Skip to main navigation Skip to search Skip to main content

No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model

  • Cyberjuice ApS
  • Security Scientist

Research output: Conference Article in Proceeding or Book/Report chapterArticle in proceedingsResearchpeer-review

Abstract

Software developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration. It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration. In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-to-business model, conducting semi-structured interviews (N=16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (N=6). Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof. We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed.
Original languageEnglish
Title of host publicationProceedings of the 2025 CHI Conference on Human Factors in Computing Systems
Number of pages17
PublisherAssociation for Computing Machinery
Publication date2025
DOIs
Publication statusPublished - 2025
EventACM Conference on Human Factors in Computing Systems - Yokohama, Japan
Duration: 26 Apr 20251 May 2025
Conference number: 25
https://dblp.org/db/conf/chi/index.html
https://chi2025.acm.org/
https://sigchi.org/events/chi-2025/
https://dl.acm.org/doi/proceedings/10.1145/3706598

Conference

ConferenceACM Conference on Human Factors in Computing Systems
Number25
Country/TerritoryJapan
CityYokohama
Period26/04/202501/05/2025
Internet address

Keywords

  • Security
  • Commerce/Business
  • Qualitative methods

Fingerprint

Dive into the research topics of 'No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model'. Together they form a unique fingerprint.

Cite this