Project
In Section 1, I provided a detailed review of the literature related to the central
research question. In Section 2, I expand on the methods and techniques I used to conduct
the research. I include a discussion of ethical requirements and strategies to ensure the
reliability and validity of the research. In Section 3, I will provide the findings of the
research, implications for social change, and recommendations for further research.
Purpose Statement
The purpose of this qualitative multiple case study was to explore strategies
CISOs of high-technology companies used to protect their businesses from cyberattacks.
The target population consisted of business leaders from three small businesses operating
in Florida who successfully protected their business from cyberattacks. Cybersecurity
managers were appropriate participants for this study due to their knowledge and
expertise in preventing cyberattacks. CISOs and other business leaders could use findings
from this study to better provide customers with a safe and secure environment for
conducting electronic transactions.
Role of the Researcher
My role as a qualitative researcher involved collecting and analyzing data from
the research participants, reviewing available documentation, and reviewing social media
sites to answer the central research question. I was the interviewer and primary data
collection instrument for this study. All participants had the capability to choose whether
or not they wanted to participate in this study. A qualitative researcher becomes
wellversed in strategies to minimize risk to participants. Bartlam et al. (2018) noted
participants act independently of the researcher. Additionally, researchers and
participants can be ethically challenging for business leaders, due to the personal
involvement in different stages of the study (Sanjari, Bahramnezhad, Fomani, Shoghi, &
Cheraghi, 2014). I collected data until no new information was available to achieve data
saturation.
My role as a researcher involved adhering to the research ethics and Belmont
research protocol. The Belmont Report summarizes ethical principles and guidelines for
research involving human subjects (Pearce, Ensafi, Li, Feamster, & Paxson, 2018).
According to the Belmont Report protocol, a researcher’s responsibility is to provide
beneficence, provide respect-for-persons, and justice to each participant (Ross, Iguchi, &
Panicker, 2018). Palmas (2018) noted the Belmont Report principles as an ethical frame
of reference. Respect for participants ensures that all participants have space to make
independent decisions (Reid et al., 2018). Justice is the concept of equal treatment for
everyone (Leiber, Beaudry-Cry, Peck, & Mack, 2018). I abided by the Belmont Report by
respecting respondents, minimizing risks, maximizing study benefits, and avoiding
impartial selection of participants.
For this qualitative multiple case study, I collected data from managers working in
information technology. Interviews were my main mode of data collection (see Yin,
2014). I also reviewed company websites and social media pages. For the interviews, I
used an interview protocol (Appendix A). An interview protocol contains the interview
questions and step-by-step guidance that I used consistently to ensure the interview
process was reliable. An interview protocol includes having a ready set of interview
questions and using a script to ensure the capture of rich thick data from each participant.
Participants
The sample for this study included individuals working in information technology
whose Florida businesses were impacted by cyberattacks. I explored the strategies those
businesses use to prevent future attacks. I initiated the data collection process after
receiving the approval from the Walden University’s IRB, and I used purposeful
sampling to recruit participants. In most case studies, coordinating resources and using a
small number of expert participants is critical (Yang et al., 2018). The participants in this
study are individuals operating small businesses. The study included two high-technology
companies operating in Florida that have successfully protected businesses from
cyberattacks. An excellent case study includes collecting interviews from multiple
businesses and analyzing the connections across those businesses. To meet the criteria for
this study, participants had to work within a business impacted by a cyberattack, were
equipped to respond successfully to remain operable. All signed a concent form before I
began their interviews.
To recruit participants, I connected with them through LinkedIn and I emailed the
informed consent form to each participant. The consent form also served as the invitation
letter, and a reply with an “I consent” indicated agreement to participate in the study. The
interview participants where individuals working for small and medium-sized businesses
who protected businesses from cyberattacks.
Research Method and Design
Research Method
The three types of research methods are qualitative, quantitative, and mixed
methods. The quantitative method is appropriate for evaluating hypotheses with
inferential statistics (Spicker, 2018). The quantitative method was not appropriate for this
study because it requires a hypothesis test. Mixed method was not appropriate because it
requires examining relationships or differences between variables, which was not
required for this study. The mixed methods approach is useful when combing the
participants’ experience and empirical data to determine the relationship and identify the
variables (Yin, 2014). Qualitative research method examines strengths and limitations
while discussing important contributions to the study (Latunde, 2017). A qualitative
method was the best choice for this study because qualitative descriptions are important
to expose dynamic processes (Matt, Gaunand, Joly, & Colinet, 2017). I used it to explore
operational strategies CISOs of high-technology companies used to protect their
businesses from cyberattacks. With this design, I captured information through
interviews, a review of available documentation, and a review of social media sites.
Research Design
Multiple case study was the most appropriate research design because the purpose
of my doctoral study was to explore operational strategies CISOs of high-technology
companies used to protect their businesses from cyberattacks. Case study research is a
useful approach for exploring contemporary phenomenon within real-life settings. Yin
(2014) noted that a case study researcher investigates a phenomenon within a specific
context to address the research questions. A phenomenological design is used to
maximize the depth of information collected (Burns et al., 2018). A phenomenological
design was not appropriate because I wanted to explore beyond lived experiences to also
capture perspectives, and any evidence found in documentation or social media sites, to
triangulate the research. A narrative researcher explores aspects of an entire lifetime to
explain phenomenon. The life stories of the participants in this study had no relevance in
the decision making processes participants used to protect their companies from
cyberattacks; therefore, the narrative design was not appropriate for this study. The case
study provided the best opportunity to gather data from various sources and was the best
approach to answer the central business question.
Population and Sampling
The population for this qualitative multiple case study consisted of CISOs from
high-technology companies operating in Florida who successfully protected businesses
from cyberattacks. The participants worked in the information technology field from a
specific sector and geographic area. In this study, I used a snowball sampling to recruit
businesses owners whose businesses were affected by cyberattacks. Robinson (2014)
developed an approach to sampling in qualitative research that includes (a) defining the
sample universe, (b) deciding on the sample size, (c) devising the sampling strategy, and
(d) sourcing the sample. Purposive sampling ensured I recruited those who would share
expertise to strengthen the study and assurance that the participants I selected were
experts in the cybersecurity field. I used a purposive sampling method to identify
interviewees who met the established criteria for the study. The study included a
purposeful selection of three small business owners. Purposive sampling allows a
researcher to complete projects on time using data collected from businesses (Mohr &
Metcalf, 2018). Data saturation is when no new data or information is needed (Moser &
Korstjens, 2018). This purposive sample was sufficient to reach data saturation.
Ethical Research
As a researcher, my role was to protect the integrity of the research, beginning
with protecting the confidentiality of participants and performing the investigation in a
respectful and cautious manner. My first task prior to conducting research was to
complete the Protecting Human Subject Research Participants training by the National
Institute of Health. Once I gained IRB approval to conduct research, I sought to ensure all
participation in the research was voluntary and that any request to withdraw from the
study was supported. I also ensured that, prior to interviews, I received participant
consent and informed participants of all rights related to their involvement in the study.
Research must be conducted in a manner that poses the least amount of harm to
participants (Ko, Ma, Bartnik, Haney, & Kang, 2018).
Informed consent is critical in research with participants (Moore, McArthur, &
Noble-Carr, 2018). Although no participants withdrew, participants were allowed to
withdraw from the study at any time before and after the interview. I used acronyms to
protect the personal identity of the participants according to the order of the interview
where the first participant is PA1, the second is PA2, and the third participant is PA3. To
comply with Walden University’s standards, I will secure all interview results for at least
5 years and then destroy them. A letter outlining the research scope and offering
introduction was provided to participants. It included details of the study, the
requirements for participation, and acknowledgement that they could withdraw from the
study at any time. The participants received no incentive for their involvement in the
study. However, each participant will receive a final approved copy of the study. Walden
University’s IRB approval number for this study is 01-24-19-0634075.
Data Collection Instruments
In this qualitative study, I was the primary data collection instrument. I collected
data from CISOs operating in Florida. The case study interview protocol includes the
interview questions, comprises a description of the organization’s procedures and general
rules guiding the research (Yin, 2014). Yin (2014) argued that the interview protocol
helps increase the reliability of case study research. Yin (2014) described that the
investigator in a case study must (a) ask important questions, (b) be a good listener, (c)
show flexibility, (d) have a firm grasp of the subject topic, and (e) avoid any bias. Renz,
Carrington, and Badger (2018) described involving the collection of data through
extensive interviews, note taking, and tape recording. Member checking and thematic
analysis adds validity to the study (Comley-White & Potterton, 2018). I used member
checking to ensure the accuracy of the data collected, data saturation, and appropriate
interpretation of the data.
Data Collection Technique
Data collection techniques depend on the research design approach that will most
appropriately answer the research question (Yin, 2014). A qualitative multiple case study
design guided the research process and was the best approach in gaining a good
understanding of the phenomenon. Interviewing participants, reviewing accessible
documentation, and physical artifacts are the most common forms of valuable data in a
case study (O Nyumba, Wilson, Derrick, & Mukherjee, 2018).
Before I conducted the interviews, the participants received a consent form. I
explained the details of the consent form. The consent form included an explanation of
the study, an explanation of what is required by participants including the right to
withdraw at any time. I provided a space on the consent form for participants to consent
or decline the invitation to participate in the study, and informed those who participate,
they will receive a courtesy summary of findings following the research. Once consent
forms were signed and returned, interviews were scheduled.
An interview is a technique for collecting data in which the researcher asks
openended questions (Smith, & McGannon, 2018). I used semistructured, face-to-face,
openended questions in this study. Using a semistructured interview technique provides
an opportunity for flexibility in the interview process, and to probe to gain rich, thick
data, to draw insightful conclusions (Nyström, Karltun, Keller, & Gäre, 2018).
Semistructured interviews could yield a broad range of perspectives, and cumulatively,
these add texture to the data collection process. Face-to-face interviews help build trust
between the researcher and the participant (Ciocănel, et al., 2018). The interview protocol
used to guide the interviews is provided in Appendix A.
Each interview took approximately 30 minutes with a brief introduction. During
the interviews, I solicited answers from the participants, reflecting the experiences and
perspectives of cybersecurity professionals. The script included an introduction to the
interviewer, the process of the study, information about the study, and the interview
questions. I encouraged the participants to provide the names of additional potential
participants who met the criteria. The interview ended with a statement thanking the
participants for their participation. After the initial interview, I engaged participants in a
follow up member checking session to verify the accuracy of their statements and add any
new information to their previous statements. Following the member checking, I
transcribed the interview material and prepared the data for analysis.
Data Organization Technique
To protect the integrity of the study, I organized the data for security and
quickretrieval purposes. I emailed the consent form to every participant once the
participants agreed to participate in the study. I secured the confidential information of
the participant by coding with letters and numbers. I kept all the research data such as
recorded interviews in one file or in a journal notebook and after the interview. Data
collected from participants is saved in a Google drive and data entry software Excel. Each
participant has a dedicated section in the Google drive and data entry software Excel. The
section included a copy of the consent form, a copy of the transcribed interview data and
all notes the researcher collected during the course of interviews. A copy of all collected
data for the study is stored on an encrypted USB drive for at least 5 years. All stored data
have a password protection for confidentiality.
Data Analysis
Data analysis involves drawing key information and strategies from the interview
data, information gained from the organization, social media sources, the conceptual
framework, and the literature, exposing a number of themes that explained the central
research question. I analyzed the data once the collection of data reached saturation and
all information has received member checking and transcription. Qualitative research
enables richer accounts but inevitably includes coder bias and subjective interpretations
(Cabrera & Reiner, 2018); however, the value gained from face to face interviews far
outweighs risks of bias that were duly noted and mitigated throughout the research
process. Data analysis refers to the assessment of gathered information from three
sources (a) notes, (b) interview responses, and (c) additional source materials collected
from the organization (Kern, 2018). Multiple sources of data helped to ground the
reliability of the research. I used methodological triangulation to strengthen the reliability
and validity of the study by conducting interviews, reviewing organizational offerings,
and review social media sites. Methodological triangulation is the exploration of
additional materials to form a conclusion (Rodgers et al., 2018). Researchers use
triangulation to enhance the confidence of a study by comparing, contrasting, and
confirming information and through checking the integrity of their inferences (Yin,
2014). Methodological triangulation adds validity to the research study (Yin, 2014).
The data analysis process included the use of software called NVivo, which is a
computer-assisted qualitative data analysis software (CAQDAS) for data collection. The
NViVo software provided features to automate and analyze data generated through a
selection of inputs. The NVivo software enables the researcher to code the data and draw
connections between codes to identify themes (Pokorny et al., 2018). After transcribing
the interviews, I categorized and coded key ideas in the responses, and through NVivo
software, I established themes from the interview data. I then incorporated the additional
source data collected, compared the findings to the conceptual framework and literature
reviewed, and established key themes representing the findings of the study. The data I
collected allowed me to answer my central research question of how small and
mediumsized businesses companies lack operational strategies to protect their businesses
from cyberattacks.
Reliability and Validity
Reliability
Reliable research is consistent in protocol, delivery, and outcomes (Leung, 2015).
For a qualitative case study, reliability means that the study is repeatable and will provide
similar results by following the same defined processes (Yin, 2014). Carefully asking
direct questions related to the central research question, recording responses, and then
ensuring the accuracy of the responses through member checking, all help to create
confidence in the procedures and findings of the study (Grossoehme, 2014). Using an
interview protocol ensure that the researcher applies the same techniques to each
interview to prevent bias and inconsistencies in the interview process. Therefore, I used
an interview protocol and ensured each question was relevant to the central research
question.
A rigorous approach to qualitative research yields the best representation of
participant experiences and perspectives (El Hussein, Jakubec, & Osuji, 2015). Marshall
and Rossman (2016) added triangulation also helps to strengthen qualitative inquiry.
Carter, Bryant-Lukosius, DiCenso, Blythe, and Neville (2014) indicated that triangulation
is a means of drawing various sources of related information together to explain
phenomenon. I interviewed the participants, reviewed company documents, and social
media sites, as a means of triangulating the study.
Validity
A valid study requires the use of appropriate methods and analysis processes to
establish sound results (Leung, 2015). Marshall and Rossman (2016) argued that
methodological triangulation of data from multiple sources, member checking, and peer
debriefing improves the validity of qualitative research. Carter et al. (2014) discussed the
importance of triangulation in qualitative research to ensure that more than one sources
leads to any conclusions about a phenomenon. Member checking adds to research
validity by ensuring that the interview data collected is interpreted accurately.
Participants review their contribution to the study, update any misinformation, and may
provide additional evidence to strengthen their arguments (Andraski, Chandler, Powell,
Humes, & Wakefield, 2014). I used both methodological triangulation and member
checking to ensure the validity of the study.
Trustworthiness in qualitative research builds confidence and credibility in the
study (El Hussein et al., 2015). Trustworthiness incorporates transferability,
confirmability, and credibility into the research process. Transferability results from a
researcher applying findings from one study to another situation and presuming the study
would have similar results.
Kihn and Ihantola (2015) added that the Researcher achieves confirmability when
the research findings are easily transmitted and understood. Data saturation in
interviewing requires that the researcher continue to ask interview questions until the
study reaches as point where the addition of new data adds no new information, and at
that point the interviews stop (Fusch & Ness, 2015). Creating an audit trail is aided by the
use of NVivo software, adding credence to the research processes (Houghton et al.,
2013). Detailing each step within the interview protocol and audit trail help to validate
the study further (Morgan, 2016). Member checking further adds trustworthiness to
qualitative research (Kornbluh, 2015). By using the interview protocol (Appendix A),
saturation, methodological triangulation, and member checking, I assured the
trustworthiness and validity of the study.
Transition and Summary
In Section 2, I provided a restatement of the purpose of the study, the role of the
researcher, participants and population, the research design, and methods. In addition, I
also discuss the data collection instruments, techniques, and data analysis. The most
appropriate research method and design were the qualitative multiple case study to
explore operational strategies some CISOs of small high-technology companies use to
protect their businesses from cyberattacks. Section 3 includes details on the findings of
the research, implications for social change, and recommendations for further research.
Section 3: Application to Professional Practice and Implications for Change
Introduction
The purpose of this qualitative multiple case study was to explore the operational
strategies CISOs of high-technology companies use to protect their businesses from
cyberattacks. In this section, I present my findings and discuss the themes identified. I
also discuss applications to professional practice and implications for social change, and
provide recommendations for action and further research, personal reflections, and
conclusions. The participants provided me with interview data that I used to address the
research questions, in conjunction with organizational documentation, social media
forums, and the literature review. Cybersecurity professionals highlighted the need for
skills in the area of communication, gaining knowledge of current cyberattacks, and risk
to the business.
Presentation of the Findings
The central research question for the study was: What operational strategies do
CISOs of high-technology companies use to protect their businesses from cyberattacks? I
asked three cybersecurity business leaders a series of questions on strategies to prevent
cyberattacks. During the data analysis process, I identified four main themes: (a) effective
leadership, (b) cybersecurity awareness, (c) reliance on third-party vendors, and (d)
cybersecurity training. The conceptual framework guiding the study was organizational
learning theory. In Table 1, I provide a summary of participants’ demographic
information of the. The three participants had over 26 years of combined experience
working in the cybersecurity field with small and medium-sized businesses.
Table 1
Cybersecurity Professionals’ Demographic Information
Characteristics Case 1 Case 2 Case 3
Code name PA1 PA2 PA3
Age 36 45 55
Highest level of
education
Bachelor’s degree Master’s degree Master’s degree
Length in current
field
6 years 9 years 11 years
Years of experience
as a business
leader
10 years 5 years 15 years
Theme 1: Effective Leadership
Leadership was the first theme that I identified through data analysis. Leadership
in the organization was the first factor that participants stressed as important in engaging
cybersecurity professionals in their leadership teams. The three participants agreed that
leadership in their organizations is motivating and transformational. In the business
world, leaders should play a strong role in professional life since leadership has a great
impact and influence on individuals (Moore et al., 2019). Effective leaders lead with a
vision, and effective leadership motivates followers to perform their best when executing
the organization’s policies after a cyberattack. Laureani and Antony (2019) explained that
effective leadership involves the right leadership style to attain the appropriate level of
motivation and vision after an attack on a business. All the participants agreed that the
business leader should create and communicate an inspiring vision for everyone working
in the workplace. The participants agreed that the vision sets the purpose of the business.
The effective leadership theme confirms the findings of Frieder, Wang, and Oh
(2018) that leader personality traits impact employee job performance especially when
the manager emphasizes the meaningfulness of employees’ work. The theme also
resounded with the findings of Ashford et al. (2018) that showed the role of optimism and
foresight in developing a robust and inspiring vision for the business’ future. Ashord et al.
(2018) indicated cybersecurity professional needs and use of resources are on the rise in
most organizations, and this development requires key leadership attributes to advance
the company competitively. Participant 1 indicated, “A growing organization develops its
security program, to guide the company in times of crisis and change, and keep it on
track.” Participant 2 indicated, “An effective leader must be a motivator and team builder
to be able to facilitate different roles on how to be an effective leader.” While Participant
3 indicated stated, “Different leaders carry out different leadership responsibilities.”
According to Nieuwboer et al. (2019), effective leaders dwell on the ability to lead others
and for that reason, a leader must adopt effective characteristics to ensure their style of
leadership is effective. The effective leader portrays maturity and skills and the capacity
to provide direction through constant change.
All participants noted that effective leaders can help employees advance with the
influence of a higher level of motivation. Participant 1 indicated, “Leaders can help
followers experience the same passion and motivation to fulfill the organization vision.”
Participant 2 indicated, “Hiring effective leader experts can help organizations find a
cost-effective strategy to introduce best practices in the business.” And Participant 3
indicated, “Effective leaders help others develop into leaders by replying to individual
needs and by aligning the organization goals.” Some capabilities may come naturally to
business leaders, while others are developed and strengthened over time. Business leaders
are faced with encounters such as satisfying employee morale, budget cuts, and
reorganization. Furthermore, business leaders are also responsible for satisfying
employee morale and being a visionary and a role model within their respective agencies
(Kopaneva, 2019). However, not every effective leader is an ethical leader. Bastian
(2019) specified one key difference between an ethical leader and an unethical leader is
the means used to motivate others and achieve goals. All participants agreed that to be an
effective leader is to lead toward a designated goal. An effective leader is able to advance
an organization and its stakeholders to new goals and outcomes. Evidence for this theme
emerged primarily from participant interviews, and was supported by the literature and
conceptual framework.
Theme 2: Cybersecurity Awareness
The most important factor in cybersecurity awareness is to make people aware of
their responsibilities and roles in information technology. Cybersecurity awareness is one
of the resources that businesses depend upon. Cybersecurity awareness prevents
information and business compromise. Business leaders should be aware of the risk in the
industry and inspire growing awareness of information security in their organizations.
Cybersecurity awareness involves knowing how to protect business information and how
to take reasonable steps for preventing data breaches.
The second theme that emerged through the research was the need for
cybersecurity awareness. The goal of cybersecurity awareness is to increase
organizational knowledge and prevention of cyberattacks and apply best practices. All the
study participants indicated that cybersecurity programs should apply to everyone
working in the business. Some businesses are conducting awareness training about
security vulnerabilities in the businesses because cybersecurity training ensures everyone
working in the IT department is aware of the risks and responsibilities of protecting
information technology assets (Bhardwaj & Goundar, 2019). Cybersecurity awareness is
increasingly relevant to all business operations to ensure the protection of company
assets.
Triangulation of interview data and available documentation provided many
revelations related to cybersecurity awareness. The review of Participant 1 indicated
security documents showed a “comprehensive card data security clarification,” which
contains electronic chip technology to authentic clients’ cards, and end-to-end encryption
and tokenization services to safeguard consumers’ information. Participant 1 indicated,
“We have a processing credit and debit payments that helps protect against new and
evolving fraud threats by realizing EMV chip technology and encryption security
technologies in conjunction.” Participant 2 indicated security plan showed “the impact of
tokenization on Payment Card Industry (PCI) agreement.” Small and medium-sized
business leaders suggested not only awareness, but also the need for cybersecurity
protection by creating and applying a written security policy. Participant 2 indicated,
“The business tie in the reasons that show changes in digital habits to protect ourselves
online which includes phishing scams and social engineering.” Participant 3 indicated,
“Cybersecurity awareness is the not only the business concern but it also concerns
insufficient awareness.” In addition, Participant 3 indicated, the business has an urgency
and adaptably to new opportunities as they arise.
Cybersecurity awareness in information systems training has become one of the
most important necessities in an organization. Lykou, Anagnostopulou, and Gritzalis
(2019) noted constant moving and technologically fragile safe communication systems
are required to ensure business sustainability and profitability. Participant 2 indicated, “In
order to decrease the number and extend in security breaches then training is
fundamental.”
Effective cybersecurity awareness programs can improve the information
assurance of an organization. Information security incorporates organizational aspects,
legal aspects, and presentations of best practices in security technologies. Participant 1
indicated, “User awareness signifies a significant challenge in the security field, with the
human factor finally being the element that is manipulated in a range of attack settings.”
An information security awareness program is a vital component of any organizations
policy. In the competitive market, cybersecurity attacks result in loss of income, loss of
customer trust, and liability issues. Therefore, information should be safeguarded and
protected.
Participant 1 indicated, “Various organizations use expedient information security
awareness tools established by some of the international information security companies,
whereas some organizations make their own awareness tools according to the needs of
the organization.” Participant 2 indicated, “Information security awareness is about
guaranteeing that all personnel is aware of the rules and regulations regarding securing
the information within the business. Information security awareness should, therefore;
form an important part of any establishments’ overall information security management
plan.” Participant 3 indicated stated, “Sending out a report monthly on all activities can
reinforce learning and the value of the business.”
Cyber attacks is reality and can cause a lot of damage if business leaders do not
target a critical infrastructure. Hackers seek to coerce users into allowing them access to a
digital resource before they try to hack their way in. Therefore, due to the quickly
changing environment, cybersecurity awareness training cannot involve a one-shot
program. In order to safeguard the network security of a business, cybersecurity teaching
must be repetitive, efficient, and repeatedly tested.
Theme 3: Reliance on Third-Party Vendors
The third major theme to emerge during data analysis of archival documents and
participant interviews was the use of cybersecurity policy and the business leaders’
documents that provide details on defending organizations and their assets. I found the
more the business relies on technology to collect data, store or manage information, the
more vulnerable the business becomes too severe security breaches. Human errors,
hacker attacks, and system malfunctions could cost the business financial damage and can
jeopardize the business reputation. My analysis specified the requirements cybersecurity
professionals use to maintain a network system. An important requirement of any
information management system is to guard data and resources against breaches, while at
the same time safeguarding data access to genuine users.
Participant 1 indicated, “I have experience in managing highly secure organizations of
major enterprises by closely integrating security and operations and the necessity small
and medium-sized business owners used to launch cybersecurity policies and efficiently
implement cybersecurity techniques to protect their businesses from cyberattacks.” One
of the challenges of responding to a cyberattack was the nonexistence of consistent
security policies and procedures disclosures a business to unforeseen threats. The
participant noted that dealing with systems handling data are delegated to track its flow to
comply with data protection regulations.
Participant 2 indicated “The goal of the company is to capture the magnificent
breadth of valid policies”. My study required participants to analysis also specified the
requirement for cybersecurity professionals and business leaders to implement
cybersecurity procedures to protect their businesses from cyberattacks. The participant
also noted to reduce expenses resulting from hackers, everyone in the business needs to
communicate, implement, and sustain security policies.
Participant 3 indicated stated “A common enterprise-wide approach has not yet been
implemented, however; for some business, the responsibility for cybersecurity has
entrusted almost entirely on the chief information security officer.” The cybersecurity
professionals believe that the teams should be led by the business leaders with an
organized strategy. One of the tasks to teamwork has been the official business
environment of the cybersecurity and a surviving condition that need be addressed when
a business entrench the risk thinking and task in cybersecurity strategy.
Business leaders must take a proactive approach to protect their data by
establishing cybersecurity plans. As organizations expand their operational processes to
their cyber infrastructure, effective cybersecurity is the key to an organization ability to
protect their assets. Participant 2 indicated “Working in the cybersecurity field is
important because it is not just about protecting the company and the company assets, it is
also about protecting the company reputation, property, and customers”. The business
owner believes the investment can be complex technical solutions, which mean that they
are well protected from cyberattacks. Participant 2 indicated believed that it is part of an
operational defense.
Business leaders facing threats must safeguard that they have a unified approach
to cybersecurity tailored to their particular business and risk profile. According to
Participant 1 indicated, “It is not only about addressing the technical aspects of their
defense, but it is also about the organizational elements”. Participant 1 indicated had an
in-depth understanding of the threat and risk-based approach to identify how it affects the
individuals in the business. An effective cybersecurity strategy must work across a
business security measure. Participant 2 indicated, “Capability in a range of key
disciplines with the ability to work across organizational functions to strengthen an
integrated cybersecurity strategy.” All organizations need to plan for a successful
cyberattack and it is also essential to ensure they have the ability and resources to rapidly
detect and isolate any problems that occur, control the level of the investigation and
respond immediately to any inquiries, and maintain business continuity. Participant 3
indicated, “Risk oversight of cybersecurity practices and the business always ensure the
strategy to protect their assets.” Lastly, it is important for security objectives are to
ensure continuous security measures. The business must review all the risks in all
departments and mitigate the most important risks by applying defense and responding to
a crisis in a prioritized way.
Theme 4: Cybersecurity Training
The business leader established a cross-training on various product lines and
career expansion for the talented remaining employees. The cross-training prepared
individuals for transferring to a different product line or department to keep busy and
engaged. The business leader is providing information and opportunity for achieving their
career desires through organization-specific preparation and guarantees that they are part
of the business because it is important to the employees. Loon (2019) emphasized that
human capital development is accepting individual foundational theories of
socioeconomic development. Participant 1 indicated “Some employees are worried that
they don’t have the understanding and skills needed to take on new tasks, or expand on
the business. While others are worried about having the time and energy necessary to step
up to the larger task. Participant 2 explained “It is hard to find talented cybersecurity
professionals due to the money the organization needs to spend and having the time to
train that individual.” Participant 3 added “The people who report to you worry for
various reasons.”
Participant 1 and Participant 2 indicated to invest in personal training and
improvement to develop employability while business leaders participate in
employeespecific training to improve organizations’ efficiency. Participant 3 indicated
“Personal training improved the business efficiency and safety.” In my examination of
the participating businesses’ websites, I recognized reports such as “we invest in the
learning and development of our employees to increase competency” and “we invite,
retain, and improve our people.” All the participants emphasized that there is a shortage
of talented cybersecurity professionals willing to work with small and medium-sized
businesses.
Supply chain finance, as the core driving force for supply chain development,
plays a vital role in resolving any financing difficulties that exist in many SMEs in the
upstream and downstream of the supply chain (Liang et al., 2018). Employee productivity
is essential to any business. Business leaders found when teams are able to make
significant gains and developments in a short amount of time, it can have a massive
impression on the bottom-line (Liang et al., 2018). The more well-organized your
employees are, the more positive you’ll be as a business. However, most agree that
employee productivity is important, but there’s a lot of misinformation about it. There are
countless business leaders doling out information on production. Occasionally, this
information could be good and bad. While it’s not supported in truth. Therefore, this
theme supports the human capital theory in that the savings in training and education lead
to improved benefit for both the organization and the people business leader employed.
To assess employee production, as well as progress operational programs for
improvements, business leaders need to engage in research, which is one of the reasons
one business leader gathered a comprehensive list of employee productivity
measurements. Therefore, is most important to encourage the people who report to you of
their importance to you and the organization. Business leaders need to talk with each
person independently to let them know why and how they are valued to the organization,
highlighting their support to the overall functioning of the operation. For some, it will be
exciting and career-expanding.
Applications to Professional Practice
The findings of this study could prove valuable to current and future leaders in the
cybersecurity field. Study findings may also help business leaders and cybersecurity
professionals reduce costs when responding to cyberattacks on businesses. The cost of
responding to cyberattacks has risen because of the need for cybersecurity professionals
needed in the market and due to the increased number of cyberattacks affecting business
operations (Abhishta, van Rijswijk-Deij, & Nieuwenhuis, 2019). Therefore, small and
medium-sized business owners can improve their business performance and best practices
to protect their businesses from cyberattacks. The study findings include four themes: (a)
effective leadership (b) cybersecurity awareness, (c) reliance on third-party vendors, and
(d) cybersecurity training. A tactical plan is serious because an awareness plan provides
the foundation to secure a business and how business could prevent cyberattacks.
Furthermore, the findings and conclusions can help small and mediumsized business
leaders mitigate against the problems arising from regulations. Access to information
about procedures should be available to small and medium-sized business at minimum
cost. Policymakers must ensure that the compliance procedures associated with new
technologies are not pointlessly overpriced, difficult, or extensive. In general, small and
medium-sized enterprises account for over 95% of businesses and 60% to 70% of
employment and generate a large share of new jobs (Alcalde-Heras, Iturrioz-Landart, &
Aragon-Amonarriz, 2019). Business leaders have specific strengths and weaknesses that
require special policy and procedure responses. As businesses see new technologies, the
reputation of economies of measure in many activities firms enhanced and the potential
contribution of smaller firms is greater. However, many of the traditional difficulties
facing small and medium-sized enterprises include the lack of financing, problems in
developing technology, controlled decision-making abilities, low efficiency,
technologydriven environment, and the business becomes more acute in globalization.
Current and future business leaders could adopt approaches to cybersecurity that will
require much more engagement from the cybersecurity professional to protect critical
business information without constraining innovation and growth.
Implications for Positive Social Change
The implications for social change from this research include the potential impact
of successful cybersecurity strategies for small and medium-sized business owners to
protect their business from future cyberattacks. The biggest issue that small and
mediumsized businesses are facing is defending themselves from potential cyberattacks
and some businesses had to pay cybercriminals even up to $1 million in a single attack,
while others have incurred losses in hundreds of millions of dollars (Zimba, &
Chishimba, 2019). In organizational learning theory, both single and double-loop learning
deal especially with the idea of the organization as whole learning and adjusting its
behavior. Organizational learning theories are included in this study since they deal with
both policies and employee behavior. The findings of the study draw attention to specific
approaches needed to strengthen businesses and optimizing the use of the Internet to
ensure businesses retain a competitive edge while diligently preventing cyberattacks.
Training employees and giving them career growth chances is one guaranteed
way to show them that the business can invest in their future? It will influence individuals
to keep employed strenuously and be improve at their jobs. These opportunities are
equally useful since training opportunities help grow the company while at the same time
they further employee knowledge and skills. Small and medium-sized businesses can be
characterized as advanced, of which some 5 percent are technology-based. Advancing small and
medium-sized business tend to be market-driven rather than research-driven, and speedier in
responding to new opportunities than large businesses. Business leaders play an important role in
groundbreaking and increasing new markets. Programs for educating the diffusion of technology
have removed from a supply focus to educating the capacity of small and medium-sized
enterprises to engage technology. The findings from the study could contribute to social change
by investing in other small and medium-sized enterprises, new entrepreneurs, and academic
establishments with successful strategies and incomes to effect changes within the community.
Recommendations for Action
The purpose of this qualitative multiple case study was to explore what
operational strategies CISOs of high-technology companies use to protect their businesses
from cyberattacks. Based on my findings of this study, I recommend several actions that
the current and future cybersecurity professionals to strengthen their cybersecurity
capabilities for the future. First, cybersecurity professionals need to properly develop
ways to identify and prioritize IT security risks and improve mitigation strategies which
hundreds of millions of dollars have been devoted to implementing these strategies.
Second, desktop environments are more vulnerable than they were even five years ago, as
USB ports have been restricted and Webmail services are blocked in some businesses.
Third, robust technologies and enterprises have been put in place to address attacks on the
perimeter. Therefore, business leaders interviews strengthened changes in how
enterprises use technology have concurrently made corporate environments tougher to
protect while snowballing the importance of protecting them. Recommendations (a)
mitigating actions should flow logically from the conclusions and contain steps to useful
action, (b) state who needs to pay attention to the results, and (c) indicate how the results
might be disseminated via literature conferences, training, and so on. Business leaders
need to expand their range of potential candidates to seek smart, encouraged and enthusiastic
individuals who work well as part of a team. One business leader felt that because they may
not have the degrees, certificates or prior experience a company might hope for doesn’t mean
they won’t be an excellent fit. I intend to publish the study and take advantage of
opportunities to share with business leaders in the cybersecurity field, colleges and
university, and business forums where business leaders discuss strategies to avoid the
unsuccessful concerns of a major cybersecurity breach.
Recommendations for Further Research
I conducted a qualitative multiple case study on the strategies used by business
cybersecurity professionals. The population for the study consisted of two small and
medium-sized businesses owners use to protect and defend their business from
cyberattacks. The study is also limited to one geographic location. Thus, to generalize the
findings, future researchers can decide on different location such as researching different
organizations impacted by cybersecurity or businesses around the countries. Furthermore,
future researchers should consider doing the study in a different industry such as
nonprofit organization, small and medium-sized businesses, government agencies, and
high-technology companies. Additionally, future researchers can use a mixed research
method to report on changes in cyberattack frequency, geographic location, preparedness
and mitigation strategies across a vast area. The findings of such a study, paired with
evidence from qualitative interviews and related evidence, will inform policymakers and
ensure a viable and aggressive response to protect businesses, consumers, and society
from the insidious impact of cyberattacks. I would recommend future researchers to
consider allocating additional time to obtain viable research to determine the
effectiveness of the cybersecurity field and make recommendations to address gaps in
security that may impact broad domains, in an era of ease of access and clandestine
actions to undermine the core economic structures of society.
Reflections
Completing the doctoral study process has been a rewarding experience since I did
not have any knowledge in the cybersecurity field. I learned valuable information about
cybersecurity in small business, what methods cybersecurity professionals use to prevent
cyberattacks, and about conducting qualitative research. The results of the study helped
me to understand the importance of protecting a business and why it is important to hire
cybersecurity professionals and to understand the difficulties of conducting qualitative
research. This qualitative case study explored successful strategies used by business
cybersecurity professionals. The results of the study helped me to understand the
difficulties of conducting qualitative research. Finding participants for a limited case
study can be very challenging. The problem results from companies not securing their
networks and small businesses need cybersecurity professionals in place. There are a
limited number of companies with cybersecurity professionals in Florida.
The data collection and analysis was sensational and fulfilling. I had a few
difficulties finding participants due to their busy schedules and wanting to ensure the
proper information to give to me due to sensitive information, but once I found one
participant everything went smooth. A lesson learned is small and medium-sized
enterprises are the main target for cyberattacks and finding the right personnel can be an
overwhelming process.
Conclusion
Cyberattacks on small and medium-sized enterprises continues to be a growing
problem due to the lack of cybersecurity professionals in business (Dolezal, &
Tomaskova, 2019). All business with top talented and major resources dedicated to
cybersecurity have suffered major cybersecurity conciliations, and organizations that do
not have such levels of talented or resources face even greater encounters. Businesses
need to find highly skilled workers in the cybersecurity field to help the nation respond
more forcefully to the cybersecurity problems it faces. All businesses need to understand
their threat situation and the threats they face, report their cybersecurity problems, and
employ the most appropriate people to do that work. The purpose of the qualitative case
study was to explore what operational strategies CISOs of high-technology companies
use to protect their businesses from cyberattacks. Cybersecurity professionals were
appropriate participants for this study because of their experience of cyberattacks on their
organizations.
Students also viewed