ganised with pairs. In our case the workshop co-
organised with the construction federation was a suc-
cess in terms of interactions and experience sharing.
Campaigns must combine both passive channels to
reach a wide audience but also active events where
SMEs can actively engage. Such events should also
evolve to avoid the pitfall of annual tick-box exercises
that can just worsen the attitude.
So far, we did not explicitly use personae to reach
the SMEs but relied on a FAQ which is regularly up-
dated to cope with new issues. Our FAQ is mostly
textual but have started to design visuals to make it
more appealing, e.g. to explain some key milestones
to progress in maturity.
Designing the quiz is an interesting and non-trivial
exercise: questions must be clear, have a good techni-
cal coverage but also address attitude and behaviour.
Our current version does not provide explanation nor
introductory material because they were respectively
provided through posters and a debriefing. Posters
also revealed interesting to make available to SMEs
for display in their premises. A minor technical point
is that for animating workshops, we preferred the mo-
bile application over the web version because of its
better usability and reliability (off-line mode).
6 CONCLUSION & NEXT STEPS
To summarise, people are a major weakness in cy-
bersecurity, but when engaged and correctly trained,
they can become the first line of defence against at-
tackers. In this paper, we reported about our on-going
experience in conducting an awareness process in the
light of existing instruments. Although this report is
still partial and hard to quantify, we believe our feed-
back can be useful for others engaged in cybersecurity
awareness. On the qualitative level, our current feel-
ing is that techniques are complementary and needs
to be combined to have a good global effectiveness.
Web tools and awareness events can initiate the pro-
cess which can then rely on more specific tools to
match the SME profile, risks and level of maturity.
Our next steps will be to set up a complete portal
and refine the self-assessment with other IT experts,
especially to make the transition with their work.
ACKNOWLEDGEMENTS
This research was partly supported by Digital Wallo-
nia and the DIGITRANS project (grant nr. 7618). We
thanks Infopole and the companies of the cybersecu-
rity cluster.
REFERENCES
ANSSI (2017). SecNumacad
´
emie. https://secnumacademie
.gouv.fr.
Ashford, W. (2017). Smes more vulnerable than ever
to cyber attacks, survey shows. http://bit.do/
computer-weekly-SME-cybersecurity.
BBB (2017). State of cybersecurity among small businesses
in north america. Better Business Bureau, http://bit.
do/2017-state-of-cybersecurity.
BSI (2018). Cyber security for SMEs. https://www.bsi
group.com/en-GB/Cyber-Security/Cyber-security-for
-SMEs.
CCB (2016). Cyber Security Guide for SME. http://www.
ccb.belgium.be/en/guide-sme.
CIS (2016). CIS Controls V6.1. https://www.cisecurity.org/
controls.
Cooper, A. (1999). The inmates are running the asylum.
Macmillan Publishing Company Inc.
ECSM (2018). European Cyber Security Month
Quiz. https://cybersecuritymonth.eu/references/quiz-
demonstration.
ISF (2002). Effective security awareness. Information Se-
curity Forum.
Ki-Aries, D. and Faily, S. (2017). Persona-centred infor-
mation security awareness. Computers & Security,
70:663 – 674.
LimeSurvey (2017). the online survey tool - open source
surveys. https://www.limesurvey.org.
Lockheed Martin (2018). Are you a cybersecurity ninja or
n00b? http://bit.do/lookheedmartin-quiz.
Muller, P. et al. (2015). Annual Report on European SMEs
2014/2015. European Commission.
NCSA (2018). Stay Safe Online - Cybersecurity Awareness
Toolkit for SMB. National Cyber Security Alliance.
Osborn, E. et al. (2015). Business Versus Tech: Sources of
the Perceived Lack of Cyber Security in SMEs. In 1st
Int. Conf. on Cyber Security for Sustainable Society.
Ponsard, C. (2018). Cybersecurity Quizz (Google Play
Store). http://bit.do/QuizzCyberSecurity.
Ponsard, C., Grandclaudon, J., and Dallons, G. (2018). To-
wards a Cyber Security Label for SMEs: A European
Perspective. In Proc. 4th ICISSP, Funchal, Madeira.
SafeOnWeb (2018). Test your digital health. https://
campagne.safeonweb.be/en.
S
´
anchez, L. E. et al. (2010). Security culture in small and
medium-size enterprise. In ENTERprise Information
Systems. Springer Berlin Heidelberg.
SBDC, M. (2018). Small business, big threat. https://small
businessbigthreat.com.
UK Gov. (2016). Cyber essentials.
https://www.cyberaware.gov.uk/cyberessentials.
UK Gov. (2018). Cyber essentials self assessment. https:
//www.cyberessentials.ie/self-assessment.
VDS (2017). A Brief Assessment for SMEs - Quick Check
for Cyber Security. http://vds-quick-check.de.
Zurich IG (2016). Smes’ cyber risk awareness is
on the rise. https://www.zurich.com/en/media/
news-releases/2016/2016-1123-01.
Survey and Lessons Learned on Raising SME Awareness about Cybersecurity
563