Aug 2026· Journal of Cybersecurity and Privacy· Vol 6, pp. 131· 0 citations· 32 references
TL;DR
Investigating stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework to help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats suggests that Information Technology and cybersecurity professionals had greater familiarity with CSA than did leaders and managers.
Abstract
Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (α = 0.868–0.926; ω = 0.870–0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (ρ = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.
Small and medium-sized educational institutions in Yemen face significant challenges in building cybersecurity readiness, particularly against phishing attacks, which serve as a primary gateway to more sophisticated threats given the absence of formal policies and weak behavioral awareness. This study proposes a practical model for adapting the NIST CSF 2.0 framework to this resource-constrained context. A quasi-experimental methodology was conducted across four sequential stages: risk assessment, framework adaptation using low-cost administrative and technical controls, expert validation of the model's validity and acceptability, and final effectiveness evaluation through phishing simulations along with measurement of perceived awareness before and after the intervention. The results showed statistically significant improvements: the click rate on suspicious links decreased from 30% to 10%, while the reporting rate increased from 10% to 45%. Expert evaluation yielded a mean total score of 3.9 out of 5, with a standard deviation of 0.41, reflecting good model acceptance and consensus among experts. The study demonstrates that flexible adaptation of global frameworks using affordable technologies and simplified procedures can achieve tangible cybersecurity improvements for such institutions, thereby enhancing cybersecurity as an indispensable pillar for sustainability in the digital age.
M. Abbas, Saleh Saleh Al-Amdi· 2026 6th International Confe...· 0 citations
The rapid growth of digital transformation has increased organizational dependence on interconnected technologies while simultaneously expanding cybersecurity risks, particularly in multi-entity organizations with diverse operational characteristics and information system environments. Conventional cybersecurity maturity assessments often provide general capability measurements but have limitations in representing variations in risk exposure across security domains. This study aims to develop the Risk-Weighted Cybersecurity Maturity Index (RWCMI) based on the NIST Cybersecurity Framework (CSF) 2.0 to provide a more contextual measurement of cybersecurity maturity by integrating risk weighting into the maturity assessment process. This research employed a quantitative, model-based evaluation approach using a case study of PTPN Group, consisting of one holding company and ten subsidiaries. Data were collected through cybersecurity maturity questionnaires, expert-based risk assessments, and supporting organizational documents. The RWCMI model integrates maturity scores from 22 NIST CSF 2.0 categories with normalized risk weights derived from expert judgments. The results indicate variations in cybersecurity maturity levels among entities, with several organizations achieving targeted maturity levels while others requiring fundamental improvements. The RWCMI approach successfully identified priority improvement areas, particularly in asset management, data security, identity management, and cybersecurity governance. In conclusion, RWCMI provides a more risk-sensitive cybersecurity maturity measurement framework that supports strategic decision-making, investment prioritization, and continuous improvement of cybersecurity governance in multi-entity organizations.
Ekky Cahya Dhitia, Ahmad Muklason· Eduvest - Journal Of Univers...· 0 citations
Cybercrime rates have increased rapidly during the last decades, resulting in cybercrimes becoming common crimes and leading to the importance of companies’ attention to cybercrime experience. Therefore, this study examines cybercrime experience and provides insights into the companies’ concern, level of information about cybercrime risks and training requirements in SMEs. An empirical analysis is conducted using a dataset collected in Europe in 2021 among more than 12,000 representative respondents of European SMEs. The results show that a higher awareness of cyber risk correlates with fewer cybercrime incidents. However, increased cybersecurity training results in increased reporting of cybercrime incidents. This suggests that increased training improves detection capabilities or that companies’ responses to cybercrime incidents are typically reactive. Increased digitalization is associated with a rise in cybercrime incidents. Therefore, recommended cybersecurity strategies for SMEs include ongoing cybersecurity training programs and the cultivation of a proactive cybersecurity culture to effectively mitigate risks.
Nessrine Omrani, Benedikt Wilke, Sascha Kraus et al.· Information Systems Frontier...· 0 citations
The rapid adoption of large language models (LLMs) in cybersecurity has created a growing need for evaluation methods that reflect operational risk rather than isolated language capability. Existing cybersecurity benchmarks assess useful dimensions such as factual knowledge, vulnerability analysis, secure coding, penetration testing, and threat intelligence reasoning, but many remain limited by static datasets, weak diagnostic granularity, limited adversarial testing, and insufficient attention to human-AI decision-making. This survey analyzes recent LLM cybersecurity benchmarks through three evaluation paradigms: knowledge-oriented, task-oriented, and holistic evaluation. From this analysis, we identify five recurring gaps between benchmark performance and real-world cybersecurity risk: knowledge-reasoning mismatch, capability-risk separation, limited failure attribution, staticity and contamination, and adversarial fragility. To address these gaps, we introduce the Reflective and Iterative Retrieval-Augmented Generation (RIRAG) framework, a dynamic and risk-aware evaluation architecture for cybersecurity LLMs. RIRAG combines continuously updated cybersecurity knowledge, retrieval- and generation-specific metrics, diagnostic logging, independent evaluation, adversarial red teaming, operational risk scoring, and human-AI teaming assessment. The framework is specified through design principles, formal components, implementation guidance, and illustrative case studies. Rather than presenting RIRAG as a validated production system, this article defines a falsifiable empirical validation protocol for future study. The central contribution is a survey-grounded reference architecture for evaluating cybersecurity LLMs as evolving, adversarially exposed, and human-interactive systems.
Unknown authors· Journal of Cybersecurity, Di...· 0 citations
Investment organizations now face greater cybersecurity risks as financial services become increasingly digitalized. Wherein the high-value transactions, sensitive client data, third-party platforms, and real-time operational systems are closely interconnected. The opinions of investment firm specialists on which specific risks pose the greatest threat to financial stability have not received as much attention as cyber risk, even though cyber risk has been thoroughly investigated using technological and quantitative approaches. This study used a qualitative case study to address the following research question: Which cybersecurity threats have the greatest impact on the financial stability of investment businesses? Semi-structured interviews with seven professionals in investment company settings were analyzed using thematic analysis informed by the Technology Acceptance Model, Risk Management Theory, and Contingency Theory. The findings demonstrate that the most serious threats are phishing, social engineering, third-party vendor risks, and the development of external threat vectors, as they have the potential to interfere with business operations, jeopardize data integrity, impair regulatory compliance, and erode investor confidence. The report argues that investment firms should view cybersecurity as a fundamental financial stability concern rather than a strictly technical function, and offers qualitative, theory-driven insights into cybersecurity threat prioritization.
Dr.Qamarsultana Alad, D. Hyatt, Dr. Rahul Azmeera· Journal of Computer Science...· 0 citations
Over the past five years, hacking incidents targeting Indonesia’s digital business ecosystem have increased significantly. The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara [BSSN]) recorded more than 1.6 billion cyberattacks throughout 2021, while 311 data breach incidents affecting 248 stakeholders were reported in 2022. However, this increase in cyber incidents has not necessarily been accompanied by a shift in the paradigm of cybersecurity research, as much of the existing literature continues to focus primarily on technical aspects. This study aims to analyze and compare approaches from previous research in mapping cybersecurity strategies for digital enterprises, particularly within the contexts of e-commerce, fintech, and local Software-as-a-Service (SaaS) platforms. Using a systematic literature review (SLR) method based on the PRISMA protocol, this study analyzed 34 articles obtained from the Scopus, IEEE Xplore, and Google Scholar databases published between 2019 and 2024. The findings identify a conceptual gap between technology-oriented approaches and integrated cybersecurity approaches that incorporate human and process dimensions through the people-process-technology framework. The results indicate that most studies continue to emphasize isolated technical solutions, while internal user behavior as a critical cybersecurity risk factor remains underexplored. This study argues that the primary vulnerability of digital enterprises lies not only in the infrastructure layer but also in the gap between formal cybersecurity policies and their actual implementation in organizational practices.
Aditya Akbar, Rafael Verdyansyah Pratama, Cahyo Purnomo et al.· Devotion : Journal of Resear...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.