Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Assessing Organizational Readiness for Information Security in Multi-Site SME: A Case Study Focused on Human Aspect
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Implementing information security measures across geographically dispersed units depends heavily on human factors dictating employee security practices and organizational readiness. This research investigates how human factors affect an organization’s readiness to implement information security measures in a multi-site SME context.

The study employs a cybersecurity cultural framework, specifically focusing on its individual level, encompassing four key dimensions: knowledge, awareness, attitudes, and behavior. The S-HAIS-Q instrument was utilized to assess these dimensions, measuring individual security practices across six critical focus areas: password management, email use, internet use, social media use, mobile device security, and incident reporting. Empirical data was collected through surveys (52 participants) and interviews (three managers) across three locations.

Statistical analysis revealed strong correlations between all human factor dimensions (r = 0.824∗∗ to 0.953∗∗, p < 0.01), demonstrating their interconnected roles in determining organization readiness for information security. While most dimensions showed consistency across locations, the knowledge dimension scores varied significantly by location.

The results show that human factors operate as an integrated system, where improvements in one dimension positively influence others. The study recommends a Human-Centric Security Readiness Model focused on systematic assessment, communication, and integrated training to enhance organizational readiness to implement information security measures.

Place, publisher, year, edition, pages
2025. , p. iv, 77
Keywords [en]
Human factors, Organizational readiness, Information security awareness, Cybersecurity Culture Framework, S-HAIS-Q
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-25485OAI: oai:DiVA.org:his-25485DiVA, id: diva2:1983530
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-07-11 Created: 2025-07-11 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(877 kB)308 downloads
File information
File name FULLTEXT01.pdfFile size 877 kBChecksum SHA-512
f5e2cada5f77cc2f0b6f32c9fcf7b4040cdfc58b5051146d5e97cac0824bc9c897fbdbdc12d75676c8a7b4b5d091eb368abc9a5227dbe65dafeabdcbe965a10b
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 312 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 195 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf