System update
On Tuesday, August 18th, between 12-1pm, a planned system update of DiVA will take place. During this time, DiVA will not be available.
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
IT Security in Small and Medium-Sized Enterprises: A Qualitative Study on Drivers and Barriers regarding IT security investments and SOC-functions Prioritization
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
2026 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Small and medium-sized enterprises (SMEs) face increasing exposure to cyberattacks while operating under significant constraints related to limited budgets, scarce in-house cybersecurity expertise, and low security maturity. This study examines two interrelated questions: what drivers and barriers determine when SMEs invest in IT security, and how Security Operations Center (SOC) functions can be prioritized under resource constraints. The study applies a qualitative approach based on nine semi-structured interviews with five SME decision-makers and four cybersecurity professionals, analyzed through abductive thematic analysis. The findings show that SME investments in IT security are primarily reactive and event-driven, triggered by direct incidents or enforceable external pressures such as regulatory, customer, and insurance requirements. These drivers operate against mutually reinforcing internal barriers, including the perception of security as a pure cost, lack of internal competence, and structural dependence on external providers. For SOC prioritization, the study identifies a previously overlooked "Before SOC" phase emphasizing consequence analysis, activation of paid-for license features, and environment inventory. Endpoint Detection and Response with automated response and phishing detection emerge as the highest-priority core functions. The findings are synthesized into a three-phase prioritization model.

Place, publisher, year, edition, pages
2026. , p. 69
Keywords [en]
Small and Medium-Sized Enterprises (SMEs), Cyber Resilience, Cybersecurity Investment, Qualitative Study, Security Operations Center (SOC), SOC Prioritization
National Category
Information Systems
Identifiers
URN: urn:nbn:se:hj:diva-73464OAI: oai:DiVA.org:hj-73464DiVA, id: diva2:2089266
Subject / course
JTH, Informatics
Supervisors
Examiners
Available from: 2026-08-03 Created: 2026-08-02 Last updated: 2026-08-03Bibliographically approved

Open Access in DiVA

IT Security in Small and Medium-Sized Enterprises(796 kB)32 downloads
File information
File name FULLTEXT01.pdfFile size 796 kBChecksum SHA-512
8a356487c256bccb98a839aa8149bcd09dd5cdaa6bd016c136eaf2b6fc30858ca52912a61eb9f65c3997bbcd4a300101609fe54544aa20d8d011ccb881b924d3
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Schoenherr, LucasSandberg, WilliamKlackensjö, Måns
By organisation
JTH, Department of Computer Science and Informatics
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 180 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf