A lack of systemic approach to identifying and fixing vulnerabilities, outdated IT-systems, the absence of risk assessments, security policies, and dedicated security personnel were among the most common challenges found at small and medium sized enterprises (SMEs) who are taking the first steps in cybersecurity, according to a study commissioned by RIA, co-funded by the European Commission and the ECCC, and conducted by PricewaterhouseCoopers in collaboration with Tallinn University of Technology. The study analyzed findings from cybersecurity assessments (“Roadmaps”) created through the Cyber Transformation grants initiative.
The Cyber Transformation grants initiative was a 1,5 year pilot program intended to boost the uptake of cybersecurity services among SMEs. RIA and the Estonian Business and Innovation Agency distributed grants of up to €10 000 for the procurement of cybersecurity assessment services, provided that they use a common RIA Cyber Transformation Roadmap methodology. After receiving a Roadmap, the SMEs could apply for another grant of up to €50 000 to implement the recommendations. A total of 62 SMEs received grants through the program.
Unified methodology contributed to the development of the market
The study demonstrates that the Cyber Transformation grants initiative reached SMEs whose cybersecurity level was relatively low and who needed to take the first and most significant steps to enhance their posture. The study concludes that the Cyber Transformation grants initiative and methodology is therefore “an excellent tool that allows SMEs to draw greater attention to cybersecurity with the support of a service provider and identify deficiencies, the resolution of which can significantly enhance the company's cybersecurity level with relatively modest resources and simple actions.”
For analysis, PwC and Taltech also interviewed several experts involved with creating the methodology and those working with the grant beneficiaries. The expert pool highlighted that, thanks to the support, even smaller companies, which otherwise were not ready to procure cybersecurity services, were reached through the program. In some cases, management began to seriously consider cybersecurity for the first time and took steps to improve the situation. Experts also expressed the opinion that the methodology developed by RIA, as a trusted party, provided SMEs a greater confidence in service quality. Consequently, the methodology has helped cybersecurity companies sell services based on RIAs methodology to SMEs that had not applied for a grant.
The study highlights that the Cyber Transformation initiative contributed to the development of the cybersecurity market in Estonia. On one hand, it increased SMEs awareness of the importance of cybersecurity. At the same time it allowed them to obtain services at more affordable prices since a common methodology allowed for greater competition and price comparison.
The “Cyber Transformation” grants pilot program and the study were co-funded by the European Union and the European Cybersecurity Competence Centre.