Date of Conferral

8-19-2026

Date of Award

August 2026

Degree

Doctor of Business Administration (D.B.A.)

School

Management

Advisor

Theresa Neal

Abstract

Cybercrime and data breaches pose a serious threat to the long‑term sustainability of small and medium‑sized enterprises (SMEs), especially those with limited cybersecurity capabilities. Leaders of these firms recognize that inadequate cybersecurity resources significantly increase the risk of instability and reduce the likelihood that their businesses will survive beyond the first 5 years. Grounded in Schumpeter’s entrepreneurship theory and Keynesian economic theory, the purpose of this qualitative multiple case study was to identify and explore effective strategies that SME owners used to protect their businesses against cybercrime and data breaches to sustain their businesses beyond the first 5 years of beginning operations. The participants were six SME owners from manufacturing businesses in the Southwest region of the United States who had successfully implemented cybersecurity strategies to sustain their businesses beyond 5 years from beginning operations. Data were collected using semistructured interviews and a review of organizational documentation. Through thematic analysis, three themes were identified: (a) people: building a human-centric security culture, (b) process: principle-based and multilayered security systems, and (c) progress: strategic prioritization and adaptive mindset. A key recommendation is for SME leaders to integrate continuous cybersecurity training, multilayered security controls, and strategic risk management into routine business operations. The implications for positive social change include the potential to improve SME resilience, protect sensitive information, preserve employment opportunities, and strengthen local economies through enhanced cybersecurity practices.

Share

 
COinS