Effective Utilization of Government-Provided CTI by Small Businesses within the Defense Industrial Base
- 1 National Security Agency, Fort Meade, MD, USA
- 2 Robert H. Smith School of Business, University of Maryland, College Park, MD, USA
- 3 Robert H. Smith School of Business, University of Maryland, College Park, MD, USA
- 4 National Security Agency, Fort Meade, MD, USA
- 5 Robert H. Smith School of Business, University of Maryland, College Park, MD, USA
Abstract
There are two broad objectives of the research reported in this paper. First, we assess whether government-provided cyber threat intelligence (CTI) is helpful in preventing, or responding to, cyber-attacks among small businesses within the U.S. Defense Industrial Base (DIB). Second, we identify ways of improving the effectiveness of government-provided CTI to small businesses within the DIB. Based on a questionnaire-based survey, our findings suggest that government-provided CTI helps businesses within the DIB in preventing, or responding to, cyber-attacks providing a firm is familiar with the CTI. Unfortunately, a large percentage of small firms are not familiar with the government-provided CTI feeds and consequently are not utilizing the CTI. This latter situation is largely due to financial constraints confronting small businesses that prevent firms from having the wherewithal necessary to effectively utilize the government-provided CTI. However, we found a significant positive association between a firm’s familiarity with the government-provided CTI and whether a firm is being periodically reviewed by the Defense Counterintelligence and Security Agency (DCSA) or is compliant with the Cybersecurity Maturity Model Certification (CMMC) program. The findings from our study also show that the participating firms believe that external cyber threats are more likely to be the cause of a future cybersecurity breach than internal cybersecurity threats. Finally, our study found that the portion of the IT budget that small businesses within the DIB spend on cybersecurity-related activities is dependent on the perception that a firm would be the target of an external cyber-attack.
- U.S. Chamber of Commerce (2023) The State of Small Business Now. https://www.uschamber.com/small-business/state-of-small-business-now
- Fanelli, B., Pessanha, R., Gwiazdowski, A., Chng-Castor, A. and Auger, G. (2017) State of Cybersecurity among Small Businesses in North America. Council of Better Bureaus . https://saginllc.com/wp-content/uploads/2017/10/Cybersecurity_FINAL_LoRes_Embargoed.pdf
- Hayes, J. and Bodhani, A. (2013) Cyber Security: Small Firms under Fire. Enginee r ing & Technology , 8, 80-83. https://doi.org/10.1049/et.2013.0614
- Onwubiko, C. and Lenaghan, A.P. (2007) Managing Security Threats and Vulnerabilities for Small to Medium Enterprises. 2007 IEEE Intelligence and Security I n formatics , New Brunswick, 23-24 May 2007, 244-249. https://doi.org/10.1109/ISI.2007.379479
- Dykstra, J., Gordon, L.A., Loeb, M.P. and Zhou, L. (2022) The Economics of Sharing Unclassified Cyber Threat Intelligence by Government Agencies and Departments. Journal of Information Security , 13, 85-100. https://doi.org/10.4236/jis.2022.133006
- Dykstra, J., Gordon, L.A., Loeb, M.P. and Zhou, L. (2023) Maximizing the Benefits from Sharing Cyber Threat Intelligence by Government Agencies and Departments. Journal of Cybersecurity , 9, tyad003. https://doi.org/10.1093/cybsec/tyad003
- Alahmari, A. and Duncan, B. (2020) Cybersecurity Risk Management in Small and Medium-Sized Enterprises: A Systematic Review of Recent Evidence. 2020 Intern a tional Conference on Cyber Situational Awareness , Data Analytics and Assessment ( CyberSA ), Dublin, 15-19 June 2020, 1-5. https://doi.org/10.1109/CyberSA49311.2020.9139638
- Paulsen, C. and Toth, P. (2016) Small Business Information Security: The Fundamentals. https://nvlpubs.nist.gov/nistpubs/ir/2016/NIST.IR.7621r1.pdf
- Chadwick, D.W., Fan, W., Costantino, G., De Lemos, R., Di Cerbo, F., Herwono, I., Manea, M., Mori, P., Sajjad, A. and Wang, X.S. (2020) A Cloud-Edge Based Data Security Architecture for Sharing and Analysing Cyber Threat Information. Future Generation Computer Systems , 102, 710-722. https://doi.org/10.1016/j.future.2019.06.026
- U.S. Small Business Administration Press Release 23-52, U.S. Small Business Administration Announces New Cybersecurity Grant Recipients for 2023. https://www.sba.gov/article/2023/08/14/us-small-business-administration-announces-new-cybersecurity-grant-recipients-2023.
- Strohmier, H., Stoker, G., Vanajakumari, M., Clark, U., Cummings, J. and Modaresnezhad, M. (2022) Cybersecurity Maturity Model Certification Initial Impact on the Defense Industrial Base. Journal of Information Systems Applied Research , 15, 17-29.