Cybersecurity Maturity Model for Small and Medium-Sized Enterprises
Keywords:
Cybersecurity Maturity Model, Small and Medium Enterprises, Cyber Resilience, Asset Management, Threat Management, Access ControlAbstract
Small and Medium Enterprises (SMEs) increasingly rely on digital technologies to support their business operations, yet they remain highly vulnerable to cyber threats due to limited cybersecurity resources and expertise. Existing cybersecurity maturity models are often designed for large organizations and may not adequately address the operational realities of SMEs. This study proposes a context-aware cybersecurity maturity framework tailored to the needs of SMEs and validates it through a rigorous three-stage process involving expert panel evaluation, content validity assessment, and empirical pilot testing. The framework is structured around five key cybersecurity domains: governance, human resource security, asset management, access control, and threat management. A five-level maturity scale was adopted to assess cybersecurity practices across these domains. The proposed framework was applied to 42 SMEs across six industry sectors to determine the maturity level of cybersecurity practices and identify areas requiring improvement. The results show varying maturity levels across domains, with access control demonstrating the highest maturity level (M = 3.89, SD = 0.52), while threat management (M = 2.18, SD = 0.76) and asset management (M = 2.34, SD = 0.81) recorded the lowest maturity levels. Statistical analysis revealed significant differences across domains (F(4, 205) = 47.32, p < 0.001), with threat management significantly lagging behind all other domains. The Cronbach's alpha for the overall assessment instrument was 0.87, indicating good internal consistency. A comparative analysis with established frameworks (NIST CSF 2.0, C2M2, CIS Controls v8, and ISO/IEC 27001) demonstrates that the proposed model offers unique advantages in terms of SME scalability, resource efficiency, and progressive implementation guidance. The proposed model provides a scalable and practical approach that supports SMEs in identifying gaps and improving cybersecurity readiness.
DOI: https://doi.org/10.5281/zenodo.21599002