Organizational cybersecurity risk pathways identified in small businesses

Toward an Empirical Probabilistic Risk Manifestation Model of Organizational Cybersecurity in SMEs

Cryptography and Security

Summary

Small and medium-sized businesses often face cybersecurity risks, but understanding exactly how these risks appear is difficult. The authors studied detailed security findings from 22 small businesses over two years to see patterns in how security problems happen. They found specific ways in which weaknesses lead to attacks, like exposed assets leading to stolen credentials and unauthorized breaks-in. They also showed it’s possible to simplify security checks while still covering most important risks.

What this means in practice

Authors

FNU Nurjahan, Aidan Eiler, Mst Eshita Khatun, Lamine Noureddine, Aisha Ali-Gombe

Abstract

In this paper, we present a cross-layer empirical study of organizational cybersecurity risk in Small and medium-sized enterprises (SMEs), analyzing 281 validated security findings from 22 real-world SME cybersecurity assessments conducted over two years through a pro bono university cybersecurity clinic. We first identify recurring organizational security functions through iterative thematic coding, then estimate an empirical Risk Manifestation Model linking these functions to exposure conditions, attack mechanisms, and cybersecurity outcomes, and use probability propagation to identify dominant risk pathways. The model characterizes empirical associations observed in this sample rather than causal or predictive relationships. Our analysis identifies eight organizational security functions associated with two exposure conditions, five attack mechanisms, and six outcome categories. Across most functions, the dominant pathway follows asset exposure to credential compromise to unauthorized access, whereas infrastructure and network security primarily propagates through network exposure; these pathways remain stable under leave-one-organization-out analysis. Finally, we evaluate whether SME cybersecurity assessments can be simplified while preserving meaningful security coverage. Retaining six functions reduces assessment burden by 24% while preserving 97% of critical findings and 92% of risk-pathway coverage, a security-oriented reduction, while retaining five functions reduces burden by 45% while preserving 89% of critical findings and 85% of risk-pathway coverage, a more efficiency-oriented alternative.