No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
Authors
Analysis of the Paper: No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
Research Background and Problem
-
What problems or challenges did the authors identify?
Small and medium enterprises (SMEs) in software development, acting as suppliers to larger companies and public administrations, need to demonstrate that their products meet certain security standards to gain trust and ensure compliance. However, existing approaches (e.g., security certifications) are costly and complex for SMEs. The practical use of alternative methods has not been sufficiently studied, especially in the context of conveying high levels of security confidence to customers in a business-to-business (B2B) model. -
Why is this issue important?
SMEs are a major part of the European economy and a significant force in software development. They are also part of critical infrastructure supply chains, where cybersecurity is crucial. Any vulnerabilities in their products or services could impact large clients and national economic or IT systems. Furthermore, regulations like the EU's NIS2 directive are increasing the requirements for SMEs to demonstrate security to external regulatory bodies. -
Research Motivation and Related Work
The authors are motivated to address the gap in the literature by exploring how SMEs meet security demonstration requirements. While prior research has addressed issues like security labels, testing methods, and certifications, it has not provided a comprehensive view of how these methods are applied in real-world industry practices. Moreover, most existing methods are not cost-effective, simple, or adaptable enough to meet the unique needs of SMEs.
Solution
-
What methods or solutions did the authors propose?
The paper proposes five methods for demonstrating security: Certifications, Tests and Reports, Questionnaires, Interactive Sessions, and Social Proof. -
What is innovative about this solution?
Through qualitative research, including semi-structured interviews and validation workshops, the authors systematically showcase the advantages and disadvantages of these methods in industry practice. They argue that there is no "one-size-fits-all" solution; instead, methods should be selected or combined based on specific contexts to achieve optimal performance. Additionally, the authors are the first to explore these security demonstration methods from the perspective of practicality and client communication. -
What are the implementation steps and key techniques used?
- Data Collection: Conducted semi-structured interviews with 16 participants from 15 Danish SMEs to gather first-hand information on their security demonstration practices.
- Data Analysis: Used Thematic Analysis and Affinity Diagrams to organize interview data and identify key demonstration methods and supporting evidence.
- Validation Workshops: Conducted workshops with six original interview participants to confirm or challenge initial findings and gather additional insights.
Research Findings
-
What specific findings were achieved?
The authors identified five main security demonstration methods and provided advantages, disadvantages, and recommendations for each:-
Certifications
- Advantages: Provide standardized, structured approaches; widely recognized; suitable for multiple clients.
- Disadvantages: Expensive, difficult to maintain, and may be too broad to cover all security needs.
- Recommendations: Even without formal certification, following the guidelines in standards can improve client communication.
-
Tests and Reports
- Advantages: Using testing tools to generate reports can highlight specific vulnerabilities and provide improvement suggestions, building trust.
- Disadvantages: Limited sustainability of a single test result; relatively high cost.
- Recommendations: Combine with automated tools to reduce costs and improve real-time detection capabilities.
-
Questionnaires
- Advantages: Detailed questionnaires can serve as internal audit tools and identify system security flaws.
- Disadvantages: Inevitably complex and lengthy; may not always align with real-world needs.
- Recommendations: Adjust questions through communication with the inquirer and use questionnaire responses to enhance the company’s image.
-
Interactive Sessions
- Advantages: Direct participation and dialogue enhance transparency and trust.
- Disadvantages: Relies on expertise and lacks sufficient documentation.
- Recommendations: Prepare in advance and allocate sufficient time to discuss security issues in detail with clients.
-
Social Proof
- Advantages: Using community recognition and product reputation increases credibility.
- Disadvantages: Relies on subjective evaluations; quality is difficult to control.
- Recommendations: Use as a supplementary method to complement other demonstration approaches.
-
-
What advantages does it have compared to existing solutions?
This paper provides a comprehensive view of how security demonstration methods are used in real-world industry practices, emphasizing the need to select or combine methods based on context. This makes the approach more flexible and applicable compared to single security certification frameworks. The proposed multi-method approach better suits the limited resources and flexible needs of SMEs. -
What were the experimental or evaluation results?
Validation workshops confirmed the findings from the interviews and provided new insights, such as the informal yet effective nature of interactive sessions and the value of social proof as a supplementary demonstration tool. Additionally, participant feedback helped refine the guidelines and operational recommendations for each method. -
Limitations and Future Directions
- Limitations: The companies interviewed were mostly based in Denmark, which may not fully represent the needs of SMEs in other regions. Furthermore, the study focused only on the service providers' perspective of demonstration methods, without addressing client preferences or requirements.
- Future Research Directions: Explore combinations and optimization of different demonstration methods; develop more user-friendly certification frameworks and automated testing tools; expand the scope of research to include client evaluation criteria for security demonstrations.
Conclusion
The authors systematically studied five main methods for SMEs to demonstrate software security in B2B contexts and provided practical recommendations, including cost management, reliability assessment, and accessibility optimization for non-technical personnel. Future research could improve existing methods and integrate them into a more comprehensive framework, offering more reliable security demonstration pathways for businesses and their clients.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can small and medium enterprises (SMEs) in B2B models cost-effectively demonstrate software security to clients?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- Which security-assurance methods are suitable for SMEs, and how are they applied in industry practice?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- How can multiple security-assurance methods be optimized to meet different business environments?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
Practical Problems
1- SMEs struggle to demonstrate software security to clients; methods are expensive and complex.Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- 100%
On the Usability of HTTPS Deployment
CHI '19· Privacy by Design & User Control +1
- 80%
'Think secure from the beginning': A Survey with Software Developers
CHI '19· Privacy by Design & User Control +2
- 80%
Understanding Privacy-Related Questions on Stack Overflow
CHI '20· Privacy by Design & User Control +1
- 67%
Sensor Illumination: Exploring Design Qualities and Ethical Implications of Smart Cameras and Image/Video Analytics
CHI '20· Privacy by Design & User Control +2
- 67%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 67%
Permission vs. App Limiters: Profiling Smartphone Users to Understand Differing Strategies for Mobile Privacy Management
CHI '22· Privacy by Design & User Control +2
- 67%
Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
CHI '24· AI Ethics, Fairness & Accountability +2
- 67%
IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi Traffic
UbiComp '23· Privacy by Design & User Control +2
- 60%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 60%
Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking
CHI '19· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)