No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model

Privacy by Design & User ControlPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersCybersecurity Engineers

Analysis of the Paper: No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model

Research Background and Problem

  • What problems or challenges did the authors identify?
    Small and medium enterprises (SMEs) in software development, acting as suppliers to larger companies and public administrations, need to demonstrate that their products meet certain security standards to gain trust and ensure compliance. However, existing approaches (e.g., security certifications) are costly and complex for SMEs. The practical use of alternative methods has not been sufficiently studied, especially in the context of conveying high levels of security confidence to customers in a business-to-business (B2B) model.

  • Why is this issue important?
    SMEs are a major part of the European economy and a significant force in software development. They are also part of critical infrastructure supply chains, where cybersecurity is crucial. Any vulnerabilities in their products or services could impact large clients and national economic or IT systems. Furthermore, regulations like the EU's NIS2 directive are increasing the requirements for SMEs to demonstrate security to external regulatory bodies.

  • Research Motivation and Related Work
    The authors are motivated to address the gap in the literature by exploring how SMEs meet security demonstration requirements. While prior research has addressed issues like security labels, testing methods, and certifications, it has not provided a comprehensive view of how these methods are applied in real-world industry practices. Moreover, most existing methods are not cost-effective, simple, or adaptable enough to meet the unique needs of SMEs.


Solution

  • What methods or solutions did the authors propose?
    The paper proposes five methods for demonstrating security: Certifications, Tests and Reports, Questionnaires, Interactive Sessions, and Social Proof.

  • What is innovative about this solution?
    Through qualitative research, including semi-structured interviews and validation workshops, the authors systematically showcase the advantages and disadvantages of these methods in industry practice. They argue that there is no "one-size-fits-all" solution; instead, methods should be selected or combined based on specific contexts to achieve optimal performance. Additionally, the authors are the first to explore these security demonstration methods from the perspective of practicality and client communication.

  • What are the implementation steps and key techniques used?

    • Data Collection: Conducted semi-structured interviews with 16 participants from 15 Danish SMEs to gather first-hand information on their security demonstration practices.
    • Data Analysis: Used Thematic Analysis and Affinity Diagrams to organize interview data and identify key demonstration methods and supporting evidence.
    • Validation Workshops: Conducted workshops with six original interview participants to confirm or challenge initial findings and gather additional insights.

Research Findings

  • What specific findings were achieved?
    The authors identified five main security demonstration methods and provided advantages, disadvantages, and recommendations for each:

    1. Certifications

      • Advantages: Provide standardized, structured approaches; widely recognized; suitable for multiple clients.
      • Disadvantages: Expensive, difficult to maintain, and may be too broad to cover all security needs.
      • Recommendations: Even without formal certification, following the guidelines in standards can improve client communication.
    2. Tests and Reports

      • Advantages: Using testing tools to generate reports can highlight specific vulnerabilities and provide improvement suggestions, building trust.
      • Disadvantages: Limited sustainability of a single test result; relatively high cost.
      • Recommendations: Combine with automated tools to reduce costs and improve real-time detection capabilities.
    3. Questionnaires

      • Advantages: Detailed questionnaires can serve as internal audit tools and identify system security flaws.
      • Disadvantages: Inevitably complex and lengthy; may not always align with real-world needs.
      • Recommendations: Adjust questions through communication with the inquirer and use questionnaire responses to enhance the company’s image.
    4. Interactive Sessions

      • Advantages: Direct participation and dialogue enhance transparency and trust.
      • Disadvantages: Relies on expertise and lacks sufficient documentation.
      • Recommendations: Prepare in advance and allocate sufficient time to discuss security issues in detail with clients.
    5. Social Proof

      • Advantages: Using community recognition and product reputation increases credibility.
      • Disadvantages: Relies on subjective evaluations; quality is difficult to control.
      • Recommendations: Use as a supplementary method to complement other demonstration approaches.
  • What advantages does it have compared to existing solutions?
    This paper provides a comprehensive view of how security demonstration methods are used in real-world industry practices, emphasizing the need to select or combine methods based on context. This makes the approach more flexible and applicable compared to single security certification frameworks. The proposed multi-method approach better suits the limited resources and flexible needs of SMEs.

  • What were the experimental or evaluation results?
    Validation workshops confirmed the findings from the interviews and provided new insights, such as the informal yet effective nature of interactive sessions and the value of social proof as a supplementary demonstration tool. Additionally, participant feedback helped refine the guidelines and operational recommendations for each method.

  • Limitations and Future Directions

    • Limitations: The companies interviewed were mostly based in Denmark, which may not fully represent the needs of SMEs in other regions. Furthermore, the study focused only on the service providers' perspective of demonstration methods, without addressing client preferences or requirements.
    • Future Research Directions: Explore combinations and optimization of different demonstration methods; develop more user-friendly certification frameworks and automated testing tools; expand the scope of research to include client evaluation criteria for security demonstrations.

Conclusion

The authors systematically studied five main methods for SMEs to demonstrate software security in B2B contexts and provided practical recommendations, including cost management, reliability assessment, and accessibility optimization for non-technical personnel. Future research could improve existing methods and integrate them into a more comprehensive framework, offering more reliable security demonstration pathways for businesses and their clients.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/189617/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713931
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, Cybersecurity Engineers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers