Supply Chain Cybersecurity and Small and Medium-Sized Enterprises (SMEs): Exploring Shortcomings in Third Party Risk Management of SMEs
| dc.contributor.author | Kwong, Jillian | |
| dc.contributor.author | Pearlson, Keri | |
| dc.date.accessioned | 2023-12-26T18:50:48Z | |
| dc.date.available | 2023-12-26T18:50:48Z | |
| dc.date.issued | 2024-01-03 | |
| dc.identifier.doi | https://doi.org/10.24251/HICSS.2024.797 | |
| dc.identifier.isbn | 978-0-9981331-7-1 | |
| dc.identifier.other | e5b406a4-c1ef-46c7-a798-46a907b9f363 | |
| dc.identifier.uri | https://hdl.handle.net/10125/107183 | |
| dc.language.iso | eng | |
| dc.relation.ispartof | Proceedings of the 57th Hawaii International Conference on System Sciences | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | Practice-based IS Research | |
| dc.subject | cyber risk management | |
| dc.subject | cybersecurity | |
| dc.subject | small and medium-sized enterprises | |
| dc.subject | supply chains | |
| dc.subject | third party risk assessments | |
| dc.title | Supply Chain Cybersecurity and Small and Medium-Sized Enterprises (SMEs): Exploring Shortcomings in Third Party Risk Management of SMEs | |
| dc.type | Conference Paper | |
| dc.type.dcmi | Text | |
| dcterms.abstract | Small and medium-sized enterprises (SMEs) have long been known to be a weak link in supply chain cybersecurity. Despite their crucial role in the global supply chain, SMEs and their struggle to increase cyber resiliency and improve their defenses is understudied in academic literature. This paper uses qualitative research methods to conduct an empirical study of the challenges SMEs encounter when participating in third party cybersecurity risk assessments. Using interviews with cybersecurity and supply chain practitioners, this study provides an overview of four major risk assessment methods (i.e., questionnaires, audits and certifications, security rating services, and direct testing) and the problems that arise when companies apply tools designed for large corporations to SMEs. Results discuss how and why traditional methods fail and offers insights on how to improve third party risk of SMEs moving forward. | |
| dcterms.extent | 9 pages | |
| prism.startingpage | 6656 |
Files
Original bundle
1 - 1 of 1
