Cybersecurity has become one of the central issues of the modern business environment due to the accelerated digitalization of business processes and the growing number of cyber threats. Small and medium-sized enterprises (SMEs) are particularly exposed, as they often face limitations in financial, human, and organizational resources for the systematic management of cyber risks. Since SMEs represent a significant part of the Slovenian economy, analyzing their cybersecurity from a risk management perspective is both professionally and socially relevant.
The research is structured on two levels. At the macro level, the relationship between the digital competences of the population and the level of cybersecurity of European Union member states was examined using correlation and linear regression analysis of secondary data. At the micro level, a quantitative study was conducted among Slovenian SMEs using a survey questionnaire. The collected data were analyzed using descriptive statistics and comparative statistical tests.
The results indicate that digital competences alone do not ensure a high level of national cybersecurity. At the SME level, basic technical security measures are relatively widespread, while formalized risk management processes remain less developed. SMEs that implement standardized cybersecurity frameworks achieve a higher and more stable level of risk management, confirming the importance of a structured and systematic approach to security governance.
The thesis contributes to a better understanding of the factors influencing SME cybersecurity and highlights the role of standardization as a supporting mechanism for systematic risk management. The findings provide a professional basis for developing recommendations for SMEs, policymakers, and supporting institutions in strengthening cyber resilience. The limitations of the study stem from the sample size and the use of self-reported data; therefore, further in-depth and longitudinal research is recommended to validate the results.
|