Human Factors in Cybersecurity in Icelandic Small and Medium-sized Enterprises

📅 2026-06-01
📈 Citations: 0
Influential: 0
📄 PDF

career value

208K/year
🤖 AI Summary
This study addresses cybersecurity challenges in Icelandic small and medium-sized enterprises (SMEs) stemming from human factors, such as insufficient security awareness, lack of training, difficulties in recruitment, weak security culture, and limited resources. Drawing on survey data and qualitative analysis from 130 public and private organizations, the research systematically evaluates, from a managerial perspective, how human resource constraints impact organizational cybersecurity posture. Innovatively contextualized within Iceland’s unique SME landscape, the work proposes tailored interventions—including customized training programs, enhanced government support, and the cultivation of a shared-responsibility security culture—to strengthen cybersecurity resilience. These locally grounded strategies offer practical guidance for improving cyber defenses in resource-constrained SME environments.
📝 Abstract
Cybersecurity threats are increasing in all aspects of society due to the integration of digital systems into modern-day life and a volatile geo-political landscape. Technical factors are an ongoing arms race; however, the threat surface from human and social factors is still present, often providing malicious actors the means to bypass complex technical security controls. Understanding human factors in light of technical evolution is essential to ensure security controls remain effective. This study presents the results of a survey on cybersecurity challenges within public and private sector organisations, including critical infrastructure providers, in Iceland (N = 130). From the management perspective, human factors were strongly noted as challenges and barriers to their organisations' security. These challenges include a lack of adequate training or awareness, hiring issues, poor cybersecurity culture, and time and/or financial resource constraints. Based on these findings, recommendations for mitigating threats from human factors are derived. These include: prioritising targeted over generic training to reduce employee fatigue, external government support for financially constrained organisations, and building a strong cybersecurity culture through constructive communication around shared responsibilities.
Problem

Research questions and friction points this paper is trying to address.

human factors
cybersecurity
small and medium-sized enterprises
security awareness
organizational challenges
Innovation

Methods, ideas, or system contributions that make the work stand out.

human factors
cybersecurity culture
targeted training
resource constraints
organizational security
🔎 Similar Papers
No similar papers found.