The Influence of Organization’s Size and Sector on Its Level of Cybersecurity
By: Lukáš Václavík and Marie Soukupová
References
- Alanazi, A. T. (2023). Clinicians’ Perspectives on Healthcare Cybersecurity and Cyber Threats. Cureus, 15(10): e47026. https://doi.org/10.7759/cureus.47026.
- Antoniuk, D. (January 10th, 2025). Slovakia’s land registry hit by biggest cyberattack in country’s history, minister says. The Record. Retrieved March 5, 2025, from https://the-record.media/slovakia-registry-cyberattack-land-agriculture.
- Arachchilage, N. A. G., & Love, S. (2014). Security awareness of computer users: A phishing threat avoidance perspective. Computers in Human Behavior, 38, 304–312. https://doi.org/10.1016/j.chb.2014.05.046.
- Biener, C., Eling, M., & Wirfs, J. H. (2015). Insurability of Cyber Risk: An Empirical Analysis. The Geneva Papers on Risk and Insurance – Issues and Practice, 40(1), 131–158. https://doi.org/10.1057/gpp.2014.19.
- Chaudhary, S., Gkioulos, V., & Katsikas, S. (2023). A quest for research and knowledge gaps in cybersecurity awareness for small and medium-sized enterprises. Computer Science Review, 50, 1–20. https://doi.org/10.1016/j.cosrev.2023.100592.
- Dinkova, M., El-Dardiry, R., & Overvest, B. (2024). Should firms invest more in cyber-security? Small Business Economics, 63(1), 21–50. https://doi.org/10.1007/s11187-023-00803-0.
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive), 2022 § (2022).
- Dvouletý, O., Jirásek, M., Giglio, C., & Liguori, E. (2025). Artificial intelligence, digitalization, and new technologies in shaping business and management research. Cogent Business & Management, 12(1). https://doi.org/10.1080/23311975.2025.2580126.
- Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., & Smeraldi, F. (2016). Decision support approaches for cyber security investment. Decision Support Systems, 86, 13–23. https://doi.org/10.1016/j.dss.2016.02.012.
- Ghernaouti-Helie, S. (2012). Going Digital – Rethinking Cybersecurity and Confidence in a Connected World: A Challenge for Society. 2012 Third International Conference on Emerging Security Technologies, 8–11. https://doi.org/10.1109/EST.2012.16.
- Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the Security Divide between SME and Large Companies: How SME Characteristics Influence Organizational IT Security Investments. Information Systems Frontiers, 21(6), 1285–1305. https://doi.org/10.1007/s10796-019-09959-1.
- Hundreds of schools paralysed by a bomb threat sent from an alleged Russian email. (2024 7). The Slovak Spectator. Retrieved March 5, 2025, from https://spectator.sme.sk/politics-and-society/c/hundreds-of-schools-paralysed-by-a-bomb-threat-sent-from-an-alleged-russian-email.
- Hyk, V., Vysochan, O., & Vysochan, O. (2026). Cyber Security in Terms of Ensuring the Digital Transformation of European Economies: Empirical Evidence. DANUBE, 17(1), 21–35. https://doi.org/10.2478/danb-2026-0002.
- Kauffman, R. J., & Sougstad, R. (2014). Risk Management of Contract Portfolios in IT Services: The Profit-at-Risk Approach. Journal of Management Information Systems, 25(1), 17–48. https://doi.org/10.2753/MIS0742-1222250102.
- Kearney, W. D., & Kruger, H. A. (2016). Can perceptual differences account for enigmatic information security behaviour in an organisation? Computers & Security, 61, 46–58. https://doi.org/10.1016/j.cose.2016.05.006.
- Kliuchnyk, A., Shyshpanova, N., Sokolik, V., Ostapenko, A., & Kryvko, O. (2025). Digitalisation of Public Administration Processes in Shaping the Investment Environment of Territorial Communities. DANUBE, 16(3), 264–276. https://doi.org/10.2478/danb-2025-0013.
- Knopová, M., & Knopová, E. (2014). The Third World War? In The Cyberspace. Cyber Warfare in the Middle East. Acta Informatica Pragensia, 3(1), 23–32. https://doi.org/10.18267/j.aip.33.
- Leirmo, J. L. (2024). Cybersecurity Awareness in Critical Sectors – a Systematic Literature Review. Flexible Automation and Intelligent Manufacturing: Manufacturing Innovation and Preparedness for the Changing World Order, 125–132. https://doi.org/10.1007/978-3-031-74482-2_15.
- Mayer, P., Kunz, A., & Volkamer, M. (2017). Reliable Behavioural Factors in the Information Security Context. Proceedings of the 12th International Conference on Availability, Reliability and Security, 1–10. https://doi.org/10.1145/3098954.3098986.
- Moody’s. (2024). Orbis Europe. Retrieved January 22, 2025, from https://orbiseurope-r1.bvdinfo.com/version-20241204-4-0/Orbis4Europe/1/Companies/Search.
- Noor, M., Abbas, H., & Shahid, W. B. (2018). Countering cyber threats for industrial applications: An automated approach for malware evasion detection and analysis. Journal of Network and Computer Applications, 103, 249–261. https://doi.org/10.1016/j.jnca.2017.10.004.
- NÚKIB. (2022 16). NÚKIB won an award in the Czech At competition. National Office for Cyber and Information Security. Retrieved May 28, 2025, from https://nukib.gov.cz/cs/infoservis/aktuality/1836-nukib-ziskal-oceneni-v-soutezi-cesky-zavinac.
- Puławska, K., Strzelczyk, W., & Orzechowski, A. (2022). Cyber Insurance and Information Sharing As Prevention From Cyber-Attacks – Pilot Study. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4260821.
- Riek, M., & Böhme, R. (2018). The costs of consumer-facing cybercrime: an empirical exploration of measurement issues and estimates. Journal of Cybersecurity, 4(1), 1–16. https://doi.org/10.1093/cybsec/tyy004.
- Rocha Flores, W., & Ekstedt, M. (2016). Shaping intention to resist social engineering through transformational leadership, information security culture and awareness. Computers & Security, 59, 26–44. https://doi.org/10.1016/j.cose.2016.01.004.
- Sarabi, A., Naghizadeh, P., Liu, Y., & Liu, M. (2016). Risky business: Fine-grained data breach prediction using business profiles. Journal of Cybersecurity, 2(1), 15–28. https://doi.org/10.1093/cybsec/tyw004.
- Tariq, M. A., Brynielsson, J., & Artman, H. (2014). The security awareness paradox: A case study. 2014 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM 2014), 704–711. https://doi.org/10.1109/ASONAM.2014.6921663.
- Uwizeyemungu, S., Poba-Nzaou, P., & Cantinotti, M. (2019). European Hospitals’ Transition Toward Fully Electronic-Based Systems: Do Information Technology Security and Privacy Practices Follow? JMIR Medical Informatics, 7(1). https://doi.org/10.2196/11211.
- Wilson, M., & McDonald, S. (2024). One size does not fit all: exploring the cybersecurity perspectives and engagement preferences of UK-Based small businesses: exploring the cybersecurity perspectives and engagement preferences of UK-Based small businesses. Information Security Journal: A Global Perspective, 1–35. https://doi.org/10.1080/19393555.2024.2357310.
- Yoo, C. W., Sanders, G. L., & Cerveny, R. P. (2018). Exploring the influence of flow and psychological ownership on security education, training and awareness effectiveness and security compliance. Decision Support Systems, 108, 107–118. https://doi.org/10.1016/j.dss.2018.02.009.
- Yulianto, S., Soewito, B., Gaol, F. L., & Kurniawan, A. (2025). Enhancing cybersecurity resilience through advanced red-teaming exercises and MITRE ATT&CK framework integration: A paradigm shift in cybersecurity assessment. Cyber Security and Applications, 3. https://doi.org/10.1016/j.csa.2024.100077.
Language: English
Page range: 116 - 132
Submitted on: Sep 22, 2025
Accepted on: Jun 5, 2026
Published on: Jul 17, 2026
Published by: European Research University
In partnership with: Paradigm Publishing Services
Keywords:
Related subjects:
© 2026 Lukáš Václavík, Marie Soukupová, published by European Research University
This work is licensed under the Creative Commons Attribution 4.0 License.