Governance provides Small-Medium Size enterprises (SMEs) with a framework to establish clear lines of accountability and responsibility for cybersecurity. It also enables SMEs to comply with legal requirements and manage cybersecurity risks.
According to a report by the National Institute of Standards and Technology (NIST), cybersecurity governance frameworks help SMEs identify, assess, and manage cybersecurity risks effectively (NIST, 2018). The structure of a cyber-security framework for an SME can cover different layers of security such as processes and policies that comply with standards, regulations, network security and asset protection (Emer et al., 2021).
According to the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD) (2022), the most impacted businesses within Australia during the 2021–22 financial year were medium enterprises who tend to be less vigilant compared to larger corporations.
According to the NIST case study on Small Enterprises (Hotel CEO Finds Unwelcome Guests in Email Account, n.d.), we can determine that small businesses can avoid risks that can potentially cause harm by embracing cybersecurity.
In conclusion, governance is important for medium and small enterprises as it could potentially save businesses from possible disasters, providing guidance on how to protect, mitigate, or recover from cyber attacks.
References
- NIST. (2018). Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. https://doi.org/10.6028/nist.cswp.04162018
- The Australian Cyber Security Centre (ACSC) & the Australian Signals Directorate (ASD). (2022). Annual Cyber Threat Report 2021–22.
- NIST. (n.d.). Hotel CEO Finds Unwelcome Guests in Email Account. Small Business Cybersecurity Corner.