Implication et action des dirigeants : quelles pistes pour améliorer la sécurité de l'information en PME ?


  • Yves Barlette Groupe Sup de Co Montpellier Business School



sécurité, dirigeant, implication, action, délégation


This article focuses on the role of SME managers in IS security (ISS), as these companies often suffer from more important ISS problems than larger companies. Although many specialists and scholars agree on the importance of their role, SME managers sometimes show little involvement or little action regarding ISS, leading to potentially disastrous consequences. In the literature, involvement and action are often merged, which limits the exploration of this issue. The research question dealt with in this paper is: How to improve the role of managers in their company's ISS? In order to respond, we examined (1) the barriers and drivers of managers’ involvement and action, (2) the consequences of their involvement and actions (3) how the roles in ISS management are shared out. This empirical study uses a qualitative methodology and an interpretive approach. The results extend our understanding of the factors that influence managers' involvement and action in ISS. Four contexts were identified, which were used as a framework for the analysis of the roles of the various people involved in SME ISS. This paper makes a theoretical contribution by shedding light on new factors of managers' involvement and actions. The smallest SMEs seldom have a chief information officer (CIO) or a chief information security officer (CISO). In this case, we found that employees sometimes assume informal responsibility for IS and ISS. We identified various factors to explain this informal position and several related issues. We also contribute to managerial practices by identifying avenues to better involve managers in the ISS of their SMEs. Our major contribution is showing for the first time that when an employee assumes the role of a CISO, whether informally or not, it is of utmost importance to provide top management support. This study is original because managers' involvement and actions are studied separately, which provides more detailed results and allowed us to propose practical recommendations to improve ISS, according to the identified situations.

Author Biography

Yves Barlette, Groupe Sup de Co Montpellier Business School

Yves Barlette est professeur associé du Groupe Sup de Co Montpellier Business School, depuis 1989. Il enseigne les systèmes d'information. Il étudie la Sécurité des Systèmes d'Information depuis l'année 2000. Ses recherches sont consacrées aux comportements des dirigeants et des employés, relatifs à la sécurité des informations.


