Assessing Ransomware Victimization Among Freelancers and Small and Medium-Sized Enterprises Using the Lifestyle-Routine Activity Approach
ABSTRACT This study examined the association between components of the lifestyle-routine activity approach and the odds of ransomware victimization using survey data collected among freelancers and small and medium-sized enterprises in the Netherlands (n = 2,685). Some findings aligned with the notion that greater target attractiveness and lower physical guardianship are associated with increased odds of victimization. Namely, a higher annual turnover and not using two-factor authentication were associated with increased odds of ransomware victimization. At the same time, other results diverged from theoretical expectations. For example, not using an online bank account to which customers can transfer payments, not using security software that scans for viruses and malware, and having cyber insurance were associated with decreased odds of ransomware victimization. This contradicts the notion that greater online exposure, lower physical guardianship, and greater target attractiveness are associated with increased odds of victimization. Moreover, several measures related to the lifestyle-routine activity approach, such as social guardianship, were not statistically significant. Overall, the findings suggest that ransomware victimization can be partially explained by exposure to motivated offenders, target attractiveness, and guardianship. The implications of the findings for theory and practice are addressed in the paper.
- Research Article
6
- 10.1108/jrf-05-2024-0151
- Jan 2, 2025
- The Journal of Risk Finance
PurposeThe cyber insurance market in Germany shows a notable gap: while many large corporations are already demanding cyber insurance, small and medium-sized enterprises (SMEs) are still reluctant, despite its benefits. This study aims to analyze the behavioral and informational factors that influence cyber insurance decision-making and uncover the determinants that may inhibit demand among German SMEs.Design/methodology/approachUsing the data from a questionnaire survey of 1,248 German SME executives, the influence of behavioral and informational factors on cyber insurance demand is assessed utilizing logistic regression.FindingsThe results reveal that the estimated financial impact and anxiety about a potential cyberattack significantly increase the likelihood of SMEs purchasing cyber insurance. Conversely, the perceived probability of future cyberattacks and prior experience do not significantly influence insurance decisions, probably due to challenges in probability estimation. In addition, confidence in the organization’s cyber risk management has a positive but insignificant influence on cyber insurance demand. External cybersecurity specialists positively impact cyber insurance demand, while internal cyber risk assessment has no significant influence, highlighting the challenges SMEs face in cyber risk assessment. Independent Internet research negatively impacts the purchase of cyber insurance, probably due to information overload.Originality/valueThis study significantly contributes to the literature on corporate (cyber) insurance purchasing by primarily focusing on behavioral influences on SMEs’ insurance decision-making. It is also the first empirical analysis of the key information sources used by SMEs in their insurance decision-making, thereby providing various academic and practical implications.
- Research Article
- 10.56975/jetir.v12i10.569274
- Jan 1, 2025
- Journal of Emerging Technologies and Innovative Research
Cybersecurity insurance, commonly referred to as cyber insurance, serves as a critical product for businesses to mitigate risks associated with cyber crime activities such as cyberattacks and data breaches. This manuscript explores the definition, importance, functionality, coverage areas, exclusions, and broader implications of cyber insurance based on detailed examinations of its components. It discusses how cyber insurance operates similarly to traditional insurance, covering first-party and third-party losses, and emphasizes its role in financial protection, legal support, and remediation following cyber incidents. Key risks covered include customer notifications, data recovery, system damage repair, ransom demands, and attack remediation, while exclusions encompass poor security processes, prior breaches, human error, insider attacks, preexisting vulnerabilities, and technology system improvements. The manuscript highlights that cyber insurance is not a substitute for robust cyber defense strategies and outlines steps to reduce cyber risk through assessment, implementation, and insurance procurement. Benefits such as forensic support, coverage for data breaches and cyber extortion, affordability, and protection against various cyber threats are detailed. Requirements for obtaining cyber insurance, including multi-factor authentication, cybersecurity training, data backups, identity access management, and data classification, are examined. The discussion extends to why cyber insurance costs are justified, factors influencing costs, average pricing, market dynamics, and major loss drivers like ransomware, business email compromise, data breaches, and supply chain vulnerabilities. This comprehensive overview underscores the necessity of integrating cyber insurance with proactive cybersecurity measures to enhance organizational resilience in a digitized economy.
- Research Article
19
- 10.3390/su15010801
- Jan 2, 2023
- Sustainability
Although agile methods gained popularity and became globally widespread, developing secure software with agile methods remains a challenge. Method elements (i.e., roles, activities, and artifacts) that aim to increase software security on one hand can reduce the characteristic agility of agile methods on the other. The overall aim of this paper is to provide small- and medium-sized enterprises (SMEs) with the means to improve the sustainability of their software development process in terms of software security despite their limitations, such as low capacity and/or financial resources. Although software engineering literature offers various security elements, there is one key research gap that hinders the ability to provide such means. It remains unclear not only how much individual security elements contribute to software security but also how they impact the agility and costs of software development. To address the gap, we identified security elements found in the literature and evaluated them for their impact on software security, agility, and costs in an international study among practitioners. Finally, we developed a novel lightweight approach for evaluating agile methods from a security perspective. The developed approach can help SMEs to adapt their software development to their needs.
- Research Article
2
- 10.29119/1641-3466.2023.179.32
- Jan 1, 2023
- Scientific Papers of Silesian University of Technology Organization and Management Series
The goal of this paper is to investigate how cyber risk perception influences medium and large companies' decisions to purchase cyber insurance. Design/methodology/approach: The study collected data from 386 managers in medium and large Polish enterprises through a questionnaire. It examined managerial perceptions of cyber risk, considering firm attributes like size, age, and type. Various statistical methods, including Pearson's chi-square test, multiple correspondence analysis, and the random forests classifier, were employed for comprehensive data analysis. Findings: The study highlighted the pivotal role that perceptions of cyber risk play in shaping decisions concerning cyber insurance. Managers' perceptions regarding the gravity and probability of cyber threats had a significant impact on the choices made by their organizations. Furthermore, the study identified the presence of the availability heuristic as a noteworthy factor influencing decision-making in the realm of cyber insurance. Moreover, specific determinants emerged as influential in a company's decision to invest in cyber coverage. These determinants encompassed the size of the employee base, annual turnover, the severity of previous cyber losses, and the frequency of successful cyber-attacks experienced by the firm over the preceding five years.
- Research Article
- 10.1016/j.cose.2025.104818
- Dec 1, 2025
- Computers & Security
Cyber insurance is increasingly positioned as a complementary tool for managing cyber risk, yet Small to Medium-Sized Enterprises (SMEs) remain underrepresented in its adoption. This study investigates the perceptions, decision-making dynamics, and support needs of SMEs regarding cyber insurance, drawing on 38 semistructured interviews with SMEs, insurers, brokers, and other relevant stakeholders. The findings reveal that many SMEs deprioritise cyber insurance; not because they dismiss its importance outright, but due to a combination of limited awareness, concerns over cost, and a perception that its value is minimal unless required by clients or regulators. This hesitation is further shaped by several key barriers: complex policy language, a lack of trust in insurers, and unclear internal ownership of cybersecurity responsibilities. Despite these challenges, the study identifies promising strategies to boost adoption. These include simplifying policy structures, fostering trust through collaborative awareness efforts, introducing financial incentives tailored to SME budgets, and offering accessible, user-friendly tools that help businesses assess their cyber risks and insurance needs. By identifying actionable strategies and addressing both cultural and structural barriers, this study contributes to efforts to enhance cybersecurity resilience in the SME sector.
- Research Article
30
- 10.3390/su11123441
- Jun 22, 2019
- Sustainability
This study discusses the organizational characteristics, driving factors, and value perceptions of small- and medium-sized construction enterprises in information and communication technology (ICT) implementation and investigates how the heterogeneous impacts of these features on subsequent ICT implementation practices are manifested. Based on questionnaire responses provided by 338 respondents from the Chinese construction industry, these associations were empirically tested using statistical methods, such as t-test, ANOVA, and correlation test. The analysis results indicate that the engagement of small- and medium-sized enterprises (SMEs) in ICT is a function of their annual sales turnover and the location in which they are operating, but no correlation was found with age, ownership structure, or business type. Moreover, strategic orientation was found to be the most effective driver in determining SMEs’ ICT-level, followed by pressures from competitors, incentive and mandatory policies from the government, intentions to improve work efficiency and quality, and ICT requirements from clients and partners, in that order. The findings further reveal that the differences in value perceptions generated after the adoption of ICT is the reason why SMEs tend to adopt less expensive ICT, that is, to use packaged rather than customized ICT, which can improve efficiency quickly, without considering the long-term benefits of the selected ICT. These findings provide insights for researchers and policymakers, allowing them to develop an in-depth understanding of the stimuli that are advantageous in ICT implementation in construction SMEs in developing countries.
- Research Article
2
- 10.1504/ijbg.2021.111961
- Jan 1, 2021
- International Journal of Business and Globalisation
Drawing from two cognitive theories (i.e., values theory and theory of planned behaviour), this study proposes a theoretically driven integrated model to offer entrepreneurship scholars a richer understanding of small and medium-sized entrepreneurs' psychological process of how their individualistic values are translated to export intention to new markets. Survey data from 243 Malaysian owners and managers of food and beverages companies were analysed with the structural equation modelling technique. The theoretically driven integrative model is empirically supported. Specifically, intrinsic motivations of self-direction and stimulation drive small and medium-sized entrepreneurs' export intentions to new markets, suggesting small and medium-sized entrepreneurs' goals of self-actualisation, self-development, growth and self-expansion. The proposed integrative model extends existing entrepreneurship theory and research and contributes to a more sophisticated theoretical model of the entrepreneurial process, that is, extended form of the theory of planned behaviour. The findings are valuable in forming the necessary basis for encouraging and developing entrepreneurial internationalisation activities.
- Research Article
2
- 10.1504/ijbg.2021.10033694
- Nov 20, 2020
- International Journal of Business and Globalisation
Drawing from two cognitive theories (i.e., values theory and theory of planned behaviour), this study proposes a theoretically driven integrated model to offer entrepreneurship scholars a richer understanding of small and medium-sized entrepreneurs' psychological process of how their individualistic values are translated to export intention to new markets. Survey data from 243 Malaysian owners and managers of food and beverages companies were analysed with the structural equation modelling technique. The theoretically driven integrative model is empirically supported. Specifically, intrinsic motivations of self-direction and stimulation drive small and medium-sized entrepreneurs' export intentions to new markets, suggesting small and medium-sized entrepreneurs' goals of self-actualisation, self-development, growth and self-expansion. The proposed integrative model extends existing entrepreneurship theory and research and contributes to a more sophisticated theoretical model of the entrepreneurial process, that is, extended form of the theory of planned behaviour. The findings are valuable in forming the necessary basis for encouraging and developing entrepreneurial internationalisation activities.
- Conference Article
56
- 10.1109/hicss.2005.245
- Apr 1, 2005
This paper investigates the relationship of enterprise size to the constraints and objectives of Enterprise Resource Planning (ERP) systems adoption. The survey data based on the responses of 44 companies indicates that significant differences exist between small, medium-sized and large enterprises in ERP system adoption. Specifically, the findings suggest that small companies experience more knowledge constraints than their larger counterparts in ERP adoption. Further, while being the most prevalent objective for ERP adoption in all the company groups, business development through ERP adoption is considered especially important by the medium-sized and large enterprises. Finally, the findings of the study suggest that instead of considering small and medium-sized enterprises as one homogenous group, the differences between these two groups of companies should be acknowledged in the future research.
- Research Article
1
- 10.3390/admsci15120481
- Dec 10, 2025
- Administrative Sciences
Small- and Medium-sized Enterprises (SMEs) play a crucial role in the global economy, accounting for approximately two-thirds of global employment and contributing significantly to the GDP of developed countries. Despite the availability of various cybersecurity standards and frameworks, SMEs remain highly vulnerable to cyber threats. Limited resources and a lack of expertise in cybersecurity make them frequent targets for cyberattacks. It is essential to identify the challenges faced by SMEs and explore effective defensive strategies to enhance the implementation of cybersecurity measures. The study aims to bridge the gap and help these organizations in implementing cost-effective and practical cybersecurity approaches through a systematic mapping study (SMS) conducted, where 73 articles were thoroughly reviewed. This research will shed light on the current cybersecurity approaches (practices) posture for different SMEs, along with the threats they are facing, which have stopped them from deciding, planning, and implementing cybersecurity measures. The study identified a wide range of cybersecurity threats, including phishing, social engineering, insider threats, ransomware, malware, denial of services attacks, and weak password practices, which are the most prevalent for SMEs. This study identified defensive practices, such as cybersecurity awareness and training, endpoint protection tools, incident response planning, network segmentation, access control, multi-factor authentication (MFA), access controls, privilege management, email authentication and encryption, enforcing strong password policies, cloud security, secure backup solutions, supply chain visibility, and automated patch management tools, as key measures. The study provides valuable insights into the specific gaps and challenges faced by SMEs, as well as their preferred methods of seeking and consuming cybersecurity assistance. The findings can guide the development of targeted defensive practices and policies to enhance the cybersecurity posture of SMEs for successful software development. This SMS will also provide a foundation for future research and practical guidelines for SMEs to improve the process of secure software development.
- Research Article
- 10.22139/jobs.1623655
- Mar 27, 2025
- İşletme Bilimi Dergisi
In this study, the importance and effectiveness of cyber hygiene in remote working environments during the digital age were examined. The results revealed that many employees lack sufficient knowledge about cybersecurity, and companies face difficulties in implementing cyber hygiene policies. With the increase in remote working, the necessity of taking stronger measures against cyber threats has been emphasized. Cyber Hygiene Training: Regular cybersecurity training should be provided for employees. Security Policies: Special cybersecurity policies for remote work should be developed and implemented. Security Software: Antivirus and other security software should be used and kept up to date. Two-Factor Authentication (2FA): 2FA should be made mandatory to enhance account security. Data Encryption: End-to-end encryption methods should be applied for sensitive data. Data Backup: Regular data backup policies should be followed. Audits: Regular cybersecurity audits should be conducted, and vulnerabilities should be addressed. Awareness Campaigns: Campaigns should be organized to raise employees' awareness of cyber threats. These recommendations provide strategic steps to enhance cybersecurity in remote working environments and minimize cyber threats.
- Book Chapter
- 10.4018/979-8-3373-5571-9.ch012
- Jan 23, 2026
Little is known about how small and medium-sized enterprises in developing economies utilise information and communications technology (ICT) to facilitate effective knowledge management, supporting their commitment to socially responsible and sustainable business transformation. This study addresses the research gap by investigating how SMEs can transform their business operations into a socially and environmentally sustainable manner by nurturing their strategic ICT orientation (ICTO) to build dynamic knowledge management capabilities. Using survey data from over 400 small and medium-sized manufacturing enterprises in Vietnam, this study reveals positive correlations between ICTO and dynamic knowledge management capabilities, which contribute to environmental sustainability engagement in business. The focus on Vietnam highlights the socially responsible transformations of firms in emerging economies during the digital era.
- Research Article
- 10.56347/jics.v4i2.318
- Nov 30, 2025
- Journal Innovations Computer Science
This study presents the design, implementation, and validation of a cloud security architecture on Amazon Web Services (AWS) that integrates Defense in Depth strategies with Identity and Access Management (IAM) Best Practices, tailored for small and medium-sized enterprises (SMEs). Using the AWS Free Tier, an experimental cloud infrastructure was constructed to evaluate the effectiveness of multi-layered protection encompassing network segmentation, least-privilege access control, and real-time monitoring. The architecture employed a segmented Virtual Private Cloud (VPC) with public and private subnets, controlled by Security Groups (SGs) and Network Access Control Lists (NACLs), while IAM policies and Multi-Factor Authentication (MFA) enforced identity-level security. Centralized monitoring through CloudTrail and CloudWatch enabled anomaly detection and event logging with high accuracy. Test results showed that unauthorized access was effectively blocked, suspicious activities were detected promptly, and all administrative actions were recorded reliably. The findings indicate that combining layered network defenses and IAM governance significantly enhances the resilience, visibility, and security posture of SMEs adopting AWS environments. Beyond its technical effectiveness, the model offers scalability, auditability, and cost-efficiency—demonstrating that enterprise-grade protection can be achieved even within the resource constraints of SMEs. Future work is encouraged to integrate automation and advanced AWS tools such as GuardDuty and Config to strengthen real-world adaptability and compliance.
- Research Article
1
- 10.18196/mb.v16i2.25192
- Aug 29, 2025
- Jurnal Manajemen Bisnis
Research aims: Using influence and route analysis tests, this study will examine how digital marketing, intellectual capital, item innovation, and competitive advantage have been used to boost the achievement of micro, small, and medium-sized enterprises (MSMEs).Design/Methodology/Approach: The researchers in this study used a quantitative research strategy based on survey data. Due to its sheer size and employment density, the food and beverage industry in East Java is chosen as the study's population of micro, small, and medium-sized enterprises (MSMEs). Probability sampling is the method used for the sampling. Various tests are employed in data analysis, including validity, reliability, hypothesis, and route analysis.Research findings: Based on the findings, digital marketing, intellectual capital, and item innovation are factors that impact MSME achievement and competitive advantage to a lesser extent. Furthermore, MSMEs' success is partially impacted by digital marketing, intellectual capital, and item innovation, all of which contribute to their competitive edge.Theoretical Contribution/Originality: This study addresses a gap in the literature by investigating the factors that contribute to the improvement of achievement for micro, small, and medium-sized enterprises (MSME), specifically looking at the effects of digital marketing, intellectual capital, and item innovation. Here, variables such as market domination, new item development, IQ, and internet advertising come into play. By exploring how this generation's digital marketing and intellectual capital function, the study adds to the field's knowledge.Practitioners/Policy Implications: Findings from this research stress the need for a multi-faceted strategy to boost MSME performance, rather than a singular emphasis on digital marketing, ICM, item innovation, and competitive advantage. With this in mind, it is anticipated that MSME players would devise plans that incorporate these four aspects in order to improve market competitiveness and welfare.Research Limitations/Implications: Although the results are significant, there are a number of caveats to this study. It is possible that the study's geographical scope and the industries it examined are too narrow. The success of micro, small, and medium-sized enterprises (MSME) in areas such as digital marketing, IP, item innovation, and competitive advantage could differ in different regions and sectors. Hence, due to variations in technical infrastructure, resources, and markets, it is possible that not all MSMEs or locations may be completely served by this study's findings.
- Research Article
- 10.61707/xn5xyv71
- Jul 24, 2024
- International Journal of Religion
This research was conducted to evaluate and measure the capabilities of management and operating small and medium-sized enterprises in Hai Phong City. Small and medium-sized enterprises in Hai Phong City with limited resources are facing fierce competition in the context of increasingly deep international integration. A survey was conducted through the analysis of survey data from 210 respondents working in small and medium-sized enterprises in Hai Phong City, including middle managers and employees. Analytical methods such as independent t-tests and ANOVA analyses are used to test and measure the scales. Analysis results based on descriptive statistical methods, comparison methods with an independent T-test, and ANOVA analysis show that, there is no statistically significant difference in the capabilities of management and operating small and medium-sized enterprises in Hai Phong City of Leaders between these different genders, job position, labor scale, and main business sectors. There is a statistically significant difference in the capabilities of management and operating small and medium-sized enterprises in Hai Phong City of Leaders between these different academic levels, and professional seniority. This research uses the contents of the theoretical and practical basis for human resource management in general and the capabilities of management and operating firm leaders in particular. Within the context of international economic integration, these variables are useful solutions for SMEs. The paper's primary contribution is findings that benefit the SMEs in Hai Phong City in the improvement of their scale expansion and business performance. Therefore, SMEs should focus on enhancing the capacity of their board of directors, thereby improving their leadership and management capabilities and contributing to improved business performance.