ПЕРЕКОНАНІ, АЛЕ НЕ ГОТОВІ: ПІЛОТНЕ ВИМІРЮВАННЯ ГОТОВНОСТІ ДО КІБЕРБЕЗПЕКИ СЛОВАЦЬКИХ МАЛИХ І СЕРЕДНІХ ПІДПРИЄМСТВ
Main Article Content
Анотація
Малі та середні підприємства (МСП) дедалі частіше стають мішенню кібератак. Однак їхню готовність у Словаччині рідко вимірюють. Це дослідження розробляє та пілотує інструмент для оцінки готовності до кібербезпеки малих і середніх підприємств. Анкета складається з шести частин. Чотири з них містять шкалу ставлення й формують вимірювані виміри готовності: технологічну готовність і сумісність, готовність процесів і управління реагуванням, сприйняту користь кібербезпеки для працівників, а також стратегічну та розвиткову орієнтацію. Пілотне обстеження провели 25 словацьких малих і середніх підприємств. Ми перевіряли дані за допомогою альфа-моделі Кронбаха, коригували кореляції між елементами й загальним аналізом та аналізом головних компонентів за допомогою обертання Varimax, разом із мірою Кайзера-Мейєра-Олкіна та тестом сферичності Бартлетта. Усі чотири виміри мають прийнятну внутрішню послідовність (альфа 0,673 до 0,886), і три перевищують поріг 0,7. Технологічний вимір є одновимірним і пояснює 60,27 % дисперсії відгуків. Один проблемний пункт був виявлений у вимірі працівника; його видалення підвищує альфу з 0,673 до 0,779. Обертована матриця компонентів свідчить, що стратегічно-фінансовий вимір поділяється на дві підшкали: економічну обізнаність і орієнтацію на стратегічні інновації. Описові результати виявляють послідовний розрив між упровадженням і перевіркою. Базові технічні методи контролю дуже поширені, водночас заходи, що підтверджують їхню ефективність, відстають. Регулярні резервні копії виконують 19 із 25 компаній, але лише 11 перевіряють, чи можна відновити дані. Дослідження пропонує оновлену модель вимірювання, готову до збирання даних на великій репрезентативній вибірці. Отож, вона забезпечує методологічну основу для систематичного збирання даних про готовність до кібербезпеки словацьких малих і середніх підприємств.
Article Details
Посилання
Accenture. (2019). At a glance: Ninth annual cost of cybercrime study. https://www.accenture.com/content/dam/accenture/final/a-com-migration/pdf/pdf-99/accenture-cost-cyber-crime-infographic.pdf
Al Aamer, A. K., & Hamdan, A. (2023). Cyber security awareness and SMEs’ profitability and continuity: Literature review. Emerging Trends and Innovation in Business and Finance, 593–604. Springer. https://doi.org/10.1007/978-981-99-6101-6_43 DOI: https://doi.org/10.1007/978-981-99-6101-6_43
Alahmari, A., & Duncan, B. (2020). Cybersecurity risk management in small and medium-sized enterprises: A systematic review of recent evidence. In 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) (pp. 1–5). IEEE. https://doi.org/10.1109/CyberSA49311.2020.9139638 DOI: https://doi.org/10.1109/CyberSA49311.2020.9139638
Allianz Commercial. (2025). Allianz Risk Barometer: Identifying the major business risks for 2025. Allianz Global Corporate & Specialty. https://commercial.allianz.com/
Allianz Commercial. (2026). Allianz Risk Barometer: Identifying the major business risks for 2026. https://commercial.allianz.com/contenat/dam/onemarketing/commercial/commercial/reports/allianz-risk-barometer-2026.pdf
Amir, E., Levi, S., & Livne, T. (2018). Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies, 23(3), 1177–1206. https://doi.org/10.1007/s11142-018-9452-4 DOI: https://doi.org/10.1007/s11142-018-9452-4
Anderson, R., & Moore, T. (2009). Information security: Where computer science, economics and psychology meet. Philosophical Transactions of the Royal Society A, 367(1898), 2717–2727. https://doi.org/10.1098/rsta.2009.0027 DOI: https://doi.org/10.1098/rsta.2009.0027
Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M. J., Levi, M., Moore, T., & Savage, S. (2013). Measuring the cost of cybercrime. In R. Böhme (Ed.), The economics of information security and privacy (pp. 265–300). Springer. https://doi.org/10.1007/978-3-642-39498-0_12 DOI: https://doi.org/10.1007/978-3-642-39498-0_12
Arroyabe, M. F., Arranz, C. F., De Arroyabe, I. F., & de Arroyabe, J. C. F. (2024a). Exploring the economic role of cybersecurity in SMEs: A case study of the UK. Technology in Society, 78, 102670. https://doi.org/10.1016/j.techsoc.2024.102670 DOI: https://doi.org/10.1016/j.techsoc.2024.102670
Arroyabe, M. F., Arranz, C. F. A., Fernandez de Arroyabe, I., & Fernandez de Arroyabe, J. C. (2024b). Revealing the realities of cybercrime in small and medium enterprises: Understanding fear and taxonomic perspectives. Computers & Security, 141, 103826. https://doi.org/10.1016/j.cose.2024.103826 DOI: https://doi.org/10.1016/j.cose.2024.103826
Bada, M., & Nurse, J. R. C. (2019). Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Information and Computer Security, 27(3), 393–410. https://doi.org/10.1108/ICS-07-2018-0080 DOI: https://doi.org/10.1108/ICS-07-2018-0080
Benz, M., & Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63(4), 531–540. https://doi.org/10.1016/j.bushor.2020.03.010 DOI: https://doi.org/10.1016/j.bushor.2020.03.010
Campbell, K., Gordon, L. A., Loeb, M. P., & Zhou, L. (2003). The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security, 11(3), 431–448. DOI: https://doi.org/10.3233/JCS-2003-11308
Celeny, D., Maréchal, L., Rousselot, E., Mermoud, A., & Humbert, M. (2024). Prioritizing investments in cybersecurity: Empirical evidence from an event study on the determinants of cyberattack costs. arXiv preprint arXiv:2402.04773. https://doi.org/10.48550/arXiv.2402.04773
Chidukwani, A., Zander, S., & Koutsakis, P. (2022). A survey on the cyber security of small-to-medium businesses: Challenges, research focus and recommendations. IEEE Access, 10, 85701–85719. https://doi.org/10.1109/ACCESS.2022.3197899 DOI: https://doi.org/10.1109/ACCESS.2022.3197899
Chidukwani, A., Zander, S., & Koutsakis, P. (2024). Cybersecurity preparedness of small-to-medium businesses: A Western Australia study with broader implications. Computers & Security, 145, 104026. https://doi.org/10.1016/j.cose.2024.104026 DOI: https://doi.org/10.1016/j.cose.2024.104026
Cybersecurity and Infrastructure Security Agency. (2020). Cyber resilience review (CRR): Question set with guidance. U.S. Department of Homeland Security. https://www.cisa.gov/
Darem, A. A., Alhashmi, A. A., Alkhaldi, T. M., Alashjaee, A. M., Alanazi, S. M., & Ebad, S. A. (2023). Cyber threats classifications and countermeasures in banking and financial sector. IEEE Access, 11, 125138–125158. https://doi.org/10.1109/ACCESS.2023.3327016 DOI: https://doi.org/10.1109/ACCESS.2023.3327016
de Vaus, D. (2002). Analyzing social science data: 50 key problems in data analysis. SAGE Publications.
DePietro, R., Wiarda, E., & Fleischer, M. (1990). The context of change: Organization, technology and environment. In L. G. Tornatzky & M. Fleischer (Eds.), The processes of technological innovation (pp. 151–175). Lexington Books.
Dinkova, M., El-Dardiry, R., & Overvest, B. (2024). Should firms invest more in cybersecurity? Small Business Economics, 63(1), 21–50. https://doi.org/10.1007/s11187-023-00803-0 DOI: https://doi.org/10.1007/s11187-023-00803-0
European Union Agency for Cybersecurity. (2022). NIS investments report 2022. ENISA. https://www.enisa.europa.eu/
European Union Agency for Cybersecurity. (2024). The EU cybersecurity index 2024: EU-level insights and next steps. ENISA. https://www.enisa.europa.eu/sites/default/files/2025-06/The%20EU%20Cubersecurity%20Index%202024_en_0.pdf
European Union Agency for Cybersecurity. (2025). NIS investments 2025: Main report. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-02/NIS%20Investments%202025%20-%20Main%20report.pdf
European Union Agency for Cybersecurity. (2026a). ENISA NIS360: Latest insights in the cybersecurity maturity and criticality of NIS sectors of high criticality. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-05/ENISA%20NIS360%202026.pdf
European Union Agency for Cybersecurity. (2026b). ENISA’s view on cybersecurity in the frontier AI era. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf
European Union Agency for Cybersecurity. (2026c). SME CRA survey report: Survey results and analysis. ENISA. https://www.enisa.europa.eu/sites/default/files/2026-06/SME%20CRA%20survey%20report.pdf
Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., & Smeraldi, F. (2016). Decision support approaches for cyber security investment. Decision Support Systems, 86, 13–23. https://doi.org/10.1016/j.dss.2016.02.012 DOI: https://doi.org/10.1016/j.dss.2016.02.012
Fotis, F. (2024). Economic impact of cyber attacks and effective cyber risk management strategies: A light literature review and case study analysis. Procedia Computer Science, 251, 471–478. https://doi.org/10.1016/j.procs.2024.11.135 DOI: https://doi.org/10.1016/j.procs.2024.11.135
Franco, M. F., Künzler, F., von der Assen, J., Feng, C., & Stiller, B. (2024). RCVaR: An economic approach to estimate cyberattacks costs using data from industry reports. Computers & Security, 139, 103737. https://doi.org/10.1016/j.cose.2024.103737 DOI: https://doi.org/10.1016/j.cose.2024.103737
Franke, U., & Wernberg, J. (2020). A survey of cyber security in the Swedish manufacturing industry. In Proceedings of the International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) (pp. 1–8). IEEE. DOI: https://doi.org/10.1109/CyberSA49311.2020.9139673
Hasani, T., O’Reilly, N., Dehghantanha, A., Rezania, D., & Levallet, N. (2023). Evaluating the adoption of cybersecurity and its influence on organizational performance. SN Business & Economics, 3(5), 97. https://doi.org/10.1007/s43546-023-00477-6 DOI: https://doi.org/10.1007/s43546-023-00477-6
Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments. Information Systems Frontiers, 21(6), 1285–1305. https://doi.org/10.1007/s10796-019-09959-1 DOI: https://doi.org/10.1007/s10796-019-09959-1
Hertzog, M. A. (2008). Considerations in determining sample size for pilot studies. Research in Nursing & Health, 31(2), 180–191. https://doi.org/10.1002/nur.20247 DOI: https://doi.org/10.1002/nur.20247
International Telecommunication Union. (2024). Global cybersecurity index 2024 (5th ed.). ITU.
Johanson, G. A., & Brooks, G. P. (2010). Initial scale development: Sample size for pilot studies. Educational and Psychological Measurement, 70(3), 394–400. https://doi.org/10.1177/0013164409355692 DOI: https://doi.org/10.1177/0013164409355692
Kabanda, S., Tanner, M., & Kent, C. (2018). Exploring SME cybersecurity practices in developing countries. Journal of Organizational Computing and Electronic Commerce, 28(3), 269–282. https://doi.org/10.1080/10919392.2018.1484598 DOI: https://doi.org/10.1080/10919392.2018.1484598
Kaiser, H. F. (1974). An index of factorial simplicity. Psychometrika, 39(1), 31–36. https://doi.org/10.1007/BF02291575 DOI: https://doi.org/10.1007/BF02291575
Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019 DOI: https://doi.org/10.1016/j.jfineco.2019.05.019
Lakhtionova, A. (2025). Global cybersecurity market 2017–2029: Dynamics, structure, challenges and key players. Society. Economy. Digitalization, 1(4), 61–75. https://doi.org/10.31379/sed.1.4.2025.38 DOI: https://doi.org/10.31379/sed.1.4.2025.38
Lee, I. (2021). Cybersecurity: Risk management framework and investment cost analysis. Business Horizons, 64(5), 659–671. https://doi.org/10.1016/j.bushor.2021.02.022 DOI: https://doi.org/10.1016/j.bushor.2021.02.022
Liu, C., & Babar, M. A. (2026). Corporate cybersecurity risk and data breaches: A systematic review of empirical research. Australian Journal of Management, 51(1), 62–92. https://doi.org/10.1177/03128962241293658 DOI: https://doi.org/10.1177/03128962241293658
Lloyd, G. (2020). The business benefits of cyber security for SMEs. Computer Fraud & Security, 2020(2), 14–17. https://doi.org/10.1016/S1361-3723(20)30019-1 DOI: https://doi.org/10.1016/S1361-3723(20)30019-1
Mayeke, N. R. (2025). Evaluating the cost-benefit dynamics of cybersecurity compliance investments: A multi-sectoral analysis across financial, educational, and ecommerce industries. Computer Science & IT Research Journal, 6(4), 266–287. https://doi.org/10.51594/csitrj.v6i4.1914 DOI: https://doi.org/10.51594/csitrj.v6i4.1914
Ministry of Investments, Regional Development and Informatization of the Slovak Republic. (2025). Methodological guideline No. 18 on the verification of enterprise size (SME). MIRRI SR. (In Slovak)
NSA—National Security Authority of the Slovak Republic. (2023a). Report on cybersecurity in the Slovak Republic in 2023. NBÚ SR. https://www.nbu.gov.sk/sprava-o-kybernetickej-bezpecnosti-v-slovenskej-republike-v-roku-2023/
NSA—National Security Authority of the Slovak Republic. (2023b). Cybersecurity 2023: Results of a telephone survey of small and medium-sized enterprises. NBÚ SR. https://cybercompetence.sk/wp-content/uploads/dokumenty/na_stiahnutie/letak_KB-prieskum_verejnej_mienky_msp_2023.pdf
Osborn, E., & Simpson, A. (2018). Risk and the small-scale cyber security decision making dialogue: A UK case study. The Computer Journal, 61(4), 472–495. https://doi.org/10.1093/comjnl/bxx093 DOI: https://doi.org/10.1093/comjnl/bxx093
Pacelli, V. (2025). Systemic risk and complex networks in modern financial systems. Springer Nature. https://doi.org/10.1007/978-3-031-64916-5 DOI: https://doi.org/10.1007/978-3-031-64916-5
Papathanasiou, A., Liontos, G., Katsouras, A., Liagkou, V., & Glavas, E. (2024). Cybersecurity guide for SMEs: Protecting small and medium-sized enterprises in the digital era. Journal of Information Security, 16(1), 1–43. https://doi.org/10.4236/jis.2025.161001 DOI: https://doi.org/10.4236/jis.2025.161001
Paulsen, C. (2016). Cybersecuring small businesses. Computer, 49(8), 92–97. https://doi.org/10.1109/MC.2016.223 DOI: https://doi.org/10.1109/MC.2016.223
Porkoláb-Angyalos, Z., & Szilágyi, R. (2026). Cyber maturity among European SMEs: A time-series and cluster-based analysis. Applied Studies in Agribusiness and Commerce, 20(1). https://doi.org/10.19041/APSTRACT/2026/1/6 DOI: https://doi.org/10.19041/APSTRACT/2026/1/6
Renaud, K., & Ophoff, J. (2021). A cyber situational awareness model to predict the implementation of cyber security controls and precautions by SMEs. Organizational Cybersecurity Journal, 1(1), 24–46. https://doi.org/10.1108/OCJ-03-2021-0004 DOI: https://doi.org/10.1108/OCJ-03-2021-0004
Renaud, K., & Weir, G. R. S. (2016). Cybersecurity and the unbearability of uncertainty. In Proceedings of the Cybersecurity and Cyberforensics Conference (CCC) (pp. 137–143). IEEE. https://doi.org/10.1109/CCC.2016.29 DOI: https://doi.org/10.1109/CCC.2016.29
Riek, M., & Böhme, R. (2018). The costs of consumer-facing cybercrime: An empirical exploration of measurement issues and estimates. Journal of Cybersecurity, 4(1), tyy004. https://doi.org/10.1093/cybsec/tyy004 DOI: https://doi.org/10.1093/cybsec/tyy004
Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135. https://doi.org/10.1093/cybsec/tyw001 DOI: https://doi.org/10.1093/cybsec/tyw001
Sawik, T. (2022). Balancing cybersecurity in a supply chain under direct and indirect cyber risks. International Journal of Production Research, 60(2), 766–782. https://doi.org/10.1080/00207543.2021.1914356 DOI: https://doi.org/10.1080/00207543.2021.1914356
SBA—Slovak Business Agency. (2026). Vznik a zánik malých a stredných podnikov na Slovensku v roku 2025. Analýza. https://www.npc.sk/media/Vznik%20a%20z%C3%A1nik%20mal%C3%BDch%20a%20stredn%C3%BDch%20podnikov%20na%20Slovensku%20v%20roku%202025_FINAL.pdf
Semenova, S., Shpyrko, O., Androsenko, O., Afanasieva, I., Kolumbet, O., & Vorchakova, I. (2024). The essence of Goodwill in disclosing the intangible value of business in the context of digital transformation. Financial and Credit Activity: Problems of Theory and Practice, 4(57), 98–113. https://doi.org/10.55643/fcaptp.4.57.2024.4449 DOI: https://doi.org/10.55643/fcaptp.4.57.2024.4449
Tahmasebi, M. (2024). Cyberattack ramifications, the hidden cost of a security breach. Journal of Information Security, 15(2), 87–105. https://doi.org/10.4236/jis.2024.152007 DOI: https://doi.org/10.4236/jis.2024.152007
Tam, T., Rao, A., & Hall, J. (2021). The good, the bad and the missing: A narrative review of cyber-security implications for Australian small businesses. Computers & Security, 109, 102385. https://doi.org/10.1016/j.cose.2021.102385 DOI: https://doi.org/10.1016/j.cose.2021.102385
Valli, C., Martinus, I., & Johnstone, M. (2014). Small to medium enterprise cyber security awareness: An initial survey of Western Australian business. In Proceedings of the International Conference on Security and Management (SAM) (pp. 1–5). CSREA Press.
Vidović, N., & Beriša, H. (2025). Economic aspects of cyber security: Socio-financial consequences of cyber attacks. International Journal of Contemporary Security Studies, 1(2), 105–118. https://doi.org/10.18485/fb_ijcss.2025.1.1.11 DOI: https://doi.org/10.18485/fb_ijcss.2025.1.2.7
Warrens, M. J. (2015). On Cronbach’s alpha as the mean of all split-half reliabilities. In R. E. Millsap, D. M. Bolt, L. A. van der Ark, & W.-C. Wang (Eds.), Quantitative psychology research (pp. 293–300). Springer. https://doi.org/10.1007/978-3-319-07503-7_18 DOI: https://doi.org/10.1007/978-3-319-07503-7_18
Wells, L. J., Camelio, J. A., Williams, C. B., & White, J. (2014). Cyber-physical security challenges in manufacturing systems. Manufacturing Letters, 2(2), 74–77. https://doi.org/10.1016/j.mfglet.2014.01.005 DOI: https://doi.org/10.1016/j.mfglet.2014.01.005
Wirth, A. (2017). The economics of cybersecurity. Biomedical Instrumentation & Technology, 51(s6), 52–59. https://doi.org/10.2345/0899-8205-51.s6.52 DOI: https://doi.org/10.2345/0899-8205-51.s6.52
World Economic Forum. (2022). Global cybersecurity outlook 2022. https://www.weforum.org/publications/global-cybersecurity-outlook-2022/
World Economic Forum. (2026). The global risks report 2026. https://reports.weforum.org/docs/WEF_Global_Risks_Report_2026.pdf
Yarovenko, H., Bilovodska, V., Bylbas, R., Pankiv, O., Baghirzade, M., Niemi, O., & Djakons, D. (2025). Digital readiness of European countries to combat corruption and cyber threats: Panel analysis. Business Ethics and Leadership, 9(2), 238–265. https://doi.org/10.61093/bel.9(2).238-265.2025 DOI: https://doi.org/10.61093/bel.9(2).238-265.2025
Zimmermann, V., & Renaud, K. (2019). Moving from a “human-as-problem” to a “human-as-solution” cybersecurity mindset. International Journal of Human-Computer Studies, 131, 169–187. https://doi.org/10.1016/j.ijhcs.2019.05.005 DOI: https://doi.org/10.1016/j.ijhcs.2019.05.005