Enhancing Cybersecurity Programs in Small and Medium Enterprises (SMEs): A Systematic Literature Review
Eliana Ludin, Masnizah Mohd, Fariza Fauzi · International Journal of Advanced Computer Science and Applications · 2025
Small and Medium Enterprises (SMEs) in Malaysia face increasing cybersecurity risks, yet their adoption of Security Education, Training, and Awareness (SETA) programs remains limited. Unlike prior reviews that focus broadly on SMEs, this study contributes novelty by systematically synthesizing empirical evidence within the Malaysian context. Guided by the PRISMA framework and supported by NVivo analysis, 57 studies published between 2019 and 2025 were examined to classify both the importance of SETA and the barriers to its implementation. The thematic analysis revealed six recurring domains of challenges: financial constraints, human resource limitations, management support, cultural resistance, technical infrastructure, and legal/data protection. Beyond consolidating fragmented insights, the study provides a taxonomy of challenges and practical recommendations such as modular training, role-specific awareness, and leveraging national initiatives. While this review offers structured guidance for policymakers and practitioners, its descriptive nature without empirical SME validation is a limitation, highlighting the need for future applied studies.