Cybersecurity Risk Management Strategies for Small Businesses in the Digital Economy
Article Information
Abstract
Many small firms rely heavily on cloud services, electronic payment methods, and customer portals while lacking advanced cyber governance, security staff, and recovery processes. This research seeks to establish cybersecurity risk management approaches capable of boosting the resilience of small firms in the digital economy era. By employing a quantitative methodology in the form of a structured survey-style data set including 120 US small businesses, the study assesses the relationships between employee training regarding cybersecurity issues, use of MFA, application of a cybersecurity framework, and yearly cyber events. It was found using descriptive analysis that 54.17%, 65.83%, and 23.33% of the respondents utilized MFA, performed employee training, and applied a cybersecurity framework, respectively. Reliability analysis showed high levels of consistency between all items in the scales measuring cybersecurity practices (Cronbach's alpha = 0.88) and business continuity (Cronbach's alpha = 0.84). Both correlation and regression analyses proved that employee training, MFA utilization, and framework adoption are linked with a lower number of annual cybersecurity events. Using SEM analysis, this research found that employee training, MFA usage, and cybersecurity framework application contribute to cybersecurity risk management capabilities, which promote business continuity. Contributions include developing an operational IEEE-style model of small-firm cybersecurity governance based on such approaches as NIST CSF 2.0, Zero Trust concepts, defense in depth, and SOC monitoring.
Keywords
Cite
Citation: Ebenezer Amakeh (2026) Cybersecurity Risk Management Strategies for Small Businesses in the Digital Economy. Epistora J. Artif. Intell. & Intell. Syst. 1(1), 1-08. Article EJAIS-103
Volume 1, Issue 1
Pages: 1-8
August 16, 2026
DOI: Pending
Research Article