Designing User-Centered Risk Management Framework to Enhance Security Posture and Security Control Model in SME

Authors

  • Jahja Mayudin Kurniawan Swiss German University
  • M. Amin Soetomo Swiss German University
  • Charles Lim Swiss German University

DOI:

https://doi.org/10.46799/adv.v4i7.580

Keywords:

Risk Management, ISO/IEC 27001, ISO/IEC 27005, SME, Security Control

Abstract

Small and Medium Enterprises (SMEs) face increasing cybersecurity risks while often having limited resources and low readiness to implement ISO/IEC 27001. This research aims to design a user-centered risk management framework to improve security posture and enhance the effectiveness of security control implementation. The study employs the Design Science Research Methodology (DSRM) by integrating ISO/IEC 27005 as an operational risk management standard and ISO 31000 as strategic guidance, supported by a Multi-Criteria Decision Analysis (MCDA) approach for security control prioritization. The framework was demonstrated through a case study at PT Pulsabayar and evaluated using Focus Group Discussions (FGDs) and expert validation. Risk analysis identified 20 cybersecurity risks, consisting of 9 medium risks and 11 low risks, with the three highest-priority risks being application account takeover, phishing attacks, and malware infections. Security control prioritization generated priority scores ranging from 0.36 to 0.64, enabling systematic resource allocation for risk mitigation. The framework received positive evaluations from internal stakeholders and external experts, confirming its clarity, usability, and alignment with organizational needs. This research concludes that a user-centered and standards-aligned framework can strengthen cybersecurity governance and support SMEs in achieving incremental compliance and sustainable security improvements.

References

Al-Dosari, K., & Fetais, N. (2023). Risk-management framework and information-security systems for small and medium enterprises (SMEs): A meta-analysis approach. Electronics, 12(17), 3629. https://doi.org/10.3390/electronics12173629

Alahmari, A., & Duncan, B. (2020). Cybersecurity risk management in small and medium-sized enterprises: A systematic review of recent evidence. 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), 1–5. https://doi.org/10.1109/CyberSA49311.2020.9139638

Aoudi, S., & Al-Aqrabi, H. (2025). Integrating IoT security practices into a risk-based framework for small and medium enterprises (SMEs). Computer Standards & Interfaces, Article 104099. https://doi.org/10.1016/j.csi.2025.104099

Benz, M., & Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63(4), 531–540. https://doi.org/10.1016/j.bushor.2020.03.010

Chaudhary, S., Gkioulos, V., & Katsikas, S. (2023). A quest for research and knowledge gaps in cybersecurity awareness for small and medium-sized enterprises. Computer Science Review, 50, Article 100592. https://doi.org/10.1016/j.cosrev.2023.100592

Chidukwani, A., Zander, S., & Koutsakis, P. (2022). A survey on the cyber security of small-to-medium businesses: Challenges, research focus and recommendations. IEEE Access, 10, 85701–85719.

Crovini, C., Santoro, G., & Ossola, G. (2021). Rethinking risk management in entrepreneurial SMEs: Towards the integration with the decision-making process. Management Decision, 59(5), 1085–1113.

Folorunso, A., Mohammed, V., Wada, I., & Samuel, B. (2024). The impact of ISO security standards on enhancing cybersecurity posture in organizations. World Journal of Advanced Research and Reviews, 24(1), 2582–2595.

Ganin, A. A., Quach, P., Panwar, M., Collier, Z. A., Keisler, J. M., Marchese, D., & Linkov, I. (2020). Multicriteria decision framework for cybersecurity risk assessment and management. Risk Analysis, 40(1), 183–199. https://doi.org/10.1111/risa.12891

Grobler, M., Gaire, R., & Nepal, S. (2021). User, usage and usability: Redefining human centric cyber security. Frontiers in Big Data, 4, Article 583723. https://doi.org/10.3389/fdata.2021.583723

International Organization for Standardization. (2018). Information technology—Security techniques—Information security risk management (ISO 27005:2018).

International Organization for Standardization. (2022). Information security, cybersecurity and privacy protection—Information security management systems—Requirements (ISO/IEC 27001:2022).

Kezron, I. E. (2024). Enhancing cybersecurity capacity in small and medium enterprises: A framework for workforce development. Iconic Research and Engineering Journals, 7(10), 421–428.

Marican, M. N. Y., Razak, S. A., Selamat, A., & Othman, S. H. (2023). Cyber security maturity assessment framework for technology startups: A systematic literature review. IEEE Access, 11, 5442–5452. https://doi.org/10.1109/ACCESS.2022.3229766

Meersman, M. W. (2019). Developing a cloud computing risk assessment instrument for small to medium sized enterprises: A qualitative case study using a Delphi technique [Doctoral dissertation, Northcentral University].

Mirza, Z. A. (2024). Protecting small and medium enterprises: A specialized cybersecurity risk assessment framework and tool [Bachelor's thesis, University of Twente]. Preprints.org. https://doi.org/10.20944/preprints202408.1691.v1

Moreira, F. R., Canedo, E. D., Nunes, R. R., Serrano, A. L. M., Abbas, C. J. B., Pereira Júnior, M. L., & Lopes de Mendonça, F. L. (2025). Cybersecurity risk assessment through analytic hierarchy process: Integrating multicriteria and sensitivity analysis. Proceedings of the 27th International Conference on Enterprise Information Systems. SciTePress.

Moschella, J., Boulianne, E., & Magnan, M. (2023). Risk management in small- and medium-sized businesses and how accountants contribute. Contemporary Accounting Research, 40(1), 668–703.

Olagbemide, V. A. (2024). Developing an effective framework for information security compliance management in small and medium-sized enterprises (SMEs) [Doctoral dissertation, University of Derby].

Osvaldo, J., & Sordi, D. (2021). Design science research methodology: Theory development from artifacts.

Papathanasiou, A., Liontos, G., Katsouras, A., Liagkou, V., & Glavas, E. (2025). Cybersecurity guide for SMEs: Protecting small and medium-sized enterprises in the digital era. Journal of Information Security, 16(1). https://doi.org/10.4236/jis.2025.161001

Ramli, A., et al. (2025). Strengthening trust and security through ISO 27001 compliance: A conceptual framework for information management. In 2025 IEEE International Conference on Artificial Intelligence in Engineering and Technology (IICAIET) (pp. 31–36). IEEE.

Sukumar, A., Hannan, A. M., & Vahid, J. (2023). Cyber risk assessment in small and medium-sized enterprises: A multilevel decision-making approach for small e-tailors. Risk Analysis, 1–17.

Taborda Blandon, G. E., Hurtado Rivera, J. F., Durán Vásquez, J. M., Monsalve Ruiz, M. J., Silva Castillo, M. T., & Vargas Montoya, H. F. (2026). Selecting a cybersecurity risk analysis methodology for MSMEs using a multi-criteria method (AHP). Technologies, 14(4), Article 227. https://doi.org/10.3390/technologies14040227

The British Standards Institution. (2018). ISO 31000:2018 Risk management—Guidelines. BSI.

U.S. Department of Commerce. (2018). NIST Special Publication 800-37 Revision 2: Risk management framework for information systems and organizations. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-37r2

Van Haastrecht, M., Sarhan, I., Shojaifar, A., Baumgartner, L., Mallouli, W., & Spruit, M. (2021). A threat-based cybersecurity risk assessment approach addressing SME needs. Proceedings of the 16th International Conference on Availability, Reliability and Security, 1–12. https://doi.org/10.1145/3465481.3469199

Downloads

Published

2026-07-18

How to Cite

Kurniawan, J. M., Soetomo, M. A. ., & Lim, C. . (2026). Designing User-Centered Risk Management Framework to Enhance Security Posture and Security Control Model in SME. Advances In Social Humanities Research, 4(7), 380–395. https://doi.org/10.46799/adv.v4i7.580