Small and medium-sized enterprises increasingly depend on digital technologies, yet their cybersecurity practices remain constrained by limited resources, expertise, governance, and employee awareness. This study aimed to explore how SMEs experience cybersecurity implementation barriers and how these barriers influence the risk mitigation strategies adopted in daily organisational practices. An exploratory qualitative design was employed involving 20 participants from 10 SMEs, including owners, managers, IT personnel, and employees selected through purposive sampling. Data were collected through semi-structured interviews, non-participant observations, and document reviews, then analysed using thematic analysis supported by triangulation, member checking, peer debriefing, and an audit trail. The findings revealed five major barriers: limited financial resources, insufficient cybersecurity expertise, low employee awareness and inconsistent behaviour, weak cybersecurity governance, and outdated technological infrastructure. SMEs responded through gradual security investment, affordable cloud-based tools, external technical assistance, employee training, multifactor authentication, simplified policies, regular backups, software updates, and network monitoring. The discussion indicates that cybersecurity resilience in SMEs is shaped by the alignment of people, processes, technology, managerial commitment, and external support rather than by sophisticated tools alone. The study concludes that effective mitigation strategies must be proportionate, affordable, operationally realistic, and adapted to each SME’s digital maturity and current organisational capacity.
Copyrights © 2026