From Maturity Models to Ground Truth: Reconciling Cybersecurity Capacity Frameworks with Household-Level Governance Realities in the Global South
Wael Albayaydh (University of Oxford)Ivan Flechais (University of Oxford)
Sep 2026
Human-computer Interaction
Abstract
National cybersecurity and digital-governance capacity frameworks, most prominently the Cybersecurity Capacity Maturity Model for Nations (CMM), shape hundreds of millions of dollars in donor-funded governance investments across the Global South. Yet a persistent, under-theorised gap remains between state-level institutional maturity and the governance actually experienced by end-users. We term this the last-mile governance gap: the structural space between what a maturity assessment can see - laws, agencies, standards, awareness campaigns - and what a household living under that formal architecture can access, understand, or enforce. Drawing on a dual vantage point combining CMM assessment experience with peer-reviewed empirical fieldwork on smart-home privacy governance in Jordan, corroborated against studies from Kenya and China, we identify four mechanisms by which national capacity fails to reach the household: legibility, intra-household power distribution, accessibility of redress, and infrastructure-affordability constraints. We map these mechanisms explicitly onto the CMM's five dimensions, propose four concrete, low-cost last-mile indicators pilotable within existing CMM deployments, and outline a staged adoption roadmap with responses to anticipated objections. With AI-enabled devices entering homes across the Global South faster than institutional capacity can adapt, the stakes are rising: this dynamic risks converting a measurable maturity gap into an invisible one. We conclude with actionable implications for the GCSCC, the ITU, the World Bank, and other institutions relying on maturity scores to prioritize investment.
This publication proposes a definition and a classification of agile software development approaches and analyses ten software development methods that can be characterized as being "agile" against the defined criterion.
P. Abrahamsson, O. Salo, Jussi Ronkainen et al.· arXiv.org· 727 citations· ⚡54
The study shows that agile practices improve both informal and formal communication, but indicates that, in larger development situations involving multiple external stakeholders, a mismatch of adequate communication mechanisms can sometimes even hinder the communication.
M. Pikkarainen, Jukka Haikara, O. Salo et al.· Empirical Software Engineeri...· 401 citations· ⚡48
The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.
Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al.· Information and Software Tec...· 394 citations· ⚡54
The perception of the impact of agile methods is predominantly positive, and several challenge areas were discovered, but based on this study, agile methods are here to stay.
M. Laanti, O. Salo, P. Abrahamsson· Information and Software Tec...· 260 citations· ⚡20
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 7, 2026
Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.
Jennifer Neville did not want to go into computer science—but that’s exactly where she landed. Neville discusses the starts and stops that led to her professional sweet spot and her work identifying “surprising failures” making it hard for AI to handle complexity. The post What AI gets wrong and what failure teaches us appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduSep 30, 2026
Able to defeat top-ranked human players and more efficient than other models, the new system could help decision-makers in military maneuvers or business negotiations.