Calibrating Secure by Design with the Risks Faced by Small Businesses
Empirical evidence suggests guiding small businesses toward more secure configurations is more important than eliminating vulnerabilities.
![](https://lawfare-assets-new.azureedge.net/assets/images/default-source/contributor-images/cybersecurity-lock.jpg?sfvrsn=6657e7d1_5)
Published by The Lawfare Institute
in Cooperation With
In this paper for Lawfare’s Security by Design Paper Series, Sezaneh Seymour and Daniel W. Woods argue that Secure by Design (SbD) policies should be calibrated to the actual risks faced by small businesses, rather than focusing primarily on software vulnerabilities. Using a dataset of over 90,000 U.S. firms, the authors find that insecure configurations are a more pressing problem than software vulnerabilities, with the latter comprising only 15% of security issues observed. You can read the paper here or below. |