Cyber resilience is not a software purchase – it is a capability

Cyber resilience is not a software purchase – it is a capability

By Christoff Oosthuysen, Founding CEO of the Entrepreneurial Planning Institute (EPI) and curator of the DigiBiz.Africa Network.

image 1

It is always encouraging when one’s approach is reconfirmed by scientific research. That was my reaction when I encountered the paper A grounded theory of SME resilience in network information security by Prof Kennedy Njenga and Yitong He form the University of Johannesburg. They develop a practical framework, the Theory of Information Security Resilience for SME Network Infrastructure (TISRI), which makes a simple point with real depth:

Cyber resilience is built through aligned habits, decisions, and systems; and culture plays a decisive role in whether security becomes “how we do things here”.

That matters a lot for how we think about digital advancement in small businesses. Moving forward is not about the next app or platform to use. It is about changing the culture of your organisation, starting exactly where your are now on your digital journey. If a business is adopting cloud tools, online payments, shared drives, remote work, and integrated supplier systems, it is also increasing its digital dependency. The paper warns that when “network dependencies increase”, the consequences of breaches are amplified.

This is where the alignment with EPI’s approach becomes clear. The MyDigiScore.com Assessment Tool (built on the Digital Progression Index logic) starts by helping a business understand its current digital state in practical terms: what tools are being used, how consistently, where risk is creeping in, and what capabilities are missing. The EPI’s DigiBiz Coaching Approach then translates that diagnosis into habits, routines, and operating decisions that stick. If you take the paper seriously, this pairing of “assessment plus “capacity building:” is not a nice to have. It is the pathway towards cyber security!

What the research found

Njenga and He used what is called “grounded theory” to build TISRI from practitioner interviews in South Africa. It means they built the model from real-world data, instead of starting with a pre-existing theory and trying to prove it. Their conclusion is that cybersecurity resilience in small businesses is not mainly a technology problem. It is an organisational capability that emerges when the social and technical sides of the business work together. In their words, resilience can be understood as an “emergent property” of alignment, not a box to tick.

TISRI is built around five interacting elements:

  • Governance, strategy and policy integration;
  • Capacity-building and skills development;
  • Culture as a foundation for resilience;
  • Adaptive security infrastructure; and
  • Network security incident management, including the use of AI-driven approaches for proactive detection and response.

Successful cyber security incident response becomes possible through these five elements. In other words, when something goes wrong, the business can respond quickly, limit damage, recover, and continue operating by understanding how to apply the five elements of the model.

Why “culture” is the hinge

The paper includes a line framed by one of the respondents, that deserves to be repeated in every small business context, namely: “The whole idea is to build a culture that surrounds the security”.  That is not a slogan. It is a description of what actually protects small businesses when budgets are tight and teams are busy.

Culture shows up in ordinary moments. Does a team member report a suspicious email or ignore it? Do people share passwords “just for today”? Does the owner insist on multi-factor authentication or keep postponing it? Does the business regularly back up and test recovery, or only learn about backups when ransomware hits? The difference between a resilient small business and a vulnerable one is rarely a single tool. It is the accumulation of everyday decisions. It is culture!

This is also why assessment or certification alone is not enough. A score can reveal risk, but it cannot change behaviour. That is where capacity building, training and coaching become central.

How MyDigiScore aligns with TISRI

The EPI’s MyDigiScore Assessment offers value in that it helps a small business to plot its digital journey from where it is at now, not where a cybersecurity framework assumes it should be, and not where a software vendor wants it to be. It position the business in its real operating context:

  • TISRI’s first element is governance and policy integration. The paper notes that small businesses often face constraints in “resources, expertise, and governance structures”, and that this context shapes what is realistic and scalable.  MyDigiScore supports this by turning “governance” into practical self-awareness. In a small business, governance does not have to mean formal committees. It can mean clarity on basics like who owns access to email or customer data; who can install software; the minimum standard for passwords; and what gets backed up, how often, and who checks it. Those are governance questions in small business language. They are also the kinds of foundations that prevent digital advancement from becoming fragile.
  • The second element is skills development. TISRI treats capacity-building as a driver of security culture and a contributor to incident management, with explicit hypotheses such as “Capacity-building and skills development will influence culture.” MyDigiScore, when used properly, becomes a starting point for targeted learning: not generic training, but specific capability-building linked to the business’s current situation and behaviours.
  • The third element is culture. MyDigiScore is designed to lead into reflection and behaviour change. It creates a structured moment where the business can name what it is doing well and what it is ignoring, then turn that into action priorities. In practice, culture change starts when people can talk honestly about risk without shame and without jargon.
  • The fourth element is adaptive infrastructure. The paper warns against approaches that are ad hoc and ultimately costly.  This is one of the most important insights for the digital progression conversation. Many small businesses end up with a patchwork of tools, outsourced fixes, and quick workarounds that feel like progress, but build hidden fragility. DigiBiz Coaching’s role is to highlight when “digital progress” is outpacing “digital discipline”, and to prompt investments in basics before complexity.
  • The fifth element is incident management. The paper recommends leveraging AI-driven security solutions to automate detection and streamline response, allowing small businesses to be proactive.  In the EPI and DigiBiz ecosystem, this aligns naturally with the broader view of AI as an accelerator, but only when it sits on top of sound habits. AI tools can help with monitoring, alerts, and even drafting incident communications, but they cannot substitute for a team that knows what to do when something goes wrong.

Why this matters

The most practical implication of Njenga and He’s work is that small business cybersecurity resilience is built through capability development, not procurement. It is a journey. TISRI “provides a roadmap” for strengthening resilience in resource-constrained contexts.  That is exactly what ecosystem programmes should be funding and enabling: diagnostics, guided behaviour change, peer learning, and practical tool adoption that fits the stage the business is at.

This is also why the MyDigiScore plus DigiBiz Coaching combination is so aligned with the research. It offers a repeatable pathway: measure where the business is, interpret the results in plain language, build the next capability through coaching, and reinforce it through community learning.

Cybersecurity can feel like a specialist topic that belongs to larger companies. This paper argues the opposite. It shows that resilience is possible for small businesses, but only if it is treated as a cultural and operational capability, built step by step through governance, skills, habits, and readiness.

#CyberResilience #CyberSecurity #SmallBusiness #DigitalTransformation #BusinessResilience #DigitalCapability #MyDigiScore #DigiBizAfrica