M-SCORE: An Explainable and Quantitative Cybersecurity Maturity Scoring Model for SMEs

Authors

DOI:

https://doi.org/10.33414/rtyc.56.99-119.2026

Keywords:

cybersecurity maturity model, SMEs, quantitative assessment, maturity scoring;, agent-assisted assessment, rule-based evaluation, cybersecurity governance, third-party risk, resilience, Design Science Research.

Abstract

Small and medium-sized enterprises (SMEs) face persistent cybersecurity exposure while often lacking the resources, expertise, and governance structures required to adopt comprehensive assessment frameworks. Existing cybersecurity maturity models provide useful guidance, yet they frequently remain fragmented across domains, weakly operationalized for SME realities, and insufficiently explicit in how maturity scores are computed and prioritized. This paper proposes M-SCORE, a quantitative and multi-dimensional cybersecurity maturity evaluation model specifically designed for SMEs. The model integrates core cybersecurity dimensions—governance, protection of data and assets, continuity and resilience, third-party risk, awareness, and detection and response, with optional coverage of AI governance—into a structured scoring approach based on measurable indicators, verifiable evidence, weighted sub-dimensions, and auditable implementation levels.
To improve practical applicability without compromising reproducibility, M-SCORE adopts a hybrid architecture in which deterministic rule-based scoring is complemented by agent-assisted semantic support for evidence interpretation, document classification, and recommendation generation. In this design, AI agents do not determine the score; instead, they enhance the efficiency and usability of the assessment workflow while preserving transparency and traceability. The paper follows a Design Science Research approach and formalizes the model, its scoring logic, and its conceptual automation architecture. A preliminary application scenario is also outlined to illustrate how M-SCORE can support maturity profiling, gap identification, and roadmap prioritization in resource-constrained SME environments.

Downloads

Download data is not yet available.

References

Ahmad, A., Maynard, S. B., & Park, S. (2014). Information security strategies: Towards an organizational multi-strategy perspective. Journal of Intelligent Manufacturing, 25(2), 357–370. https://doi.org/10.1007/s10845-012-0683-0

Almuhammadi, S., & Alsaleh, M. (2017). Information security maturity model for NIST cybersecurity framework. Computer Science & Information Technology (CS & IT), 7(3), 51–62. https://doi.org/10.5121/csit.2017.70305

Azmi, R., Tibben, W., & Win, K. T. (2018). Review of cybersecurity frameworks: Context and shared concepts. Journal of Cyber Policy, 3(2), 258–283. https://doi.org/10.1080/23738871.2018.1520271

Bada, M., Sasse, A. M., & Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour? arXiv preprint. (Original work presented at CSSS 2015) https://doi.org/10.48550/arXiv.1901.02672.

Bolatti, D., Díaz, J., & Bollati, V. A. (2025). Strategic cybersecurity governance for SMEs: An adaptive and progressive governance model. In Proceedings of the XXXI Congreso Argentino de Ciencias de la Computación (CACIC 2025) (pp. 893–902). Red de Universidades con Carreras en Informática. http://sedici.unlp.edu.ar/handle/10915/189846

Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2022). Cybersecurity supply chain risk management practices for systems and organizations (NIST SP 800-161 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-161r1

Malatji, M., Marnewick, A. L., & Von Solms, S. (2022). Cybersecurity capabilities for critical infrastructure resilience. Information & Computer Security, 30(2), 255–279. https://doi.org/10.1108/ICS-06-2021-0091

National Institute of Standards and Technology (NIST). (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1

National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29

National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5

National Institute of Standards and Technology. (2018). Risk management framework for information systems and organizations (NIST SP 800-37 Rev. 2). https://doi.org/10.6028/NIST.SP.800-37r2

Pearce, H., Ahmad, B., Tan, B., Dolan-Gavitt, B., & Karri, R. (2022). Asleep at the keyboard? Assessing the security of GitHub Copilot’s code contributions. 2022 IEEE Symposium on Security and Privacy (SP), 754–768. https://doi.org/10.1109/SP46214.2022.9833571

Petersen, R., Santos, D., Smith, M. C., Wetzel, K. A., & Witte, G. (2020). Workforce framework for cybersecurity (NICE framework) (NIST SP 800-181 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-181r1

Rebollo, O., Mellado, D., Fernández-Medina, E., & Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58, 44–57. https://doi.org/10.1016/j.infsof.2014.10.003

Ríos Insua, D., Couce-Vieira, A., Rubio, J. A., Pieters, W., Labunets, K., & Rasines, D. G. (2021). An Adversarial risk analysis for cybersecurity. Risk Analysis, 41(1), 16–36. https://doi.org/10.1111/risa.13331

Samek, W., Montavon, G., Lapuschkin, S., Anders, C. J., & Müller, K.-R. (2021). Explaining deep neural networks and beyond: A review of methods and applications. Proceedings of the IEEE, 109(3), 247–278. https://doi.org/10.1109/JPROC.2021.3060483

Sulistyowati, D., Handayani, F., & Suryanto, Y. (2020). Comparative analysis and design of cybersecurity maturity assessment methodology using NIST CSF, COBIT, ISO/IEC 27002 and PCI DSS. JOIV: International Journal on Informatics Visualization, 4(4), 225–230. https://doi.org/10.30630/joiv.4.4.482

Tjoa, E., & Guan, C. (2021). A survey on explainable artificial intelligence (XAI): Toward medical XAI. IEEE Transactions on Neural Networks and Learning Systems, 32(11), 4793–4813. https://doi.org/10.1109/TNNLS.2020.3027314

Downloads

Published

2026-07-20 — Updated on 2026-07-20

How to Cite

Bolatti, D. A., Diaz, J., & Bollati, V. (2026). M-SCORE: An Explainable and Quantitative Cybersecurity Maturity Scoring Model for SMEs . Technology and Science Magazine, (56), 99–119. https://doi.org/10.33414/rtyc.56.99-119.2026