"It's Confusing, Insecure, and Messy" – Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence Sector

要旨

Small and medium-sized enterprises (SMEs) are facing growing cybersecurity threats amidst limited resources and regulatory complexity. This complexity stems from diverse stakeholders in the regulatory process, including policymakers, industry associations, and companies that must implement the regulations. Misalignments between these different stakeholders can further compound the complexity. Against this backdrop, we investigate the cybersecurity mental models held by three stakeholder groups in Denmark’s defence sector and how these mental models might influence regulatory processes. Using a qualitative approach combining focus groups with 6 policymakers, 11 policy promoters (industry associations), and 12 policy implementers (SMEs), we reveal key misalignments in perceptions of risk, threats, cyber readiness, and policy interpretation. Our findings further show that SMEs often treat cybersecurity as a compliance task, while policymakers assume strategic readiness. Based on our results, we suggest recommendations for aligning governance frameworks with organisational realities.

著者
Judith Kankam-Boateng
University of Southern Denmark, Odense, Denmark
Marco Peressotti
University of Southern Denmark, Odense, Denmark
Jan Stentoft
University of Southern Denmark, Kolding, Denmark
Kent Wickstrøm Jensen
University of Southern Denmark, Kolding, Denmark
Vincent Charles. Keating
University of Southern Denmark, Odense, Denmark
Louise Alison Tumchewics
University of Southern Denmark, Odense, Denmark
Olivier Schmitt
Royal Danish Academy, Copenhagen, Denmark
Amelie Theussen
Royal Danish Academy, Copenhagen, Denmark
Peter Mayer
University of Southern Denmark, Odense, Denmark
動画

会議: CHI 2026

ACM CHI Conference on Human Factors in Computing Systems

セッション: Privacy and Security in Software Development

Area 1 + 2 + 3: theatre
7 件の発表
2026-04-16 18:00:00
2026-04-16 19:30:00