Information Security and Business Continuity in SMEs

Antti Tuomisto, Mikko Savela



The information society leads the way to the tomorrow’s success. However, many SMEs are not on the fast lane of this highway. In this paper we give a description of what is going on and what is going to happen to SMEs in which the ICT has not yet established a central role. The aim is to describe the situation in these SMEs. The objectives of information society strategies might seem inappropriate or impractical from the perspective of non-IT-intensive SMEs. We describe the current situation of information security, and the development trends based on our survey. Our act-oriented framework suggests improvement areas in SMEs for information security and business continuity management. This management contains i) prevention, ii) recovery and iii) the procedure of information security initiation activities. The initiation process of new employees seems to be one of the few practical and cost-effective ways to make a durable change in the work place.


