No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
- ,
- Bodil Biering,
- Vincent van Dijk,
- ,
- ,
- ,
- Cyberjuice ApS,
- Security Scientist,
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOriginal language
EnglishPublication milestones
- Published - 2025
Publication status
Published - 2025
Publisher
Association for Computing Machinery, United StatesHost publication title
Proceedings of the 2025 CHI Conference on Human Factors in Computing SystemsAbstract
Software developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration. It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration. In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-to-business model, conducting semi-structured interviews (N=16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (N=6). Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof. We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed.
Access to documents
Related Event
Title
ACM Conference on Human Factors in Computing Systems
Event type
ConferenceLinks
Degree of recognition
International eventDate
26/04/2025 - 01/05/2025Location
YokohamaJapan
