IDEAS home Printed from https://ideas.repec.org/a/vrs/cejopp/v19y2025i2p87-110n1006.html

Small Firms, Big Threats: Cybersecurity Research and the Role of Public Policy in the SME Sector

Author

Listed:
  • Panko Matúš

    (Technical University of Košice, Faculty of Economics, Department of Banking and Investment, Němcovej 32, 040 01 Košice, Slovakia)

  • Šafár Leoš

    (Technical University of Košice, Faculty of Economics, Department of Banking and Investment, Němcovej 32, 040 01 Košice, Slovakia)

  • Mešťan Michal

    (Matej Bel University in Banská Bystrica, Faculty of Economics, Department of Finance and Accounting, Tajovského 10, 975 90 Banská Bystrica, Slovakia)

Abstract

Small-sized and medium-sized enterprises (SMEs) are vital to global economies but remain highly vulnerable to cyber threats due to limited resources, technical capacity, and awareness. This bibliometric study analyzes 245 peer-reviewed documents on SME cybersecurity published between 2005 and 2025, mapping the field through keyword co-occurrence, author productivity, citation patterns, and collaboration networks. Results show steady growth, with research output increasing at 16.7% annually. Core themes include awareness, governance, risk management, digital adoption, and Industry 4.0 integration, with a clear shift from technical toward strategic and human-centered approaches. Lotka's Law indicates fragmentation, as most authors contribute only once, underscoring the need for academic continuity. The United States, the United Kingdom, and South Africa dominate in volume, while France and Australia stand out for international collaboration. Influential contributors such as Spruit M and De Arroyabe JCF emphasize regulatory compliance and resilience. The literature highlights persistent challenges for SMEs in adopting standards like ISO 27001 and emerging technologies such as machine learning. Promising interventions include gamified training tools like CySecEscape 2.0 to strengthen awareness. This study advances understanding of SME cybersecurity research and calls for tailored, interdisciplinary strategies to enhance resilience, offering insights for policy, scholarship, and practice. The bibliometric evidence also reveals a growing recognition of the role of public policy and regulation in shaping SME cybersecurity practices. Highly cited works such as Kabanda et al. (2018), Heidt et al. (2019), Kljucnikov et al. (2019), and Tamvada et al. (2022) emphasize that national and European regulatory frameworks, including the NIS2 Directive and the Cyber Resilience Act, significantly influence SMEs' readiness, compliance behavior, and investment in security. These findings underline that effective cybersecurity strategies for SMEs require not only technological and organizational measures but also coherent public policy support and accessible institutional mechanisms.

Suggested Citation

  • Panko Matúš & Šafár Leoš & Mešťan Michal, 2025. "Small Firms, Big Threats: Cybersecurity Research and the Role of Public Policy in the SME Sector," Central European Journal of Public Policy, Sciendo, vol. 19(2), pages 87-110.
  • Handle: RePEc:vrs:cejopp:v:19:y:2025:i:2:p:87-110:n:1006
    DOI: 10.2478/cejpp-2025-0010
    as

    Download full text from publisher

    File URL: https://doi.org/10.2478/cejpp-2025-0010
    Download Restriction: no

    File URL: https://libkey.io/10.2478/cejpp-2025-0010?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:vrs:cejopp:v:19:y:2025:i:2:p:87-110:n:1006. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Peter Golla (email available below). General contact details of provider: https://www.sciendo.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.