Ilmu Komputer & AI editorial
Open AccessOA2026
Toward an Empirical Probabilistic Risk Manifestation Model of Organizational Cybersecurity in SMEs
A cross-layer analysis of 281 security findings from 22 SME assessments reveals dominant risk pathways and a streamlined assessment framework.
FNU Nurjahan; Aidan Eiler; Mst Eshita Khatun; Lamine Noureddine; Aisha Ali-Gombeยท 2026ยท DOI 10.48550/arXiv.2609.14888
The core problem
Small and medium-sized enterprises (SMEs) face significant cybersecurity risks but often lack the resources for comprehensive assessments. This paper presents a cross-layer empirical study of organizational cybersecurity risk in SMEs, analyzing 281 validated security findings from 22 real-world SME cybersecurity assessments conducted over two years through a pro bono university cybersecurity clinic. The authors aim to identify recurring organizational security functions and estimate an empirical Risk Manifestation Model linking these functions to exposure conditions, attack mechanisms, and cybersecurity outcomes. The model characterizes empirical associations observed in this sample rather than causal or predictive relationships. The study also evaluates whether SME cybersecurity assessments can be simplified while preserving meaningful security coverage.
Innovation
The analysis identified eight organizational security functions associated with two exposure conditions, five attack mechanisms, and six outcome categories. Across most functions, the dominant pathway follows asset exposure to credential compromise to unauthorized access. For infrastructure and network security, the dominant pathway primarily propagates through network exposure. These pathways remained stable under leave-one-organization-out analysis. Regarding simplified assessments, retaining six functions reduces assessment burden by 24% while preserving 97% of critical findings and 92% of risk-pathway coverage. Retaining five functions reduces burden by 45% while preserving 89% of critical findings and 85% of risk-pathway coverage.
Small and medium-sized enterprises (SMEs) face significant cybersecurity risks but often lack the resources for comprehensive assessments. This paper presents a cross-layer empirical study of organizational cybersecurity risk in SMEs, analyzing 281 validated security findings from 22 real-world SME cybersecurity assessments conducted over two years through a pro bono university cybersecurity clinic. The authors aim to identify recurring organizational security functions and estimate an empirical Risk Manifestation Model linking these functions to exposure conditions, attack mechanisms, and cybersecurity outcomes. The model characterizes empirical associations observed in this sample rather than causal or predictive relationships. The study also evaluates whether SME cybersecurity assessments can be simplified while preserving meaningful security coverage.
The study employed iterative thematic coding to identify recurring organizational security functions from the 281 validated security findings. These functions were then linked to exposure conditions, attack mechanisms, and cybersecurity outcomes to construct an empirical Risk Manifestation Model. Probability propagation was used to identify dominant risk pathways. The robustness of these pathways was tested using leave-one-organization-out analysis. Finally, the authors evaluated simplified assessment frameworks by retaining subsets of functions and measuring the reduction in assessment burden, preservation of critical findings, and coverage of risk pathways. The analysis is based on data from 22 SME assessments conducted over two years through a pro bono university cybersecurity clinic.
Why it matters
The empirical Risk Manifestation Model provides a structured view of how organizational security functions relate to exposure conditions, attack mechanisms, and outcomes in SMEs. The dominance of the asset exposure โ credential compromise โ unauthorized access pathway across most functions highlights the critical role of credential management and access control. The distinct pathway for infrastructure and network security, primarily through network exposure, suggests that these areas require targeted network-focused mitigations. The stability of pathways under leave-one-organization-out analysis indicates robustness within this sample. The simplified assessment frameworks offer practical trade-offs: a security-oriented reduction (six functions) maintains high coverage of critical findings and risk pathways with moderate burden reduction, while an efficiency-oriented reduction (five functions) achieves greater burden reduction at a slight cost to coverage. These findings can inform the design of more efficient cybersecurity assessments for resource-constrained SMEs.
Who should read this
CS practitioners and researchers
Opening member contentโฆ