Purpose

Historically, discussion of organizational resilience (OR) was dedicated to a generic event. However, nowadays a new research domain oriented to the cyber side of OR (i.e. cyber-OR) has developed. Inspired by the principles of Resilience Engineering and adaptive capacity theories, this research aims to assess cyber-OR tools and practices in the context of Italian small and medium-sized enterprises (SMEs) alongside the hindering factors they encounter while implementing cyber-OR practices. The SME context is particularly suitable for this investigation due to the excessive cyberattacks they face and the crucial economic role they play in many Western countries, including Italy.

Design/methodology/approach

The qualitative research design used semistructured interviews and data collected from 31 Italian SMEs. Data analysis followed thematic analysis principles using the NVivo 12 software package.

Findings

Results show a low level of cyber-OR across the SMEs the authors assessed, especially in the post-event phase. Moreover, SMEs are affected by several factors that hinder cybersecurity (i.e. lack of awareness, lack of resources and budget, and small organization size).

Practical implications

The authors offer a new perspective for practitioners and institutions to develop frameworks and strategies targeted for SMEs to overcome the effects posed by the hindering factors that are still unclear in the cyber-OR domain.

Originality/value

This research advances knowledge in the context of cyber-OR and SMEs, an area which needs further investigation.

Resilience is widely accepted as a critical pillar in supporting contemporary organizations navigating evolving and complex environmental challenges such as climate change, digital transformation, and hyper-competition (Bouaziz and Hachicha, 2018). Organizational resilience (OR) empowers organizations to proactively plan for and anticipate an event, effectively respond to it and resist it, as well as to recover while embedding continuous learning (Hillmann, 2021).

The concept of OR has taken on diverse ontological perspectives and operational settings (Hillmann, 2021; Sawalha, 2015), which makes it highly interdisciplinary (Frigotto et al., 2022). In conceptualizing OR, developers have typically linked it to a generic triggering event, e.g. disruptive surprises (Ortiz-de-Mandojana and Bansal, 2016; Neri et al., 2023a), which has led to a debate on the question of “resilience to what?” (Hepfer and Lawrence, 2022; Pinheiro et al., 2022). A growing body of literature is focused on OR and cyberattacks (Dalal et al., 2022; Tejay and Klein, 2021). While organizations currently find cybersecurity a major challenge, cybercrime shows no signs of decreasing (ENISA, 2022). Accordingly, year upon year, the global cybersecurity market is increasing so that it is predicted to reach $13.82tn by 2028 (Petrosyan, 2023).

Following these issues, this study focuses on a specific event, namely, a cyberattack and the related incident [i.e. the successful compromise of “confidentiality, integrity, and/or availability of the data and/or systems/network” as per Gafni and Levy (2023, p. 603)].

This research has been conducted in the context of Italian small and medium enterprises (SMEs). Globally, data breaches and cyber incidents impact every kind of organization, particularly the very small ones (Verizon, 2023). The Italian entrepreneurial system, which for 95.2% consists of SMEs (Italian National Statistical Institute, 2022a, 2022b) is no exception, ranking third worldwide in the number of cyberattacks delivered via malware (Trend Micro, 2023).

In addition, research has indicated that a fruitful avenue of investigation would be in the area of OR in SMEs (Pal et al., 2014; Saad et al., 2021; Sullivan-Taylor and Branicki, 2011). To date only a limited number of studies have investigated how SMEs respond to and plan for disruptive and extreme events (Herbane, 2010; Saad et al., 2021), especially regarding cyberattacks (Wilson et al., 2022).

However, more so than large companies, SMEs face significant cybersecurity and resilience challenges (Gafni and Levy, 2023; Neri et al., 2023b; Bada and Nurse, 2019). Thus, the research presented here is aimed at:

  • exploring how SMEs implement cyber-OR tools and practices; and

  • investigating the hindering factors SMEs encounter in implementing cyber-OR tools and practices.

This paper is structured as follows. First, section two present a literature overview. Then, section three is devoted toresearch method, data analysis and sample description. Then, section four gives the results and discusses the findings, while section five provides implications and contributions.

A large volume of literature on resilience has been done across many research areas, such as ecology (Folke et al., 2010; Holling, 1973), engineering (Hollnagel et al., 2006) and psychology (Youssef and Luthans, 2007). Over time, several concepts of resilience have been developed in the organizational research domain, relating to diversified settings and ontological meanings (Granig and Hilgarter, 2020; Hillmann, 2021; Sawalha, 2015). Where resilience concerning organizations features, we observed a high level of fragmentation (Khan et al., 2019).

First, we have not yet reached agreement on the various conceptualizations of OR (Agostini and Nosella, 2022), a major issue being the question regarding “resilience to what?” (Pinheiro et al., 2022). This is especially relevant because OR is mainly associated with generic disruptive events (Hepfer and Lawrence, 2022). However, there is a research gap concerning how, in adopting a reactive approach, organizations develop resilience toward cyber incidents (Appiah et al., 2022). The debate about what kind of resilience is in question has opened a new research area that investigates OR to cyberattacks (cyber-OR) (Dalal et al., 2022; Tejay and Klein, 2021), which extends the general notion of security to that of cybersecurity (Tsen et al., 2022). However, conceptualizing cyber-OR is also fragmented (Bagheri et al., 2023).

Regarding the fragmentation issue, our literature overview was inspired by the principles of resilience engineering (RE), which incorporate the idea of a feedback process and are also used as a basis for cyber-resilient frameworks (see Bodeau et al., 2011).

According to Hollnagel et al. (2006), “resilience engineering’s goal is to enhance the ability of a complex sociotechnical system to adapt or absorb disturbances, disruption, and change” (p. 24). Further, Ayyub (2014, p. 4) finds that:

Resilience notionally means the ability to prepare for and adapt to changing conditions and withstand and recover rapidly from disruptions. Resilience includes the ability to withstand and recover from disturbances of the deliberate attack types, accidents, or naturally occurring threats or incidents. The resilience of a system's function can be measured based on the persistence of a similar functional performance under uncertainty on the face of disturbances.

Following Hollnagel (2014), four abilities operationalize these conceptualizations of RE by:

  1. Responding: knowing what to do with a planned set of activities or by adjusting the functional performance (i.e. addressing the actual).

  2. Monitoring: knowing what to look for, covering both the external environment and the system performance (i.e. addressing the critical).

  3. Learning from experience: knowing what exactly happened, thus learning the right lessons from the experiences (addressing the factual).

  4. Anticipating: knowing what to expect, which means anticipating threats and opportunities (i.e. addressing the potential).

In sum, Hollnagel’s (2014) perspective emphasizes that RE is built on a proactive rather than a reactive approach. Indeed, anticipation is necessary for long-term strategies that develop new responses, also via learning activities and sustained monitoring.

The abovementioned concepts could also be applied in the cybersecurity research domain. The idea of temporality (i.e. of timing before, during and after a cyberattack) and related abilities is widely recognized in academic work on cyber-OR (Linkov et al., 2013; Schinagl and Shahim, 2020). Most cyber-OR conceptualizations depict it as a feedback process, of which there are extensive conceptualizations, usually including notions of preparing, responding, adapting and recovering (Ahmad et al., 2015; Armour, 2015; Bodeau et al., 2011; Hausken, 2020; Linkov et al., 2013). Björck et al. (2015, p. 2) focused on “the ability to continuously deliver the intended outcome despite adverse cyber events.” Osborn and Sepulveda-Estay (2021, p. 1) discussed how organizations should focus on practices before, during and after the event which led to “an ongoing, cyclical and cumulative process to prepare organizations to react timely.”

According to van der Kleij and Leukfeldt (2019, p. 20), the four Hollnagel domains of RE “have high face validity in the domain of cybersecurity,” thus they conclude that frameworks similar to the one National Institute of Standards and Technology (NIST) proposed should be enriched by the RE approach to offer a broader view in managing cybersecurity risks and enhancing OR.

Indeed, the idea of temporality is also incorporated in the cyber RE framework which “draws the goals of anticipate, withstand, recover from and evolve from resilience engineering” (Bodeau et al., 2011, p. 13). The framework encompasses all the phases Hollnagel depicted, yet with different labels, excepting for anticipation. Indeed, evolution corresponds to learning, withstanding and recovering align with the ideas of responding, and monitoring is conceived as incorporated in all the aspects we mentioned.

A key concept included in the RE is that of adaptability, as presented by Woods’ (2015) theory of graceful extensibility and sustained adaptability. Cook and Long (2021, p. 2) summarized graceful extensibility as bringing “extra adaptive capacity to bear, when surprise events challenge its boundaries” while sustained adaptability refers to capability “to adapt to future surprises as conditions continue to evolve.”

The adaptive capacity theory has been applied in many disciplines, including in the OR field. Indeed, according to Hillmann (2021), OR based on the principles of RE also entails adaptability and thus adaptation. According to Bhamra et al. (2011, p. 5387), OR is a function of adaptive capacity that enables organizations not “to experience environments passively, instead the organisation will continuously develop and apply new knowledge in relation to the operating environment.” According to McManus et al. (2008, p. 83) adaptive capacity to sustain OR “is defined as the ability of an enterprise to alter its ‘strategy, operations, management systems, governance structure, and decision-support capabilities’ to withstand perturbations and disruptions.”

The adaptive capacity theory has also been applied in the cyber-OR domain. For example, Dupont (2019, p. 3) conceives resilience as an enduring adaptive capacity, pointing out that:

Resilient organizations not only display adaptive capacities during a crisis but, once basic operations have been restored, are able to learn from their experience and identify improvements in their systems and procedures that will enhance their level of preparedness against future hazards.

Grøtan et al. (2022) were inspired by Woods (2015) and Hollnagel’s (2014) theories of RE and adaptive capacity, envisaging one viable path to theorizing cyber resilience as being “poised to adapt” (p. 222). This is especially true for SMEs considering that “adaptation of SMEs is important to their survival, since their limited resources make them particularly susceptible to threats” (Quansah et al., 2022).

A great deal of prior research has defined the requirements of being resilient, and especially being cyber-resilient. However, we do not have a complete list (Sawalha, 2015) for resilience or cyber-OR as the latter’s fragmentation has inhibited theoretical development (Bagheri and Ridley, 2017).

As mentioned, the literature overview on cyber-OR tools and practices has been inspired by RE principles. Thus, we identified tools and practices aimed at enhancing the four RE abilities. We highlight the fundamental components of cyber-OR below, following a feedback process and a three-time dimensions approach (i.e. before, during and after a cyberattack).

2.1.1 Plan and prepare.

According to Bodeau et al. (2011, p. 15), the objective regarding anticipation is to “maintain a state of informed preparedness to forestall compromises of mission/business functions from adversary attacks,” thus this objective entails prediction, prevention, and preparation. Prediction refers to monitoring the environment looking out for malicious activities and early signals of anomalous events (Bodeau et al., 2011). Indeed, situational awareness enables cyber-risk detection (Sepúlveda Estay et al., 2020), recognizing cyberthreat frequency and sophistication (Ferdinand, 2015). Environmental monitoring ensures early threat detection and vulnerability evaluation (Amin, 2019; Bodeau et al., 2011), which is enhanced by assessing weak spots (Annarelli et al., 2020; Borrett et al., 2013; Caron, 2019) in a way that allows the organization to identify Information Technology (IT) vulnerabilities and how they are exploited (Bayuk and Silverstein, 2007; Borrett et al., 2013). The ideas of situational awareness and vulnerability assessment also relate to identifying risk in the form of threats and vulnerabilities both from internal and external users (Lee, 2021), which can enable addressing changes in the cybersecurity environment. In addition, by foreseeing future scenarios organizations practice anticipation, based on which they can revise risk models. Through such business continuity management they develop capacities of responding appropriately (Steen et al., 2024).

Being prepared includes exercise and training (Bodeau et al., 2011). This is especially true due to human error issues. Employees should be properly informed on what to do in the event of a cyberattack (Wilding, 2016). Resilient organizations train staff to enhance awareness (Sepúlveda Estay et al., 2020) and improve prevention (Ferdinand, 2015). Training also encourages the implementation of best practices in the domain of mitigating actions (Carías et al., 2019). In addition, proper employee sensitization (e.g. via security guidelines) is a central component of cybersecurity culture that can support preparedness (Hoppe et al., 2021). Effective training sustains awareness and transforms policies, developing a culture of cybersecurity in which employees behave according to security guidelines (Tsen et al., 2022). Annarelli et al. (2020) establish a strong need to foster an organizational culture of cybersecurity in which employees develop knowledge rather than passively adopting technologies. Indeed, as Linkov et al. (2013) indicate, planning and preparation rely on building a cyber awareness culture.

Various plans, such as recovery, business continuity, contingency and incident response, are included in the cyber-OR approach (Brown, 2016; Ferdinand, 2015; Hult and Sivanesan, 2013; Kachgal, 2015; Zdravkovic et al., 2018). This approach includes regulatory cybersecurity frameworks such as the one proposed by the NIST (Tsen et al., 2022). Overall, this framework’s successful application enables organizations to better detect and respond to cyberthreats (Yigit Ozkan et al., 2021). However, to increase and sustain organizational adaptive capacity, all such plans should be tested via scenario exercises (McManus et al., 2008).

Implementing these strategies and adopting the tools are contingent on resource availability (Linkov et al., 2013; Hausken, 2020). This includes a variety of resources, ranging from a dedicated budget to infrastructure investments and staffing (Appiah et al., 2022; Garcia-Perez et al., 2021; North and Pascoe, 2016). Enhanced resource allocation is attained via risk quantification, which calculates cyberattack frequencies and their impact (Lee, 2021).

2.1.2 Respond and withstand.

The cyber-resilient organization should maintain its core functions and continue to deliver the intended outcome to enable recovery processes without interrupting operations (Björck et al., 2015; Bodeau et al., 2011). According to Bodeau et al. (2011, p. 16), resilient organizations maintain essential functions until the cyberattack is “well enough addressed that recovery becomes possible” (e.g. via graceful degradation and alternative courses of action). Linkov et al. (2013) suggested that addressing experts is functional to absorption. The cybersecurity role (Tsen et al., 2022) assists in mitigating the impact, providing support and monitoring control measures’ effectiveness. Cybersecurity experts, such as the Chief Technology Officer (CTO) (Trim and Lee, 2021) increase agility, enhance communication and ensure best practices implementation (Hult and Sivanesan, 2013; North and Pascoe, 2016). Furthermore, an incident response team could be put together to mitigate the impact of cyber incidents as “at its most basic level, incident response teams may be purely reactionary, with the team forming together in an ad-hoc fashion once an incident has been detected” (Ahmad et al., 2012, p. 644). The incident response team is included in the broad process of responding to incidents, which entails identifying, analyzing and responding to cyber incidents (Shaikh and Siponen, 2024).

Leadership is the key for organizations to become cyber-resilient (Armour, 2015; Hult and Sivanesan, 2013). Leadership motivation enables employees’ resilience and motivation (Osborn and Sepulveda-Estay, 2021; Trim and Lee, 2021; Wilding, 2016). As van der Kleij and Leukfeldt (2019, p. 21) put it, “lack of motivation hinders resilient functioning of an organization.” Leadership also enhances absorptive capacity, innovation, and organizational learning (Carayannis et al., 2021). As a core feature of cybersecurity culture, management attitude could sustain decision-making and avoid procrastination (Hoppe et al., 2021). Furthermore, leadership plays a pivotal role in building a culture of trust in cybersecurity, which in turn enables the development of cyber-resilient capabilities and a shared perception of cyber risks and threats regarding the organization (Loonam et al., 2022). In addition, management support contributes to shaping a cyber-organizational culture, which enables employees to understand the importance of cybersecurity and act accordingly (Uchendu et al., 2021). Cyber-aware employees are fundamental in early-breach identification (McIlwraith, 2021), especially ensuring that clear communication channels with cybersecurity functions are established. Early detection can reduce the cost of a cyber incident (Shaikh and Siponen, 2024).

While maintaining a minimal amount of function to approach the recovery phase (Bodeau et al., 2011), organizations should collaborate with data breach specialized third parties (Appiah et al., 2022; Brown, 2016) to enable a resilient digital ecosystem (Ahmad et al., 2015) and cybersecurity knowledge that shapes the environment (Trim and Lee, 2021). Adaptive responses are also enhanced by reallocating and reconfiguring existing resources (Bodeau et al., 2011). Resources additionally are pivotal in enabling employee response to cyber incidents (van der Kleij and Leukfeldt, 2019).

2.1.3 Recover and learn.

Cyberattacks can turn into cyber-incidents or even a data breach. Therefore, after an attack, a set of practices and tools should be implemented to reinforce the anticipation phase (Brown, 2016; Ferdinand, 2015). Typically, cyber-resilient organizations emphasize a learning approach (Hult and Sivanesan, 2013). In the spirit of RE, Steen et al. (2024, p. 6) defined proactive learning as “a search for trade‐offs and re-prioritizations, thus monitoring the adaptive cycle of work.”

Incident learning and investigation enable a better response to future cyber incidents, thus protecting the organization against catastrophic events (North and Pascoe, 2016; Nurse, 2019), while also enhancing risk management and predictive analysis (Borrett et al., 2013). Brown (2016) pointed out that incident reports should include a detailed description of the event, which covers the procedures implemented. According to Linkov et al. (2013, p. 474), “organizations should review management response and decision-making processes” alongside reviewing employees’ response to the event “to determine preparedness and communications effectiveness.”

Contrary to blame-centric organizations that hold employees personally accountable, the cyber-resilient organization incorporates lessons learned into institutional learning, thus improving cybersecurity (Hult and Sivanesan, 2013). According to Bada and Nurse (2019) open communication about cyber incidents also fosters a cybersecurity culture.

In addition, a good incident management analysis and organizational learning allow efficient resource allocation (Shaikh and Siponen, 2024).

The post-event phase includes post-event feedback, education, training and lesson-learnt processes (Groenendaal and Helsloot, 2021; Sepúlveda Estay et al., 2020). The incident response team could be in charge of learning activities, thus leading the incident follow-up by providing the cyber-incident data to be used in risk analysis or evaluation (Ahmad et al., 2012). This is related to postincident reviewing which “consists of reflecting on incident handling to improve processes for managing future incidents” (Shaikh and Siponen, 2024, p. 1112). Overall, as Steen et al. (2024, p. 6) indicated, “learning outcomes provide insights that enable organizations to adjust plans, reorganize structures or innovate new ways to respond to expected and unforeseen changes through an iterative process.”

The ability to maintain an intended outcome is directly related to restoring processes and mechanisms (Björck et al., 2015). First, restoration could imply returning to an acceptable state or recreating capabilities (Bodeau et al., 2011). A recovery phase entails practices such as updating and reviewing (Annarelli et al., 2020), as well as taking technical and nontechnical measures (e.g. system reconfiguration and recovery policies) (Linkov et al., 2013).

Overall, organizations should implement environmental changes regarding the threat (e.g. updating capabilities), their systems (e.g. revising mission and priorities) and technology (e.g. introducing new technology) (Bodeau et al., 2011).

Bodeau et al. (2011) conceptualized the postevent phase focusing on two main actions: recovering and evolving. Recovering refers to function and mission restoration via damage identification and capabilities restoration. Evolving happens through change in a wide spectrum of cyber capabilities, which decrease and mitigate a cyberattack’s impact. A series of practices are then suggested, such as those in the systems and technologies environment (Bodeau et al., 2011). Management changes reinforce anticipation via learning from the event, which enables preemptive transformation anticipating future changes (Carayannis et al., 2021).

Consistent with the literature overview, we conceptualize cyber-OR as a complex organizational feature resulting from an articulated system of activities formed by planning and preparing, responding and withstanding, learning and recovering.

This study specifically responds to:

RQ1.

What are the cyber-OR tools and practices that SMEs implement?

The scale and nature of cyber threats faced by SMEs are also shaped by the geographic and economic context. Although most recorded data breaches affect Europe and the USA, and Asian countries have significantly lower rates, we note a common ground for such breaches in the high prevalence of cyberattack types used in social engineering, of those financially motivated. Cybercriminals indicate this as the primary motivation for a cyberattack, with only a residual part of such breaches committed for espionage (Verizon, 2024). Furthermore, SMEs worldwide reportedly continue to be hugely impacted by data breaches without signs of decreasing (ENISA, 2022). According to Arroyabe et al. (2024, p. 8) “cybercriminals exploit the vulnerabilities of SMEs to commit crimes that impact the SME, whether through financial gains, compromising data, or disrupting digital operations.” With this in mind, academic debates have widely acknowledged that SMEs’ peculiarities should be considered regarding cybersecurity (Benz and Chatterjee, 2020; Neri et al., 2023a; Tam et al., 2021), the general notion of OR (Sullivan-Taylor and Branicki, 2011) and cyber-OR (Carías et al., 2021).

The challenges SMEs face have been reported across different geographical contexts, and across different regulatory frameworks and economic resources. Bada and Nurse (2019) analyzed UK SMEs and the benefits of introducing support centers to develop awareness. For Portuguese SMEs, Antunes et al. (2021) proposed a project aimed at introducing a tailored version of the ISO-27001:2013 standard. For Australian SMEs dealing with cybersecurity, Tam et al. (2021) reported resource constraints, organizational process maturity and legal structures as key challenges. Regarding South African SMEs, Kabanda et al. (2018) reported similar challenges, namely, budget factors, management support and attitudes. Thus, common themes emerged across different geographical contexts.

We therefore proceed to trace common ground on inhibiting factors, as presented in previous research. In dealing with cybersecurity, Benz and Chatterjee (2020, p. 532) claimed that SMEs have inadequate resources, yet are “overly confident about the level of preparedness and defence capabilities in their organization.” This can be ascribed to their focus on keeping day-to-day activities running, which neglects cybersecurity awareness (Gafni and Levy, 2023). Accordingly, Renaud and Weir (2016) reported that UK SMEs gave an optimistic risk appraisal about the likelihood of a cyberattack affecting them, which resulted in an underimplementation of protection measures. Paulsen (2016) claimed that SMEs usually undervalue their information and provide none or very limited training to their employees. Thus, lacking employee awareness, combined with the absence of cybersecurity expertise and the belief of not being targeted by cybercriminals, become major issues withholding SMEs from implementing best practices regarding cybersecurity (Kabanda et al., 2018).

Moving to the general notion of OR, resource constraints and poor long-term planning are key inhibitors for European SMEs, such as Sweden and Italy (Ates and Bititci, 2011; Neri et al., 2023b; Pal et al., 2014), which traditionally have taken a reactive approach due to their focus on operational issues (Garengo and Bernardi, 2007). Thus, many report a “muddling-through” approach (Sullivan-Taylor and Branicki, 2011) for SMEs. In addition, due to poor strategic planning, no formalized decision-making processes and a strong focus on short-term benefits, SMEs’ capability in adapting to disruption is compromised, as has also been evident in countries such as Italy and the UK (Agostini and Nosella, 2022; Burnard and Bhamra, 2011; Burnard et al., 2018; Herbane, 2019). Besides the few studies mentioned here, little to no research has been done in the context of SMEs and cyber-OR. Related considerations that have emerged so far, indicate, e.g. that a long-term plan is difficult to achieve due to SMEs’ limited budget (Carías et al., 2021). Achieving cyber resilience could be daunting for SMEs due to challenges such as limited funds and inadequately trained employees (Jahankhani et al., 2022). Van der Kleij and Leukfeldt (2019) found poor levels of cyber resilience, especially in postevent learning of SMEs based in the Netherlands. Similarly, Sukumar et al. (2023), considering cyber resilience as being prepared, reported poor risk assessment in UK SMEs.

Because the above discussion considers factors inhibiting SMEs’ cybersecurity (i.e. challenges SMEs face in implementing cyber-OR tools and practices that act as barriers), we have formulated the following research questions:

RQ2.

What are the hindering factors SMEs face in implementing cyber-OR tools and practices?

RQ3.

How do hindering factors affect the overall implementation of cyber-OR?

This research adopts an exploratory approach which is valuable in studying a new topic in which previous research is lacking (Creswell, 2009). While scholars emphasize various events related to OR, such as the COVID-19 pandemic (Dhoopar et al., 2021), cyberattacks are still underrepresented. Moreover, SMEs remain unexplored, and only a “few studies have sought to gauge SMEs’ attitude toward cybersecurity” (Wilson et al., 2022, p. 397).

We used semistructured interviews as part of the qualitative research design. The interviews were conducted online via Microsoft Teams and Google Meet across four months in the mid-to-end of 2022. Each interview lasted an average of 45 min.

We used a preinterview authorization to obtain permission for the data collection, recording, processing and treatment. Participants were informed of the purposes and objectives of the study, advised that participation was voluntary and anonymity ensured. SMEs autonomously selected key informants (Bell et al., 2022). After 31 interviews we had reached saturation (Guest et al., 2006). We followed Onwuegbuzie and Collins (2007) who suggest:

Sample sizes in qualitative research should not be so small as to make it difficult to achieve data saturation, theoretical saturation, or informational redundancy. At the same time, the sample should not be so large that it is difficult to undertake a deep, case-oriented analysis (p. 289).

The call for participation was disseminated via direct contact with professional associations. The interview schedule was based on a systematic literature review of cyber-OR main themes and reflected the idea of the three-time dimensions approach. Accordingly, some questions involved postevent learning activities, training and overall planning. We performed a pretest with ten subject matter experts (e.g. CTO) and we took input into consideration to revise and finalize the questionnaire, while also ensuring the questionnaire’s face validity.

The interviews were analyzed with the NVivo12 software, following Braun and Clarke's (2006) thematic analysis. In phase one we transcribed the interviews, thereby also starting to familiarize ourselves with the material and the emerging ideas. We read the interviews several times to improve interpretation, and discussed impressions with two independent researchers to ensure a holistic perspective and interrater reliability (Bryman and Bell, 2015). We also conducted a first round of provisional coding following Saldaña's (2013) directions. As Miles and Huberman (1994, p. 58) suggested, provisional coding ensures a “start list of codes prior to fieldwork.” Provisional coding is applied within the study’s conceptual framework (i.e. three-time dimensions), thus providing anticipated categories with a high likelihood of being found during the analysis. After the first codebook development, we followed an inductive process to encourage the rise of emerging topics, thereby allowing unexpected and unpredicted themes to emerge during the coding process (Boyatzis, 1998). This second step follows the logic of both provisional and open coding (Miles et al., 2014). Following this initial coding development, we performed a search for themes and aggregated codes in candidate themes and subthemes. Each theme was then reviewed and either aggregated or collapsed if an overlapping pattern was identified, or if code frequency and relevance did not justify maintaining the category as distinct.

The sample consisted of 31 Italian SMEs (45% small, 36% medium and 19% micro) belonging to several sectors such as manufacturing or commercial domains. We decided on classification using the criteria approved by the European Union (EU). Key informants included Chief Executive Officers (CEO) (36%), general managers (16%), CTOs (6%) and IT specialists (6%). Clearly, there are no cybersecurity experts.

Most participant SMEs had suffered either an attempted cyber incident (57%) or one that resulted in a data breach (16%) with cyberattack methodologies that exploit human vulnerabilities (i.e. 67% phishing and 19% ransomware). These results highlight that organizational approaches to cybersecurity are increasingly relevant alongside technological ones. A sociotechnical synergy between the two approaches is necessary for dealing with cyber incidents.

The analysis led to the development of 15 themes and 19 subthemes (see Figure 1). The NVivo usage assisted in interview analysis and categorization, as well as calculating each team’s coverage percentage. We aggregated themes in the three-time dimension and followed the feedback process proposed in the literature overview.

Figure 1.

Thematic analysis’ results

Figure 1.

Thematic analysis’ results

Close Figure 1.

Furthermore, a visual representation (see Figure 2) summarizes the three temporal dimension coverage percentages.

Figure 2.

Cyber-OR dimensions percentage coverage

Figure 2.

Cyber-OR dimensions percentage coverage

Close Figure 2.

The plan and prepare themes arose in 84% of the interviews, thus these were the most discussed during the interviews. Table 1 summarizes the thematic analysis.

Table 1.

Thematic analysis of the plan and prepare dimension

DimensionThemeSubtheme(s)
Plan and prepare (84%) – PP1 – Environmental monitoring (58%)P1.1 – Technical environmental monitoring (39%)
P1.2 – Nontechnical environmental monitoring (26%)
 P2 – Overall plan implementation (61%)P2.1 – Remediation plan (48%)
P2.2 – Risk management plan (42%)
P2.3 – Recovery plan (23%)
P2.4 – Business continuity plan (10%)
 P3 – Resources (83%)P3.1 – Technological resources (63%)
P3.2 – Human resources (23%)
P3.3 – Financial resources (31%)
 P4 –Training (84%)P4.1 – Diversified training (29%)
P4.2 – Formal training (71%)
P4.3 – Informal training (29%)
P4.4 – Training timeline (27%)
 P5 – Vulnerability assessment (61%) 
 P6 – Impact assessment (68%) 

Source(s): Authors’ own work

Environmental monitoring (P1) was the least implemented practice, thus its inner value for understanding cyber threats’ frequency and sophistication (Ferdinand, 2015) and keeping up with cybercrimes trends (Trim and Lee, 2021) was compromised.

We further categorized the data into technical (P1.1) and nontechnical subthemes (P1.2). Many SMEs relied on environmental monitoring to be updated via partners or service providers, and on the cyber environment via newsletters:

I read a newsletter since I'm subscribed to one, and I try to stay informed about the numerous ransomware types that are circulating (CEO).

Other SMEs focused on the technological side of environmental monitoring (e.g. perimeter monitoring or intrusion detection).

We have software which monitors our systems and alerts us to any anomalies via message and mail (IT specialist).

Vulnerability assessment (P5) was perceived as a primary methodology for identifying systems’ vulnerabilities and prioritizing interventions. This approach followed previous research on the role vulnerability plays (Annarelli et al., 2020; Borrett et al., 2013). Many SMEs relied on third-party suppliers for advice on technology solutions (e.g. penetration testing), whereas others used an informal and unstructured vulnerability analysis:

We do have processes that help us assess vulnerabilities, but we do not have written reports (Software developer).

Informal discussion impairs the value of its application and results on hindering factors have shown that resource scarcity often inhibits resolving vulnerabilities.

Concerning overall plan implementation (P2), we found four “plans” during interview analysis, namely, remediation (P2.1), risk management (P2.2), recovery (P2.3) and business continuity (BCP) (P2.4). The remediation and risk management plans were the most discussed. Recovery and BCP were extremely underimplemented, yet were depicted as functional in maintaining continuity of operations, thus facilitating a quick recovery (Tsen et al., 2022; Zdravkovic et al., 2018), and in taking appropriate emergency measures (Kachgal, 2015). Contingency plans, which are needed when other plans fail (Hult and Sivanesan, 2013), were not highlighted.

Other SMEs relied on unformalized and adapted best practices that could assist in the event of a cyber incident. Prior research reported these as inadequate because they compromise adjustment to disruption (Agostini and Nosella, 2022; Burnard and Bhamra, 2011).

These best practices primarily remain in the knowledge of those who developed them (e.g. IT department):

We don't have a full-fledged emergency plan prepared and signed by a cybersecurity office. We rely on internal procedures (IT specialist).

We found no evidence of either structured or unstructured application of cybersecurity frameworks, such as what the NIST proposes.

Impact assessment (P6), although widely implemented, was largely unstructured, showing that it is perceived as an enabler of proper protective countermeasures in the organization. Impact assessment was either included in the above-discussed plans or supplied by external providers. For example:

We evaluated what might completely stop and what would be our difficulties in restarting. But we never formalized them (CTO).

Human resources (P3.2) were underrepresented but discussed as a source in preparing for cyber incidents. The focus was on training investments:

The most important resource to invest in is more human resources. So, some training is required (IT Director).

Financial resources (P3.3) were strictly related to a cybersecurity budget, which is based on necessity and included in the IT budget.

Training (P4) was the most implemented practice. However, some organizations did not have a structured (P4.3), ongoing training approach considering diversified needs. Only a few SMEs used multiple training methods. Different to previous research suggestions (Annarelli et al., 2020; Linkov et al., 2013), training is not built around employee learning needs (in-person lectures or simulations). Diversification (P4.1) involved tailoring content to job descriptions:

Training sessions are also specific to their job description. Maybe to those who are exposed to the risk of phishing, we try to convey some kind of awareness (Software developer).

Many SMEs adopted formalized training programs (P4.2). These included mainly:

Learning platforms with workshops and actual lessons targeted to the context (CEO).

Overall, a recurrent theme in training activities referred to the content, which focused mainly on phishing and how to counter it. This means that, the potential for training to improve IT skills, knowledge bases and for properly adopting cybersecurity policies is significantly undermined (Trim and Lee, 2021). As several studies suggest, training should also focus on teaching the proper mitigation techniques (Carías et al., 2019; Wilding, 2016).

Training on current demand, when introducing new systems, or hiring new employees, happened widely (P4.4):

When installing some system or maintaining it, we use the outsourced company that does some training (CEO).

This could lead to outdated cybersecurity knowledge misaligned with cybercrime trends.

The respond and withstand theme arose in 78% of the interviews. In wide discussion among interviewees, some criticality emerged in each theme. Table 2 summarizes the thematic analysis.

Table 2.

Thematic analysis of the respond and withstand dimension

DimensionTheme
Respond and withstand (78%) – RR1 – Cybersecurity role (78%)
 R2 – Leadership (71%)
 R3 – Function maintenance (48%)
 R4 – External collaboration (58%)

Source(s): Authors’ own work

A recurrent theme related to the cybersecurity specialist (R1), e.g. those identified as IT department members, software developers and the CEO. However, all these roles were involved in IT-related activities. Those who held the role of cybersecurity specialist were responsible for allocating budgets, deciding on best practices and ensuring policy implementation (if policies were in place). This role was envisioned as the first contact during a cyber incident (e.g. taking decisions or interacting with external partners). These themes align with the function suggested in the literature (North and Pascoe, 2016; Tsen et al., 2022):

The key person to refer to is me, also because I did the network configurations and designs. However, I have coworkers that can handle the event on their own (IT specialist).

The cybersecurity role was strictly linked to the leadership theme (R2), coordinating actions during an incident (i.e. interacting with external partners and ensuring business continuity). The leadership theme raised issues regarding the role of managers, both in terms of coordinating and endowing the necessary resources. The management role was depicted as highly marginal and uninterested in cybersecurity issues as long as they were resolved without major damages:

If the problem is technical or operational in its nature and does not go to business protection, data protection, infrastructure, or operations, the direction is only updated (IT Director).

Concepts such as employee motivation or transformational leadership (Carayannis et al., 2021; Osborn and Sepulveda-Estay, 2021; Trim and Lee, 2021) were not noted. Outcomes prompted by leadership, such as a culture of continuous improvement (Osborn and Sepulveda-Estay, 2021), absorptive capacity, innovation and organizational learning (Carayannis et al., 2021), as well as sustained cyber-resilient behavior among employees (Wilding, 2016), are severely impacted.

The theme of asset functionality (R3) was the least discussed although it is a key pillar of cyber-OR (Björck et al., 2015). Some organizations had institutionalized methods that were fully dependent on technology (e.g. backup). These results are closely linked to the very limited implementation of BCP and contingency plans. Overall, these solutions were applied to assets according to their relevance:

The design of our operation system includes backup as well as redundancy, which can be hardware or software, to keep these services functioning (CTO).

The external collaboration theme (R4) was conceived as partnering with service providers who assist in the software or hardware functioning. There was no evidence of partnership with cybersecurity companies. This emphasizes the necessity of having external third parties that can support during a cyber incident (Brown, 2016):

As customers, we have a relationship with a third-party company that handles all of the IT systems (CEO).

This perspective constrained the effect partnerships could have in shaping a digital ecosystem and increasing knowledge in the surrounding environment (Appiah et al., 2022; Trim and Lee, 2021).

The recover and learn dimension was the least implemented among the interviewees. Table 3 summarizes the thematic analysis.

Table 3.

Thematic analysis on the recover and learn dimension

DimensionThemeSubtheme(s)
Recover and learn (45%) – LL1 – Recovery measures (26%)L1.1 – Update procedures (16%)
L1.2 – Reviewing procedures (16%)
L1.3 – System reconfiguration (13%)
 L2 – Learning processes (39%)L2.1 – Incident report analysis (36%)
L2.2 – Feedback analysis (13%)
L2.3 – Postevent training (13%)

Source(s): Authors’ own work

Starting from learning processes (L2), incident report analysis (L2.1) was the most implemented (even if residual) activity, ranging from less detailed to very formalized. Reports typically described the cyber-incident methodology, the resources involved and compromises (if any). For example:

We include what we did, the procedures we took, the time we lost, and we indicated the people who worked on that activity (CEO).

In a few interviews, an informal feedback analysis (L2.2) arose as a postevent learning process and postevent training activities. Although incident reports (L2.1) were used as a tool for postevent analysis, only a few measures were implemented as learning procedures related to report examination. These results compromised the perspective that cyber-OR implies a learning organization (Ferdinand, 2015; Hult and Sivanesan, 2013). Without postevent learning, the organization fails to change, thus the same problems could reoccur in the future (North and Pascoe, 2016; Nurse, 2019).

Overall, recovery measures (L1) were the least discussed, giving them a marginal role in the investigated context. Three themes arose, namely updating procedures (L1.1), reviewing procedures (L1.2) and system reconfiguration (L1.3). These activities resulted directly from the post-cyber-incident analysis (incident report and feedback analysis). In addition, systems were reviewed and updated or, where applicable, they would be replaced:

We revise the security assessment to update or revise mitigations that have been involved to increase the organization's coverage level against cyberattacks (IT Director).

Three main themes emerged from the analysis: lack of awareness, budget and resource scarcity and small organization size. Table 4 summarizes the thematic analysis.

Table 4.

Thematic analysis on the hindering factors dimension

DimensionTheme
SMEs hindering factors (65%) – FF1 – Small organization size (65%)
 F2 – Lack of awareness (45%)
 F3 – Budget and resources scarcity (62%)

Source(s): Authors’ own work

Many SMEs did not envision themselves as possible targets of cybercriminals and had an optimistic outlook because of misconceptions about their information’s value:

We believe the risk is pretty low because we work in a mature industry, so it's not highly innovative so there's definitely no trade secrets to take from us (Manager).

The awareness theme (F2) was largely linked to the organization’s functional area:

Fortunately, being all IT people, we imagine we can handle these situations (IT Specialist).

This misconception about being targeted by cybercriminals led to resource underestimation. This perception affects several areas of cyber-OR, such as training, plan implementation, hiring a cybersecurity expert and budget allocation:

Being attacked by a cyber-criminal has always been seen as an unlikely scenario, and so for the same reason as above we have not spent time and money in training (Manager).

The lacking-a-budget theme (F3) affected many SMEs, even those aware of cyber risks. Indeed, many SMEs with limited cyber-OR tools and practices lacked a dedicated cybersecurity budget, as prior research advises (Gafni and Levy, 2023):

Resources are limited and so everything is always focused as much as possible toward what is the core of the business aimed at generating profits. Cybersecurity is not our priority (CEO).

Although an adequate budget and staff are foundational to cyber-OR (Garcia-Perez et al., 2021), limited budget issues emerged as a major factor affecting cyber-OR. For example, budget constraints impede training:

The overall budget affects training because the few employees at the time they are training are missing out on their main goals and tasks (CTO).

This theme aligns with previous research which depicted it as a key challenge for SMEs in OR (Pal et al., 2014) and cyber-OR (Jahankhani et al., 2022), subsequently results in poor long-term planning (Carías et al., 2021; Sullivan-Taylor and Branicki, 2011).

Furthermore, the organization’s size (F1) appeared as a limitation to cyber-OR, especially to adopting formalized plans. This coincided with cybersecurity management based on disseminating practices in an oral and unstructured form:

Everything happens orally, and so there is no real documentation. I think that is a major limitation of small companies (IT Director).

The muddling-through approach has already been highlighted as a peculiarity of SMEs (Sullivan-Taylor and Branicki, 2011), as has the lack of formalized plans (Herbane, 2019). Overall, the organization’s size dimension appeared to affect the implementation of tools and practices, especially concerning plans and training:

Very thick updating of procedures is not sustainable for the dimension of our organization (IT Specialist).

Moreover, organizational size affected the presence or absence of a cybersecurity expert, thus small SMEs make do with decision-making processes managed by people not formally responsible for cybersecurity:

Of the IT part of the organization, we don't have a dedicated manager, let's say we have a team of people who deal with it but on an occasional basis, that's not their role (IT Specialist).

Overall, cybersecurity hindering factors arose as a major obstacle in SMEs. Our study’s results shed light on the poor implementation of cyber-OR practices. Figure 3 below summarizes how hindering factors affect cyber-OR dimensions and related tools and practices.

Figure 3.

Conceptual summary of hindering factors’ effect on cyber-OR

Figure 3.

Conceptual summary of hindering factors’ effect on cyber-OR

Close Figure 3.

The above conceptual synthesis reinforces the idea that SMEs largely lack implementing recovery measures and learning practices. This, in addition to their optimistic outlook on cyberthreats, explains why SMEs do not implement recovery and learning practices.

Figure 4 summarizes results within the conceptual approach adopted (i.e. three-times frame and feedback process).

Figure 4.

Conceptual summary of research findings

Figure 4.

Conceptual summary of research findings

Close Figure 4.

This research has several implications for theory, practice and society.

From a theoretical perspective, this research contributes to theory highlighting how SMEs deal with OR and cybersecurity, thus refining the existing conceptual framework and informing the development of more contextualized models. It responds to the wide call for in-depth studies on OR related to a specific event, thus elaborating on tools and practices relevant to cyber-OR within SMEs (Hepfer and Lawrence, 2022; Pinheiro et al., 2022; Su and Junge, 2023). Furthermore, by identifying hindering factors, such as limited resources and organizational size, this study responds to ongoing calls for research into SME-specific challenges (Benz and Chatterjee, 2020; Carías et al., 2021).

By focusing on SMEs, an underrepresented yet critical research area regarding cybersecurity (Annarelli and Nonino, 2016; Pal et al., 2014; Saad et al., 2021; Sukumar et al., 2023; Wilson et al., 2022), this study reveals informal and simplified best practices being implemented, mainly due to hindering factors such as resource constraints. This result reinforces prior claims that traditional theories and frameworks on OR do not entirely apply to SMEs (Sullivan-Taylor and Branicki, 2011) given the features distinguishing them from large companies (Antunes et al., 2021; Bada and Nurse, 2019; Gafni and Levy, 2023).

This research provides practical guidance for SME managers to address critical areas of cyber-OR by developing frameworks and strategies that are context-specific. This could assist them in overcoming the effects of the identified hindering factors. Managers aiming to assess cyber-OR could use the literature systematization with an RE approach, alongside the conceptual framework, as a roadmap.

Considering the research findings, SMEs should focus on regulatory framework compliance, given their pivotal role in building cyber-OR via risk mitigation and assessment, spreading a cybersecurity culture (Itani et al., 2024), saving time and providing business continuity (Taherdoost, 2022). Although security standards (e.g. ISO/IEC 27001) are fundamental in enhancing cybersecurity (Antunes et al., 2021), regulatory bodies should propose tailor-made regulatory frameworks that “could provide a better solution and a ‘better’ fit model to process methods of regulation and requirements which SMEs can follow and adhere to whilst still being security compliant” (Rawindaran et al., 2023).

Managers could also consider fostering a proactive organizational cyberculture based on awareness building, employee training and cross-functional collaboration.

SMEs should devote their effort to building a BCP, which most currently do not have, thus downtimes and financial losses could be avoided (Bajgoric, 2006). Following Steen et al. (2024), in the spirit of RE, organizations should implement BCPs, which also account for metrics and targets, financial impact, resource requirements and iteratively adjusts these via learning outcomes analysis. Not having a BCP is narrowly related to the underrepresentation of learning activities that could enhance the effectiveness of plans for continuous improvement. SMEs could also actively engage stakeholders to participate in the BCP, thus ensuring access to expertise that could be missing inside the organization. This would complement cyber-OR practices adoption with a cost-effective approach.

The study results imply that the investigated SMEs could be more prone to experiencing cyber incidents than anticipated, which could harm their cyber reputation (Perera et al., 2022), causing stigma, loss of operational credibility and reduced support from both the public and the government (Hampel and Tracey, 2017). As Boakye et al. (2024) indicated, several strategies could counteract the effects of cyber incidents. Such strategies include clear communication channels with stakeholders, strong leadership that oversees resource allocation and crisis management, cooperation with regulatory bodies and developing foresight via anticipation and incident response planning. Because reputational harm is an indirect cost of cyber incidents (Franco et al., 2024), applying these strategies could further lead to cost reduction, especially via disclosure to customers and stakeholders. Organizations that openly share information on cyber incidents and related lessons learned contribute to building a collective cyber awareness that benefits the SME ecosystem.

Turning now to societal implications, policymakers can leverage these findings to develop targeted frameworks and policies concerning cyber-OR, taking SME peculiarities into account. Considering the economic role of SMEs in Western countries, improving their cyber-OR could prevent economic downturns and reduce the social impact of cyber incidents (e.g. financial losses and digital trust). Policymakers’ initiatives, such as incentives or tax benefits, could promote SME cybersecurity investments. Cybersecurity hubs or information-sharing platforms could provide access to state-of-the-art information and resources, thus enhancing cyber-OR.

This research sheds light on the cyber-OR tools and practices SMEs implement, thus investigating this relatively underresearched topic. The plan and prepare phase currently shows numerous limitations, including informality, lack of structured form and the absence of cybersecurity expertise. The recover and learn dimension is a missing piece within the investigated SMEs. The approach SMEs take is completely dedicated to prevention. These results misalign with proposed learning approaches which limits SMEs’ cyber-OR achievement per se. Then, three main hindering factors emerged as affecting SMEs cyber-OR. The results reinforce the idea that theories on OR and the typically used frameworks are not entirely applicable to SMEs (Pal et al., 2014; Sullivan-Taylor and Branicki, 2011) since SMEs’ distinguishing features especially affect their dealing with cybersecurity (Bada and Nurse, 2019; Gafni and Levy, 2023).

This study’s research design is distinctly qualitative, which is appropriate for exploring SMEs’ nuanced challenges and perspectives in achieving cyber-OR. although qualitative methods miss statistical generalizability, they offer a rich and in-depth insight that is critical for understanding this complex and underresearched topic. Further, subjectivity bias was reduced by enhancing interrater reliability (Bryman and Bell, 2015), using NVivo for coding and interpretation and using a specific protocol to analyze raw data (Braun and Clarke, 2006). Future research could complement our findings with quantitative methods and approaches, thus enhancing the generalizability and further validating the identified themes. The authors’ access to the sector’s key constituents and their collaboration with focal professional associations, justifies the focus on the Italian context which, admittedly, prevents comparison across states. This focus has helped in overcoming SMEs’ reluctance to openly discuss their cybersecurity practices. In addition, Italy is worth investigating since it is the European nation most affected by cyberattacks and sixth in the world.

The sample included diverse groups of SMEs whose distribution reflects the Italian landscape composition, thus ensuring appropriate representation. However, we recognize that the relative organizational size could influence the ability to implement cyber-OR tools and practices, as well as hindering factors’ severity. To illustrate, while medium-size organizations may have greater access to resources (e.g. budgets) and more structured practices, microsized enterprises mostly rely on informal processes, which leads to different levels of cyber-OR. All these potential variations considered, this study remains robust in its methodological approach, offering critical qualitative insights on cyber-OR within SMEs. While we provide insight into SMEs as a collective, the findings should be interpreted with an understanding of this size-based variability. Thus, we propose as a further area of investigation a comparative analysis to consider the nuanced differences between micro, small and medium organizations to examine the size influence on cyber-OR tools and practices adoption. Such research would offer the possibility of addressing each group’s unique needs and developing more size-specific frameworks.

Future research could perform comparative studies with other European and non-European countries to explore the role of regulations. Future studies could also assess the role of the sector as a contextual factor in shaping and achieving cyber-OR (e.g. digitally driven industries). Future research could focus on performing case studies in organizations that have experienced a cyber incident. This would clarify the idea of a different path for SMEs in achieving cyber-OR (e.g. best practices possibly more functional than implementing structured plans). The sample of key informants included managers or CEOs, which provided a valuable perspective and insights concerning SMEs’ cyber-OR tools, practices and related challenges. While this approach captured managerial viewpoints, future research could benefit from including other experts (i.e. the cybersecurity agents), thus providing a more technical understanding of cyber-OR and offering a broader and holistic view of OR.

The authors are grateful to Prof. Francesco Virili (Catholic University of the Sacred Heart), whose expertise provided us with insightful guidance throughout the development of the literature overview and inspired us with precious advice. The authors want to extend their gratitude to the anonymous peer reviewers who dedicated their time to provide constructive feedback that enhanced the quality of our research. The authors are thankful to key informants who agreed to participate and dedicate their time to our research.

Declarations of interest: The authors report there are no competing interests to declare.

Funding: Funding statements are not applicable since this research received none.

Agostini
,
L.
and
Nosella
,
A.
(
2022
), “
Intellectual capital and resilience: evidence from two cases of SMEs
”,
Knowledge Management Research and Practice
, Vol.
21
No.
5
, pp.
1
-
14
, doi: .
Ahmad
,
A.
,
Hadgkiss
,
J.
and
Ruighaver
,
A.B.
(
2012
), “
Incident response teams – challenges in supporting the organisational security function
”,
Computers and Security
, Vol.
31
No.
5
, pp.
643
-
652
, doi: .
Ahmad
,
A.
,
Johnson
,
C.
and
Storer
,
T.
(
2015
), “
An investigation on organisation cyber resilience
”,
International Journal of Computer and Systems Engineering
, Vol.
9
No.
7
, pp.
1696
-
1701
.
Amin
,
Z.
(
2019
), “
A practical road map for assessing cyber risk
”,
Journal of Risk Research
, Vol.
22
No.
1
, pp.
32
-
43
, doi: .
Annarelli
,
A.
and
Nonino
,
F.
(
2016
), “
Strategic and operational management of organizational resilience: current state of research and future directions
”,
Omega
, Vol.
62
, pp.
1
-
18
, doi: .
Annarelli
,
A.
,
Nonino
,
F.
and
Palombi
,
G.
(
2020
), “
Understanding the management of cyber resilient systems
”,
Computers and Industrial Engineering
, Vol.
149
, p.
106829
, doi: .
Antunes
,
M.
,
Maximiano
,
M.
,
Gomes
,
R.
and
Pinto
,
D.
(
2021
), “
Information security and cybersecurity management: a case study with SMEs in Portugal
”,
Journal of Cybersecurity and Privacy
, Vol.
1
No.
2
, pp.
219
-
238
, doi: .
Appiah
,
G.
,
Amankwah-Amoah
,
J.
and
Liu
,
Y.-L.
(
2022
), “
Organizational architecture, resilience, and cyberattacks
”,
IEEE Transactions on Engineering Management
, Vol.
69
No.
5
, pp.
2218
-
2233
, doi: .
Armour
,
C.
(
2015
), “
Cyber resilience health check
”,
Governance Directions
, Vol.
67
No.
5
, pp.
264
-
265
.
Arroyabe
,
M.F.
,
Arranz
,
C.F.A.
,
De Arroyabe
,
I.F.
and
de Arroyabe
,
J.C.F.
(
2024
), “
Revealing the realities of cybercrime in small and medium enterprises: understanding fear and taxonomic perspectives
”,
Computers and Security
, Vol.
141
, p.
103826
, doi: .
Ates
,
A.
and
Bititci
,
U.S.
(
2011
), “
Change process: a key enabler for building resilient SMEs
”,
International Journal of Production Research
, Vol.
49
No.
18
, pp.
5601
-
5618
, doi: .
Ayyub
,
B.M.
(
2014
), “
Systems resilience for multihazard environments: definition, metrics, and valuation for decision making
”,
Risk Analysis
, Vol.
34
No.
2
, pp.
340
-
355
.
Bada
,
M.
and
Nurse
,
J.R.C.
(
2019
), “
Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs)
”,
Information and Computer Security
, Vol.
27
No.
3
, pp.
393
-
410
, doi: .
Bagheri
,
S.
and
Ridley
,
G.
(
2017
), “
Organisational cyber resilience: research opportunities
”,
ACIS2017: Australasian Conference on Information Systems
, pp.
1
-
10
,
available at:
www.acis2017.org/program/conference-program/conference-proceeding/
Bagheri
,
S.
,
Ridley
,
G.
and
Williams
,
B.
(
2023
), “
Organisational cyber resilience: management perspectives
”,
Australasian Journal of Information Systems
, Vol.
27
, doi: .
Bajgoric
,
N.
(
2006
), “
Information technologies for business continuity: an implementation framework
”,
Information Management and Computer Security
, Vol.
14
No.
5
, pp.
450
-
466
, doi: .
Bayuk
,
J.
and
Silverstein
,
K.
(
2007
), “
Utilising information security to improve resilience
”,
Journal of Business Continuity and Emergency Planning
, Vol.
2
No.
1
, pp.
7
-
12
.
Bell
,
E.
,
Bryman
,
A.
and
Harley
,
B.
(
2022
),
Business Research Methods
,
Oxford university press
,
Oxford
.
Benz
,
M.
and
Chatterjee
,
D.
(
2020
), “
Calculated risk? A cybersecurity evaluation tool for SMEs
”,
Business Horizons
, Vol.
63
No.
4
, pp.
531
-
540
, doi: .
Bhamra
,
R.
,
Dani
,
S.
and
Burnard
,
K.
(
2011
), “
Resilience: the concept, a literature review and future directions
”,
International Journal of Production Research
, Vol.
49
No.
18
, pp.
5375
-
5393
.
Björck
,
F.
,
Henkel
,
M.
,
Stirna
,
J.
and
Zdravkovic
,
J.
(
2015
), “Cyber resilience – fundamentals for a definition”, in
Rocha
,
A.
,
Correia
,
A.M.
,
Costanzo
,
S.
and
Reis
,
L.P.
(Eds),
New Contributions in Information Systems and Technologies
,
Springer International Publishing
,
Cham
, pp.
311
-
316
, doi: .
Boakye
,
D.
,
Sarpong
,
D.
,
Meissner
,
D.
and
Ofosu
,
G.
(
2024
), “
How TalkTalk did the walk-walk: strategic reputational repair in a cyber-attack
”,
Information Technology and People
, Vol.
37
No.
4
, pp.
1642
-
1673
, doi: .
Bodeau
,
D.
,
Graubart
,
R.
,
Picciotto
,
J.
and
McQuaid
,
R.
(
2011
), “
Cyber resiliency engineering framework
”,
MTR110237, MITRECorporation
.
Borrett
,
M.
,
Carter
,
R.
and
Wespi
,
A.
(
2013
), “
How is cyber threat evolving and what do organisations need to consider?
”,
Journal of Business Continuity and Emergency Planning
, Vol.
7
No.
2
, pp.
163
-
171
.
Bouaziz
,
F.
and
Hachicha
,
Z.S.
(
2018
), “
Strategic human resource management practices and organizational resilience
”,
Journal of Management Development
, Vol.
37
No.
7
, pp.
537
-
551
, doi: .
Boyatzis
,
R.E.
(
1998
),
Transforming Qualitative Information: Thematic Analysis and Code Development
,
SAGE Publications
,
Thousand Oaks, CA
.
Braun
,
V.
and
Clarke
,
V.
(
2006
), “
Using thematic analysis in psychology
”,
Qualitative Research in Psychology
, Vol.
3
No.
2
, pp.
77
-
101
.
Brown
,
H.S.
(
2016
), “
After the data breach: managing the crisis and mitigating the impact
”,
Journal of Business Continuity and Emergency Planning
, Vol.
9
No.
4
, pp.
317
-
328
.
Bryman
,
A.
and
Bell
,
E.
(
2015
),
Business Research Methods
,
University Press
,
Oxford
.
Burnard
,
K.
and
Bhamra
,
R.
(
2011
), “
Organisational resilience: development of a conceptual framework for organisational responses
”,
International Journal of Production Research
, Vol.
49
No.
18
, pp.
5581
-
5599
, doi: .
Burnard
,
K.
,
Bhamra
,
R.
and
Tsinopoulos
,
C.
(
2018
), “
Building organisational resilience: four configurations
”,
IEEE Transactions on Engineering Management
, Vol.
65
No.
3
, doi: .
Carayannis
,
E.G.
,
Grigoroudis
,
E.
,
Rehman
,
S.S.
and
Samarakoon
,
N.
(
2021
), “
Ambidextrous cybersecurity: the seven pillars (7Ps) of cyber resilience
”,
IEEE Transactions on Engineering Management
, Vol.
68
No.
1
, pp.
223
-
234
, doi: .
Carías
,
J.F.
,
Arrizabalaga
,
S.
,
Labaka
,
L.
and
Hernantes
,
J.
(
2021
), “
Cyber resilience self-assessment tool (CR-SAT) for SMEs
”,
IEEE Access
, Vol.
9
, pp.
80741
-
80762
, doi: .
Carías
,
J.F.
,
Sarriegi
,
J.M.
,
Labaka
,
L.
,
Tapia
,
A.
and
Hernantes
,
J.
(
2019
), “
The dynamics of cyber resilience management
”.
Caron
,
F.
(
2019
), “
Obtaining reasonable assurance on cyber resilience
”,
Managerial Auditing Journal
, Vol.
36
No.
2
, pp.
193
-
217
, doi: .
Cook
,
R.I.
and
Long
,
B.A.
(
2021
), “
Building and revising adaptive capacity sharing for technical incident response: a case of resilience engineering
”,
Applied Ergonomics
, Vol.
90
, p.
103240
.
Creswell
,
J.W.
(
2009
),
Research Design: Qualitative, Quantitative, and Mixed Methods Approaches
,
Sage publications
,
London
.
Dalal
,
R.S.
,
Howard
,
D.J.
,
Bennett
,
R.J.
,
Posey
,
C.
,
Zaccaro
,
S.J.
and
Brummel
,
B.J.
(
2022
), “
Organizational science and cybersecurity: abundant opportunities for research at the interface
”,
Journal of Business and Psychology
, Vol.
37
No.
1
, pp.
1
-
29
, doi: .
Dhoopar
,
A.
,
Sihag
,
P.
,
Kumar
,
A.
and
Suhag
,
A.K.
(
2021
), “
Organizational resilience and employee performance in COVID-19 pandemic: the mediating effect of emotional intelligence
”,
International Journal of Organizational Analysis
, Vol.
30
No.
1
, pp.
130
-
155
, doi: .
Dupont
,
B.
(
2019
), “
The cyber-resilience of financial institutions: Significance and applicability
”,
Journal of Cybersecurity
, Vol.
5
No.
1
, p.
tyz013
, doi: .
ENISA
(
2022
), “
Threat landscape (ETL) report
”,
available at:
www.enisa.europa.eu/publications/enisa-threat-landscape-2021?v2=1
Ferdinand
,
J.
(
2015
), “
Building organisational cyber resilience: a strategic knowledge-based view of cyber security management
”,
Journal of Business Continuity and Emergency Planning
, Vol.
9
No.
2
, pp.
185
-
195
.
Folke
,
C.
,
Carpenter
,
S.R.
,
Walker
,
B.
,
Scheffer
,
M.
,
Chapin
,
T.
and
Rockström
,
J.
(
2010
), “
Resilience thinking: integrating resilience, adaptability and transformability
”,
Ecology and Society
, Vol.
15
No.
4
.
Franco
,
M.F.
,
Künzler
,
F.
,
von der Assen
,
J.
,
Feng
,
C.
and
Stiller
,
B.
(
2024
), “
RCVaR: an economic approach to estimate cyberattacks costs using data from industry reports
”,
Computers and Security
, Vol.
139
, p.
103737
, doi: .
Frigotto
,
M.L.
,
Young
,
M.
and
Pinheiro
,
R.
(
2022
), “Resilience in organizations and societies: the state of the art and three organizing principles for moving forward”, in
Pinheiro
,
R.
,
Frigotto
,
M.L.
and
Young
,
M.
(Eds),
Towards Resilient Organizations and Societies: A Cross-Sectoral and Multi-Disciplinary Perspective
,
Springer International Publishing
,
Cham
, pp.
3
-
40
, doi: .
Gafni
,
R.
and
Levy
,
Y.
(
2023
), “
Experts’ feedback on the cybersecurity footprint elements: in pursuit of a quantifiable measure of SMBs’ cybersecurity posture
”,
Information and Computer Security
, Vol.
31
No.
5
, doi: .
Garcia-Perez
,
A.
,
Sallos
,
M.P.
and
Tiwasing
,
P.
(
2021
), “
Dimensions of cybersecurity performance and crisis response in critical infrastructure organisations: an intellectual capital perspective
”,
Journal of Intellectual Capital
, doi: .
Garengo
,
P.
and
Bernardi
,
G.
(
2007
), “
Organizational capability in SMEs: performance measurement as a key system in supporting company development
”,
International Journal of Productivity and Performance Management
, Vol.
56
Nos
5/6
, pp.
518
-
532
, doi: .
Granig
,
P.
and
Hilgarter
,
K.
(
2020
), “
Organisational resilience: a qualitative study about how organisations handle trends and their effects on business models from experts’ views
”,
International Journal of Innovation Science
, Vol.
12
No.
5
, pp.
525
-
544
, doi: .
Groenendaal
,
J.
and
Helsloot
,
I.
(
2021
), “
Cyber resilience during the COVID-19 pandemic crisis: a case study
”,
Journal of Contingencies and Crisis Management
, Vol.
29
No.
4
, pp.
439
-
444
, doi: .
Grøtan
,
T.O.
,
Antonsen
,
S.
and
Haavik
,
T.K.
(
2022
), “Cyber resilience: a pre-understanding for an abductive research agenda”, in
Matos
,
F.
,
Selig
,
P.M.
and
Henriqson
,
E.
(Eds),
Resilience in a Digital Age: Global Challenges in Organisations and Society
,
Springer International Publishing
,
Cham
, pp.
205
-
229
, doi: .
Guest
,
G.
,
Bunce
,
A.
and
Johnson
,
L.
(
2006
), “
How many interviews are enough? An experiment with data saturation and variability
”,
Field Methods
, Vol.
18
No.
1
, pp.
59
-
82
.
Hampel
,
C.E.
and
Tracey
,
P.
(
2017
), “
How organizations move from stigma to legitimacy: the case of cook’s travel agency in Victorian Britain
”,
Academy of Management Journal
, Vol.
60
No.
6
, pp.
2175
-
2207
, doi: .
Hausken
,
K.
(
2020
), “
Cyber resilience in firms, organizations and societies
”,
Internet of Things
, Vol.
11
, p.
100204
, doi: .
Hepfer
,
M.
and
Lawrence
,
T.B.
(
2022
), “
The heterogeneity of organizational resilience: exploring functional, operational and strategic resilience
”,
Organization Theory
, Vol.
3
No.
1
, pp.
1
-
29
, doi: .
Herbane
,
B.
(
2010
), “
Small business research: time for a crisis-based view
”,
Strategic Direction
, Vol.
26
No.
8
, pp.
43
-
65
, doi: .
Herbane
,
B.
(
2019
), “
Rethinking organizational resilience and strategic renewal in SMEs
”,
Entrepreneurship and Regional Development
, Vol.
31
Nos
5/6
, pp.
476
-
495
, doi: .
Hillmann
,
J.
(
2021
), “
Disciplines of organizational resilience: contributions, critiques, and future research avenues
”,
Review of Managerial Science
, Vol.
15
No.
4
, pp.
879
-
936
, doi: .
Holling
,
C.S.
(
1973
), “
Resilience and stability of ecological systems
”,
Annual Review of Ecology and Systematics
, Vol.
4
No.
1
, pp.
1
-
23
, doi: .
Hollnagel
,
E.
(
2014
), “
Resilience engineering and the built environment
”,
Building Research and Information
, Vol.
42
No.
2
, pp.
221
-
228
.
Hollnagel
,
E.
,
Woods
,
D.D.
and
Leveson
,
N.
(
2006
),
Resilience Engineering: Concepts and Precepts
,
Ashgate Publishing
,
Aldershot
.
Hoppe
,
F.
,
Gatzert
,
N.
and
Gruner
,
P.
(
2021
), “
Cyber risk management in SMEs: insights from industry surveys
”,
The Journal of Risk Finance
, Vol.
22
Nos
3/4
, pp.
240
-
260
, doi: .
Hult
,
F.
and
Sivanesan
,
G.
(
2013
), “
What good cyber resilience looks like
”,
Journal of Business Continuity and Emergency Planning
, Vol.
7
No.
2
, pp.
112
-
125
.
Italian National Statistical Institute
(
2022a
), “
Enterprises and employees dataset
”,
available at:
http://dati.istat.it/index.aspx?queryid=20596
Italian National Statistical Institute
(
2022b
),
available at:
www.istat.it/it/archivio/277962
Itani
,
D.
,
Itani
,
R.
,
Eltweri
,
A.A.
,
Faccia
,
A.
and
Wanganoo
,
L.
(
2024
), “
Enhancing cybersecurity through compliance and auditing: a strategic approach to resilience
”,
2024 2nd International Conference on Cyber Resilience (ICCR)
, pp.
1
-
10
, doi:
Jahankhani
,
H.
,
Meda
,
L.N.K.
and
Samadi
,
M.
(
2022
), “Cybersecurity challenges in small and medium enterprise (SMEs)”, in
Jahankhani
,
H.
,
Kilpin
,
D.V.
and
Kendzierskyj
,
S.
(Eds),
Blockchain and Other Emerging Technologies for Digital Business Strategies
,
Springer International Publishing
,
Cham
, pp.
1
-
19
, doi: .
Kabanda
,
S.
,
Tanner
,
M.
and
Kent
,
C.
(
2018
), “
Exploring SME cybersecurity practices in developing countries
”,
Journal of Organizational Computing and Electronic Commerce
, Vol.
28
No.
3
, pp.
269
-
282
, doi: .
Kachgal
,
J.A.
(
2015
), “
The synergy needed for business resilience
”,
Journal of Business Continuity and Emergency Planning
, Vol.
9
No.
1
, pp.
10
-
17
.
Khan
,
T.Z.A.
,
Farooq
,
W.
and
Rasheed
,
H.
(
2019
), “
Organizational resilience: a dynamic capability of complex systems
”,
Journal of Management and Research
, Vol.
6
No.
1
, pp.
1
-
26
, doi: .
Lee
,
I.
(
2021
), “
Cybersecurity: risk management framework and investment cost analysis
”,
Business Horizons
, Vol.
64
No.
5
, pp.
659
-
671
, doi: .
Linkov
,
I.
,
Eisenberg
,
D.A.
,
Plourde
,
K.
,
Seager
,
T.P.
,
Allen
,
J.
and
Kott
,
A.
(
2013
), “
Resilience metrics for cyber systems
”,
Environment Systems and Decisions
, Vol.
33
No.
4
, pp.
471
-
476
, doi: .
Loonam
,
J.
,
Zwiegelaar
,
J.
,
Kumar
,
V.
and
Booth
,
C.
(
2022
), “
Cyber-resiliency for digital enterprises: a strategic leadership perspective
”,
IEEE Transactions on Engineering Management
, Vol.
69
No.
6
, pp.
3757
-
3770
, doi: .
McIlwraith
,
A.
(
2021
), “Information security and employee behaviour: how to reduce risk through employee education”,
Training and Awareness
, (2nd ed.)  
Routledge
,
New York, NY
, doi: .
McManus
,
S.T.
,
Seville
,
E.
,
Vargo
,
J.J.
and
Brunsdon
,
D.
(
2008
), “
Facilitated process for improving organizational resilience
”,
Natural Hazards Review
, Vol.
9
No.
2
, pp.
81
-
90
.
Miles
,
M.B.
and
Huberman
,
A.M.
(
1994
),
Qualitative Data Analysis
, (2nd ed.)  
Sage Publications
,
London
.
Miles
,
M.B.
,
Huberman
,
A.M.
and
Saldana
,
J.
(
2014
),
Qualitative Data Analysis: A Methods Sourcebook
,
Sage Publications
,
London
.
Neri
,
M.
,
Niccolini
,
F.
and
Francesco
,
V.
(
2023a
), “
Organizational resilience: state of the art and new future cyber inquiries
”,
Impresa Progetto
, Vol.
1
No.
1
, pp.
1
-
33
, doi: .
Neri
,
M.
,
Niccolini
,
F.
and
Martino
,
L.
(
2023b
), “
Organizational cybersecurity readiness in the ICT sector: a quanti-qualitative assessment
”,
Information and Computer Security
, doi: .
North
,
J.
and
Pascoe
,
R.
(
2016
), “
Cyber security and resilience—it’s all about governance
”,
Governance Directions
, Vol.
68
No.
2
, pp.
146
-
151
.
Nurse
,
J.
(
2019
), “
Cyber resilience: what is it and how do we get it?
”,
CREST Security Review Magazine
, Vol.
10
, p.
10
.
Onwuegbuzie
,
A.J.
and
Collins
,
K.M.
(
2007
), “
A typology of mixed methods sampling designs in social science research
”,
The Qualitative Report
, Vol.
12
No.
2
, pp.
281
-
316
, doi: .
Ortiz-de-Mandojana
,
N.
and
Bansal
,
P.
(
2016
), “
The long-term benefits of organizational resilience through sustainable business practices
”,
Strategic Management Journal
, Vol.
37
No.
8
, pp.
1615
-
1631
, doi: .
Osborn
,
J.K.
and
Sepulveda-Estay
,
D.A.
(
2021
), “
A comparative analysis of the impact-wave analogy cyber-resilience framework
”,
Proceedings of the 2021 IEEE International Conference on Industrial Engineering and Engineering Management (IEEM)
, pp.
333
-
337
, doi: .
Pal
,
R.
,
Torstensson
,
H.
and
Mattila
,
H.
(
2014
), “
Antecedents of organizational resilience in economic crises—an empirical study of Swedish textile and clothing SMEs
”,
International Journal of Production Economics
, Vol.
147
, pp.
410
-
428
, doi: .
Paulsen
,
C.
(
2016
), “
Cybersecuring small businesses
”,
Computer
, Vol.
49
No.
8
, pp.
92
-
97
, doi: .
Perera
,
S.
,
Jin
,
X.
,
Maurushat
,
A.
and
Opoku
,
D.-G.J.
(
2022
), “
Factors affecting reputational damage to organisations due to cyberattacks
”,
Informatics
, Vol.
9
No.
1
, doi: .
Petrosyan
,
A.
(
2023
), “
Annual cost of cybercrime worldwide 2017-2028
”,
available at:
www.statista.com/forecasts/1280009/cost-cybercrime-worldwide
Pinheiro
,
R.
,
Frigotto
,
M.L.
and
Young
,
M.
(
2022
),
Towards Resilient Organizations and Societies: A Cross-Sectoral and Multi-Disciplinary Perspective
,
Springer Nature
,
Bern
, doi: .
Quansah
,
E.
,
Hartz
,
D.E.
and
Salipante
,
P.
(
2022
), “
Adaptive practices in SMEs: leveraging dynamic capabilities for strategic adaptation
”,
Journal of Small Business and Enterprise Development
, Vol.
29
No.
7
, pp.
1130
-
1148
, doi: .
Rawindaran
,
N.
,
Jayal
,
A.
,
Prakash
,
E.
and
Hewage
,
C.
(
2023
), “
Perspective of small and medium enterprise (SME’s) and their relationship with government in overcoming cybersecurity challenges and barriers in Wales
”,
International Journal of Information Management Data Insights
, Vol.
3
No.
2
, p.
100191
, doi: .
Renaud
,
K.
and
Weir
,
G.R.S.
(
2016
),
Cybersecurity and the Unbearability of Uncertainty
,
IEEE
,
NJ
, doi: .
Saad
,
M.H.
,
Hagelaar
,
G.
,
van der Velde
,
G.
and
Omta
,
S.W.F.
(
2021
), “
Conceptualization of SMEs’ business resilience: a systematic literature review
”,
Cogent Business and Management
, Vol.
8
No.
1
, pp.
1
-
33
, doi: .
Saldaña
,
J.
(
2013
),
The Coding Manual for Qualitative Researchers
,
Sage Publications
,
London
.
Sawalha
,
I.H.S.
(
2015
), “
Managing adversity: understanding some dimensions of organizational resilience
”,
Management Research Review
, Vol.
38
No.
4
, pp.
346
-
366
.
Schinagl
,
S.
and
Shahim
,
A.
(
2020
), “
What do we know about information security governance? ‘from the basement to the boardroom’: towards digital security governance
”,
Information and Computer Security
, Vol.
28
No.
2
, pp.
261
-
292
, doi: .
Sepúlveda Estay
,
D.A.
,
Sahay
,
R.
,
Barfod
,
M.B.
and
Jensen
,
C.D.
(
2020
), “
A systematic review of cyber-resilience assessment frameworks
”,
Computers and Security
, Vol.
97
, p.
101996
, doi: .
Shaikh
,
F.A.
and
Siponen
,
M.
(
2024
), “
Organizational learning from cybersecurity performance: effects on cybersecurity investment decisions
”,
Information Systems Frontiers
, Vol.
26
No.
3
, pp.
1109
-
1120
, doi: .
Steen
,
R.
,
Haug
,
O.J.
and
Patriarca
,
R.
(
2024
), “
Business continuity and resilience management: a conceptual framework
”,
Journal of Contingencies and Crisis Management
, Vol.
32
No.
1
, p.
e12501
, doi: .
Su
,
W.
and
Junge
,
S.
(
2023
), “
Unlocking the recipe for organizational resilience: a review and future research directions
”,
European Management Journal
, Vol.
41
No.
6
, doi: .
Sukumar
,
A.
,
Mahdiraji
,
H.A.
and
Jafari-Sadeghi
,
V.
(
2023
), “
Cyber risk assessment in small and medium-sized enterprises: a multilevel decision-making approach for small e-tailors
”,
Risk Analysis
, Vol.
43
No.
10
, pp.
1
-
17
, doi: .
Sullivan-Taylor
,
B.
and
Branicki
,
L.
(
2011
), “
Creating resilient SMEs: why one size might not fit all
”,
International Journal of Production Research
, Vol.
49
No.
18
, pp.
5565
-
5579
, doi: .
Taherdoost
,
H.
(
2022
), “
Understanding cybersecurity frameworks and information security standards—a review and comprehensive overview
”,
Electronics
, Vol.
11
No.
14
, pp.
1
-
20
, doi: .
Tam
,
T.
,
Rao
,
A.
and
Hall
,
J.
(
2021
), “
The good, the bad and the missing: a narrative review of cyber- security implications for Australian small businesses
”,
Computers and Security
, Vol.
109
, p.
102385
, doi: .
Tejay
,
G.
and
Klein
,
G.
(
2021
), “
Organizational cybersecurity journal editorial introduction
”,
Organizational Cybersecurity Journal: Practice, Process and People
, Vol.
1
No.
1
, pp.
1
-
4
, doi: .
Trend Micro
(
2023
), “
Malware Q1: l’Italia è sempre la terza nazione al mondo più attaccata
”,
available at:
www.trendmicro.com/it_it/about/newsroom/press-releases/2023/20230515-malware-q1-l-italia-e-sempre-la-terza-nazione-al-mondo-piu-attaccata.html
Trim
,
P.R.J.
and
Lee
,
Y.-I.
(
2021
), “
The global cyber security model: counteracting cyber attacks through a resilient partnership arrangement
”,
Big Data and Cognitive Computing
, Vol.
5
No.
3
, doi: .
Tsen
,
E.
,
Ko
,
R.K.L.
and
Slapnicar
,
S.
(
2022
), “
An exploratory study of organizational cyber resilience, its precursors and outcomes
”,
Journal of Organizational Computing and Electronic Commerce
, Vol.
32
No.
2
, pp.
153
-
174
, doi: .
Uchendu
,
B.
,
Nurse
,
J.R.C.
,
Bada
,
M.
and
Furnell
,
S.
(
2021
), “
Developing a cyber security culture: current practices and future needs
”,
Computers and Security
, Vol.
109
, p.
102387
, doi: .
van der Kleij
,
R.
and
Leukfeldt
,
E.
(
2019
),
Cyber Resilient Behavior: Integrating Human Behavioral Models and Resilience Engineering Capabilities into Cyber Security
,
Springer
,
Cham
, pp.
16
-
27
, doi: .
Verizon
(
2023
), “
Data breach investigations report
”,
available at:
www.verizon.com/business/resources/Ta5a/reports/2023-dbir-public-sector-snapshot.pdf
Verizon
(
2024
), “
Data breach investigations report
”,
available at:
www.verizon.com/business/resources/reports/dbir/
Wilding
,
N.
(
2016
), “
Cyber resilience: how important is your reputation? How effective are your people?
”,
Business Information Review
, Vol.
33
No.
2
, pp.
94
-
99
, doi: .
Wilson
,
M.
,
McDonald
,
S.
,
Button
,
D.
and
McGarry
,
K.
(
2022
), “
It won’t happen to me: surveying SME attitudes to cyber-security
”,
Journal of Computer Information Systems
, Vol.
63
No.
2
, pp.
1
-
13
, doi: .
Woods
,
D.D.
(
2015
), “
Four concepts for resilience and the implications for the future of resilience engineering
”,
Reliability Engineering and System Safety
, Vol.
141
, pp.
5
-
9
.
Yigit Ozkan
,
B.
,
van Lingen
,
S.
and
Spruit
,
M.
(
2021
), “
The cybersecurity focus area maturity (CYSFAM) model
”,
Journal of Cybersecurity and Privacy
, Vol.
1
No.
1
, doi: .
Youssef
,
C.M.
and
Luthans
,
F.
(
2007
), “
Positive organizational behavior in the workplace: the impact of hope, optimism, and resilience
”,
Journal of Management
, Vol.
33
No.
5
, pp.
774
-
800
, doi: .
Zdravkovic
,
J.
,
Stirna
,
J.
and
Sandkuhl
,
K.
(
2018
), “Future of capability management”, in
Sandkuhl
,
K.
and
Stirna
,
J.
(Eds),
Capability Management in Digital Enterprises
,
Springer International Publishing
,
Cham
, pp.
385
-
396
, doi: .
Hillmann
,
J.
and
Guenther
,
E.
(
2021
), “
Organizational resilience: a valuable construct for management research?
”,
International Journal of Management Reviews
, Vol.
23
No.
1
, pp.
7
-
44
, doi: .
Hillmann
,
J.
,
Duchek
,
S.
,
Meyr
,
J.
and
Guenther
,
E.
(
2018
), “
Educating future managers for developing resilient organizations: the role of scenario planning
”,
Journal of Management Education
, Vol.
42
No.
4
, pp.
461
-
495
, doi: .
Ho
,
G.K.S.
,
Lam
,
C.
and
Law
,
R.
(
2023
), “
Conceptual framework of strategic leadership and organizational resilience for the hospitality and tourism industry for coping with environmental uncertainty
”,
Journal of Hospitality and Tourism Insights
, Vol.
6
No.
2
, pp.
835
-
852
, doi: .
Hollnagel
,
E.
(
2006
), “Resilience: the challenge of the unstable”, in
Hollnagel
,
E.
,
Woods
,
D.D.
and
Leveson
,
N.C.
(Eds),
Resilience Engineering: Concepts and Precepts
,
Ashgate
,
Aldershot
.
Ma
,
Z.
,
Xiao
,
L.
and
Yin
,
J.
(
2018
), “
Toward a dynamic model of organizational resilience
”,
Nankai Business Review International
, Vol.
9
No.
3
, pp.
246
-
263
, doi: .
Woods
,
D.D.
(
2006
), “Essential characteristics of resilience”, in
Hollnagel
,
E.
,
Woods
,
D.D.
and
Leveson
,
N.
(Eds),
Resilience Engineering: Concepts and Precepts
,
Ashgate Publishing
,
Aldershot
, pp.
21
-
34
.
Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence maybe seen at Link to the terms of the CC BY 4.0 licenceLink to the terms of the CC BY 4.0 licence.

or Create an Account

Close subscription notice
Close access options