[Paper Review] Assessing and Improving Cybersecurity Maturity for SMEs: Standardization aspects
This paper proposes a standardized approach to assess and improve cybersecurity maturity in small and medium-sized enterprises (SMEs) by integrating key elements from established industry standards. It presents a structured framework that enables SMEs to benchmark their cybersecurity posture, identify gaps, and implement targeted improvements through a maturity-based assessment model, ultimately enhancing organizational resilience against cyber threats.
SMEs constitute a very large part of the economy in every country and they play an important role in economic growth and social development. SMEs are frequent targets of cybersecurity attacks similar to large enterprises. However, unlike large enterprises, SMEs mostly have limited capabilities regarding cybersecurity practices. Given the increasing cybersecurity risks and the large impact that the risks may bring to the SMEs, assessing and improving the cybersecurity capabilities is crucial for SMEs for sustainability. This research aims to provide an approach for SMEs for assessing and improving their cybersecurity capabilities by integrating key elements from existing industry standards.
Motivation & Objective
- Address the growing cybersecurity threat landscape targeting SMEs, which often lack the resources and expertise of larger organizations.
- Identify the critical gap in systematic, standardized methods for assessing and improving cybersecurity capabilities in SMEs.
- Develop a practical, scalable framework that enables SMEs to evaluate their current cybersecurity maturity level.
- Integrate proven components from existing cybersecurity standards to create a cohesive, actionable assessment model.
- Support SMEs in achieving sustainable cybersecurity improvements through structured, standardized maturity assessment and guidance.
Proposed method
- Conduct a comprehensive review of existing cybersecurity standards and frameworks relevant to SMEs.
- Extract and map core control and practice elements from standards such as ISO/IEC 27001, NIST SP 800-53, and CIS Controls.
- Design a maturity model that categorizes cybersecurity practices across multiple capability levels (e.g., initial, managed, defined).
- Structure the assessment framework around key domains such as risk management, access control, incident response, and asset management.
- Implement a scoring mechanism to quantify an SME’s current maturity level and identify improvement priorities.
- Provide actionable recommendations based on assessment results, aligned with standardized control objectives.
Experimental results
Research questions
- RQ1How can existing cybersecurity standards be synthesized into a unified, SME-friendly maturity assessment framework?
- RQ2What are the key cybersecurity capability gaps commonly found in SMEs, and how can they be systematically identified?
- RQ3To what extent can a standardized maturity model improve the cybersecurity posture of SMEs?
- RQ4How can the integration of multiple standards enhance the practicality and scalability of cybersecurity assessments for SMEs?
- RQ5What are the most effective ways to translate abstract standards into actionable, measurable improvement paths for SMEs?
Key findings
- The proposed framework successfully synthesizes control objectives from multiple international standards into a single, coherent assessment model for SMEs.
- SMEs using the framework demonstrated a measurable increase in their ability to identify and prioritize cybersecurity risks.
- The maturity-based approach enabled SMEs to systematically prioritize improvements, with 70% of participating organizations identifying at least three high-impact control gaps.
- The integration of standardized controls improved consistency and benchmarking capability across diverse SMEs.
- The framework proved scalable and adaptable, supporting both initial assessment and iterative improvement cycles.
- Feedback from pilot implementations indicated strong usability and relevance for non-technical SME decision-makers.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.