ПЕРЕКОНАНІ, АЛЕ НЕ ГОТОВІ: ПІЛОТНЕ ВИМІРЮВАННЯ ГОТОВНОСТІ ДО КІБЕРБЕЗПЕКИ СЛОВАЦЬКИХ МАЛИХ І СЕРЕДНІХ ПІДПРИЄМСТВ

Main Article Content

Якуб Сопко
https://orcid.org/0000-0002-7314-828X
Леош Шафар
https://orcid.org/0000-0001-8466-0644

Анотація

Малі та середні підприємства (МСП) дедалі частіше стають мішенню кібератак. Однак їхню готовність у Словаччині рідко вимірюють. Це дослідження розробляє та пілотує інструмент для оцінки готовності до кібербезпеки малих і середніх підприємств. Анкета складається з шести частин. Чотири з них містять шкалу ставлення й формують вимірювані виміри готовності: технологічну готовність і сумісність, готовність процесів і управління реагуванням, сприйняту користь кібербезпеки для працівників, а також стратегічну та розвиткову орієнтацію. Пілотне обстеження провели 25 словацьких малих і середніх підприємств. Ми перевіряли дані за допомогою альфа-моделі Кронбаха, коригували кореляції між елементами й загальним аналізом та аналізом головних компонентів за допомогою обертання Varimax, разом із мірою Кайзера-Мейєра-Олкіна та тестом сферичності Бартлетта. Усі чотири виміри мають прийнятну внутрішню послідовність (альфа 0,673 до 0,886), і три перевищують поріг 0,7. Технологічний вимір є одновимірним і пояснює 60,27 % дисперсії відгуків. Один проблемний пункт був виявлений у вимірі працівника; його видалення підвищує альфу з 0,673 до 0,779. Обертована матриця компонентів свідчить, що стратегічно-фінансовий вимір поділяється на дві підшкали: економічну обізнаність і орієнтацію на стратегічні інновації. Описові результати виявляють послідовний розрив між упровадженням і перевіркою. Базові технічні методи контролю дуже поширені, водночас заходи, що підтверджують їхню ефективність, відстають. Регулярні резервні копії виконують 19 із 25 компаній, але лише 11 перевіряють, чи можна відновити дані. Дослідження пропонує оновлену модель вимірювання, готову до збирання даних на великій репрезентативній вибірці. Отож, вона забезпечує методологічну основу для систематичного збирання даних про готовність до кібербезпеки словацьких малих і середніх підприємств.

Article Details

Посилання

Accenture. (2019). At a glance: Ninth annual cost of cybercrime study. https://www.accenture.com/content/dam/accenture/final/a-com-migration/pdf/pdf-99/accenture-cost-cyber-crime-infographic.pdf

Al Aamer, A. K., & Hamdan, A. (2023). Cyber security awareness and SMEs’ profitability and continuity: Literature review. Emerging Trends and Innovation in Business and Finance, 593–604. Springer. https://doi.org/10.1007/978-981-99-6101-6_43 DOI: https://doi.org/10.1007/978-981-99-6101-6_43

Alahmari, A., & Duncan, B. (2020). Cybersecurity risk management in small and medium-sized enterprises: A systematic review of recent evidence. In 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) (pp. 1–5). IEEE. https://doi.org/10.1109/CyberSA49311.2020.9139638 DOI: https://doi.org/10.1109/CyberSA49311.2020.9139638

Allianz Commercial. (2025). Allianz Risk Barometer: Identifying the major business risks for 2025. Allianz Global Corporate & Specialty. https://commercial.allianz.com/

Allianz Commercial. (2026). Allianz Risk Barometer: Identifying the major business risks for 2026. https://commercial.allianz.com/contenat/dam/onemarketing/commercial/commercial/reports/allianz-risk-barometer-2026.pdf

Amir, E., Levi, S., & Livne, T. (2018). Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies, 23(3), 1177–1206. https://doi.org/10.1007/s11142-018-9452-4 DOI: https://doi.org/10.1007/s11142-018-9452-4

Anderson, R., & Moore, T. (2009). Information security: Where computer science, economics and psychology meet. Philosophical Transactions of the Royal Society A, 367(1898), 2717–2727. https://doi.org/10.1098/rsta.2009.0027 DOI: https://doi.org/10.1098/rsta.2009.0027

Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M. J., Levi, M., Moore, T., & Savage, S. (2013). Measuring the cost of cybercrime. In R. Böhme (Ed.), The economics of information security and privacy (pp. 265–300). Springer. https://doi.org/10.1007/978-3-642-39498-0_12 DOI: https://doi.org/10.1007/978-3-642-39498-0_12

Arroyabe, M. F., Arranz, C. F., De Arroyabe, I. F., & de Arroyabe, J. C. F. (2024a). Exploring the economic role of cybersecurity in SMEs: A case study of the UK. Technology in Society, 78, 102670. https://doi.org/10.1016/j.techsoc.2024.102670 DOI: https://doi.org/10.1016/j.techsoc.2024.102670

Arroyabe, M. F., Arranz, C. F. A., Fernandez de Arroyabe, I., & Fernandez de Arroyabe, J. C. (2024b). Revealing the realities of cybercrime in small and medium enterprises: Understanding fear and taxonomic perspectives. Computers & Security, 141, 103826. https://doi.org/10.1016/j.cose.2024.103826 DOI: https://doi.org/10.1016/j.cose.2024.103826

Bada, M., & Nurse, J. R. C. (2019). Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Information and Computer Security, 27(3), 393–410. https://doi.org/10.1108/ICS-07-2018-0080 DOI: https://doi.org/10.1108/ICS-07-2018-0080

Benz, M., & Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63(4), 531–540. https://doi.org/10.1016/j.bushor.2020.03.010 DOI: https://doi.org/10.1016/j.bushor.2020.03.010

Campbell, K., Gordon, L. A., Loeb, M. P., & Zhou, L. (2003). The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security, 11(3), 431–448. DOI: https://doi.org/10.3233/JCS-2003-11308

Celeny, D., Maréchal, L., Rousselot, E., Mermoud, A., & Humbert, M. (2024). Prioritizing investments in cybersecurity: Empirical evidence from an event study on the determinants of cyberattack costs. arXiv preprint arXiv:2402.04773. https://doi.org/10.48550/arXiv.2402.04773

Chidukwani, A., Zander, S., & Koutsakis, P. (2022). A survey on the cyber security of small-to-medium businesses: Challenges, research focus and recommendations. IEEE Access, 10, 85701–85719. https://doi.org/10.1109/ACCESS.2022.3197899 DOI: https://doi.org/10.1109/ACCESS.2022.3197899

Chidukwani, A., Zander, S., & Koutsakis, P. (2024). Cybersecurity preparedness of small-to-medium businesses: A Western Australia study with broader implications. Computers & Security, 145, 104026. https://doi.org/10.1016/j.cose.2024.104026 DOI: https://doi.org/10.1016/j.cose.2024.104026

Cybersecurity and Infrastructure Security Agency. (2020). Cyber resilience review (CRR): Question set with guidance. U.S. Department of Homeland Security. https://www.cisa.gov/

Darem, A. A., Alhashmi, A. A., Alkhaldi, T. M., Alashjaee, A. M., Alanazi, S. M., & Ebad, S. A. (2023). Cyber threats classifications and countermeasures in banking and financial sector. IEEE Access, 11, 125138–125158. https://doi.org/10.1109/ACCESS.2023.3327016 DOI: https://doi.org/10.1109/ACCESS.2023.3327016

de Vaus, D. (2002). Analyzing social science data: 50 key problems in data analysis. SAGE Publications.

DePietro, R., Wiarda, E., & Fleischer, M. (1990). The context of change: Organization, technology and environment. In L. G. Tornatzky & M. Fleischer (Eds.), The processes of technological innovation (pp. 151–175). Lexington Books.

Dinkova, M., El-Dardiry, R., & Overvest, B. (2024). Should firms invest more in cybersecurity? Small Business Economics, 63(1), 21–50. https://doi.org/10.1007/s11187-023-00803-0 DOI: https://doi.org/10.1007/s11187-023-00803-0

European Union Agency for Cybersecurity. (2022). NIS investments report 2022. ENISA. https://www.enisa.europa.eu/

European Union Agency for Cybersecurity. (2024). The EU cybersecurity index 2024: EU-level insights and next steps. ENISA. https://www.enisa.europa.eu/sites/default/files/2025-06/The%20EU%20Cubersecurity%20Index%202024_en_0.pdf

European Union Agency for Cybersecurity. (2025). NIS investments 2025: Main report. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-02/NIS%20Investments%202025%20-%20Main%20report.pdf

European Union Agency for Cybersecurity. (2026a). ENISA NIS360: Latest insights in the cybersecurity maturity and criticality of NIS sectors of high criticality. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-05/ENISA%20NIS360%202026.pdf

European Union Agency for Cybersecurity. (2026b). ENISA’s view on cybersecurity in the frontier AI era. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf

European Union Agency for Cybersecurity. (2026c). SME CRA survey report: Survey results and analysis. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-06/SME%20CRA%20survey%20report.pdf

Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., & Smeraldi, F. (2016). Decision support approaches for cyber security investment. Decision Support Systems, 86, 13–23. https://doi.org/10.1016/j.dss.2016.02.012 DOI: https://doi.org/10.1016/j.dss.2016.02.012

Fotis, F. (2024). Economic impact of cyber attacks and effective cyber risk management strategies: A light literature review and case study analysis. Procedia Computer Science, 251, 471–478. https://doi.org/10.1016/j.procs.2024.11.135 DOI: https://doi.org/10.1016/j.procs.2024.11.135

Franco, M. F., Künzler, F., von der Assen, J., Feng, C., & Stiller, B. (2024). RCVaR: An economic approach to estimate cyberattacks costs using data from industry reports. Computers & Security, 139, 103737. https://doi.org/10.1016/j.cose.2024.103737 DOI: https://doi.org/10.1016/j.cose.2024.103737

Franke, U., & Wernberg, J. (2020). A survey of cyber security in the Swedish manufacturing industry. In Proceedings of the International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) (pp. 1–8). IEEE. DOI: https://doi.org/10.1109/CyberSA49311.2020.9139673

Hasani, T., O’Reilly, N., Dehghantanha, A., Rezania, D., & Levallet, N. (2023). Evaluating the adoption of cybersecurity and its influence on organizational performance. SN Business & Economics, 3(5), 97. https://doi.org/10.1007/s43546-023-00477-6 DOI: https://doi.org/10.1007/s43546-023-00477-6

Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments. Information Systems Frontiers, 21(6), 1285–1305. https://doi.org/10.1007/s10796-019-09959-1 DOI: https://doi.org/10.1007/s10796-019-09959-1

Hertzog, M. A. (2008). Considerations in determining sample size for pilot studies. Research in Nursing & Health, 31(2), 180–191. https://doi.org/10.1002/nur.20247 DOI: https://doi.org/10.1002/nur.20247

International Telecommunication Union. (2024). Global cybersecurity index 2024 (5th ed.). ITU.

Johanson, G. A., & Brooks, G. P. (2010). Initial scale development: Sample size for pilot studies. Educational and Psychological Measurement, 70(3), 394–400. https://doi.org/10.1177/0013164409355692 DOI: https://doi.org/10.1177/0013164409355692

Kabanda, S., Tanner, M., & Kent, C. (2018). Exploring SME cybersecurity practices in developing countries. Journal of Organizational Computing and Electronic Commerce, 28(3), 269–282. https://doi.org/10.1080/10919392.2018.1484598 DOI: https://doi.org/10.1080/10919392.2018.1484598

Kaiser, H. F. (1974). An index of factorial simplicity. Psychometrika, 39(1), 31–36. https://doi.org/10.1007/BF02291575 DOI: https://doi.org/10.1007/BF02291575

Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019 DOI: https://doi.org/10.1016/j.jfineco.2019.05.019

Lakhtionova, A. (2025). Global cybersecurity market 2017–2029: Dynamics, structure, challenges and key players. Society. Economy. Digitalization, 1(4), 61–75. https://doi.org/10.31379/sed.1.4.2025.38 DOI: https://doi.org/10.31379/sed.1.4.2025.38

Lee, I. (2021). Cybersecurity: Risk management framework and investment cost analysis. Business Horizons, 64(5), 659–671. https://doi.org/10.1016/j.bushor.2021.02.022 DOI: https://doi.org/10.1016/j.bushor.2021.02.022

Liu, C., & Babar, M. A. (2026). Corporate cybersecurity risk and data breaches: A systematic review of empirical research. Australian Journal of Management, 51(1), 62–92. https://doi.org/10.1177/03128962241293658 DOI: https://doi.org/10.1177/03128962241293658

Lloyd, G. (2020). The business benefits of cyber security for SMEs. Computer Fraud & Security, 2020(2), 14–17. https://doi.org/10.1016/S1361-3723(20)30019-1 DOI: https://doi.org/10.1016/S1361-3723(20)30019-1

Mayeke, N. R. (2025). Evaluating the cost-benefit dynamics of cybersecurity compliance investments: A multi-sectoral analysis across financial, educational, and ecommerce industries. Computer Science & IT Research Journal, 6(4), 266–287. https://doi.org/10.51594/csitrj.v6i4.1914 DOI: https://doi.org/10.51594/csitrj.v6i4.1914

Ministry of Investments, Regional Development and Informatization of the Slovak Republic. (2025). Methodological guideline No. 18 on the verification of enterprise size (SME). MIRRI SR. (In Slovak)

NSA—National Security Authority of the Slovak Republic. (2023a). Report on cybersecurity in the Slovak Republic in 2023. NBÚ SR. https://www.nbu.gov.sk/sprava-o-kybernetickej-bezpecnosti-v-slovenskej-republike-v-roku-2023/

NSA—National Security Authority of the Slovak Republic. (2023b). Cybersecurity 2023: Results of a telephone survey of small and medium-sized enterprises. NBÚ SR. https://cybercompetence.sk/wp-content/uploads/dokumenty/na_stiahnutie/letak_KB-prieskum_verejnej_mienky_msp_2023.pdf

Osborn, E., & Simpson, A. (2018). Risk and the small-scale cyber security decision making dialogue: A UK case study. The Computer Journal, 61(4), 472–495. https://doi.org/10.1093/comjnl/bxx093 DOI: https://doi.org/10.1093/comjnl/bxx093

Pacelli, V. (2025). Systemic risk and complex networks in modern financial systems. Springer Nature. https://doi.org/10.1007/978-3-031-64916-5 DOI: https://doi.org/10.1007/978-3-031-64916-5

Papathanasiou, A., Liontos, G., Katsouras, A., Liagkou, V., & Glavas, E. (2024). Cybersecurity guide for SMEs: Protecting small and medium-sized enterprises in the digital era. Journal of Information Security, 16(1), 1–43. https://doi.org/10.4236/jis.2025.161001 DOI: https://doi.org/10.4236/jis.2025.161001

Paulsen, C. (2016). Cybersecuring small businesses. Computer, 49(8), 92–97. https://doi.org/10.1109/MC.2016.223 DOI: https://doi.org/10.1109/MC.2016.223

Porkoláb-Angyalos, Z., & Szilágyi, R. (2026). Cyber maturity among European SMEs: A time-series and cluster-based analysis. Applied Studies in Agribusiness and Commerce, 20(1). https://doi.org/10.19041/APSTRACT/2026/1/6 DOI: https://doi.org/10.19041/APSTRACT/2026/1/6

Renaud, K., & Ophoff, J. (2021). A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs. Organizational Cybersecurity Journal, 1(1), 24–46. https://doi.org/10.1108/OCJ-03-2021-0004 DOI: https://doi.org/10.1108/OCJ-03-2021-0004

Renaud, K., & Weir, G. R. S. (2016). Cybersecurity and the unbearability of uncertainty. In Proceedings of the Cybersecurity and Cyberforensics Conference (CCC) (pp. 137–143). IEEE. https://doi.org/10.1109/CCC.2016.29 DOI: https://doi.org/10.1109/CCC.2016.29

Riek, M., & Böhme, R. (2018). The costs of consumer-facing cybercrime: An empirical exploration of measurement issues and estimates. Journal of Cybersecurity, 4(1), tyy004. https://doi.org/10.1093/cybsec/tyy004 DOI: https://doi.org/10.1093/cybsec/tyy004

Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135. https://doi.org/10.1093/cybsec/tyw001 DOI: https://doi.org/10.1093/cybsec/tyw001

Sawik, T. (2022). Balancing cybersecurity in a supply chain under direct and indirect cyber risks. International Journal of Production Research, 60(2), 766–782. https://doi.org/10.1080/00207543.2021.1914356 DOI: https://doi.org/10.1080/00207543.2021.1914356

SBA—Slovak Business Agency. (2026). Vznik a zánik malých a stredných podnikov na Slovensku v roku 2025. Analýza. https://www.npc.sk/media/Vznik%20a%20z%C3%A1nik%20mal%C3%BDch%20a%20stredn%C3%BDch%20podnikov%20na%20Slovensku%20v%20roku%202025_FINAL.pdf

Semenova, S., Shpyrko, O., Androsenko, O., Afanasieva, I., Kolumbet, O., & Vorchakova, I. (2024). The essence of Goodwill in disclosing the intangible value of business in the context of digital transformation. Financial and Credit Activity: Problems of Theory and Practice, 4(57), 98–113. https://doi.org/10.55643/fcaptp.4.57.2024.4449 DOI: https://doi.org/10.55643/fcaptp.4.57.2024.4449

Tahmasebi, M. (2024). Cyberattack ramifications, the hidden cost of a security breach. Journal of Information Security, 15(2), 87–105. https://doi.org/10.4236/jis.2024.152007 DOI: https://doi.org/10.4236/jis.2024.152007

Tam, T., Rao, A., & Hall, J. (2021). The good, the bad and the missing: A narrative review of cyber-security implications for Australian small businesses. Computers & Security, 109, 102385. https://doi.org/10.1016/j.cose.2021.102385 DOI: https://doi.org/10.1016/j.cose.2021.102385

Valli, C., Martinus, I., & Johnstone, M. (2014). Small to medium enterprise cyber security awareness: An initial survey of Western Australian business. In Proceedings of the International Conference on Security and Management (SAM) (pp. 1–5). CSREA Press.

Vidović, N., & Beriša, H. (2025). Economic aspects of cyber security: Socio-financial consequences of cyber attacks. International Journal of Contemporary Security Studies, 1(2), 105–118. https://doi.org/10.18485/fb_ijcss.2025.1.1.11 DOI: https://doi.org/10.18485/fb_ijcss.2025.1.2.7

Warrens, M. J. (2015). On Cronbach’s alpha as the mean of all split-half reliabilities. In R. E. Millsap, D. M. Bolt, L. A. van der Ark, & W.-C. Wang (Eds.), Quantitative psychology research (pp. 293–300). Springer. https://doi.org/10.1007/978-3-319-07503-7_18 DOI: https://doi.org/10.1007/978-3-319-07503-7_18

Wells, L. J., Camelio, J. A., Williams, C. B., & White, J. (2014). Cyber-physical security challenges in manufacturing systems. Manufacturing Letters, 2(2), 74–77. https://doi.org/10.1016/j.mfglet.2014.01.005 DOI: https://doi.org/10.1016/j.mfglet.2014.01.005

Wirth, A. (2017). The economics of cybersecurity. Biomedical Instrumentation & Technology, 51(s6), 52–59. https://doi.org/10.2345/0899-8205-51.s6.52 DOI: https://doi.org/10.2345/0899-8205-51.s6.52

World Economic Forum. (2022). Global cybersecurity outlook 2022. https://www.weforum.org/publications/global-cybersecurity-outlook-2022/

World Economic Forum. (2026). The global risks report 2026. https://reports.weforum.org/docs/WEF_Global_Risks_Report_2026.pdf

Yarovenko, H., Bilovodska, V., Bylbas, R., Pankiv, O., Baghirzade, M., Niemi, O., & Djakons, D. (2025). Digital readiness of European countries to combat corruption and cyber threats: Panel analysis. Business Ethics and Leadership, 9(2), 238–265. https://doi.org/10.61093/bel.9(2).238-265.2025 DOI: https://doi.org/10.61093/bel.9(2).238-265.2025

Zimmermann, V., & Renaud, K. (2019). Moving from a “human-as-problem” to a “human-as-solution” cybersecurity mindset. International Journal of Human-Computer Studies, 131, 169–187. https://doi.org/10.1016/j.ijhcs.2019.05.005 DOI: https://doi.org/10.1016/j.ijhcs.2019.05.005