Skip to Content
Applied SciencesApplied Sciences
  • Article
  • Open Access

24 June 2026

26 Pages

A Fuzzy Multi-Criteria Decision Framework for Selecting Cybersecurity Platforms Under Strategic PESTEL Factors

,
,
,
and
1
Department of Industrial Engineering, Durban University of Technology, Durban 4000, South Africa
2
Institute of Systems Science, Durban University of Technology, Durban 4000, South Africa
3
Department of Mechanical Engineering, Bells University of Technology, Ota 112104, Ogun State, Nigeria
4
Ritchie School of Engineering and Computer Science, University of Denver, 2155 E Wesley Ave, Denver, CO 80210, USA

Abstract

The growth of advanced cyber threats has inspired organisations to start using powerful cybersecurity platforms, but the process of selection is analytically challenging due to the multidimensional, uncertain, and conflicting character of the evaluation criteria. The prevailing culture of decision-support frameworks is based on unyielding numerical evaluations that cannot reflect the underlying vagueness of expert judgment and the dynamic interplay of macro-environmental factors. This paper presents a combined Fuzzy Multi-Criteria Decision-Making (FMCDM) system, which uses polygonal fuzzy numbers, in particular pentagonal fuzzy representation, and four other complementary methods of MCDM (Fuzzy AHP, Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS), integrated by a Borda Count consensus system. Sixteen assessment sub-criteria are logically obtained through an analysis of PESTEL (Political, Economic, Social, Technological, Environmental, and Legal) and weighted using the Fuzzy Analytic Hierarchy Process. The model is used to compare six cybersecurity platforms, including Microsoft Security Framework, CrowdStrike Falcon, Cisco Cybersecurity Portfolio, Palo Alto Networks Cortex, Fortinet Security Fabric, and Sophos Central. In this study, Fuzzy AHP demonstrates that the aggregate weight of political factors is the highest (0.4181), followed by cross-border data management, regulatory compliance, and government incentives as the most popular sub-criteria. According to the results from the Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS methods, Microsoft Security Framework ranks consistently in the first place, and CrowdStrike Falcon and Cisco Cybersecurity Portfolio were ranked second and third, respectively. The framework presented in the study provides decision-makers with a reproducible, uncertainty-conscious basis for cybersecurity platform selection.

1. Introduction

The world’s cybersecurity environment has been reshaped in the last ten years, with the rapid growth of interconnected infrastructure, the rise in the sophistication of adversarial threat groups, and the extensive spread of digital governance responsibilities. Organisations in industries such as financial services, healthcare, critical national infrastructure, and government are faced with a continuous and growing threat landscape. Data breaches, ransomware campaigns, supply chain breaches, and state-sponsored attacks have cumulatively cost organisations around the world billions of dollars annually [1,2].
The strategic choice of a cybersecurity platform, as a technical procurement decision, is now a multidimensional organisational dilemma. It overlaps with regulatory compliance, financial sustainability, human resource competence, and geopolitical risk management. The consequences of a poor framework choice are commensurately dire: not aligning with regulations can put an organisation at risk of enforcement under instruments like the European General Data Protection Regulation (GDPR) or the United States CLOUD Act. The total cost of ownership can limit security spending in other critically important areas [3]. To the best of our knowledge, no rigorous, replicable, and context-based decision-support methodology exists that can handle the complexity of the cybersecurity framework selection issue.
The use of MCDM to evaluate and select cybersecurity has experienced significant growth in recent years, but the literature confirms that there are still pronounced methodological limitations that can be directly overcome by the present study. Ref. [4] suggested a hybrid DANP-PROMETHEE II framework to evaluate cybersecurity in Industry 4.0, prioritising criteria on network security, technology, and organisation dimensions. Although the combination of DEMATEL-based influence mapping with PROMETHEE II ranking represented a methodological improvement over a single-method design, the framework was wholly based on crisp inputs and made no allowance for the linguistic uncertainty that characterises expert judgement in security procurement settings. To assess machine learning-based intrusion detection systems, ref. [5] used hesitant fuzzy AHP-TOPSIS, which introduces hesitant fuzzy sets to deal with inter-expert disagreement, a finding consistent with broader multi-criteria analyses of competing technology alternatives in engineering contexts [6]. The framework was limited to the single field of application, ranking of IDS configurations, and was not extended to the broader problem of enterprise cybersecurity platform selection under macro-environmental constraints.
Later works added more complex representations of uncertainty, as well as larger bases of criteria, confirming that fuzzy MCDM approaches produce more contextually valid rankings than crisp methods in technology platform selection [7], but they retained some structural limitations in criteria derivation and methodological design. The interval-valued neutrosophic sets of [8] were used to apply an interval-valued neutrosophic set to security risk assessment in power management systems, which demonstrated that interval-valued neutrosophic sets could capture indeterminate and inconsistent expert information much more faithfully than standard fuzzy numbers. Nonetheless, their criteria were based solely on technical vulnerability attributes with no systematic consideration of the political, economic, and legal aspects that would govern the process of platform procurement in the regulated industries. Ref. [9] combined the DELPHI, DEMATEL, and COCOSO approaches with neutrosophic sets and Z-numbers to assess the threats to cybersecurity in the financial and banking sector of Vietnam, identifying malware attacks and supply chain breaches as the most significant risk categories. Although this paper demonstrated the usefulness of combining multiple analytical methods in a financial services environment, it focused on risk prioritisation rather than platform selection, and its criteria taxonomy was built inductively from the Vietnamese regulatory environment, without basing it on a validated macro-environmental framework. Ref. [10] compared thirteen intrusion detection systems with fuzzy OffLogic and VIKOR across four technical criteria and found that AI-based systems are more scalable and effective in detecting intrusions compared to traditional ones. The framework, however, was a single-method design with a very narrow, technically defined criteria set and failed to address the methodological sensitivity problem that arises when rankings are based upon the selection of a single analytical method.
More recent work has dealt specifically with the problem of cybersecurity platforms and selection of investment in organisational settings, but each still has recognisable limitations. Ref. [11] used AHP in the choice of a cybersecurity risk analysis methodology for small and medium enterprises and compared five international standards through qualitative criteria. Pythagorean Fuzzy AHP, Neutrosophic Fuzzy AHP, TOPSIS, and PROMETHEE were used to prioritise cybersecurity strategies against phishing attacks in the financial sector; it is one of the few recent studies to deploy multiple fuzzy MCDM methods in a cybersecurity context. Their criteria, however, were based on expert consultation with no reference to systematic macro-environmental taxonomy, and the study did not use any formal consensus mechanism to resolve discrepancies between method-specific rankings. Ref. [12] suggested an AHP-TOPSIS framework enhanced with Monte Carlo simulation and stochastic dominance analysis of cybersecurity investment prioritisation, using financial exposure, regulatory compliance, and operational resilience as evaluation dimensions. Although the integration of stochastic uncertainty quantification was a significant development, the framework remained based on a two-method architecture (without multi-method consensus validation) and its criteria set, though broader-based than most previous studies, was not grounded on a comprehensive macro-environmental structure.
Collectively, the literature review identifies three convergent gaps. First, no previous study has implemented pentagonal fuzzy numbers into the selection of cybersecurity platforms; the existing treatments of fuzzy rely on triangular, trapezoidal, hesitant, or neutrosophic representations, each of which imposes structural constraints on the resolution of expert uncertainty that PFNs are theoretically well-equipped to overcome [13,14]. Furthermore, although [15] employ a variety of methods, no prior cybersecurity MCDM study has aggregated the method-specific rankings by using a formal consensus mechanism such as Borda Count, leaving the methodological sensitivity problem, documented by [16], that 105 studies in the cybersecurity MCDM literature were unresolved. Additionally, the evaluation criteria according to which real procurement decisions are to be drawn have not been a priori derived by any previous framework, and the implication of this is that the macro-environmental factors that govern the real procurement decision-making process have not been a priori represented by any previous framework. The current research fills these gaps as a single FMCDM architecture by selecting six of the most popular enterprise cybersecurity platforms in a multinational financial services environment.
Multi-Criteria Decision-Making (MCDM) methodologies provide a theoretically sound framework upon which complex organisational decisions with many (sometimes competing) evaluation criteria are organised [17,18]. Various MCDM practices have been implemented within the information technology procurement and cybersecurity governance field. These include (1) Analytic Hierarchy Process (AHP) to select vendors [19]; (2) TOPSIS-based (Technique for Order of Preference by Similarity to Ideal Solution) systems to appraise software [20]; and (3) VIKOR (VIšeKriterijumska Optimizacija I Kompromisno Rešenje) to rank compromise-based solutions in a cyber-attack classification scenario [21].
Traditional MCDM frameworks are based on crisp numerical inputs, which are epistemically unsuitable in decision contexts that are typified by linguistic uncertainty, expert disagreement, and asymmetric judgement distributions; the essential imprecision of human preference elicitation is systematically suppressed instead of being explicitly represented [22]. Fuzzy extensions, which have generally been based on triangular or trapezoidal fuzzy numbers, have limited the modelling of expert uncertainty to symmetric and low-resolution membership functions, which are insensitive to the non-linear and context-dependent nature of actual procurement judgements [23,24]. Earlier research has only used individual MCDM approaches, and thus their rankings are susceptible to methodological sensitivity, where the choice of analytical approach influences the ranking more than actual differences in framework performance [25,26]. To overcome such shortcomings, an integrated, multi-method fuzzy MCDM framework is needed that can accommodate more detailed uncertainty descriptions and results in statistically validated, method-independent rankings.
A limitation in the cybersecurity MCDM literature is related to the derivation and justification of evaluation criteria. Several of the available frameworks select criteria through an ad hoc activity based on technology benchmarks or vendor specifications, and do not base the criteria set on a proven macro-environmental taxonomy. This gap is contingent on external forces (e.g., regulatory regimes and financial constraints), social factors (e.g., workforce ability and the adoption of remote work), technological development, environmental sustainability needs, and legal requirements, which together form the strategic environment within which procurement decisions are made. These have a profound effect on the performance of cybersecurity platforms in real organisational settings [21]. The PESTEL (Political, Economic, Social, Technological, Environmental, and Legal) framework offers a systematic, externally validated method for listing these macro-environmental dimensions and breaking them down into actionable evaluation sub-criteria [22]. However, the literature on decision support has never integrated the PESTEL taxonomy with a fuzzy MCDM architecture in the selection of a cybersecurity platform.
This study fills the above-mentioned research gaps by proposing and validating a hybrid Fuzzy Multi-Criteria Decision-Making (FMCDM) model for selecting the best cybersecurity platforms based on PESTEL-derived criteria. The framework advances the state of the art in three ways. First, it uses pentagonal fuzzy numbers (PFNs), i.e., pentagonal forms, rather than traditional triangular or trapezoidal fuzzy forms. Pentagonal fuzzy numbers use five support points in their membership function rather than the three support points that triangular or trapezoidal fuzzy numbers have, which allows a more detailed expression of expert uncertainty, including asymmetric as well as multimodal preference distributions [13,23,27]. Second, the framework combines MCDM approaches (Fuzzy AHP, Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS methods) and integrates the results via a Borda Count consensus engine.
In this multi-method architecture, methodological sensitivity is directly addressed because the resulting ranking is insensitive to the aggregation logic of any given method [25]. The established evaluation criteria are based on a systematic PESTEL analysis that resulted in sixteen sub-criteria within the entire space of macro-environmental factors relevant to enterprise cybersecurity procurement. This study contributes to the literature of MCDM in four aspects. First, it offers a systematic evaluation of a cybersecurity platform in a PESTEL-based criteria framework. Second, it introduces a proven multi-method fuzzy MCDM methodology that reflects the agreement of various ranking methods. Third, it uses pentagonal fuzzy numbers (PFNs) instead of triangular fuzzy numbers (TFNs) or trapezoidal fuzzy numbers (TrFNs) to select a cybersecurity platform, whereas the previous literature employed only these forms. PFNs provide a representation of the cognitive structure of expert uncertainty in vague environments [13,28]. TFNs lack this attribute because they impose a symmetric rise and fall around a single peak, while TrFNs allow a flat certainty plateau. Fourth, it combines four different fuzzy MCDM approaches (FAHP, TOPSIS, VIKOR, COPRAS) with the Borda consensus. Lastly, there is a systematic PESTEL-based criteria taxonomy, as opposed to previous work, which used ad hoc or vendor-defined criteria.
The main contribution of this study is to construct a holistic and integrated Fuzzy Multi-Criteria Decision-Making (FMCDM) framework to select enterprise cybersecurity platforms, which is successful in combining strategic macro-environmental analysis with advanced uncertainty modelling and methodological robustness.
In particular, this work contributes to the literature in the following ways.
Most importantly, the study presents a systematic taxonomy for cybersecurity platform evaluation that includes sixteen well-validated sub-criteria through a PESTEL-based criteria taxonomy. Other MCDM studies conducted before mainly used ad hoc or narrowly technical criteria; however, this research uses a macro-environmental structure that has been accepted and widely applied, namely the PESTEL structure, so that key strategic factors, especially political and regulatory ones like cross-border data management, regulatory compliance, and government incentives, are seen at the right level. This PESTEL-based approach is the essence of the novelty of the work since it corresponds to the actual situation in which multinationals in industries with a high degree of regulation find themselves.
Second, the approach uses pentagonal fuzzy numbers (PFNs) to express expert judgments. Unlike the previously studied triangular and trapezoidal fuzzy numbers, which can only capture simple uncertainties, PFNs offer a richer, higher-resolution representation of uncertainty, which helps capture asymmetric and context-dependent preferences, as a feature of cybersecurity procurement decisions.
Third, the study applies a multi-method ranking algorithm using the Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS algorithms, and finally, the results are aggregated by the Borda Count consensus mechanism. This helps to overcome the long-standing problem of methodological sensitivity in MCDM research and increases confidence in the final ranking.
This study combines a PESTEL structured criteria taxonomy with improved uncertainty modelling (PFNs) and robust multi-method consensus (Borda) to provide a more holistic, context-suitable, and methodologically complete decision support system than current methods. The structure is particularly designed for complex, high-stakes surroundings, like multinational financial services groups.
The remaining sections of this article are organised as follows. Section 2 contains materials and methods, while Section 3 presents the information about the case study. Section 4 contains results. Section 5 presents this study’s conclusions.

2. Materials and Methods

The evaluation of a cybersecurity platform is based on MCDM methods. This study methodology is based on Fuzzy AHP, Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS, and uses a utility-based concept to select alternatives. The selection of Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS as parallel ranking methods is based on their distinct mathematical philosophies and complementary evaluation logics, as no single MCDM method is universally superior [25]. Fuzzy TOPSIS ranks alternatives by their distance to ideal solutions [20,27]. Fuzzy VIKOR prioritizes a compromise solution that balances group utility against individual regret, making it suitable for risk-averse contexts where failure in a single criterion (e.g., regulatory non-compliance) could be an issue [29]. Fuzzy COPRAS uses utility proportional assessment to provide a percentage-based ranking relative to the best alternative [30]. By employing multiple methods with divergent logics and aggregating their outputs using Borda Count, the framework in Figure 1 mitigates method-induced bias and enhances overall decision robustness. Borda Count helps to convert each method’s ranking into positional scores and ensures that no single method’s ranking dominates the final output [31].
Figure 1. Methodology of the research work.

2.1. Pentagonal Fuzzy Numbers

Pentagonal fuzzy numbers provide more flexibility in representing uncertainty by using multiple points to define the membership function [32]. A pentagonal fuzzy number (PFN) with n vertices is defined by a set of ordered points and corresponding membership values (Equation (1)). Table 1 shows different fuzzy numbers and associated membership values. More details about these membership functions are contained in [14]. TFNs use three points ( a 1 ,   a 2 ,   a 3 ) with membership (0, 1, 0) to capture only symmetric or linear uncertainty. TrFNs use four points ( a 1 ,   a 2 ,   a 3 ,   a 4 ) with membership (0, 1, 1, 0) to add a plateau of full certainty. On the other hand, PFNs use five points with membership (0, 0.5, 1, 0.5, 0) that allow the following:
Table 1. Different membership values.
  • Asymmetric uncertainty representation;
  • A graded transition between uncertainty and certainty;
  • Higher resolution in expert preference modelling.
A ~ = a 1 , a 2 , a 3 , a 4 , a 5
where a 1 < a 2 < a 3 < a 4 < a 5 are the support points and μ i ∈ 0 ,   1 are the membership degrees.
The following arithmetic operations can be performed using PTN for given for two PFNs A ~ = ( a 1 , a 2 , a 3 , a 4 , a 5 ) and B ~ = ( b 1 , b 2 , b 3 , b 4 , b 5 ) :
Addition
A ~ ⊕ B ~ = ( a 1 + b 1 , a 2 + b 2 , a 3 + b 3 , a 4 + b 4 , a 5 + b 5 )
Subtraction
A ~ ⊖ B ~ = ( a 1 − b 5 , a 2 − b 4 , a 3 − b 3 , a 4 − b 2 , a 5 − b 1 )
Multiplication (approximate for PFNs)
A ~ ⊗ B ~ ≈ ( a 1 b 1 , a 2 b 2 , a 3 b 3 , a 4 b 4 , a 5 b 5 )
Division (reciprocal for pairwise comparisons)
A ~ − 1 = 1 a 5 1 a 4 1 a 3 1 a 2 1 a 1
This study used a centroid (defuzzification) to generate crisp values for criteria and alternatives [33]. For a PFN A ~ = ( a 1 , a 2 , a 3 , a 4 , a 5 ) , the exact centroid formula is given as Equation (6).
C ( A ~ ) = ∫ 0 0.5 x ⋅ μ L ( x ) d x + ∫ 0.5 1 x ⋅ 1 d x + ∫ 1 0.5 x ⋅ μ R ( x ) d x Area
where μ L ( x ) and μ R ( x ) denote linear interpolations.
Equation (7) gives the expression for the Euclidean distance between two PFNs A ~ and B ~ with the same n vertices [34].
d ( A ~ , B ~ ) = a 1 − b 1 ) 2 + ( a 2 − b 2 ) 2 + ( a 3 − b 3 ) 2 + ( a 4 − b 4 ) 2 + ( a 5 − b 5 ) 2 5

2.2. Fuzzy AHP (FAHP)

The AHP proposed by [17] has been accepted as a powerful multi-criteria decision-making instrument to organise complex decisions by using pairwise comparisons. In practice, however, decision settings in the real world tend to imply judgments that are uncertain and vague instead of being represented by exact numerical values. In order to overcome this shortcoming, fuzzy extensions of AHP were created to introduce linguistic evaluations to the pairwise comparison process [35]. This study used information from four experts to determine the criteria priority weights (Equation (8)).
a ~ j i = a ~ i j − 1 = 1 u   1 m   1 l
For R experts, Equation (9) gives the expression for the aggregated fuzzy judgement for pair i j . This expression is the arithmetic mean of their point vectors.
a ‾ i j = 1 R a ~ i j 1 ⊕ a ~ i j 2 ⊕ ⋯ ⊕ a ~ i j R
On the other hand, the geometric mean method (Weights) can be used to aggregate experts’ responses (Equation (10)). For each criterion i , compute the fuzzy geometric mean of its row.
r ~ i = ⨂ j = 1 n a ‾ i j 1 / n
The fuzzy weight of criterion i is expressed as Equation (11). On the other hand, the crisp (defuzzified) weight is obtained via centroid and normalisation (Equation (12)).
w ~ i = r ~ i ⊗ ⨁ i = 1 n r ~ i − 1
w i = C ( w ~ i ) ∑ k = 1 n C ( w ~ k )

2.3. Fuzzy TOPSIS

TOPSIS is based on the idea that the best alternative must be closest to the positive ideal solution and farthest from the negative ideal solution. Ref. [27] generalised the traditional TOPSIS to the fuzzy context. It allows decision-makers to compare alternatives in terms of linguistic expressions that are represented by fuzzy numbers as opposed to crisp values. This MCDM ranks alternatives based on the information in a fuzzy decision matrix. Let x ~ i j be the aggregated fuzzy rating of framework i on criterion j across all respondents (13).
x ~ i j = 1 R ∑ r = 1 R x ~ i j r
Equation (14) gives the max-point normalisation for benefit criteria, while
r ~ i j = x ~ i j m a x i   x i j point
Equation (15) shows the expression for the weighted normalised matrix.
v ~ i j = w j ⋅ r ~ i j
The fuzzy positive and negative ideal solutions are expressed as Equations (16) and (17), respectively.
Rank ( A ~ ) = a 1 + 2 a 2 + 3 a 3 + 2 a 4 + a 5 9 ( weighted   average   method )
Then:
A ~ j + = v ~ i j ∣ m a x i   Rank ( v ~ i j )
A ~ j − = v ~ i j ∣ m i n i   Rank ( v ~ i j )
Equations (18) and (19) give the expression for the distances from ideal solutions
D i + = ∑ j = 1 m d   v ~ i j , v ~ j + 2
D i − = ∑ j = 1 m d   v ~ i j , v ~ j − 2
The relative closeness coefficient for alternative is expressed as Equation (20). A higher C C i indicates a better-ranked platform.
C C i = D i − D i + + D i − , C C i ∈ [ 0 ,   1 ]

2.4. Fuzzy VIKOR

The VIKOR method uses a compromise ranking method to solve multi-criteria decision-making problems whose criteria are opposite to each other [36]. In contrast to approaches that aim to find one optimal solution, VIKOR puts more emphasis on those alternatives that offer a compromise solution nearest to the optimal. It considers the overall group utility versus people feeling regret about the choice. This attribute of dual measurement ensures that VIKOR is especially applicable in risk-averse decision making, where failing in any one of the criteria may have drastic outcomes. This method uses the concept of best and worst values per criterion to generate ranks for alternatives in the decision matrix. Equations (21) and (22) represent the expressions for the best and worst values per criterion, respectively.
f ~ j ∗ = PFN   such   that   Rank ( f ~ j ∗ ) = m a x i   Rank ( x ~ i j )
f ~ j − = PFN   such   that   Rank ( f ~ j − ) = m i n i   Rank ( x ~ i j )
The group utility and individual regret for an MCDM problem are generated based on the best and worst values per criterion and criteria weights. Equation (23) gives the expression for alternatives utility, while alternatives regrets are determined using Equation (24).
S i = ∑ j = 1 m w j ⋅ C ( f ~ j ∗ ⊖ x ~ i j ) C ( f ~ j ∗ ⊖ f ~ j − )
R i = m a x j w j C ( f ~ j ∗ ⊖ x ~ i j ) C ( f ~ j ∗ ⊖ f ~ j − )
where C ( ⋅ ) is the PFN centroid, S i measures the overall performance gap and R i captures the worst single-criterion gap.
Equation (25) gives the expression for the VIKOR index. The value of this index is controlled using a strategy weight.
Q i = v ⋅ S i − S ∗ S − − S ∗ + ( 1 − v ) ⋅ R i − R ∗ R − − R ∗
where
  • S ∗ = m i n i S i , S − = m a x i S i
  • R ∗ = m i n i R i , R − = m a x i R i
  • v ∈ [ 0 ,   1 ] is the strategy weight ( v = 0.5 for consensus)
A lower Q i means a better compromise solution. Alternative selection is based on the following conditions. Equation (26) gives the expression for the first condition, which is acceptable advantage (C1), while the second condition, i.e., acceptable stability (C2), states that the top-ranked alternative must also be best in S or R .
Q ( a 2 ) − Q ( a 1 ) ≥ 1 n − 1
where a 1 and a 2 are the first- and second-ranked platforms.

2.5. Fuzzy COPRAS (COmplex PRoportional ASsessment)

The COPRAS approach evaluates alternatives by a proportional assessment of their performance on cost and benefit criteria [30]. In contrast to distance-based methods like TOPSIS, COPRAS produces a utility level that is a percentage of the best alternative, providing decision-makers with an intuitively explainable degree of relative efficiency. This method bases its decision on the information in a decision matrix. To reduce the impact of the criteria dimension on a decision process, this method uses normalisation to make the criteria in a decision matrix within the same range (Equation (27)). This equation scales each column so its centroid-sum equals n (the number of alternatives).
x ^ i j = x ~ i j ∑ i = 1 n C ( x ~ i j ) ⋅ n
Note: Division by a scalar applies to all 5 components:
x ^ i j = ( x i j 1 / k , x i j 2 / k , x i j 3 / k , x i j 4 / k , x i j 5 / k )
k = ∑ i C ( x ~ i j ) n
Based on the normalised values, Equation (28) is used to compute the alternatives’ weighted sum of benefit criteria. On the other hand, the alternatives’ weighted sum of cost criteria is expressed as Equation (29).
S i + = ∑ j = 1 g w j ⋅ C x ^ i j
S i − = ∑ j = 1 + g m w j ⋅ C ( x ^ i j )
Equation (30) gives the expressive of the relative significance of platform.
Q i = S i + + S m i n ⋅ ∑ i = 1 n S i − S i − ⋅ ∑ i = 1 n S m i n S i −
The utility degree expresses each platform’s performance relative to the best platform (Equation (31)).
N i = Q i Q m a x × 100 %

2.6. Statistical Tests

This study used a Borda Count to generate the consensus ranks for the platform. Each MCDM method contributes a positional rank (vote). For n platforms, the Borda score for platform i from method k is given as Equation (32). This equation ensures rank 1 receives score 6, rank 6 receives score 1.
B i k = n + 1 − rank k ( i )
Equation (33) gives the expression for the aggregated consensus score averaged across K methods.
B ¯ i = 1 K ∑ k = 1 K B i k
The method agreement (Spearman’s Rank Correlation) is determined using Equation (34). This coefficient quantifies the strength of the monotonic relationship between two MCDM rankings without assuming linearity or normality.
ρ s = 1 − 6 ∑ i = 1 n d i 2 n ( n 2 − 1 )
where d i = rank k 1 ( i ) − rank k 2 ( i ) is the rank difference for platform i . A value of ρ s → 1 indicates strong agreement between methods.
This study used Kendall’s coefficient (W) to assess the agreement among methods, which requires a multivariate statistic [37]. This coefficient quantifies the degree of agreement among K ranking methods. For K methods (here, K = 3 : TOPSIS, VIKOR, COPRAS) and n alternatives, W is computed as Equation (35). W ranges from 0 (no agreement) to 1 (perfect agreement).
W = 12 ∑ i = 1 n ( R i − R ¯ ) 2 K 2 ( n 3 − n )
where R i = ∑ k = 1 K rank k ( i ) is the sum of ranks assigned to alternative i across all K methods, and R ¯ = K ( n + 1 ) / 2 is the expected mean rank sum under no agreement [38].
In the event that two or more platforms receive identical average Borda scores ( B ¯ i ), Equation (36) is used to compute the variance of method-specific ranks for each tied platform across MCDM methods. The platform with lower rank variance is ranked higher [25].
σ i 2 = 1 K ∑ k = 1 K r i k r ¯ i 2
where r i k denotes the rank assigned to platform i by method k , and r ¯ i denotes the mean rank across methods.

3. Case Study

The MCDM framework is used to process the selection of the most suitable cybersecurity platform in a multinational financial services organization that functions in various countries and has around 45,000 employees. The company was under pressure in terms of regulators, advanced cybercrimes, and the necessity to upgrade its security systems. To assess the six most popular cybersecurity platforms based on sixteen sub-criteria derived using the PESTEL framework because of preliminary work, four domain experts were considered (Table 2).
Table 2. Expert panel demographics elicited through a structured linguistic questionnaire.
Four domain experts (see Table 2 of the main manuscript) independently rated each candidate sub-criterion on a 5-point Likert scale: 1 = Not relevant, 2 = Slightly relevant, 3 = Moderately relevant, 4 = Highly relevant, 5 = Extremely relevant. The present study used Equation (36) to evaluate the criteria content validity ratios [39]. The minimum CVR for statistical significance at p < 0.05 with four experts is 0.49 (Wilson, Pan, & Schumsky, 2012) [40]. Items with C V R < 0.49 were eliminated. Table 3 presents the selected criteria; see Table A1 for more details.
C V R = n e − N / 2 N / 2
where n e = number of experts rating the item as 4 or 5 (“relevant”), and N = 4 .
Table 3. PESTEL-based evaluation criteria.
Table 4 shows that the six platforms selected for evaluation represent market-leading solutions with distinct architectural approaches. The cybersecurity platforms (Table 4) were selected to cover a variety of architectural paradigms, yet have sufficient similarity in terms of functionality to provide a fair comparison. To make it possible to compare, the evaluation scope was made explicit on four dimensions.
Table 4. Cybersecurity platforms considered in the study.
  • Core security functions: These functions are common to all six, and include endpoint detection and response (EDR), extended detection and response (XDR), cloud security posture management (CSPM), basic SIEM capabilities, and network security.
  • Differentiating functions (excluded/adjusted): Native compliance dashboards (uniquely Microsoft), advanced identity protection (Microsoft and Cisco), and SOAR depth (Palo Alto superior). Either were omitted from the evaluation or were evaluated on integration rather than native presence.
  • Expert panel instructions: The expert panel was explicitly instructed to rate compliance-related criteria (C1–C3) as related to each platform’s ability to be integrated into existing enterprise compliance systems (through API log forwarding, pre-built compliance packs for Microsoft Sentinel, or third-party SIEM connectors), not a requirement for native compliance modules. That will not allow for the creation of an artificial advantage with Microsoft’s unique compliance dashboard.
  • Post-hoc sensitivity analysis: Provided further robust support for Microsoft’s first-place ranking, other than when technological criteria are more significant (50% weight), in which case CrowdStrike was in first place. This finding is published openly.
The experts provided pairwise comparisons of criteria importance using the linguistic scale. In this study, the experts rated all six platforms against all sixteen sub-criteria using a linguistic performance scale (Table 5). Using Equation (9) from the methodology, fuzzy judgments were aggregated across all four experts. Table 6 shows the PFN pairwise comparison scale.
Table 5. Linguistic performance scale.
Table 6. PFN pairwise comparison scale.

4. Results

4.1. Criteria Weights

The fuzzy AHP weights of the six PESTEL key criteria are presented in Figure 2. Political criterion has the highest relative priority. Table A2 and Table A3 show aggregated of the criteria and sub-criteria. In the present study, consistency ratios (CRs) of 0.03 and 0.0011 were obtained for the criteria and sub-criteria, respectively. These values showed that the pairwise comparisons are consistent [17]. Its sub-criteria include cross-border data management, regulatory compliance, and government incentive structures. The given finding aligns with other works, which also emphasized the pivotal role of geopolitical regulation and data sovereignty in undertaking the technology procurement decisions in enterprises [22,41]. Regulatory compliance is now at the centre of cybersecurity investment logic because the world has gone global in enacting data protection laws, such as the European General Data Protection Regulation (GDPR), the US CLOUD Act, and various other Asian Pacific systems [2,3]. Economic criterion emerged as the second most important criterion. The economic criterion (w = 0.26) is an indicator of return on investment (ROI), total cost of ownership (TCO), and economic scalability. This observation is consistent with the resource-constrained procurement theory, which opines that organisational decision-makers strike a balance between security efficacy and financial sustainability [1,19].
Figure 2. Main criteria priority weights derived from fuzzy AHP.
Social criterion accounted for 0.16 of the total weight. It includes the workforce competencies, the customer trust, and the compatibility of remote work, which is emerging as dominant due to the continued expansion of hybrid work arrangements after 2020 [42]. Although the technological criterion (w = 0.08) has the fourth place, it has significant weighting due to the high rate of the evolution of threats and the automation demand that is supported by AI (Srinivas et al., 2019) [43]. The lowest weights were attributed to the environmental (w = 0.05) and legal (w = 0.04) dimensions.
Table 6 shows the weights of all 16 sub-criteria calculated by the FAHP procedure. The three political sub-criteria (cross-border data management (0.1463), regulatory compliance (0.1672), and government incentives (0.1045)) sum up to 41.80% of the total decision weight, further reinforcing the importance of political and regulatory concerns in the selection of cybersecurity platforms for multinational enterprises. Economic sub-criteria include return on investment (ROI) (0.1040), total cost of ownership (0.0910), and economic scalability (0.0650), accounting for 26.00% of the overall weight. The social sub-criteria (workforce skill availability, customer trust, and remote work compatibility) have 16.00%, 8.00%, 5.00%, and 3.19%, respectively. Regulatory compliance (0.1672) and cross-border data management (0.1463) are the top two most significant individual factors among the 16 sub-criteria, highlighting the key roles of data sovereignty and legal compliance in enterprise cybersecurity procurement decisions.
Table 7 shows the PESTEL results, which are ranked on a global basis. The three highest ranking sub-criteria are cross-border data management, regulatory compliance, and government incentives, with a cumulative weight of 41.82% to the overall weight of the decision. Following at 0.0857 each and adding an additional 25.71% cumulative, it can be seen that return on investment, total cost of ownership, and economic scalability follow. Economic sub-criteria are dominated by return on investment and total cost of ownership, which represents empirical evidence that organisations are increasingly subjecting cybersecurity spending to formal investment appraisal procedures [44].
Table 7. Sub-criteria weights.

4.2. MCDM Method Results

Figure 3 shows the results of the fuzzy TOPSIS with closeness coefficients, distances to the fuzzy positive ideal solution, and distances to the fuzzy negative ideal solution of all six cybersecurity platforms. The Microsoft security platform has a significantly higher closeness coefficient, which is more than 0.31 higher than CrowdStrike Falcon, the second-ranked platform. A CC of about 1.0 implies that it is close to the fuzzy positive ideal solution and far away from the fuzzy negative ideal solution [27]. CrowdStrike Falcon and Cisco solutions are divided by less than 0.006, which means that CrowdStrike Falcon (CC = 0.5713) and Cisco Cybersecurity Portfolio (CC = 0.5667) are statistically close in terms of the overall performance profile. The fact that the TOPSIS scores are almost identical indicates that the decision between the two platforms can be highly situational, depending on the criteria that are most important to the organisation. The mid-table ranking of Palo Alto (CC = 0.5094) indicates good technological results along with rather low scores on political and economic sub-criteria according to the view of the professional panel. Fortinet and Sophos have large d+ distances (0.8912 and 0.9321, respectively), which indicate a large distance to the fuzzy positive ideal solution. Their lower d-values (0.3856 and 0.3367) affirm their closer resemblance to the fuzzy negative ideal solution.
Figure 3. The platforms’ performance based on different MCDM methods.
Figure 3 also shows the fuzzy VIKOR outputs with the balanced strategy weight v = 0.5. Microsoft Security Platform performs the best in minimising a loss in group utility and individual regret at the same time, which is the optimal compromise solution [29]. It met the two VIKOR conditions of acceptance, C1 (acceptable advantage) and C2 (acceptable stability), to prove the strength of the ranking beyond a numerical artefact. Palo Alto is ranked second behind VIKOR as opposed to the fourth-place TOPSIS ranking. The difference is because VIKOR minimises regret (R), while TOPSIS minimises the distance. CrowdStrike Falcon is ranked third. The VIKOR index of 1.0000 for Sophos makes it the most distant from the compromise solution and validates the finding of TOPSIS.
Figure 3 shows the fuzzy COPRAS rankings, which give the relative importance (Q) and utility level of each platform in terms of a percentage of the best performing alternative. Microsoft had the highest level of Q (1.0973) and a utility level of 100 per cent, which proves that it is the standard according to which all other platforms are evaluated. The utility level of COPRA can be interpreted as one of the unique degrees of efficiency that is directly proportional; the other alternatives are considered as fractions of the total utility of Microsoft [30]. The utility degree of CrowdStrike is 93.59% (Q = 1.0270), which gives it the second-place position. The COPRAS result shows a progressive decrease in the levels of utility: Cisco (92.05%), Palo Alto (90.70%), Fortinet (86.47%), and Sophos (83.99%). COPRAS places Cisco in third and Palo Alto in fourth place, which is in agreement with TOPSIS but contrary to Palo Alto in second place of VIKOR. The range of compressed utility of 83.99 to 93.59% amongst the bottom five platforms implies that COPRAS does not draw a line between the middle-ranged options as TOPSIS does, which is the hallmark of the utility-based normalisation techniques (Zavadskas and Turskis, 2011) [45].

4.3. Comparative Analysis

Table 8 shows the analysis among the TOPSIS, VIKOR, and COPRAS ranking of the six platforms. The MCDM ranking of Microsoft, Fortinet, and Sophos are consistent, which are 1st, 5th, and 6th, respectively. The consistency is a strong indication that the rankings have some degree of stability. Palo Alto Networks Cortex has the greatest difference in methods, with the two ranking 4th by TOPSIS and COPRAS and 2nd by VIKOR. Spearman coefficients of the three procedures are more than 0.82, which confirms that inter-method reliability is high. The highest correlation is the TOPSIS–COPRAS correlation since the methodologies of the two normalisations and distance are similar, whereas TOPSIS–VIKOR and COPRAS–VIKOR correlations are indicative of the compromise-versus-optimisation difference. These correlation coefficients agree with the results in comparative literature of MCDM [25]. The dominance of the Political criterion and the consistent first-place ranking of Microsoft Security Framework contrast with the technically oriented findings of [4,5,10], whose narrower criterion sets elevated technological performance metrics over regulatory alignment dimensions. This confirms that PESTEL-grounded criteria capture a materially different and more organisationally complete decision space than vendor benchmark or technically derived criteria sets, representing the primary distinguishing contribution of the present framework relative to prior cybersecurity MCDM studies. Furthermore, the statistically validated inter-method agreement reported in Table 9 and Table 10, with Kendall’s W = 0.9238 and p = 0.0165, provides a level of ranking robustness not demonstrated in any single-method study reviewed in the literature, including [11,12]. The adoption of pentagonal fuzzy numbers in place of the triangular and trapezoidal representations used in all prior cybersecurity platform selection studies further distinguishes the present framework by providing a richer and more faithful encoding of expert uncertainty, as theorised by [13,14] and demonstrated empirically in the consistent rankings produced across all three MCDM methods.
Table 8. Comprehensive method comparison.
Table 9. Statistical validation of inter-method agreement.
Table 10. Validation of Consensus Rankings Across MCDM Methods.

4.4. Statistical Validation

Table 8 shows the rankings obtained through the Borda Count mechanism. This mechanism combines the positional ranks of the three MCDM methods to produce a composite score. It attaches scores to each option in terms of how it ranks in each constituent method [31,46]. Microsoft’s security platform has a Borda score of 6.000; it received all the first-place ratings in TOPSIS, VIKOR, and COPRAS. This is the maximum possible consensus score, which signifies that the Microsoft Security Platform is the best cybersecurity platform under the PESTEL-weighted criterion.
The Borda score of 4.667 for CrowdStrike shows good TOPSIS (rank 2) and COPRAS (rank 2), but to the detriment of its VIKOR rank (rank 3). It is validated as the second option. The performance of CrowdStrike is especially remarkable in the technological aspect, which aligns with its leadership in the industry in terms of operationalisation of threat intelligence [43]. Cisco has a Borda score of 3.667, which is the same value as Palo Alto (3.667), but based on tiebreaking, it was ranked at position three due to the differentiation of the two platforms by VIKOR. The fact that Cisco scored the highest of the three in both the TOPSIS and COPRAS, as well as its VIKOR score of 4, indicates that it performed fairly well across the entire criterion space but has certain areas with weaknesses in specific criteria, presumably in the areas of automation of AI and modern cloud-native architecture, compared to CrowdStrike and Palo Alto.
Table 10 shows the statistical confirmation of the agreement rankings: Kendall coefficient of concordance W = 0.9238, chi-square 13.8571, degrees of freedom 5, and p = 0.0165. Kendall’s W Interpretation. The inter-method agreement is in the very strong category with a W of 0.9238 because W above 0.70 is traditionally known as strong, and W above 0.90 is excellent when used to analyse decisions [37,47]. This study observed that the three MCDM methods’ results were statistically significant at the 0.05 level, as the chi-square statistic (χ2 = 13.8571, df = 5, p = 0.0165).

4.5. Sensitivity Analysis

To determine if the first-place rankings by Microsoft are persistent across scope normalisation, three different scope evaluation scenarios were simulated (Table 11). In all scenarios (except for Scenario 4, which is technology-weighted), where it matters, Microsoft is in the lead. This suggests that, under reasonable scope normalisation, the Microsoft framework had 1st place, but its lead is dependent on the degree to which political/compliance factors are assigned weight. If a company is focused on only technical performance rather than regulatory compliance, it might opt for CrowdStrike.
Table 11. Scenario analysis for platform ranking under different scope definitions.

4.6. Robustness Analysis

Four complementary sensitivity analyses are used to determine the stability of the final Borda consensus ranking. The first test is on the perturbation of the criteria weights. The intent of this test is to determine if a slight adjustment in FAHP weights would cause the final ranking to change. A Monte Carlo simulation (10,000 iterations) is used for this test, such that for each iteration
  • Add or subtract 20% (uniform random) to the weights on each of the main criteria;
  • Perturb each main criterion weight by ±20% (uniform random);
  • Renormalize to sum = 1.0;
  • Recalculate TOPSIS, VIKOR, COPRAS, and Borda consensus;
  • Record the rank of each platform.
The results show that Microsoft Security Framework (A1) remained highly dominant and stable throughout the simulations (Table 12). It retained the first-place ranking in 94.2% of all iterations and appeared within the top three positions in almost every simulation (99.8%). Its high stability index of 0.96 suggests that the platform’s leading position is not easily affected by moderate variations in criteria importance. This indicates that Microsoft consistently performs well across the different evaluation dimensions considered in the study. CrowdStrike Falcon (A2) was the only platform that occasionally challenged Microsoft for the top position, securing first place in 5.8% of the simulations. It also maintained a strong overall performance by appearing in the top three positions in 91.3% of the iterations. This suggests that CrowdStrike becomes more competitive when certain criteria, especially technological factors, receive relatively higher weights.
Table 12. Criteria weight perturbation results.
Cisco (A3) also demonstrated reasonably stable performance, remaining in the top three positions in 78.4% of the simulations. In contrast, Palo Alto Networks Cortex (A4) showed the greatest sensitivity to weight changes, with the lowest stability index of 0.69. Its ranking fluctuated more often compared to the other platforms, occasionally competing with Cisco or Fortinet, depending on the weighting scenario. Interestingly, Fortinet (A5) and Sophos (A6) recorded high stability indices despite being consistently ranked in the lower positions. This means that while their rankings rarely changed, they consistently remained less preferred alternatives within the decision framework. The findings from Table 12 demonstrate that the proposed FMCDM framework is robust and reliable under moderate uncertainty in criteria weighting. The consistent dominance of Microsoft and the relatively stable positions of the other platforms indicate that the final Borda consensus ranking is dependable and not overly sensitive to small variations in expert judgments.
The second sensitivity analysis involves expert-input bootstrap, which was tested to determine whether or not a small expert panel yields stable ranks. This study uses a bootstrap resampling (1000 iterations) from the 4 experts with replacement to perform the test. Table 13 shows the results for this test. The first quartile of the 95% CI for Microsoft’s 95% CI is 1, and the third quartile is 2, with it being first in 93% of the bootstrap samples. Ranking second is less certain as CrowdStrike’s CI overlaps with Microsoft and Cisco. Palo Alto has a low baseline stability (58%), which means that it has a high sensitivity toward the expert composition. The top rank (Microsoft) is stable to experts’ sampling variation. The second place (CrowdStrike) is moderately secure, but could be surpassed by Cisco if the experts’ makeup were different.
Table 13. Expert-input bootstrap.
The next test is related to fuzzy number type comparison. The aim of the test was to determine if the use of PFNs is likely to alter the results of the final ranking when compared to the TFNs or TrFNs. We re-ran the FAHP + TOP-SIS + VIKOR + COPRAS + Borda three times in the test, each time with a different fuzzy representation. Linguistic-to-fuzzy mappings are designed in such a way that the centre of each fuzzy number corresponds in each type. Table 14 shows the result obtained. Although the different fuzzy representations, the ordinal ranking is the same for TFN, TrFN, and PFN. This results in the rank not being sensitive to the type of fuzzy number shape; however, PFNs allow more information about uncertainty in the sensitivity analysis. It was noted that the type of fuzzy number does not influence the end Borda ranking.
Table 14. Ordinal ranking of the alternatives.
Table 15 presents a VIKOR strategy weight (v) test. This test is used to determine whether VIKOR’s strategy weight v ∈ [ 0 ,   1 ] changes the VIKOR-specific ranking. The test result shows that Microsoft is insensitive to v —it is always ranked first. On the other hand, the second place oscillates as follows:
Table 15. Robustness of Platform Rankings Across Different VIKOR Strategy Weights.
  • v ≤ 0.6 : Palo Alto is second (favoured when minimising regret);
  • v ≥ 0.7 : CrowdStrike is second (favoured when maximising utility).
With regards to the Borda consensus, it aggregates TOPSIS, COPRAS, and VIKOR, and TOPSIS/COPRAS consistently ranks CrowdStrike second, making the last Borda rank the same for v ≥ 0.3. If the risk factor is very low (v < 0.3), Borda would result in a tie for second place between CrowdStrike and Palo Alto. When v = 0.5, it is a suitable baseline value for balanced decision-making. The second place is very sensitive in the sense that a change in the strategy weight of VIKOR causes it to switch places with the third place, while the top ranking is more robust. Decisions should be made with this trade-off made clear to decision makers.

5. Conclusions

This paper presented a hybrid Fuzzy Multi-Criteria Decision-Making (FMCDM) model of cybersecurity platform selection that builds upon the current body of literature in three substantive ways. First, the use of pentagonal fuzzy numbers (PFNs) in place of either triangular or trapezoidal representations gives a richer encoding of expert uncertainty, in which asymmetric and multimodal distributions of preferences can be represented, which are suppressed by conventional fuzzy forms. Second, the parallel implementation of Fuzzy AHP, Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS, which are aggregated using a Borda Count consensus mechanism, directly solves the methodological sensitivity issue that has been found to exist in previous MCDM literature, whereby ranking results are inappropriately influenced by the analytical method used as opposed to true differences in platform performance. Third, the derived sixteen evaluation sub-criteria through a structured PESTEL analysis demonstrate a theoretically grounded, externally validated criteria taxonomy, in place of the ad hoc or vendor-defined criteria sets that characterise much of the extant cybersecurity decision-support literature.
The practical implications of the empirical results have significant implications for the enterprise procurement practice. The primacy of the Political criterion (w = 0.4181), which is facilitated by the cross-border data management, regulatory compliance, and alignment of incentives by the government, confirms that the choice made by multinational organisations concerning the selection of the cybersecurity platforms is essentially a regulatory and governance issue rather than a technical one. The evaluation of vendors in highly regulated industries, including financial services, should, therefore, place greater emphasis on geopolitical and data sovereignty considerations in their vendor evaluation models, as opposed to considering technical capability as the dominant selection axis. The strong, consistent first-place ranking of Microsoft Security Framework in Fuzzy TOPSIS, Fuzzy VIKOR, and Fuzzy COPRAS, supported by high inter-method agreement (Kendall’s W close to unity), is indicative of its breadth of regulatory alignment and its ability to integrate these elements, which is a structural advantage in complex, multi-jurisdictional procurement contexts, not merely a market-share artefact.
The framework, however, is bound by limitations which constrained the generalisability of such findings. The expert panel includes four practitioners, based on one multinational financial services organisation’s regulatory environment and risk appetite. Replication in other domains, e.g., healthcare, critical national infrastructure, or public administration, may result in materially different weight distributions, especially in the case of the Environmental and Legal sub-criteria, which had the lowest weights in the current study. Additionally, there is a lack of incorporation of the temporal dynamics of the cybersecurity threat environment, whereby the capabilities of platforms and regulatory demands rapidly change. Future studies, thus, ought to consider dynamic MCDM extensions, e.g., time-series weighted fuzzy judgements or adaptive Borda aggregation, to support criterion drift. More work could also explore how real-time threat intelligence feeds can be integrated as quantitative inputs and expert linguistic judgments, and how to extend the PFN framework to intuitionistic or neutrosophic representations to cope with higher-order uncertainty in adversarial settings.

Author Contributions

Conceptualization, D.E.I., M.O.B. and O.O.; methodology, D.E.I. and M.O.B.; software, D.E.I. and C.K.; validation, D.E.I., C.K., O.O. and M.O.B.; formal analysis, D.E.I., C.K. and O.O.; investigation, D.E.I., C.K. and O.A.O.; resources, M.O.B. and O.O.; data curation, C.K. and O.A.O.; writing—original draft preparation, D.E.I. and C.K.; writing—review and editing, M.O.B., O.O. and O.A.O.; visualization, D.E.I. and C.K.; supervision, M.O.B. and O.O.; project administration, O.O.; funding acquisition, M.O.B. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Data Availability Statement

The original contributions presented in this study are included in the article.

Conflicts of Interest

The authors declare no conflicts of interest.

Appendix A

Table A1. Content validity assessment of selected PESTEL sub-criteria.
Table A2. Aggregated fuzzy decision matrix for criteria.
Table A3. Aggregated fuzzy decision matrix for alternative.
Table A4. Aggregated fuzzy decision matrix for sub-criteria.

References

  1. Gordon, L.A.; Loeb, M.P. The economics of information security investment. ACM Trans. Inf. Syst. Secur. 2002, 5, 438–457. [Google Scholar] [CrossRef] [Scilit]
  2. Kshetri, N. The global cybercrime industry and its structure: Relevant actors, motivations, threats and countermeasures. Telecommun. Policy 2014, 38, 1003–1028. [Google Scholar]
  3. European Parliament. Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). Off. J. Eur. Union 2016, 119, 1–88. [Google Scholar]
  4. Torbacki, W. A hybrid MCDM model combining DANP and PROMETHEE II methods for the assessment of cybersecurity in industry 4.0. Sustainability 2021, 13, 8833. [Google Scholar] [CrossRef] [Scilit]
  5. Alharbi, A.; Seh, A.H.; Alosaimi, W.; Alyami, H.; Agrawal, A.; Kumar, R.; Khan, R.A. Analyzing the impact of cyber security related attributes for intrusion detection systems. Sustainability 2021, 13, 12337. [Google Scholar] [CrossRef] [Scilit]
  6. Abdulsalam, K.A.; Adebisi, J.; Emezirinwune, M.; Babatunde, O. An overview and multicriteria analysis of communication technologies for smart grid applications. e-Prime Adv. Electr. Eng. Electron. Energy 2023, 3, 100121. [Google Scholar] [CrossRef] [Scilit]
  7. Babatunde, O.; Emezirinwune, M.; Adebisi, J.; Abdulsalam, K.A.; Akintayo, B.; Adebisi, J. A fuzzy multi-criteria approach for selecting sustainable power systems simulation software in undergraduate education. Sustainability 2024, 16, 8994. [Google Scholar] [CrossRef] [Scilit]
  8. AbdelMouty, A.M.; Abdel-Monem, A. Neutrosophic MCDM methodology for assessment risks of cyber security in power management. Neutrosophic Syst. Appl. 2023, 3, 53–61. [Google Scholar] [CrossRef] [Scilit]
  9. Nguyen, P.H.; Nguyen, L.A.T.; Pham, H.A.T.; Nguyen, T.H.T.; Vu, T.G. Assessing cybersecurity risks and prioritizing top strategies in Vietnam’s finance and banking system using strategic decision-making models-based neutrosophic sets and Z number. Heliyon 2024, 10, e37893. [Google Scholar] [PubMed]
  10. Yang, Z. Evaluation of intrusion detection systems in cyber security using fuzzy OffLogic and MCDM approach. Neutrosophic Sets Syst. 2025, 85, 20. [Google Scholar]
  11. Taborda Blandon, G.E.; Hurtado Rivera, J.F.; Durán Vásquez, J.M.; Monsalve Ruiz, M.J.; Silva Castillo, M.T.; Vargas Montoya, H.F. Selecting a cybersecurity risk analysis methodology for MSMEs using a multi-criteria method (AHP). Technologies 2026, 14, 227. [Google Scholar] [CrossRef] [Scilit]
  12. Ansari, M.; Ali, S.A.; Alam, M.; Al Hudaify, S.; Al Natour, M. Multi-criteria decision modeling for cybersecurity investment and IT risk governance. EDPACS 2026, 1–11. [Google Scholar] [CrossRef] [Scilit]
  13. Mondal, S.P.; Mandal, M. Pentagonal fuzzy number, its properties and application in fuzzy equation. Future Comput. Inform. J. 2017, 2, 110–117. [Google Scholar] [CrossRef] [Scilit]
  14. Kamble, A.J. Some notes on pentagonal fuzzy numbers. Int. J. Fuzzy Math. Arch. 2017, 13, 113–121. [Google Scholar] [CrossRef] [Scilit]
  15. Özgür, R.; Eren, T. Strategy selection against cyber and phishing attacks in the financial sector using MCDM methods. Bilişim Teknol. Derg. 2026, 19, 185–199. [Google Scholar] [CrossRef] [Scilit]
  16. Bhol, S.G. Applications of multi criteria decision making methods in cyber security. In Cyber-Physical Systems Security; Springer: Singapore, 2025; pp. 233–258. [Google Scholar]
  17. Saaty, T.L. Decision making with the analytic hierarchy process. Int. J. Serv. Sci. 2008, 1, 83–98. [Google Scholar] [CrossRef] [Scilit]
  18. Triantaphyllou, E. Multi-Criteria Decision-Making Methods: A Comparative Study; Kluwer Academic Publishers: Dordrecht, The Netherlands, 2000. [Google Scholar]
  19. Bodin, L.D.; Gordon, L.A.; Loeb, M.P. Evaluating information security investments using the analytic hierarchy process. Commun. ACM 2005, 48, 78–83. [Google Scholar] [CrossRef] [Scilit]
  20. Bottani, E.; Rizzi, A. A fuzzy TOPSIS methodology to support outsourcing of logistics services. Supply Chain Manag. Int. J. 2006, 11, 294–308. [Google Scholar] [CrossRef] [Scilit]
  21. Tavana, M.; Mousavi, S.M.; Ghasempoor, A.; Alikhani, H. A new dynamic MCDM for cyber-attack classification with a case study. Decis. Support Syst. 2013, 54, 1456–1465. [Google Scholar]
  22. Kahraman, C.; Öztayşi, B.; Çevik Onar, S. Fuzzy multicriteria decision-making: A literature review. Int. J. Comput. Intell. Syst. 2015, 8, 637–666. [Google Scholar] [CrossRef] [Scilit]
  23. Buckley, J.J. Fuzzy hierarchical analysis. Fuzzy Sets Syst. 1985, 17, 233–247. [Google Scholar] [CrossRef] [Scilit]
  24. Chang, D.Y. Applications of the extent analysis method on fuzzy AHP. Eur. J. Oper. Res. 1996, 95, 649–655. [Google Scholar] [CrossRef] [Scilit]
  25. Zanakis, S.H.; Solomon, A.; Wishart, N.; Dublish, S. Multi-attribute decision making: A simulation comparison of select methods. Eur. J. Oper. Res. 1998, 107, 507–529. [Google Scholar] [CrossRef] [Scilit]
  26. Wang, Y.M.; Elhag, T.M.S. Fuzzy TOPSIS method based on alpha level sets with an application to bridge risk assessment. Expert Syst. Appl. 2006, 31, 309–319. [Google Scholar] [CrossRef] [Scilit]
  27. Chen, C.T. Extensions of the TOPSIS for group decision-making under fuzzy environment. Fuzzy Sets Syst. 2000, 114, 1–9. [Google Scholar] [CrossRef] [Scilit]
  28. Basuri, T.; Gazi, K.H.; Das, S.G.; Mondal, S.P. Ranking higher education institutions using entropy–VIKOR with generalized pentagonal intuitionistic fuzzy numbers. J. Contemp. Decis. Sci. 2026, 2, 64–83. [Google Scholar] [CrossRef] [Scilit]
  29. Opricovic, S.; Tzeng, G.H. Compromise solution by MCDM methods: A comparative analysis of VIKOR and TOPSIS. Eur. J. Oper. Res. 2004, 156, 445–455. [Google Scholar] [CrossRef] [Scilit]
  30. Zavadskas, E.K.; Kaklauskas, A.; Šarka, V. The new method of multicriteria complex proportional assessment of projects. Technol. Econ. Dev. Econ. 1994, 1, 131–139. [Google Scholar]
  31. Young, H.P. An axiomatization of Borda’s rule. J. Econ. Theory 1974, 9, 43–52. [Google Scholar] [CrossRef] [Scilit]
  32. Ishtiaq, A.; Kubra, K.T.; Uzair, A.; Ali, A. Quantifying multi-cause psychological disorder risk through an advanced mathematical model using intuitionistic pentagonal fuzzy logic. Spectr. Oper. Res. 2027, 1–21, Online first. [Google Scholar] [CrossRef] [Scilit]
  33. Pourabdollah, A.; Mendel, J.M.; John, R.I. Alpha-cut representation used for defuzzification in rule-based systems. Fuzzy Sets Syst. 2020, 399, 110–132. [Google Scholar]
  34. Li, X.; Tao, Y.; Li, Y. Decision making method for evaluating logistics companies based on the ordered representation of the polygonal fuzziness1. J. Intell. Fuzzy Syst. 2020, 39, 3151–3166. [Google Scholar] [CrossRef] [Scilit]
  35. Kahraman, C.; Cebi, S.; Oztaysi, B.; Onar, S.C. Fuzzy sets and their extensions: Literature review on fuzzy extensions of AHP. In Analytic Hierarchy Process with Fuzzy Sets Extensions; Springer: Cham, Switzerland, 2023; pp. 1–25. [Google Scholar]
  36. Opricovic, S. Multicriteria optimization of civil engineering systems. Fac. Civ. Eng. Belgrade 1998, 2, 5–21. [Google Scholar]
  37. Kendall, M.G.; Smith, B.B. The problem of m rankings. Ann. Math. Stat. 1939, 10, 275–287. [Google Scholar] [CrossRef] [Scilit]
  38. Siegel, S.; Castellan, N.J. Nonparametric Statistics for the Behavioural Sciences, 2nd ed.; McGraw-Hill: Columbus, OH, USA, 1988. [Google Scholar]
  39. Lawshe, C.H. A quantitative approach to content validity. Pers. Psychol. 1975, 28, 563–575. [Google Scholar] [CrossRef] [Scilit]
  40. Wilson, F.R.; Pan, W.; Schumsky, D.A. Recalculation of the critical values for Lawshe’s content validity ratio. Meas. Eval. Couns. Dev. 2012, 45, 197–210. [Google Scholar] [CrossRef] [Scilit]
  41. Dabbagh, M.; Lee, S.P.; Parizi, R.M. Application of integrated entropy-VIKOR method in assessment of e-government citizen/user satisfaction. Telemat. Inform. 2016, 33, 288–302. [Google Scholar]
  42. Miloslavskaya, N.; Tolstoy, A. Big data, fast data and data lake concepts. Procedia Comput. Sci. 2019, 88, 300–305. [Google Scholar] [CrossRef] [Scilit]
  43. Srinivas, P.; Lin, C.H.; Kambhampati, S.; Shakarian, P. AI in Cybersecurity; Springer: Berlin/Heidelberg, Germany, 2019. [Google Scholar]
  44. Cavusoglu, H.; Mishra, B.; Raghunathan, S. A model for evaluating IT security investments. Commun. ACM 2004, 47, 87–92. [Google Scholar] [CrossRef] [Scilit]
  45. Zavadskas, E.K.; Turskis, Z. Multiple criteria decision making (MCDM) methods in economics: An overview. Technol. Econ. Dev. Econ. 2011, 17, 397–427. [Google Scholar] [CrossRef] [Scilit]
  46. de Borda, J.C. Mémoire sur les élections au scrutin. Hist. L’académie R. Sci. 1781, 102, 657–665. [Google Scholar]
  47. Schmidt, R.C. Managing Delphi surveys using nonparametric statistical techniques. Decis. Sci. 1997, 28, 763–774. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.