Abstract
In the current context of digital transformation, Micro-, Small-, and Medium-Sized Enterprises (MSMEs) are increasingly exposed to cybersecurity risks. This exposure is intensified by the limited adoption of international standards for identifying impacts, low budgets, and shortages of trained personnel, which collectively result in the absence of structured control plans for mitigating cyber risks. (1) This study proposes a mechanism for selecting a cybersecurity risk analysis and management methodology suited to Colombian MSMEs by applying the multi-criteria Analytic Hierarchy Process (AHP) method. (2) The employed approach is qualitative and follows the AHP procedure to select the most suitable option that can be applied to cybersecurity. This selection process evaluated different criteria in five standards: ISO/IEC 27005:2022, NIST SP 800-30, OCTAVE-S, MAGERIT, and EBIOS-RM. (3) The AHP method enabled, in a practical manner, the selection of OCTAVE-S as the primary methodology, complemented with elements from other standards. Finally, the proposed methodology was implemented in a cloud-based web application called the Risk Analysis Module, integrated into the Keru IT security platform. It is concluded that the multi-criteria AHP method is effective and allows organizations to select the standards most appropriate to their needs, with potential applicability to other types of decisions.
1. Introduction
Micro-, Small-, and Medium-Sized Enterprises (MSMEs) account for more than 99% of the business landscape in Latin America [1] and are fundamental to the region’s productivity [2]. However, the rapid pace at which these organizations have been adopting digital technologies [3] has not been accompanied by equally mature cybersecurity practices [4], leaving them highly vulnerable to attacks at the network, system, and application layers [5,6,7]. Considering the vulnerabilities affecting different sectors, it has been found that 88% of problems affect small- and medium-sized enterprises, of which 44% are related to ransomware [8], representing a significant increase in impact. The success of ransomware-type malware is due to the limited resources of SMEs, associated with a lack of training and few technical protection tools [9].
On the other hand, in terms of risk management and the processes that must be carried out, in Colombia, 62.48% of companies have a manual risk process that uses Excel, while 42% do not have a clear training plan on risk calculation and impact reduction through controls [10]. Many companies have tried to start using artificial intelligence components applied to cybersecurity, but this is not yet possible.
The problem is exacerbated by the inability to clearly identify cybersecurity risks, given the insufficient use or lack of use of available security or risk standards, such as ISO/IEC 27005:2022, NIST SP 800-30, MAGERIT, OCTAVE-S, and EBIOS RM [11,12,13,14,15], due to their complexity and applicability in small- and medium-sized enterprises. Most of these standards were created for large organizations, leaving aside the fast and efficient processes that small businesses must have [16,17].
As a result, many MSMEs lack systematic mechanisms to help them choose an appropriate methodology based on their size, operational context, and available resources [18]. In practice, the choice of a risk analysis framework is often guided by informal recommendations, sectoral habits, or subjective criteria, which compromises the effectiveness and traceability of the process [19,20].
The question that arises is how micro-, small-, and medium-sized enterprises with limited financial resources and without specialized IT security personnel (whose salaries are high) can select a framework or standard tailored to the organizational needs of this type of company to assess and manage cybersecurity risks.
Considering the challenges faced by businesses and seeking potential solutions, the multi-criteria methodology (AHP) was used to support decision-making regarding risk management standards or processes applicable to small- and medium-sized enterprises (SMEs). The process considered the sector’s needs, limitations, and responses to the problems it faces. The AHP method takes the defined criteria and performs a series of comparisons on the characteristics that should be sought in risk standards, such as their simplicity, their technical and administrative dimensions, and whether the standard offers recommendations for risk treatment. This work is part of a broader project funded by the Colombian Ministry of Science and Technology (abbreviated MinCiencias in Spanish), the Institución Universitaria ITM, and Grupo NEX company. The project, entitled “Prototipo funcional de una plataforma informática para la gestión del riesgo de seguridad de la información y pentesting, utilizando tecnologías de automatización y técnicas de inteligencia artificial” (functional prototype of a computer platform for information security risk management and penetration testing, using automation technologies and artificial intelligence techniques), aims to enhance digital resilience through tools designed for the actual needs of MSMEs.
The results obtained in the research process suggest the use of the OCTAVE-S risk management methodology, given its practical approach and focus on small businesses. However, during the AHP selection process, it was found that other standards can contribute to the overall risk process, including elements that are more robust than OCTAVE-S itself, such as the regulatory issues addressed in ISO 27002 [21,22]. The vulnerability and threat catalogs in the MAGERIT standard are also highlighted, as they would facilitate the initiation of the risk process [23]. The selection process used in this research combines simple steps with technical rigor, generating practical results applicable to any company. Finding solutions based on parameter selection provides a significant incentive for developing software applications that reflect the chosen risk assessment process and methodology.
On different occasions, companies use mechanisms to identify risks due to regulatory requirements, but these mechanisms are not focused on meeting the needs associated with their type of business. Using AHP allows them to meet that need, and by using a scientifically proven method, the result is more reliable. This means that decision-making is no longer a process based on opinions, but on demonstrable evidence.
The contribution of this research lies in enabling micro-, small-, and medium-sized enterprises to adopt a practical, scientifically grounded, and straightforward process for selecting a cybersecurity risk management standard. This contribution incrementally strengthens decision-making in MSMEs, represented in a functional software prototype and applied rather than purely theoretical, allowing MSMEs to replicate the process while accounting for their specific business needs and risk assessment capabilities.
The use of the AHP method proves to be a sound practice for selecting a tailored cybersecurity risk management methodology. It provides a set of internationally recognized parameters and standards that can serve as a baseline, requiring organizations only to review or redefine the criteria applicable to their specific context. In addition, this study demonstrates the feasibility of developing a software application capable of supporting the final decision-making process.
2. Related Work
2.1. Regulatory Foundations and Conceptual Differences
Various international frameworks have been established to support cybersecurity risk management. This study focuses on five widely accepted references due to their relevance and regulatory coverage, each offering complementary scopes and approaches [24]. In this regard, the ISO/IEC 27005:2022 standard [25] provides guidelines for information security risks, complying with the requirements demanded by ISO 27001:2022 [26].
Similarly, the open-source NIST SP 800-30 standard focuses on assessing threats and vulnerabilities in information assets, enabling the calculation of the probability and impact of such threats [12]. Likewise, MAGERIT v3 (from the Spanish government) focuses on asset-based selection, threats, and controls; this standard is based on the PILAR software (version 2025.1.4) [13]. Similarly, the OCTAVE-S standard prioritizes cyber incidents, allowing process owners to better understand the risks [14].
Finally, EBIOS Risk Manager (developed by ANSSI in France) structures risk analysis around threat scenarios that consider intentions, capabilities, and feared events. Through iterative cycles, it links business risks with security decisions, helping balance the analysis and treatment of events that may compromise the IT infrastructure [27].
2.2. Practical Approaches for MSMEs and Differences in Complexity Between Risk Management Standards
The applicability of these methodologies within Small- and Medium-Sized Enterprises (MSMEs) is largely determined by their complexity, documentation burden, and technical requirements. In this context, ISO/IEC 27005:2022 represents a viable alternative when an Information Security Management System (ISMS) has been implemented or certification is being pursued, as it exhibits moderate complexity and acceptable scalability, assuming streamlined record-keeping practices [20,28]. NIST SP 800-30 offers sufficiently detailed guidance for prioritizing risk treatments without requiring full implementation of the RMF, placing it similarly within the medium-complexity category [29,30].
MAGERIT, in contrast, due to its granularity and extensive taxonomies, reaches a high level of complexity, making it more suitable for contexts that require comprehensive documentation or alignment with public administration needs [31]. In this regard, OCTAVE-S uses scoring matrices, allowing individuals to contribute to the final evaluation [32]. On the other hand, EBIOS-RM transforms business risks into security opportunities [33,34]. The diversity of standards complements the selection process and makes decision-making more interesting by using AHP as a scientific method [35,36].
2.3. Applications of the AHP and MCDM Methods in Risk Management
Multi-Criteria Decision-Making MCDM methods provide a structured approach for evaluating and ranking alternatives by considering multiple criteria and potentially conflicting objectives, thereby supporting the selection of the most suitable solution [37]. Among these methods, AHP has gained particular relevance in cybersecurity studies due to its ability to structure complex problems, decompose criteria, and prioritize alternatives [38,39,40]. It has been employed to evaluate regulatory frameworks [41], select security controls [42], prioritize vulnerabilities, and model decisions under uncertainty across a wide range of domains [43,44], including through hybrid approaches such as Fuzzy AHP, AHP–TOPSIS, and AHP–AI [38,45,46].
Despite this, recent reviews suggest that most studies remain theoretical or rely on simulation, with few providing empirical validation—and even fewer focusing on MSMEs [47,48,49]. A further gap lies in research that simultaneously compares established frameworks using reproducible criteria [50]. The present study contributes to addressing this gap by integrating empirical and technical evidence to guide methodological decision-making in organizations with limited resources.
3. Methodology
This study adopts a propositional–comparative design with a mixed (quantitative–qualitative) approach, aimed at selecting a risk analysis methodology suited to the needs of Colombian MSMEs. The research was developed in 3 stages (Figure 1), considering the objectives to be met, the use of the AHP method, consolidation of results in matrices, and finally, construction of a support software program.
Figure 1.
Phases of the research methodology.
By integrating a literature review, an empirical survey, and an AHP-based evaluation, the study contrasts theoretical models with the real-world practices of MSMEs. This integrated approach ensures that the selected methodology is relevant, applicable, and traceable.
In general, the proposed methodology establishes a structured sequence of steps that includes: (i) identifying the organization and its business processes; (ii) recognizing the need to adopt a cybersecurity risk management standard; (iii) defining, according to the business context, the criteria and characteristics required of the standard to be selected; (iv) selecting a set of cybersecurity risk management standards for evaluation, prioritizing those that are widely used, internationally recognized, and applicable to the organization; and (v) applying the Analytic Hierarchy Process (AHP) to compare and weight the defined criteria in order to select the most appropriate option. This final process results in the selection of a standard that can be used within the organization. As an added value, a cloud-based web application can be developed to support and operationalize the selection process.
Each phase is described in detail below.
3.1. Phase 1: Problem Characterization
The objective of this phase was to understand how risk management is actually being carried out in MSMEs in the service sector in Colombia. To do so, a systematic literature review was conducted and complemented with a survey administered to 72 organizations, which made it possible to confirm, for that group of organizations, the existing practical–theoretical gap in the field.
In order to validate the problems faced by MSMEs found in the literature, a survey was conducted among different companies.
The survey results helped identify specific weaknesses in organizational practice and potential areas for improvement. The questions addressed the following aspects:
- Demographic information: organization name, respondent position, economic sector, number of employees, and annual income.
- Risk management practices: use of any risk management methodology, level of staff training, degree of automation, perceived importance of risk management, and types of controls implemented to mitigate risks.
The questionnaire was designed with a “Yes” or “No” answer option, as well as multiple-choice, which allowed for faster responses and consolidation of results.
Since the survey is a study that explores the needs of companies, statistical calculations associated with populations of companies were not considered; however, the variability of the companies, the people who responded, and the role they fulfill in the company was reviewed, which allowed the process to be more random.
3.2. Phase 2: Evaluation Using the AHP Method
In this phase, the AHP method was applied to carry out a structured multi-criteria evaluation. The procedure followed a series of steps:
- Defining the features to be assessed in the different risk management standards.
- Definition of risk management standards.
- Definition of the measurement mechanism: use of the Saaty scale (1–9).
- Creation of the paired comparison matrix: Criteria are compared to determine which is most important. This is done by studying the standards and validating them with the needs of the company.
- Weighting of characteristics versus alternatives: the importance of the alternatives with respect to each of the criteria is analyzed.
- Creation of the hierarchical matrix. All values from the matrices already obtained are taken and the respective formula is applied to determine which standard is the most appropriate.
- Creation of an application that successfully achieved the desired result.
The features evaluated were derived from the survey responses provided by the participating companies. Likewise, the comparison matrices were initially completed individually by subject-matter experts and later validated collectively during a consensus session. The standards considered in the evaluation included ISO/IEC 27005:2022, NIST SP 800-30, MAGERIT, OCTAVE-S, and EBIOS RM.
The AHP method [20] enables the selection of one alternative among several based on defined evaluation criteria. As illustrated in Figure 2, the process requires establishing the criteria to be assessed for each alternative (ISO 27005:2022, NIST 800-30, MAGERIT, OCTAVE, and EBIOS), creating the pairwise comparison matrix, and rating each criterion using Saaty’s scale (Table 1) [51]. The results are then normalized to obtain the average vector (Table 2). Next, the criteria are weighed against the elements to produce the hierarchical matrix (Table 3).
Figure 2.
General multi-criteria process. First, the required criteria are defined, then the different risk standards are reviewed, and based on these, the AHP process is executed, resulting in a final selected alternative. The Keru web application was developed using the selected standard.
Table 1.
Saaty’s scale for pairwise comparison in AHP [51].
Table 2.
Weighting between alternatives.
Table 3.
Weighting of alternatives with respect to the criteria.
The measurements were made based on the analysis of each standard and its relative strength, which made it possible to determine how well they aligned with the defined criteria. Each alternative was compared against the others (Table 2) and rated using Saaty’s scale. When an alternative was judged to be better than another, it was assigned the corresponding score; the reverse comparison, in turn, received the reciprocal value (1/rating). Clearly, diagonal values were set to 1, as each alternative is compared with itself. Afterward, the values were standardized by multiplying each entry by the sum of its respective column, and the average value for each factor was subsequently calculated (Equation (1)):
To obtain the pairwise comparison matrix (Equation (2)), we have:
where
The AHP has a relative level of subjectivity and cannot be precise, given the needs and particularities of companies. The way to avoid deviations was the participation of the six researchers, who provided their evaluations independently, which were then averaged.
Next, all alternatives were evaluated according to the different criteria, obtaining the final results (Equation (3)) and indicating which alternative is the most robust or best meets each criterion (Table 3). The question to ask is: considering criterion 1 and Saaty’s values (Table 1), to what extent (greater, equal, or lesser) does alternative 1 meet criterion 1 compared to alternative 2? And so on for all alternatives and criteria.
Total Average:
Finally, to construct the consolidated hierarchical matrix, the average vectors were combined (Table 4), yielding the final score (Equation (4)). The standard with the highest score was selected as the preferred methodology.
Table 4.
Hierarchical matrix–Final decision matrix.
The total value of the sum-product is:
where
3.3. Phase 3: Conceptual Modeling
Building on the selected risk management methodology, a Risk Analysis Module was designed and implemented within a cloud-based web application to streamline the process of selecting the most appropriate standard. The design and development of the module considered the following elements:
- Developing software for a cloud-based web application.
- Structuring catalogs of assets, threats, vulnerabilities, and controls.
- Defining the processes and subprocesses for risk analysis.
- Ensuring traceability between the methodological selection and its practical application in MSME environments.
The resulting design included operational guidelines, adapted taxonomies, and functional components that support the entire cycle of risk analysis, treatment, and monitoring.
4. Results
Given the need to better understand the current situation of companies in Colombia, it was necessary to conduct a diagnosis of how they are addressing and mitigating cybersecurity risks.
4.1. Phase 1: Result of the Problem Characterization
To better understand the current cybersecurity posture of companies in Colombia, a diagnostic assessment of cyber risk management practices was conducted. The survey analysis material is used as context to confirm certain security issues. It should not be used directly to infer the need for a risk framework.
The analysis of 72 fully completed surveys showed that 41.67% of the participating organizations were micro-enterprises, 41.67% were medium-sized enterprises, and 16.67% were large enterprises. In terms of respondents’ professional profiles, systems or computer engineers accounted for 28.57%, business administrators for 14.29%, and other professional backgrounds—including business owners, individuals with master’s degrees in information security and related fields, educators, and engineers from allied disciplines—accounted for 7.14% (See the full report in Appendix C).
The results obtained demonstrate that the business population is diverse, given the variability in company size and the range of services they offer. In this regard, 68% of companies manage risks (using different methods), while 32% indicated that they do not (Figure 3).
Figure 3.
Organizations that use a methodology for risk management.
Similarly, 52.8% of respondents reported having experienced a cyberattack, and 47.2% had a history of attacks. These results demonstrate that threats continue to rise, but there are still companies that need to strengthen their security risk management processes.
Regarding cyberattacks, companies indicated that 34.38% were phishing attacks, 25% ransomware attacks, and 21.88% denial-of-service (DoS) attacks. When asked about their risk management processes, companies indicated that they use various tools to comply with the process (Figure 4). The most frequently mentioned were specialized software (36%), Microsoft Word (21%), and Excel (40%). Although diverse tools are employed, it is evident that most do not support automated processes.
Figure 4.
Types of tools used by organizations to estimate and manage risks.
With respect to the automation of cybersecurity operations related to risk management, 73% of respondents reported clear agreement, whereas 24% indicated a willingness to consider such automation.
Lastly, respondents were also consulted about whether their organizations had adopted a control plan to reduce exposure to cybersecurity risks (Figure 5). In this case, 43% reported that no such plan exists, 20% noted that their organizations respond reactively to incidents, and 6% indicated that they outsource the management of security controls.
Figure 5.
Management of controls in response to security incidents.
In general, the perceptions reported by the organizations suggest that, although some are managing risks through manual procedures, they still lack more automated processes capable of strengthening both risk identification and treatment. Enhancing these capabilities would facilitate the more effective definition and implementation of cybersecurity controls.
4.2. Phase 2: Result of the Evaluation Using the AHP Method
Based on the results obtained from the participating organizations, it became necessary to select a methodology for identifying, analyzing, and managing risks that could better support cybersecurity processes in MSMEs, including the ability to generate controls once risks are identified. Accordingly, five globally recognized methodologies were selected, and four features were evaluated for each standard using the Analytic Hierarchy Process (AHP).
Considering the needs highlighted through the survey responses, the following features were established to determine which risk management methodology would be most suitable:
- Practicality and simplicity: It assesses whether the standard facilitates a practical, agile, and concise approach to risk management.
- Technical and administrative considerations: It examines the extent to which the standard offers clear guidelines for achieving an effective balance between technical measures and administrative practices.
- Risk controls: Identify whether the standard under evaluation offers recommendations for mitigating impacts.
- Implementation of controls: This section assesses whether the standard provides guidelines on how to implement controls in systems, once risks have been identified.
- Based on these parameters, the AHP method was applied as follows. Appendix A contains the various Excel tables with the calculations performed. Appendix B contains tables listing the assets, vulnerabilities, threats, and controls used to calculate risk levels.
The general process consists of comparing the criteria and deciding which is the most relevant, assigning it a score according to Saaty’s scale. The fields that are left blank are filled in with the inverse of the score already assigned.
It begins with the assessment of criteria, then the criteria as they are met in the different risk standards, and finally, the paired matrix is created, selecting from it the standard that obtains the highest score.
4.2.1. Step 1: Assessment of Criteria
In this first step, the relative importance of each criterion was evaluated using Saaty’s scale (Table 4), taking into account the information provided in Table 2. This process provides a comparative measurement that determines the extent to which one factor may be considered more important than another.
The first step is to compare the importance of the criteria (Table 5), defining which is the most relevant according to Saaty’s table. The diagonal matrix is 1, since when comparing the same criterion, there is no relevance. The next step is to evaluate the paired matrix using the formula indicated in Table 2, the result of which is shown in Table 5.
Table 5.
(a) Hierarchical matrix results, comparing the same criterion. (b) Hierarchical matrix results.
To better understand the process, the first criterion, “Practicality and simplicity (PS)”, is taken and compared with “Technical and administrative considerations (TAC)”. For researchers, TAC offers better alternatives than PS, so it has been given a rating of 4.0 (according to Table 1). Once these two criteria have been compared, the reverse rating will be 1/4 or 0.25 (comparison of TAC versus PS). And so on for all criteria.
In the standardized matrix, the criterion “Guidelines for the Implementation of Controls (GIC)” (Figure 6) is the most representative, with a final weighting of 14 points, followed by “Recommendations for Risk Treatment (RRT),” with 9.33 points. This indicates that companies require practical guidelines for implementing the strategy, rather than lengthy explanatory documents.
Figure 6.
Results of the normalized matrix.
Based on the comparative evaluation of the criteria, practicality and simplicity emerged as the most influential criterion (Figure 7), providing a foundation for selecting the most appropriate risk management methodology. This result is consistent with the survey findings, which highlighted the need for agile risk management approaches, particularly given the operational dynamics of MSMEs.
Figure 7.
Results of the assessment of “practicality and simplicity” with respect to the standards.
It can also be observed (Figure 8) that the criterion “Technical and administrative considerations” is the second most relevant, considering that companies require technical support for the implementation of standards, which can be combined in the final methodology to be selected.
Figure 8.
Results of the pairwise comparison matrix.
4.2.2. Step 2: Assessment of Each Criterion Across the Selected Standard Alternatives
In this step, each criterion was analyzed, and its importance was evaluated across the five risk management standards, using the information in Table 3. Like step 1, the selection criteria are compared with the different risk standards to determine which standard has the best characteristics. In the case of “Practicality and simplicity”, the standard that is best in this regard is reviewed, finding, for example (Table 6), that NIST800-30 has better characteristics than ISO 27005 (but not very relevant), which is why the researchers gave it a value of 3.0. Likewise, the inverse value (ISO vs. NIST) is 1/3.
Table 6.
(a) Evaluation of the criterion “practicality and simplicity”. (b) Evaluation of the criterion practicality and simplicity, final matrix.
The results are presented below.
For the first criterion (Table 6), “Practicality and simplicity”, the comparison showed that OCTAVE-S exhibits stronger features than the other standards, reflected in its markedly higher score.
In the evaluation of the “Practicality and Simplicity” criterion, the OCTAVE-s standard stands out (Figure 8), considering the ease of use that those industries seek in standards. OCTAVE-s establishes quick and practical processes for obtaining results. Similarly, the NIST standard achieves an acceptable score of 15.33 and can complement some processes that do not have strong support from OCTAVE-s.
Regarding the second criterion (Table 7), technical and administrative considerations, NIST 800-3 emerged as the standard offering the highest level of compliance, followed by ISO 27005. Overall, NIST demonstrates stronger features than the other standards regarding both technical and administrative aspects.
Table 7.
Evaluation of the criterion and technical and administrative considerations.
Considering “Technical and Administrative Considerations,” the NIST standard stands out (Figure 9). In its various implementation stages, this standard offers better recommendations for implementing technical components once a consolidated risk assessment has been completed. Subsequently, ISO 27005 (based on the ISO 27001 family of standards) considers multiple technical mechanisms for implementation.
Figure 9.
Comparison of the standards regarding “Technical and administrative considerations”.
With respect to the third criterion (Table 8), Recommendations for risk treatment, the comparison revealed that ISO 27005 and NIST 800-30 perform best and at an equivalent level. Both standards provide robust guidance for formulating risk treatment plans.
Table 8.
Evaluation of the criterion recommendations for risk treatment.
When analyzing the standards related to risk management recommendations (control plans), ISO 27005 and NIST 800-30 are tied with an average score of 0.34 points (Figure 10). This indicates that, regardless of the standard selected, both meet the project scope.
Figure 10.
Assessment of the standard with respect to risk treatment.
Finally, for the fourth criterion (Table 9), guidelines for implementing controls, the comparison showed that NIST 800-30 is the model that most effectively addresses this requirement.
Table 9.
Evaluation of the criterion guidelines for implementing controls.
In this latest evaluation of standards regarding compliance with the “Guidelines for Implementing Controls” criterion (Figure 11), NIST 800-30 stands out significantly. This means that its documentation offers better recommendations on how to implement controls once risks have been identified.
Figure 11.
Result of the assessment of standards on the implementation of controls.
These final results indicate that the evaluated standards have different characteristics for risk management. Although one standard ultimately obtained the highest overall score—and will therefore serve as the primary reference for the methodology—the others can still offer valuable support for areas that the selected option may not address fully.
4.2.3. Step 3: Obtaining the Hierarchical Matrix
After creating the normalized matrices, the final consolidated matrix was created, into which the values were integrated (Table 10). The results indicate that OCTAVE-s presents better characteristics (35.4 points) than the other standards, being more practical and functional.
Table 10.
Final decision matrix.
It is important to highlight that the most relevant criterion is “Practicality and simplicity,” with a significant margin of 0.57 points compared to the second criterion of 0.24 (Figure 12). This aligns with the needs of small businesses to be agile and effective in risk management. Furthermore, OCTAVE-s is solidified as the most suitable risk management methodology for its implementation.
Figure 12.
Final comparison, resulting matrix.
It can also be observed that standards such as NIST 800-30 (20.34 points) can provide complementary support, particularly in the areas of “Technical and administrative considerations” and “Recommendations for risk treatment”. In this regard, the application of the AHP method not only facilitates the selection of a primary standard but also helps identify additional standards that can strengthen the overall risk management process.
4.3. Phase 3: Results of Conceptual Modeling
Since OCTAVE-S emerged as the preferred option based on the AHP analysis—and recognizing that other standards may still contribute in areas where they are stronger—the general process defined in the selected standard [52] involves a series of practical and easy-to-follow steps for conducting risk management (Figure 13).
Figure 13.
Steps for risk management according to the OCTAVE-S standard.
Taking all these aspects into account, the KeruRM cloud-based web application (Figure 14) was developed in its first version. This tool enables the consolidation of the entire risk analysis and management process within a single platform. The Keru user manual has been provided to supplement the article. It is in the original language (Manual de Usuario Análisis de Riesgos-Keru.pdf).
Figure 14.
Log-in interface of the KeruRM cloud-based web application developed for risk management.
The web-based support application includes the following elements (Figure 15):
Figure 15.
Main menu of the KeruRM cloud-based web application developed for risk management.
The following can be seen in the drop-down menu (Figure 15):
- Asset List: This includes the various assets a company may have, allowing users to freely select them according to their needs.
- Vulnerability List: This also includes a list of potential vulnerabilities associated with the assets, enabling quick and timely identification.
- Threat List: Based on global lists and the MAGERIT catalog, a resource was created to select threats to systems and assets within the risk assessment process. The probability and potential impact of each threat are also included.
- Risk identification and assessment: This component establishes the steps for determining the probability and impact of risks associated with each asset, considering both threats and vulnerabilities. The process also makes it possible to evaluate the risks and generate a heat map (with different levels of criticality), which shows the degree of exposure that the organization faces.
- Controls catalog: Drawing on the ISO/IEC 27001:2022 standard, this catalog provides specific mitigation measures for the identified risks. A key strength is that the controls are directly linked to the corresponding vulnerabilities and threats, facilitating a consistent and coherent implementation. This catalog is particularly useful for designing treatment strategies in MSMEs, as it supports the design of concrete and effective actions.
To simplify the process for organizations, the system comes with assets, threats, and vulnerabilities already preloaded. Users can begin by selecting the information assets they wish to evaluate (Figure 16) from a predefined list and subsequently choose the corresponding threats and vulnerabilities from the available catalogs (Figure 17). Nonetheless, given the evolving nature of cybersecurity threats, the system allows users to create, delete, or update entries as needed.
Figure 16.
Process for selecting assets, threats, and vulnerabilities. The number in the “Threats” and “vulnerabilities” column is the pre-calculated number of threats and vulnerabilities the asset has. The system retrieves this information automatically.
Figure 17.
Threat selection interface for identifying threats that may impact organizational assets, within the KeruRM cloud-based web application developed for risk management. The checked boxes are the threats that have been selected for the assets.
The next step is to rate the risks associated with each asset (Figure 18). This is done using a scale from 1 to 5 for both probability and impact, where 1 represents the lowest value and 5 the highest. Finally, the system calculates the risks and then generates the corresponding heat map (Figure 19).
Figure 18.
Interface for rating risks based on assets, threats, and vulnerabilities within the KeruRM cloud-based web application supporting risk management processes. The “Probability” field can be improbable, probable, or certain. Regarding risk levels, green indicates an “acceptable” risk and orange, an “unacceptable” one. “Proposed Control” can be added depending on the system. The other values are automatically retrieved from what has already been calculated.
Figure 19.
Heat map illustrating the results of the risk estimation within the KeruRM cloud-based web application. The risk score is the probability (P) multiplied by the impact (I). It is a scale from 1 to 5, where 5 is the highest probability and the greatest impact. Table 11 explains the risk levels (colors).
The heat map’s criticality levels are defined by score ranges, each expressed as a percentage of the maximum possible score (Table 11). Given that probability (P) and impact (I) are rated on a scale from 1 to 5, the highest achievable risk score is P (5) × I (5) = 25, which corresponds to 100%. The percentages for all other levels are calculated relative to this value.
Table 11.
Percentage distribution of the heat map.
Once the heat map is generated, a risk treatment plan is developed to define the controls required to reduce risk levels (Figure 20). These controls must be aligned with the resources available to each organization and may be further refined using guidance from standards such as ISO/IEC 27002:2022 or NIST SP 800-53.
Figure 20.
Interface for creating the risk treatment plan based on identified risks within the Keru cloud-based web application. The “Status” field indicates whether the risk is still active and untreated or has been closed. The “Control action” field specifies whether the risk is mitigated, transferred, or assumed.
The treatment plan is generated exclusively for high-level risks, specifically those classified within the orange or red zones of the heat map. Risks located in the yellow and green zones are considered acceptable, as they do not pose an imminent threat to the organization and can be addressed promptly should they materialize.
5. Discussion
It is crucial to understand the cybersecurity needs and risks of SMEs, considering resource limitations and the business context. In this regard, having lists of assets, threats, and vulnerabilities allows for a more agile process and optimal results in the implementation of risk controls. This must be coordinated with security incident management processes, which leverage the advantage of knowing the risks and preparing for different eventualities.
Cyberattacks continue to grow, as demonstrated by CVEs (Figure 21). The exponential trend of attacks on different services and technologies creates the need to predict the risks and impacts that may occur over time, preventing irreversible damage to technological operations.
Figure 21.
Number of CVEs, ten thousand to fifty thousand per year [53].
Cybersecurity and risk professionals commonly use the Common Vulnerability Scoring System (CVSS) to identify, catalog, and validate potential system vulnerabilities. However, the information obtained through CVSS assessments remains inherently technical, and a process is required to identify and classify which group of vulnerabilities can affect an organization [54]. In this regard, some studies have applied the AHP method, but their scope has been limited to prioritizing technical vulnerabilities—such as those affecting web applications—rather than supporting a broader risk management process capable of assessing organizational impact or addressing non-technical cybersecurity issues. The approach presented in this study extends beyond purely technical evaluation by enabling risk-based decision-making applicable across different cybersecurity domains.
Moreover, the practical and focused design of the risk management process presented here—structured into three phases—helps guide the identification of critical assets and their associated risks, the prioritization of those risks according to their impact and probability, and the implementation of controls tailored to the specific resources and needs of MSMEs. In this sense, providing a basic risk management tool contributes to strengthening cybersecurity awareness and supports faster control identification across different organizations [55,56].
The AHP method has multiple applications in information security. According to [57], it has been used to identify the most efficient investment strategies in security, supporting senior management in selecting and implementing effective security initiatives. That study evaluated criteria such as confidentiality, integrity, and availability for specific providers, as well as the investments required for different security solutions. Similarly, AHP has been applied to support the selection of security maturity models by defining clear parameters for assessing the status of organizational controls [58]. Such maturity models provide organizations with a structured understanding of their current security posture and the steps required to achieve higher levels of security.
On the other hand, AHP has been combined with Evolutionary Game Theory (EGT) to support the selection of authentication methods, enabling security administrators to identify the most appropriate controls for their organizations. In that study, the results prioritized risk reduction strategies such as password-based protection, followed by token-based and biometric authentication mechanisms [59]. The evaluation considered characteristics including applicability, cost, and the duration for which an attacker could gain access to organizational assets. However, this research focused primarily on control selection and did not address how risks were identified or assessed, nor which risk management standard was used as the basis for the analysis.
The AHP method has also been applied to support risk management decision-making. In a Brazilian public agency, it was used to identify appropriate controls for risk reduction based on the NIST Cybersecurity Framework (NIST CSF) and ISO 31000, considering actions such as threat detection and continuous monitoring of cybersecurity events, including network and personnel activities [60]. Although this research relied on the ISO 31000 standard, it did not consider or compare other risk management standards.
The catalogs and matrices developed in this study not only offer a practical and accessible solution for MSMEs but also underscore the importance of systematic risk management aligned with international standards and adapted to the realities of organizations with limited resources. Consequently, these organizations can establish a more robust foundation for initiating risk management activities, supported by a software tool that promotes a pragmatic approach to cybersecurity issue identification [57].
Although some authors highlight the need to automate risk management using machine learning and thus accelerate the detection of problems within organizations [58], the situation of MSMEs in Colombia—along with the insights gathered from the surveys— indicates that establishing fundamental criteria is a necessary first step. These include the provision of a clear risk management framework and a supporting application. Once these foundations are in place, the possibility of introducing automation can be considered [61,62].
The AHP method would allow for the selection of standards and the determination of which one best suits the company. Some studies have used the same selection method, but the defined characteristics of the process are not clear.
6. Conclusions
The approach developed in this study represents a meaningful contribution to strengthening the analysis and management of information security risks in MSMEs. By applying the AHP method and selecting OCTAVE-S as the base methodology, a practical framework was established that is both understandable and suitable for the technical and resource constraints typical of these organizations. A key outcome of this research is the development of a systematic and criteria-driven reference that supports organizations in selecting an appropriate cybersecurity risk management methodology aligned with their specific objectives and constraints.
This effort is further supported by the development of a cloud-based web application that provides detailed reference templates and catalogs of assets, vulnerabilities, threats, and controls. These elements are organized into relational matrices that help prioritize risks and design treatment plans. Certainly, and objectively, the proposed approach offers a systematic and functional structure that could be incorporated into a risk management module as part of a broader technology platform.
The AHP method allowed us to proactively achieve the expected results: selecting a risk standard that meets a specific need (NIST SP 800-30, ISO/IEC 27005, or MAGERIT). The combination of advantages of each standard studied and selected allows us to infer the method’s potential for application in other decision-making processes.
Therefore, the AHP method strikes a balance between the scientific method and the technical elements to be selected, addressing the specific needs of each company and focusing the process on the minimum requirements for risk management.
Our next step as researchers is to promote this process in other companies, enabling more people to acquire this knowledge. Consequently, future work may include expanding the methodology through additional validations—for example, incorporating criteria specific to the industrial or service sectors—or by exploring advanced techniques, such as artificial intelligence, as complementary tools to enhance risk detection and mitigation, leveraging the statistical capabilities of learning models.
Supplementary Materials
The following supporting information can be downloaded at: https://www.keru.com.co/ (accessed on 4 March 2025) [63] and https://bit.ly/4baikjp (accessed on 4 March 2026) [64].
Author Contributions
Project administration and research, G.E.T.B.; Research and Validation, J.F.H.R.; Research, Teams QA (Testing), conceptual model validator, J.M.D.V.; Validation and Teams QA (Testing), M.J.M.R.; Writing—review and editing, conceptual model design risk analysis, M.T.S.C.; Writing—original draft preparation, Lead risk analysis researcher, conceptual model validator, visualization, H.F.V.M. All authors have read and agreed to the published version of the manuscript.
Funding
This research was funded in large part by the Colombian Ministry of Science, Technology, and Innovation, https://minciencias.gov.co/ (accessed on 4 March 2026).
Institutional Review Board Statement
Not applicable.
Informed Consent Statement
Not applicable.
Data Availability Statement
The following supporting information (data and analyses) can be downloaded at OCTAVE-s (https://www.sei.cmu.edu/documents/1608/2005_002_001_14273.pdf, accessed on 16 February 2026), NIST (https://csrc.nist.gov/pubs/sp/800/30/r1/final, accessed on 16 February 2026), CVE (https://www.cvedetails.com/browse-by-date.php, accessed on 16 February 2026) and Supplementary Materials.
Acknowledgments
This research was conducted under the project “Functional Prototype of an Information Platform for Information Security Risk Management and Pentesting, Using Automation Technologies and Artificial Intelligence Techniques,” implemented by the ITM University Institution and the company Grupo NEX. The authors gratefully acknowledge the support of the Ministry of Science, Technology and Innovation of Colombia (MinCiencias), the contributions of project collaborators Paulo Díaz Ordoñez, César Álcazar Paternina and María José Yepes Díaz. The contributions of the Agencia de Traducción ITM (traducciones@itm.edu.co), which translated the manuscript into English.
Conflicts of Interest
Author Javier Mauricio Durán Vásquez was employed by the company Grupo Nex. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest. Author Maria José Monsalve Ruiz was employed by the company Grupo Nex. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.
Abbreviations
The following abbreviations are used in this manuscript:
| MSMEs | Micro-, Small-, and Medium-Sized Enterprises |
| AHP | Analytic Hierarchy Process |
| NIST | National Institute of Standards and Technology |
| MCDM | Multi-Criteria Decision Making |
| OCTAVE-s | Operational Critical Threat, Asset, and Vulnerability Evaluation |
| MAGERIT | Metodología de Análisis y Gestión de Riesgos de los Sistemas de Información. |
Appendix A
Below are the different calculations performed in Excel to arrive at the final matched matrix. A comparison of criteria is made and the most relevant one is decided, assigning a score according to Saaty’s scale. Fields left blank are filled in with the inverse of the score already assigned.
To evaluate the different tables, each expert researcher should consider the following questions:
- How important is each criterion to the object of study? The researcher ranks each criterion from 1 to 4, where 4 is the criterion with the best characteristic or the one that contributes most to the selection, and 1 is the least important.
- How important is each criterion, when evaluated individually, in relation to the other criteria?
Each researcher completes the comparison matrix between the criteria, assigning a value from 1 to 9 according to Saaty’s scale. The evaluation is then reviewed, considering the importance and applicability of the criterion to the object of evaluation. As mentioned, the evaluation is subjective, but it is based on a measurement scale.
Finally, all individual measurements are compiled, and an arithmetic average is calculated, rounding up to the nearest (up) value on the Saaty scale, resulting in the final score for each matrix.
Table A1.
Weighting between criteria.
Table A2.
Weighting of criteria versus elements: evaluation of “Practicality and simplicity (PS)”.
Table A3.
Weighting of criteria versus elements: evaluation of “Technical and administrative considerations (TAC)”.
Table A4.
Weighting of criteria versus elements: evaluation of “Recommendations for risk treatment (RRT)”.
Table A5.
Weighting of criteria versus elements: evaluation of “Guidelines for implementing controls (GIC)”.
Appendix B
Some elements illustrating the OCTAVE-s process have been taken: Asset catalog, Vulnerabilities catalog, Threats catalog ANS some Controls catalog.
| (a) | |
| Asset catalog | |
| Administrative staff | Network services |
| AP | Personal computers |
| Brands | Sales application |
| Contracts | Service provider |
| Software | |
| Information | Switch |
| Linux servers | Websites |
| Source code | Windows servers |
| (b) | |
| Vulnerabilities catalog | |
| Day Zero | Poor authentication configuration |
| Failure to implement MFA | Poor data sanitisation |
| Human error | Remote code execution (RCE) |
| Lack of access control | Unauthorised access |
| Lack of malware control | Unpatched software |
| Insecure Docker | Vulnerable APIs |
| (c) | |
| Threats catalog | |
| ARP spoofing | Phishing, vishing, Smishing |
| TCP syn attack | Botnet. |
| SQL injection | Deface |
| Cross-site scripting | Password Cracking, Password Spraying |
| CSRF: Cross-Site Request Forgeries | Exploit |
| NTP Reflexion | The man in the middle |
| BlueSnarfing | DoS/DDoS |
| bluebugging | Malware/Ransomware |
| (d) | |
| Controls catalog | |
| Access to source code | Monitoring activities |
| Capacity management | Network segregation |
| Data masking | Network service security |
| Encryption | Redundancy of information processing facilities |
| Firewall | Secure authentication |
| IDS/IPS/NDR/XDR | Technical vulnerability management |
| Information backup | Training |
| Anti-malware | Web filtering |
Appendix C
Survey details in https://bit.ly/4jXYgou (accessed on 16 February 2026).
References
- Tam, T.; Rao, A.; Hall, J. The Good, The Bad and The Missing: A Narrative Review of Cyber-security Implications for Australian Small Businesses. Comput. Secur. 2021, 109, 102385. [Google Scholar] [CrossRef] [Scilit]
- Taborda Blandón, G.E.; Castaño Zuluaga, B.S.; Durán Vásquez, J.M.; Conto López, R.; Reyes Moreno, E.R. Propuesta de modelo de analítica para flujo de caja en mipymes en Colombia. Rev. CEA 2024, 10, 2607. [Google Scholar] [CrossRef] [Scilit]
- Metin, B.; Özhan, F.G.; Wynn, M. Digitalization and Cybersecurity: Towards an Operational Framework. Electronics 2024, 13, 4226. [Google Scholar] [CrossRef] [Scilit]
- Ozkan, B.Y.; Spruit, M. Assessing and Improving Cybersecurity Maturity for SMEs: Standardization aspects. arXiv 2020, arXiv:2007.01751. [Google Scholar] [CrossRef] [Scilit]
- Alvarez, M.A.R.; Vargas Montoya, H.F. Ciberseguridad en las redes móviles de telecomunicaciones y su gestión de riesgos. Ing. Desarro. 2020, 38, 279–297. [Google Scholar] [CrossRef] [Scilit]
- Lucky Bamidele, B.; Ayodeji Enoch, A.; Prisca Amajuoyi, M.D.; Kudirat Bukola, A. Digital transformation in SMEs: Identifying cybersecurity risks and developing effective mitigation strategies. Glob. J. Eng. Technol. Adv. 2024, 19, 134–153. [Google Scholar] [CrossRef] [Scilit]
- Rawindaran, N.; Jayal, A.; Prakash, E. Exploration of the Impact of Cybersecurity Awareness on Small and Medium Enterprises (SMEs) in Wales Using Intelligent Software to Combat Cybercrime. Computers 2022, 11, 174. [Google Scholar] [CrossRef] [Scilit]
- Verizon Business. 2025 Data Breach Investigations Report. 2025. Available online: https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf (accessed on 20 December 2025).
- Rawindaran, N.; Jayal, A.; Prakash, E.; Hewage, C. Perspective of small and medium enterprise (SME’s) and their relationship with government in overcoming cybersecurity challenges and barriers in Wales. Int. J. Inf. Manag. Data Insights 2023, 3, 100191. [Google Scholar] [CrossRef] [Scilit]
- Instituto Tecnológico Metropolitano (ITM); Empresa de Negocios NEX. Instrumento de Recolección de Datos del Cliente Diseño, Construcción y Análisis de Resultados de la Encuesta para la Recolección de los Datos del Cliente. 2024. Available online: https://bit.ly/4jXYgou (accessed on 16 February 2026).
- ISO 27005:2022; Information Security, Cybersecurity and Privacy Protection-Guidance on Managing Information Security Risks. International Organization for Standardization—ISO: Geneva, Switzerland, 2022.
- National Institute of Standards and Technology. NIST Special Publication 800-30: Guide for Conducting Risk Assessments; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2012. [CrossRef] [Scilit]
- Gobierno de España. Magerit Versión 3.0: Metodología de Análisis y Gestión de Riesgos de los Sistemas de Información. Libro I: Método. 2025. Available online: https://administracionelectronica.gob.es/ctt/verPestanaGeneral.htm?idIniciativa=magerit (accessed on 16 February 2026).
- Alberts, C.J.; Dorofee, A.J. OCTAVE SM Criteria, Version 2.0; Carnegie Mellon University: Pittsburgh, PA, USA, 2001.
- National Cybersecurity Agency of France-ANSSI. anssi-guide-ebios_risk_manager-en-v1.0. Available online: https://cyber.gouv.fr/sites/default/files/2019/11/anssi-guide-ebios_risk_manager-en-v1.0.pdf (accessed on 16 February 2026).
- Awan, M.; Alam, A.; Kamran, M. Cybersecurity Challenges in Small and Medium Enterprises: A Scoping Review. J. Cyber Secur. Risk 2025, 3, 89–102. [Google Scholar] [CrossRef] [Scilit]
- Adapa, S.; McKeown, T.; Lazaris, M.; Jurado, T. Small and Medium-Sized Enterprises, and Business Uncertainty; Springer Nature: Singapore, 2023. [Google Scholar] [CrossRef] [Scilit]
- AL-Dosari, K.; Fetais, N. Risk-Management Framework and Information-Security Systems for Small and Medium Enterprises (SMEs): A Meta-Analysis Approach. Electronics 2023, 12, 3629. [Google Scholar] [CrossRef] [Scilit]
- Gazzawi, A.; Hammarberg, R. Risk Management Challenges for SMEs A Case Study. Master’s Thesis, Luleå University of Technology, Luleå, Sweden, 2022. Available online: https://www.diva-portal.org/smash/get/diva2:1667846/FULLTEXT01.pdf (accessed on 21 December 2025).
- Fahrurozi, M.; Tarigan, S.A.; Tanjung, M.A.; Mutijarsa, K. The Use of ISO/IEC 27005: 2018 for Strengthening Information Security Management (A Case Study at Data and Information Center of Ministry of Defence). In ICITEE 2020—Proceedings of the 12th International Conference on Information Technology and Electrical Engineering; Institute of Electrical and Electronics Engineers Inc.: Yogyakarta, Indonesia, 2020; pp. 86–91. [Google Scholar] [CrossRef] [Scilit]
- ISO 27001:2022; Information Security, Cybersecurity and Privacy Protection-Information Security Management Systems-Requirements. International Organization for Standardization—ISO: Geneva, Switzerland, 2022.
- ISO 27002:2022; Information Security, Cybersecurity and Privacy Protection-Information Security Controls. International Organization for Standardization—ISO: Geneva, Switzerland, 2022.
- Gobierno de España. Magerit Versión 3.0: Metodología de Análisis y Gestión de Riesgos de los Sistemas de Información. Libro II: Catálogo de Elementos. 2012. Available online: http://administracionelectronica.gob.es/ (accessed on 15 December 2025).
- Syalim, A.; Hori, Y.; Sakurai, K. Comparison of risk analysis methods: Mehari, MAGERIT, NIST800-30 and Microsoft’s security management guide. In Proceedings of the 2009 International Conference on Availability, Reliability and Security, Fukuoka, Japan, 16–19 March 2009; pp. 726–731. [Google Scholar] [CrossRef] [Scilit]
- Mahfud, A.Z.; Hikmah, I.R.; Sunaringtyas, S.U.; Yulita, T. Information Security Risk Management Design Based on ISO/IEC 27005:2022, ISO/IEC 27001:2022, and NIST SP 800-53 Revision 5 (A Case Study at ABC Agency). In Proceedings of the 2024 4th International Conference on Electronic and Electrical Engineering and Intelligent System (ICE3IS), Yogyakarta, Indonesia, 7–8 August 2024; pp. 181–186. [Google Scholar] [CrossRef] [Scilit]
- Malatji, M. Management of enterprise cyber security: A review of ISO/IEC 27001:2022. In Proceedings of the 2023 International Conference on Cyber Management and Engineering (CyMaEn), Bangkok, Thailand, 6–27 January 2023; pp. 117–122. [Google Scholar] [CrossRef] [Scilit]
- Abbass, W.; Baina, A.; Bellafkih, M. Using EBIOS for risk management in critical information infrastructure. In Proceedings of the 5th World Congress on Information and Communication Technologies (WICT), Marrakech, Morocco, 14–16 December 2015; pp. 107–112. [Google Scholar] [CrossRef] [Scilit]
- Folorunso, A.; Mohammed, V.; Wada, I.; Samuel, B. The impact of ISO security standards on enhancing cybersecurity posture in organizations. World J. Adv. Res. Rev. 2024, 24, 2582–2595. [Google Scholar] [CrossRef] [Scilit]
- Ali, T.; Al-Khalidi, M.; Al-Zaidi, R. Information Security Risk Assessment Methods in Cloud Computing: Comprehensive Review. J. Comput. Inf. Syst. 2024, 66, 123–150. [Google Scholar] [CrossRef] [Scilit]
- Putra, A.P.; Soewito, B. Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector. Int. J. Adv. Comput. Sci. Appl. 2023, 14, 4. [Google Scholar] [CrossRef] [Scilit]
- Barraza de la Paz, J.V.; Rodríguez-Picón, L.A.; Morales-Rocha, V.; Torres-Argüelles, S.V. A Systematic Review of Risk Management Methodologies for Complex Organizations in Industry 4.0 and 5.0. Systems 2023, 11, 218. [Google Scholar] [CrossRef] [Scilit]
- García Porras, J.C.; Huamani Pastor, S.C.; Alvarado, R.F.L. Modelo de gestión de riesgos de seguridad de la información para PYMES peruanas. Rev. Peru. Comput. Sist. 2018, 1, 47–56. [Google Scholar] [CrossRef] [Scilit]
- Esselin, F.; Coulon, K. Ebios risk manager: Accessible methodology to secure digital transformation. Notes CREOGN 2021, 62, 255. [Google Scholar] [CrossRef]
- Chernyaev, M. EBIOS and FSTEC Risk Assessment Method Comparison. In Proceedings of the 2023 16th International Conference Management of Large-Scale System Development, MLSD, Moscow, Russia, 26–28 September 2023; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Sukumar, A.; Mahdiraji, H.A.; Jafari-Sadeghi, V. Cyber risk assessment in small and medium-sized enterprises: A multilevel decision-making approach for small e-tailors. Risk Anal. 2023, 43, 2082–2098. [Google Scholar] [CrossRef] [Scilit]
- Curtin, M.; Sheehan, B.; Gruben, M.; Kozma, N.; O’Carroll, G.; Murray, H. Development of a cyber risk assessment tool for Irish small business owners. arXiv 2024, arXiv:2408.16124. [Google Scholar] [CrossRef] [Scilit]
- Petrova, V. A cybersecurity risk assessment. Int. Sci. J. Ind. 4.0 2021, 6, 37–40. Available online: https://stumejournals.com/journals/i4/2021/1/37.full.pdf (accessed on 21 December 2025).
- Božanić, D.; Tešić, D.; Komazec, N.; Marinković, D.; Puška, A. Interval fuzzy AHP method in risk assessment. Rep. Mech. Eng. 2023, 4, 131–140. [Google Scholar] [CrossRef] [Scilit]
- Svoboda, I.; Lande, D. Enhancing Multi-Criteria Decision Analysis with AI: Integrating Analytic Hierarchy Process and GPT-4 for Automated Decision Support. arXiv 2024, arXiv:2402.07404. [Google Scholar] [CrossRef] [Scilit]
- Moreira, F.R.; Canedo, E.D.; Nunes, R.R.; Serrano, A.L.M.; Abbas, C.J.B.; Júnior, M.L.P.; de Mendonça, F.L.L. Cybersecurity Risk Assessment Through Analytic Hierarchy Process: Integrating Multicriteria and Sensitivity Analysis; SciTePress: Setúbal, Portugal, 2025. [Google Scholar] [CrossRef] [Scilit]
- Sendón-Varela, J.C.; Herrera-Tapia, J.; Fernández-Capestany, L.; Felipe, M.D.R.C.; Chancay-García, L.; García-Quilachamín, W. Análisis comparativo entre distintas metodologías para la realización de auditorías de seguridad informática, aplicando el Proceso Analítico Jerárquico (AHP). Rev. Ibérica Sist. Tecnol. Informação 2021, 40, 352–367. Available online: https://search.proquest.com/openview/885db17165523c1e07aa2f01683aae00/1?pq-origsite=gscholar&cbl=1006393 (accessed on 21 December 2025).
- Tariq, M.I.; Ahmed, S.; Memon, N.A.; Tayyaba, S.; Ashraf, M.W.; Nazir, M.; Hussain, A.; Balas, V.E.; Balas, M.M. Prioritization of information security controls through fuzzy AHP for cloud computing networks and wireless sensor networks. Sensors 2020, 20, 1310. [Google Scholar] [CrossRef] [Scilit]
- Nobili, M.; Fioravanti, C.; Guarino, S.; Ansaldi, S.M.; Milazzo, M.F.; Bragatto, P.; Setola, R. DRIVERS: A platform for dynamic risk assessment of emergent cyber threats for industrial control systems. In Proceedings of the 2023 31st Mediterranean Conference on Control and Automation (MED), Limassol, Cyprus, 26–29 June 2023; pp. 395–400. [Google Scholar] [CrossRef] [Scilit]
- Lan, J. Research on Cybersecurity Risk Assessment in SCADA Networks Based on AHP-RSR. In Proceedings of the 2020 International Conference on Communications, Information System and Computer Engineering (CISCE), Kuala Lumpur, Malaysia, 3–5 July 2020; pp. 361–364. [Google Scholar] [CrossRef] [Scilit]
- Guo, C.; Wang, X.; Chu, P. Fuzzy AHP-Based Security Evaluation for Wireless Integrated Access System. In Proceedings of the 2021 International Conference on Intelligent Transportation, Big Data and Smart City (ICITBS), Xi’an, China, 27–28 March 2021; pp. 554–557. [Google Scholar] [CrossRef] [Scilit]
- Sarkar, B.; Biswas, A. Pythagorean fuzzy AHP-TOPSIS integrated approach for transportation management through a new distance measure. Soft Comput.—Fusion Found. Methodol. Appl. 2021, 25, 4073–4089. [Google Scholar] [CrossRef] [Scilit]
- Mubarak, S.; Heyasat, H.; Wibowo, S. Information Security Models are a Solution or Puzzle for SMEs? A Systematic Literature Review Research in Progress. In Proceedings of the 30th Australasian Conference on Information Systems, Perth, Australia, 9–11 December 2019; pp. 148–154. Available online: https://acis2019.io/pdfs/ACIS2019_PaperFIN_037.pdf (accessed on 16 February 2026).
- Ambreen, L.; Jain, M.; Yadav, R.K.; Loonkar, S. Effective cybersecurity risk management practices for small and medium-sized enterprises: A comprehensive review. Multidiscip. Rev. 2023, 6, 2023ss080. [Google Scholar] [CrossRef] [Scilit]
- Alahmari, A.A.; Duncan, R.A. Towards Cybersecurity Risk Management Investment: A Proposed Encouragement Factors Framework for SMEs. In Proceedings of the IEEE International Conference on Computing, ICOCO 2021, Kuala Lumpur, Malaysia, 17–19 November 2021; pp. 115–121. [Google Scholar] [CrossRef] [Scilit]
- Alahmari, A.; Duncan, B. Cybersecurity Risk Management in Small and Medium-Sized Enterprises: A Systematic Review of Recent Evidence. In Proceedings of the 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), Dublin, Ireland, 15–19 June 2020; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Saaty, T.L. Decision making for leaders. IEEE Trans. Syst. Man Cybern. 1985, SMC-15, 450–452. [Google Scholar] [CrossRef] [Scilit]
- Carnegie Mellon University’s Software Engineering Institute. OCTAVE®-S Implementation Guide, Version 1.0; Carnegie Mellon University’s Software Engineering Institute: Pittsburgh, PA, USA, 2005; Available online: https://www.sei.cmu.edu/documents/1608/2005_002_001_14273.pdf (accessed on 25 November 2025).
- MITRE Corporation. Browse Vulnerabilities by Date. 2025. Available online: https://www.cvedetails.com/browse-by-date.php (accessed on 25 November 2025).
- Sharma, A.; Singh, U.K. Prioritization of Security Vulnerabilities under Cloud Infrastructure Using AHP. Nat. Lang. Process. Softw. Eng. 2025, 248, 335–355. [Google Scholar] [CrossRef] [Scilit]
- Ruiz-Vanoye, J.A.; Ponce-Medellin, I.R.; Diaz-Parra, O.; Zavala-Diaz, J.C.; Zarate-Marceleno, J.A.; Fuentes-Penna, A. MISMA: An Approach to Mexican Information Security Methodology and Architecture for PYMES. In Proceedings of the 2009 International Conference on Electrical, Communications, and Computers, Cholula, Mexico, 26–28 February 2009; pp. 65–68. [Google Scholar] [CrossRef] [Scilit]
- Solsol, I.L.; Vargas, H.F.; Díaz, G.M. Security mechanisms in NoSQL dbms’s: A technical review. In International Conference on Smart Technologies, Systems and Applications; Springer International Publishing: Cham, Switzerland, 2019; pp. 215–228. [Google Scholar]
- Bodin, L.D.; Gordon, L.A.; Loeb, M.P. Evaluating information security investments using the analytic hierarchy process. Commun. ACM 2005, 48, 78–83. [Google Scholar] [CrossRef] [Scilit]
- Nasser, A.A.; Al-Khulaidi, A.A.; Aljober, M.N. Measuring the information security maturity of enterprises under uncertainty using fuzzy AHP. Int. J. Inf. Technol. Comput. Sci. 2018, 10, 10–25. [Google Scholar] [CrossRef] [Scilit]
- Loo, B.W.; Tan, P.L.; Tey, S.K.; Chin, W.Y. Authentication methods selection in information security through hybrid AHP and EGT. J. Adv. Res. Appl. Sci. Eng. Technol. 2024, 50, 171–185. [Google Scholar] [CrossRef] [Scilit]
- Awang, N.; Narayana Samy, G.; Hassan, H. Prioritizing Cybersecurity Management Guidelines using Analytical Hierarchy Process (AHP) Decision Technique. Open Int. J. Inform. 2022, 10, 1–10. Available online: https://oiji.utm.my/index.php/oiji/article/view/175 (accessed on 1 March 2026).
- Annunziata, G.; Lambiase, S.; Palomba, F.; Ferrucci, F. SERGE—Serious Game for the Education of Risk Management in Software Project Management. In Proceedings of the 2024 IEEE/ACM 46th International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET), Lisbon, Portugal, 14–20 April 2024; pp. 264–273. [Google Scholar] [CrossRef] [Scilit]
- Koirala, G.; Bista, R.; Poudel, S. Empirical Software Risk Calculation with Software Risk Factors. In Proceedings of the 2025 International Conference on Software, Knowledge, Information Management & Applications (SKIMA), Paisley, UK, 9–11 June 2025; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Grupo Nex and ITM University Institution. Risk Management and Penetration Testing Portal. 2025. Available online: https://www.keru.com.co/ (accessed on 4 March 2026).
- Grupo Nex and ITM University Institution. User Manual of Keru. 2025. Available online: https://bit.ly/4baikjp (accessed on 4 March 2026).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.




















