Wake up Calling: Impacting businesses by communicating cybersecurity risk
Cybercrimeology1 Mar 2025

Wake up Calling: Impacting businesses by communicating cybersecurity risk

Episode Notes
  • SMEs struggle with cybersecurity due to time, cost, and lack of expertise, despite recognizing its importance.
  • An automated cybersecurity scan was developed to assess SME websites and email security without requiring them to opt-in.
  • Physical reports were mailed instead of emailed to avoid phishing concerns and increase credibility.
  • Reports included security ratings on ten key areas and recommendations for improvement.
  • Businesses were encouraged to consult their existing IT providers for fixes rather than relying on external services.
  • Different risk communication strategies were tested to encourage SMEs to act on the findings.
  • “Anticipated Regret” messaging (“Fix it now or regret it later”) led to the highest cybersecurity improvements.
  • All groups, including the control group, showed some improvement, suggesting broader awareness of cybersecurity issues.
  • Engagement was low, with only a small number of businesses reaching out after receiving the report.
  • Legal concerns about scanning businesses without consent were addressed—publicly available cybersecurity data can be legally assessed.
  • Ethical approval confirmed the project was non-commercial and aimed solely at helping businesses improve security.
  • A follow-up version of the project will introduce an opt-out option before scanning businesses.
  • Industry associations may partner with the project to increase credibility and adoption.
  • The intervention will be scaled up, with more businesses included and a longer time frame for assessing impact.
  • Future plans include adapting the intervention internationally, using lessons learned to assist SMEs in other regions.
About Our Guest

Dr. Susanne van ’t Hoff-de Goede

https://www.linkedin.com/in/susanne-van-t-hoff-de-goede/

https://www.thuas.com/research/centre-expertise/team-cyber-security

Resources and Research Mentioned

Examining Ransomware Payment Decision-making Among SMEs

Matthijsse, S. R., Moneva, A., van ’t Hoff-de Goede, M. S., & Leukfeldt, E. R.

European Journal of Criminology.

Explaining Cybercrime Victimization Using a Longitudinal Population-based Survey Experiment

van ’t Hoff-de Goede, M. S., van de Weijer, S., & Leukfeldt, R.

Journal of Crime and Justice, 47(4), 472-491 (2024).

How Safely Do We Behave Online? An Explanatory Study into the Cybersecurity Behaviors of Dutch Citizens

van der Kleij, R., van ’t Hoff-de Goede, S., van de Weijer, S., & Leukfeldt, R.

In: International Conference on Applied Human Factors and Ergonomics (2021), pp. 238-246.

The Online Behaviour and Victimization Study

van ’t Hoff-de Goede, M. S., Leukfeldt, E. R., van der Kleij, R., …

In:Cybercrime in Context: The human factor in victimization, offending, and … (2021).

Other

Dutch Government Cybersecurity Resource

https://english.ncsc.nl

(English-language site for the Netherlands’ National Cyber Security Centre)

Secure Internetting (in Dutch)

https://veiliginternetten.nl/

Episoder(127)

Disordered Sense-Making: Conflict Narratives in the Digital Era

Disordered Sense-Making: Conflict Narratives in the Digital Era

Notes: Dr Samuel Tanner began his doctoral research examining war crimes and armed militias involved in mass violence in the Balkans, conducting extensive fieldwork and interviews with participants ...

1 Mar 36min

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Notes:Dr Bekkers describes his academic pathway from psychology to criminology and explains why his research focus has consistently been on offenders and their behaviour rather than on offences or tec...

1 Feb 25min

Systematically Improving Cybersecurity Training

Systematically Improving Cybersecurity Training

Notes:Julia Prümmer describes her transition from legal psychology into cybersecurity research and how psychological methods shape her approach to cybersecurity training.The discussion explores the ro...

1 Jan 49min

The Human beneath the Hoodie: Profiling pathways into cybercrime

The Human beneath the Hoodie: Profiling pathways into cybercrime

otes:Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.Her research focuses on understanding the human behind ...

1 Des 202533min

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Episode Notes:Dr Ho describes an empirical research agenda focused on how security actually operates in organisations. He explains his experience with getting this research off the ground to allow the...

1 Nov 20251h 4min

The many minds of MITRE: building multidisciplinary human insider-risk research

The many minds of MITRE: building multidisciplinary human insider-risk research

Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber. Episode NotesDr Caputo's path ...

1 Okt 202544min

Follow the Honey: Experiments in Cybercriminal Decision-Making

Follow the Honey: Experiments in Cybercriminal Decision-Making

Show Notes:Daniëlle began her academic path in psychology, later moving into criminology through her interest in decision making and online behaviour.Her PhD research at NSCR focuses on cybercriminal ...

1 Sep 202530min

Crime Online: Hashtag Like and Subscribe, or don't

Crime Online: Hashtag Like and Subscribe, or don't

Episode NotesAbout our guest:Dr. Francesco Carlo CampisiPhD in Criminology, Université de MontréalResearcher, International Centre for Comparative Criminology🔗 https://www.cicc-iccc.org/fr/personnes/...

1 Aug 202529min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
foreldreradet
treningspodden
rss-strid-de-norske-borgerkrigene
jakt-og-fiskepodden
sinnsyn
rss-sunn-okonomi
mikkels-paskenotter
hverdagspsyken
gravid-uke-for-uke
rss-kunsten-a-leve
takk-og-lov-med-anine-kierulf
rss-kull
hagespiren-podcast
rss-var-forste-kaffe
fryktlos
rss-mann-i-krise-med-sagen
tomprat-med-gunnar-tjomlid