"It's Confusing, Insecure, and Messy" – Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector

Privacy Perception & Decision-MakingCybersecurity Training & AwarenessPrivacy by Design & User ControlGovernment Officials & Civil ServantsPrivacy Policy MakersSoftware Engineers & Developers

Paper Title

"It's Confusing, Insecure, and Messy" -- Mapping the Gaps Between Stakeholders’ Cybersecurity Mental Models in the Danish Defence Sector

Publication Info

  • Topic area: Cybersecurity governance and stakeholder mental models in SMEs within Denmark's defence sector.
  • Keywords: Cybersecurity, SMEs, mental models, Denmark, defence sector, policy implementation, stakeholder alignment, supply chain security, regulatory complexity, cross-sector collaboration.

Background and Problem

  • Problem / challenge: Misalignments in cybersecurity mental models among policymakers, policy promoters, and policy implementers (SMEs) hinder effective policy translation and implementation in Denmark's defence sector.
  • Significance: SMEs, which constitute 99% of Danish businesses, are critical to national economic and defence supply chains but face disproportionate cybersecurity risks due to limited resources and expertise.
  • Motivation and related work: Previous research has focused on large corporations and individual user behaviors, leaving gaps in understanding multi-stakeholder dynamics, especially in high-trust environments like Denmark. This study addresses how mental model misalignments affect cybersecurity governance and SME readiness.

Solution

  • Proposed approach: A qualitative study mapping cybersecurity mental models across three stakeholder groups—policymakers (PMs), policy promoters (PPs), and policy implementers (PIs)—to identify gaps and propose actionable recommendations.
  • Novelty:
    1. First empirical mapping of cybersecurity mental models across PMs, PPs, and PIs in Denmark’s defence sector.
    2. Identification of structural and cultural factors unique to high-trust environments that influence cybersecurity practices.
    3. Recommendations for aligning governance frameworks with SME realities, including tailored awareness programs and regulatory simplifications.
  • Procedure and key techniques:
    • Conducted focus groups with 45 participants: 6 PMs, 11 PPs, and 28 representatives from 12 SMEs.
    • Thematic analysis of transcripts using inductive coding to identify misalignments in perceptions of threats, readiness, and responsibilities.
    • Developed practical design implications for improving cybersecurity governance and stakeholder alignment.

Results

  • Concrete findings:
    • SMEs perceive cybersecurity as a financial burden, while policymakers view it as a strategic investment.
    • SMEs rely on informal communication and reactive measures, with only 3 of 12 having formal training programs.
    • Key threats identified include phishing, ransomware, insider threats, and supply chain vulnerabilities.
    • Regulatory complexity (e.g., NIS2 compliance) overwhelms SMEs, leading to superficial compliance without capability building.
    • Denmark’s high digitalization increases vulnerability, creating a paradox where advanced digital maturity outpaces security capabilities.
  • Advantage over baselines:
    • Provides a nuanced understanding of stakeholder misalignments in a high-trust cultural context, contrasting with prior studies in low-trust environments.
    • Offers actionable insights for tailoring cybersecurity policies and interventions to SME realities.
  • Experiments / evaluation:
    • Focus groups structured around themes like awareness, threats, training, and regulatory challenges.
    • Participants included policymakers, industry association experts, and SME representatives from Denmark’s defence sector.
    • Data analyzed through a three-phase coding process, resulting in 23 thematic categories and overarching themes.
  • Limitations and future work:
    • Limited generalizability beyond Denmark due to cultural specificity.
    • Gender imbalance among participants and potential selection bias.
    • Future research should explore cross-national comparisons, longitudinal studies, and the impact of NIS2 on SME compliance.

Summary

This study investigates cybersecurity mental models among policymakers, policy promoters, and SMEs in Denmark’s defence sector, revealing significant misalignments in perceptions of threats, responsibilities, and readiness. SMEs view cybersecurity as a compliance cost, while policymakers emphasize strategic investment. Regulatory complexity and resource constraints hinder SME implementation of effective measures. The findings highlight the need for tailored awareness programs, simplified compliance frameworks, and cross-sector collaboration to bridge governance and implementation gaps. These insights inform cybersecurity policy design in high-trust environments and provide a foundation for future research on stakeholder alignment and socio-technical governance.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/223230/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3791032
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
9 authors
sell
Subtopics
Privacy Perception & Decision-Making, Cybersecurity Training & Awareness, Privacy by Design & User Control
work
Professions
Government Officials & Civil Servants, Privacy Policy Makers, Software Engineers & Developers
article
Content Status
Full text indexed
hub
Related Papers
6 related papers