Enhancing Cyber Resilience of Small and Medium-sized Enterprises through Cyber Security Communities of Support
通过网络安全支持社区增强中小企业的网络弹性
基本信息
- 批准号:EP/X037282/1
- 负责人:
- 金额:$ 88.09万
- 依托单位:
- 依托单位国家:英国
- 项目类别:Research Grant
- 财政年份:2023
- 资助国家:英国
- 起止时间:2023 至 无数据
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Small and Medium-sized Enterprises (SMEs) are a vital element of the economy, accounting for 99.9% of UK businesses, generating three fifths of employment and turnover of £2.3 trillion. They are a crucial asset requiring protection as part of our overall national resilience. Unfortunately, the UK Cyber Security Breaches Survey indicates that half of small and a third of micro businesses experienced breaches or attacks in the last year. Moreover, while they frequently seek external guidance in relation to cyber security, they do so via a huge range of sources, and often find themselves overwhelmed with information and unable to understand the advice. Research is required to better understand SME needs and the perspective of those that they turn to for support, and to then use these insights as a foundation for the design and evaluation of a new and more accessible approach. The research begins with an investigation of the support needs of small businesses, to establish their current understanding and confidence around cyber security, and their awareness and perceptions of available support. The investigation will seek to determine the scenarios in which cyber security advice is sought (e.g. during product evaluation, at point of purchase, in response to threats and incidents), and whether it is deemed effective. In parallel, the project analyses support routes available to these businesses, with focus upon the coverage and consistency of advice, as well as the confidence and capacity of those providing it. This will include a range of online and in-person sources, in order to capture the diversity of routes that businesses themselves tend to pursue, and will include those specifically designated to provide support (e.g. Cyber Resilience Centres) and those that may find themselves facing cyber security queries when potentially less well-placed to handle them (e.g. retailers). From these foundations, the research then conducts more detailed analysis of business and advisor experiences by tracking individual support journeys as they occur. This offers more direct intelligence on the nature and volume of support being sought, as well as the extent to which the requests led to an effective outcome. The analysis delivers a series of case studies identifying factors that led to successful or unsuccessful outcomes. The findings inform activities to enhance support provision through the design, implementation and pilot evaluation of Cyber Security Communities of Support (CyCOS), representing local collaboration and cooperation between SMEs and advisory sources. The foundations include the creation of an online Support Broker, enabling the SMEs to identify support needs and contact advisory sources positioned to help them (which, as the community develops and grows in experience, may include peer support from other SMEs). In parallel, the project offers upskilling opportunities for advisors and interested SMEs, via foundational cyber security certification to increase their related knowledge and capability. The project will then trial the operation of the CyCOS via three pilots. This will enable practical evaluation of the approach, culminating an established and repeatable model that can then be adopted more widely. The delivery of the research is supported by relevant industry partners, including those providing expertise and resources to support the CyCOS, and those offering channels for engagement with the SME community. Partner representatives will form an Advisory Board, meeting regularly throughout the project, offering input and feedback to further guide the activities. The resulting 30-month project contributes to national resilience by addressing an area of existing vulnerability and potential compromise. It will enhance understanding of SMEs' cyber security support needs and the ability to address them, while enabling SMEs themselves to recognise and embrace a core aspect of their digital responsibility.
中小企业是经济的重要组成部分,占英国企业的99.9%,创造了五分之三的就业机会和2.3万亿英镑的营业额。他们是一项重要资产,需要作为我们国家总体复原力的一部分加以保护。不幸的是,英国网络安全漏洞调查显示,去年有一半的小型企业和三分之一的微型企业经历了漏洞或攻击。此外,虽然他们经常寻求与网络安全有关的外部指导,但他们是通过各种来源这样做的,而且经常发现自己被信息淹没,无法理解这些建议。需要开展研究,以更好地了解中小企业的需求和它们寻求支持的对象的观点,然后利用这些见解作为设计和评价新的、更容易获得的办法的基础。该研究首先调查了小企业的支持需求,以建立他们目前对网络安全的理解和信心,以及他们对可用支持的认识和看法。调查将试图确定寻求网络安全建议的场景(例如,在产品评估期间,在购买时,在应对威胁和事件时),以及它是否被视为有效。与此同时,该项目分析了这些企业可用的支助途径,重点是咨询的覆盖面和一致性,以及提供咨询者的信心和能力,其中包括一系列在线和面对面的来源,以了解企业本身倾向于采用的途径的多样性,并将包括那些专门指定提供支持的机构(例如网络弹性中心)以及那些可能面临网络安全查询但可能不太适合处理这些查询的机构(例如零售商)。 在这些基础上,该研究通过跟踪个人支持旅程,对业务和顾问体验进行更详细的分析。这提供了关于所寻求的支持的性质和数量以及请求在多大程度上导致有效结果的更直接的情报。该分析提供了一系列案例研究,确定了导致成功或不成功结果的因素。 调查结果为通过网络安全支持社区(CyCOS)的设计,实施和试点评估加强支持提供的活动提供了信息,代表了中小企业和咨询来源之间的本地协作与合作。这些基础包括创建一个在线支助经纪人,使中小企业能够确定支助需求,并联系能够帮助它们的咨询来源(随着社区的发展和经验的增长,可能包括其他中小企业的同行支助)。与此同时,该项目通过基础网络安全认证为顾问和感兴趣的中小企业提供技能提升机会,以增加他们的相关知识和能力。该项目将通过三个试点项目测试CyCOS的运行。这将使实际评估的方法,最终建立一个既定的和可重复的模式,然后可以更广泛地采用。研究的交付得到了相关行业合作伙伴的支持,包括那些提供专业知识和资源以支持CyCOS的合作伙伴,以及那些提供与中小企业社区接触渠道的合作伙伴。合作伙伴代表将组成一个咨询委员会,在整个项目期间定期开会,提供意见和反馈,以进一步指导活动。由此产生的为期30个月的项目通过解决一个现有脆弱性和潜在危害的领域,促进国家复原力。它将加强对中小企业网络安全支持需求的理解和解决这些需求的能力,同时使中小企业自己能够认识和接受其数字责任的核心方面。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Steven Furnell其他文献
Leveraging reputation for enhanced decision accuracy in vehicle-to-vehicle communications under limited infrastructure
在基础设施有限的情况下,利用声誉来提高车对车通信中的决策准确性
- DOI:
10.1016/j.vehcom.2025.100927 - 发表时间:
2025-08-01 - 期刊:
- 影响因子:6.500
- 作者:
Dimah Almani;Tim Muller;Steven Furnell - 通讯作者:
Steven Furnell
Cybersecurity Incident Response Readiness in Organisations
组织中的网络安全事件响应准备情况
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Aseel Aldabjan;Steven Furnell;Xavier Carpent;Maria Papadaki - 通讯作者:
Maria Papadaki
Trust, Privacy, and Security in Digital Business
数字业务中的信任、隐私和安全
- DOI:
10.1007/978-3-642-40343-9 - 发表时间:
2013 - 期刊:
- 影响因子:9.8
- 作者:
Steven Furnell;Costas Lambrinoudakis;Javier Lopez - 通讯作者:
Javier Lopez
Editorial for Security and Privacy in Wireless Networks Special Issue
- DOI:
10.1007/s11036-013-0471-x - 发表时间:
2013-10-13 - 期刊:
- 影响因子:2.000
- 作者:
Muttukrishnan Rajarajan;Steven Furnell - 通讯作者:
Steven Furnell
Masquerader Detection in Mobile Context Based on Behaviour and Environment Monitoring Based on Behaviour and Environment Monitoring Masquerader Detection in Mobile Context Masquerader Detection in Mobile Context Based on Behaviour and Environment Monitoring Jyväskylä Studies in Computing 74 Masquera
基于行为和环境监控的移动环境中的伪装者检测 基于行为和环境监控的移动环境中的伪装者检测 基于行为和环境监控的移动环境中的伪装者检测 于韦斯屈莱 计算研究 74 Masquera
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
O. Mazhelis;S. Puuronen;Irene Ylönen;Marja;J. Veijalainen;A. Seleznyov;K. Sokratis;Katsikas;Sushil Jajodia;Steven Furnell - 通讯作者:
Steven Furnell
Steven Furnell的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
相似国自然基金
Cyber体系脆弱性仿真分析方法研究
- 批准号:61403400
- 批准年份:2014
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
基于复杂网络理论的Cyber体系效能仿真分析方法研究
- 批准号:61374179
- 批准年份:2013
- 资助金额:77.0 万元
- 项目类别:面上项目
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
- 批准号:61300132
- 批准年份:2013
- 资助金额:23.0 万元
- 项目类别:青年科学基金项目
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
- 批准号:61174035
- 批准年份:2011
- 资助金额:58.0 万元
- 项目类别:面上项目
基于Cyber空间的体系脆弱性仿真分析方法研究
- 批准号:61174156
- 批准年份:2011
- 资助金额:59.0 万元
- 项目类别:面上项目
相似海外基金
CAREER: Understanding the Integrated Cyber-Physical Resilience of Continuous Critical Manufacturing
职业:了解连续关键制造的集成网络物理弹性
- 批准号:
2338968 - 财政年份:2024
- 资助金额:
$ 88.09万 - 项目类别:
Standard Grant
Cyber Risk-Resilience of Wind Plants: A Formal Approach to Verify Safety and Stability of Wind Turbines and Power Plants
风力发电厂的网络风险抵御能力:验证风力涡轮机和发电厂安全性和稳定性的正式方法
- 批准号:
2881978 - 财政年份:2023
- 资助金额:
$ 88.09万 - 项目类别:
Studentship
ASCENT: Boosting Cyber and Physical Resilience of Power Electronics-Dominated Distribution Grids in Energy Space
ASCENT:增强能源空间中电力电子主导的配电网的网络和物理弹性
- 批准号:
2328205 - 财政年份:2023
- 资助金额:
$ 88.09万 - 项目类别:
Standard Grant
VIrtual center with Triangle Architecture and CYber-resilience
具有三角架构和网络弹性的虚拟中心
- 批准号:
10091978 - 财政年份:2023
- 资助金额:
$ 88.09万 - 项目类别:
EU-Funded
ResilMesh: Situation Aware enabled Cyber Resilience for Dispersed, Heterogenous Cyber Systems
ResilMesh:态势感知为分散的异构网络系统提供网络弹性
- 批准号:
10079399 - 财政年份:2023
- 资助金额:
$ 88.09万 - 项目类别:
EU-Funded
CAREER: Reliability and Resilience Assurance of Cyber-Physical Energy Systems
职业:网络物理能源系统的可靠性和弹性保证
- 批准号:
2404872 - 财政年份:2023
- 资助金额:
$ 88.09万 - 项目类别:
Continuing Grant
Cyber-resilience of critical infrastructures
关键基础设施的网络弹性
- 批准号:
RGPIN-2022-03536 - 财政年份:2022
- 资助金额:
$ 88.09万 - 项目类别:
Discovery Grants Program - Individual
Stochastic Energy Management in Smart Grid with Cyber-Physical Resilience Enhancement
智能电网中的随机能源管理与网络物理弹性增强
- 批准号:
RGPIN-2021-03844 - 财政年份:2022
- 资助金额:
$ 88.09万 - 项目类别:
Discovery Grants Program - Individual
ERI: Multi-Layer Dynamic Strategic Decision-Making for Integrated Cyber-Physical Energy Systems Security and Resilience
ERI:综合网络物理能源系统安全性和弹性的多层动态战略决策
- 批准号:
2138956 - 财政年份:2022
- 资助金额:
$ 88.09万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Collaborative: A Framework for Enhancing the Resilience of Cyber Attack Classification and Clustering Mechanisms
SaTC:核心:小型:协作:增强网络攻击分类和集群机制弹性的框架
- 批准号:
2122631 - 财政年份:2021
- 资助金额:
$ 88.09万 - 项目类别:
Standard Grant