Abstract
There was an era when cybersecurity was treated as a technical afterthought. With the increasing digitalisation of business operations, things have changed, and it is now perceived as a strategic organisational imperative. This is especially the case for Small and Medium-Sized Enterprises (SMEs) in the IT sector. Even though they play a central role in supply chains, IT SMEs are still facing challenges related to the effective integration of cybersecurity into organisational culture, processes, and strategic workflows. This study draws on a systematic qualitative document analysis of peer-reviewed academic studies, government cybersecurity surveys, and industry threat intelligence reports to demonstrate that the unrelenting “integration gap” does not primarily represent a strategic failure, but rather a profoundly embedded sociotechnical challenge. Current frameworks, including ISO 27001, COBIT, NIST CSF, and the Technology-Organisation-Environment (TOE) model, depend on enterprise-capacity assumptions that are counter to SME agility, resource constraints, and realities related to usability. Five recurrent integration breakdown mechanisms are identified by the analysis: resource–risk asymmetry, governance–agility conflict, usability-driven security fatigue, supply-chain dependency pressure, and security tool fragmentation. Using these insights derived from the analysis, the study established the Lean Sociotechnical Cybersecurity Integration Framework (LSCIF). This framework is a theory-building extension of TOE, consisting of Lean Governance, Human-Centric Usability, and Commercial Trust Alignment. The study contributes to the advancement of information management and cybersecurity theory by extending TOE for adversarial settings, assimilating human-computer interaction doctrines into cybersecurity integration theory, which reframes cybersecurity as an embedded societal and commercial capability.