Date of Conferral

9-5-2024

Date of Award

September 2024

Degree

Doctor of Information Technology (D.I.T.)

School

Information Systems and Technology

Advisor

Gary Griffith

Abstract

Small business owners are concerned about incorporating security best practices, security frameworks, and critical business functions into a cybersecurity strategy, which is necessary to adapt to the increased sophistication and occurrence of cyber-attacks. Grounded in Von Bertalanffy’s general system theory, the purpose of this qualitative pragmatic study was to explore strategies cybersecurity professionals use to mitigate cybersecurity threats in small businesses. A sample of 14 security professionals on LinkedIn shared their perspectives on how cybersecurity strategies successfully mitigated recent cybersecurity threats. Data were collected through semi-structured interviews, and data analysis was performed by coding keywords, phrases, and methods. The following themes emerged: cyber security strategy based on business needs, security practices & cyber hygiene, risk management, security controls, continuous monitoring, proactive security, and incident response. A key recommendation is for business leaders is to establish a security culture where cybersecurity strategies are part of the overall business strategy. Implications for positive social change include the potential for economic growth within the small and medium business population, leading to more jobs.

Share

 
COinS