M-SCORE: An Explainable and Quantitative Cybersecurity Maturity Scoring Model for SMEs
DOI:
https://doi.org/10.33414/rtyc.56.99-119.2026Keywords:
cybersecurity maturity model, SMEs, quantitative assessment, maturity scoring;, agent-assisted assessment, rule-based evaluation, cybersecurity governance, third-party risk, resilience, Design Science Research.Abstract
Small and medium-sized enterprises (SMEs) face persistent cybersecurity exposure while often lacking the resources, expertise, and governance structures required to adopt comprehensive assessment frameworks. Existing cybersecurity maturity models provide useful guidance, yet they frequently remain fragmented across domains, weakly operationalized for SME realities, and insufficiently explicit in how maturity scores are computed and prioritized. This paper proposes M-SCORE, a quantitative and multi-dimensional cybersecurity maturity evaluation model specifically designed for SMEs. The model integrates core cybersecurity dimensions—governance, protection of data and assets, continuity and resilience, third-party risk, awareness, and detection and response, with optional coverage of AI governance—into a structured scoring approach based on measurable indicators, verifiable evidence, weighted sub-dimensions, and auditable implementation levels.
To improve practical applicability without compromising reproducibility, M-SCORE adopts a hybrid architecture in which deterministic rule-based scoring is complemented by agent-assisted semantic support for evidence interpretation, document classification, and recommendation generation. In this design, AI agents do not determine the score; instead, they enhance the efficiency and usability of the assessment workflow while preserving transparency and traceability. The paper follows a Design Science Research approach and formalizes the model, its scoring logic, and its conceptual automation architecture. A preliminary application scenario is also outlined to illustrate how M-SCORE can support maturity profiling, gap identification, and roadmap prioritization in resource-constrained SME environments.
Downloads
References
Ahmad, A., Maynard, S. B., & Park, S. (2014). Information security strategies: Towards an organizational multi-strategy perspective. Journal of Intelligent Manufacturing, 25(2), 357–370. https://doi.org/10.1007/s10845-012-0683-0
Almuhammadi, S., & Alsaleh, M. (2017). Information security maturity model for NIST cybersecurity framework. Computer Science & Information Technology (CS & IT), 7(3), 51–62. https://doi.org/10.5121/csit.2017.70305
Azmi, R., Tibben, W., & Win, K. T. (2018). Review of cybersecurity frameworks: Context and shared concepts. Journal of Cyber Policy, 3(2), 258–283. https://doi.org/10.1080/23738871.2018.1520271
Bada, M., Sasse, A. M., & Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour? arXiv preprint. (Original work presented at CSSS 2015) https://doi.org/10.48550/arXiv.1901.02672.
Bolatti, D., Díaz, J., & Bollati, V. A. (2025). Strategic cybersecurity governance for SMEs: An adaptive and progressive governance model. In Proceedings of the XXXI Congreso Argentino de Ciencias de la Computación (CACIC 2025) (pp. 893–902). Red de Universidades con Carreras en Informática. http://sedici.unlp.edu.ar/handle/10915/189846
Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2022). Cybersecurity supply chain risk management practices for systems and organizations (NIST SP 800-161 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-161r1
Malatji, M., Marnewick, A. L., & Von Solms, S. (2022). Cybersecurity capabilities for critical infrastructure resilience. Information & Computer Security, 30(2), 255–279. https://doi.org/10.1108/ICS-06-2021-0091
National Institute of Standards and Technology (NIST). (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29
National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5
National Institute of Standards and Technology. (2018). Risk management framework for information systems and organizations (NIST SP 800-37 Rev. 2). https://doi.org/10.6028/NIST.SP.800-37r2
Pearce, H., Ahmad, B., Tan, B., Dolan-Gavitt, B., & Karri, R. (2022). Asleep at the keyboard? Assessing the security of GitHub Copilot’s code contributions. 2022 IEEE Symposium on Security and Privacy (SP), 754–768. https://doi.org/10.1109/SP46214.2022.9833571
Petersen, R., Santos, D., Smith, M. C., Wetzel, K. A., & Witte, G. (2020). Workforce framework for cybersecurity (NICE framework) (NIST SP 800-181 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-181r1
Rebollo, O., Mellado, D., Fernández-Medina, E., & Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58, 44–57. https://doi.org/10.1016/j.infsof.2014.10.003
Ríos Insua, D., Couce-Vieira, A., Rubio, J. A., Pieters, W., Labunets, K., & Rasines, D. G. (2021). An Adversarial risk analysis for cybersecurity. Risk Analysis, 41(1), 16–36. https://doi.org/10.1111/risa.13331
Samek, W., Montavon, G., Lapuschkin, S., Anders, C. J., & Müller, K.-R. (2021). Explaining deep neural networks and beyond: A review of methods and applications. Proceedings of the IEEE, 109(3), 247–278. https://doi.org/10.1109/JPROC.2021.3060483
Sulistyowati, D., Handayani, F., & Suryanto, Y. (2020). Comparative analysis and design of cybersecurity maturity assessment methodology using NIST CSF, COBIT, ISO/IEC 27002 and PCI DSS. JOIV: International Journal on Informatics Visualization, 4(4), 225–230. https://doi.org/10.30630/joiv.4.4.482
Tjoa, E., & Guan, C. (2021). A survey on explainable artificial intelligence (XAI): Toward medical XAI. IEEE Transactions on Neural Networks and Learning Systems, 32(11), 4793–4813. https://doi.org/10.1109/TNNLS.2020.3027314
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Diego Angelo Bolatti, Javier Diaz, Veronica Bollati

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.











