Papers for

cybersecurity assessment teams

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Organizational cybersecurity risk pathways identified in small businesses

Toward an Empirical Probabilistic Risk Manifestation Model of Organizational Cybersecurity in SMEs

Abstract: In this paper, we present a cross-layer empirical study of organizational cybersecurity risk in Small and medium-sized enterprises (SMEs), analyzing 281 validated security findings from 22 real-world SME cybersecurity assessments conducted over two years through a pro bono university cybersecurity clinic. We first identify recurring organizational security functions through iterative thematic coding, then estimate an empirical Risk Manifestation Model linking these functions to exposure conditions, attack mechanisms, and cybersecurity outcomes, and use probability propagation to identify dominant risk pathways. The model characterizes empirical associations observed in this sample rather than causal or predictive relationships. Our analysis identifies eight organizational security functions associated with two exposure conditions, five attack mechanisms, and six outcome categories. Across most functions, the dominant pathway follows asset exposure to credential compromise to unauthorized access, whereas infrastructure and network security primarily propagates through network exposure; these pathways remain stable under leave-one-organization-out analysis. Finally, we evaluate whether SME cybersecurity assessments can be simplified while preserving meaningful security coverage. Retaining six functions reduces assessment burden by 24% while preserving 97% of critical findings and 92% of risk-pathway coverage, a security-oriented reduction, while retaining five functions reduces burden by 45% while preserving 89% of critical findings and 85% of risk-pathway coverage, a more efficiency-oriented alternative.

Mon 14 SeptCryptography and Security
The gist
Small and medium-sized businesses often face cybersecurity risks, but understanding exactly how these risks appear is difficult. The authors studied detailed security findings from 22 small businesses over two years to see patterns in how security problems happen. They found specific ways in which weaknesses lead to attacks, like exposed assets leading to stolen credentials and unauthorized breaks-in. They also showed it’s possible to simplify security checks while still covering most important risks.
Open 2609.14888v1