"It's Confusing, Insecure, and Messy" – Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector
Authors
Paper Title
"It's Confusing, Insecure, and Messy" -- Mapping the Gaps Between Stakeholders’ Cybersecurity Mental Models in the Danish Defence Sector
Publication Info
- Topic area: Cybersecurity governance and stakeholder mental models in SMEs within Denmark's defence sector.
- Keywords: Cybersecurity, SMEs, mental models, Denmark, defence sector, policy implementation, stakeholder alignment, supply chain security, regulatory complexity, cross-sector collaboration.
Background and Problem
- Problem / challenge: Misalignments in cybersecurity mental models among policymakers, policy promoters, and policy implementers (SMEs) hinder effective policy translation and implementation in Denmark's defence sector.
- Significance: SMEs, which constitute 99% of Danish businesses, are critical to national economic and defence supply chains but face disproportionate cybersecurity risks due to limited resources and expertise.
- Motivation and related work: Previous research has focused on large corporations and individual user behaviors, leaving gaps in understanding multi-stakeholder dynamics, especially in high-trust environments like Denmark. This study addresses how mental model misalignments affect cybersecurity governance and SME readiness.
Solution
- Proposed approach: A qualitative study mapping cybersecurity mental models across three stakeholder groups—policymakers (PMs), policy promoters (PPs), and policy implementers (PIs)—to identify gaps and propose actionable recommendations.
- Novelty:
- First empirical mapping of cybersecurity mental models across PMs, PPs, and PIs in Denmark’s defence sector.
- Identification of structural and cultural factors unique to high-trust environments that influence cybersecurity practices.
- Recommendations for aligning governance frameworks with SME realities, including tailored awareness programs and regulatory simplifications.
- Procedure and key techniques:
- Conducted focus groups with 45 participants: 6 PMs, 11 PPs, and 28 representatives from 12 SMEs.
- Thematic analysis of transcripts using inductive coding to identify misalignments in perceptions of threats, readiness, and responsibilities.
- Developed practical design implications for improving cybersecurity governance and stakeholder alignment.
Results
- Concrete findings:
- SMEs perceive cybersecurity as a financial burden, while policymakers view it as a strategic investment.
- SMEs rely on informal communication and reactive measures, with only 3 of 12 having formal training programs.
- Key threats identified include phishing, ransomware, insider threats, and supply chain vulnerabilities.
- Regulatory complexity (e.g., NIS2 compliance) overwhelms SMEs, leading to superficial compliance without capability building.
- Denmark’s high digitalization increases vulnerability, creating a paradox where advanced digital maturity outpaces security capabilities.
- Advantage over baselines:
- Provides a nuanced understanding of stakeholder misalignments in a high-trust cultural context, contrasting with prior studies in low-trust environments.
- Offers actionable insights for tailoring cybersecurity policies and interventions to SME realities.
- Experiments / evaluation:
- Focus groups structured around themes like awareness, threats, training, and regulatory challenges.
- Participants included policymakers, industry association experts, and SME representatives from Denmark’s defence sector.
- Data analyzed through a three-phase coding process, resulting in 23 thematic categories and overarching themes.
- Limitations and future work:
- Limited generalizability beyond Denmark due to cultural specificity.
- Gender imbalance among participants and potential selection bias.
- Future research should explore cross-national comparisons, longitudinal studies, and the impact of NIS2 on SME compliance.
Summary
This study investigates cybersecurity mental models among policymakers, policy promoters, and SMEs in Denmark’s defence sector, revealing significant misalignments in perceptions of threats, responsibilities, and readiness. SMEs view cybersecurity as a compliance cost, while policymakers emphasize strategic investment. Regulatory complexity and resource constraints hinder SME implementation of effective measures. The findings highlight the need for tailored awareness programs, simplified compliance frameworks, and cross-sector collaboration to bridge governance and implementation gaps. These insights inform cybersecurity policy design in high-trust environments and provide a foundation for future research on stakeholder alignment and socio-technical governance.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 83%
From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms
CHI '26· Privacy by Design & User Control +2
- 71%
Why Johnny Checks but Doesn’t Alert: Reporting as the Missing Step in Verifiable Internet Voting
CHI '26· Privacy by Design & User Control +2
- 67%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 67%
Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges
CHI '21· Privacy by Design & User Control +1
- 67%
Field Evidence of the Effects of Privacy, Data Transparency, and Pro-social Appeals on COVID-19 App Attractiveness
CHI '22· Privacy by Design & User Control +1
- 67%
Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current Practices
CHI '23· Privacy Perception & Decision-Making +1
Based on Jaccard similarity of research subtopics & professions (≥60%)