Cybersecurity4 min read

Governance: A Cybersecurity Lifeline for SMEs

How cybersecurity governance frameworks help small and medium enterprises identify, assess, and manage risks, and why the most impacted businesses in Australia are often the ones with the least protection.

Marco Cavani

Marco Cavani

Cybersecurity Analyst

|
Governance: A Cybersecurity Lifeline for SMEs

Governance provides Small-Medium Size enterprises (SMEs) with a framework to establish clear lines of accountability and responsibility for cybersecurity. It also enables SMEs to comply with legal requirements and manage cybersecurity risks.

According to a report by the National Institute of Standards and Technology (NIST), cybersecurity governance frameworks help SMEs identify, assess, and manage cybersecurity risks effectively (NIST, 2018). The structure of a cyber-security framework for an SME can cover different layers of security such as processes and policies that comply with standards, regulations, network security and asset protection (Emer et al., 2021).

According to the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD) (2022), the most impacted businesses within Australia during the 2021–22 financial year were medium enterprises who tend to be less vigilant compared to larger corporations.

According to the NIST case study on Small Enterprises (Hotel CEO Finds Unwelcome Guests in Email Account, n.d.), we can determine that small businesses can avoid risks that can potentially cause harm by embracing cybersecurity.

In conclusion, governance is important for medium and small enterprises as it could potentially save businesses from possible disasters, providing guidance on how to protect, mitigate, or recover from cyber attacks.


References

  • NIST. (2018). Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. https://doi.org/10.6028/nist.cswp.04162018
  • The Australian Cyber Security Centre (ACSC) & the Australian Signals Directorate (ASD). (2022). Annual Cyber Threat Report 2021–22.
  • NIST. (n.d.). Hotel CEO Finds Unwelcome Guests in Email Account. Small Business Cybersecurity Corner.
#Governance#SME#Cybersecurity#NIST#Risk Management#ACSC
Marco Cavani

Written by

Marco Cavani

Cybersecurity analyst and IT governance professional. Author of digital reports on threat intelligence, critical infrastructure security, and IT audit frameworks.

Related articles

Network Segmentation and VPN for Critical Infrastructure
Cybersecurity8 min read

Network Segmentation and VPN for Critical Infrastructure

In critical infrastructure a network breach is not a data problem, it is a physical one. Here is why segmentation is the control that keeps a compromised laptop away from a turbine, and why the VPN meant to protect the network is so often the way in.

Read more →
Critical InfrastructureNetwork SegmentationVPN

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.

ITGC Audit Tool

Streamline Your IT General Controls Audits

The RACM ITGC SaaS platform helps audit professionals manage IT General Controls assessments, from risk and control mapping to workpaper generation and evidence tracking.