A Mixed-method Study on Security and Privacy Practices in Danish Companies
This addresses security and privacy practices for companies in Denmark, but it is incremental as it focuses on specific regional and contextual challenges.
The study investigated security and privacy challenges in Danish companies, revealing issues such as misalignment between developers and management, difficulties with GDPR compliance, and differing views on adapting to COVID-19.
Increased levels of digitalization in society expose companies to new security threats, requiring them to establish adequate security and privacy measures. Additionally, the presence of exogenous forces like new regulations, e.g., GDPR and the global COVID-19 pandemic, pose new challenges for companies that should preserve an adequate level of security while having to adapt to change. In this paper, we investigate such challenges through a two-phase study in companies located in Denmark -- a country characterized by a high level of digitalization and trust -- focusing on software development and tech-related companies. Our results show a number of issues, most notably i) a misalignment between software developers and management when it comes to the implementation of security and privacy measures, ii) difficulties in adapting company practices in light of implementing GDPR compliance, and iii) different views on the need to adapt security measures to cope with the COVID-19 pandemic.