Cyber Defense Readiness and Adoption Barriers among Small and Medium-Sized Businesses in Nepal: A Mixed-Methods Study
Keywords:
cybersecurity, small and medium-sized businesses, Nepal, cyber resilience, training, technology adoption, TOE frameworkAbstract
Small and medium-sized businesses (SMBs) are key drivers of Nepal's growing digital economy, yet their cybersecurity readiness remains underexplored. This study assesses the organizational preparedness of Nepalese SMBs by examining cybersecurity awareness, organizational practices, training, incident experience, and confidence in mitigating cyber threats. A mixed-methods research design was adopted, combining a structured questionnaire administered to 150 stakeholders representing SMBs with semi-structured interviews to enrich the interpretation of quantitative findings. The survey instrument demonstrated good internal reliability (Cronbach's alpha = 0.82). The findings reveal that cybersecurity preparedness is primarily constrained by low awareness, limited organizational resources, budget limitations, and insufficient technical expertise, which together constitute the dominant barriers to effective cybersecurity implementation. Regular cybersecurity training remains inadequate across many organizations, while reported cyber incidents increase with organizational size. Furthermore, confidence in preventing cyber threats is generally low, indicating significant gaps between perceived risks and organizational preparedness. Interpreted through the Technology Organization Environment (TOE) framework, the results suggest that cybersecurity readiness is influenced more by organizational capacity, resource availability, and institutional support than by the sophistication of cyber threats alone. Based on these findings, the study proposes a practical four-stage cybersecurity maturity roadmap, Govern and Baseline, Protect Essentials, Detect and Respond, and Optimize and Collaborate, aligned with the NIST Cybersecurity Framework (CSF) 2.0 and Nepal's National Cyber Security Policy. The proposed framework provides a scalable, resource-sensitive approach to strengthening cyber resilience among Nepalese SMBs and offers practical guidance for business leaders, policymakers, and cybersecurity practitioners seeking to enhance organizational security in resource-constrained environments.
Downloads
Published
How to Cite
Issue
Section
License
Copyright is held by the authors.