The growing integration of Internet of Things (IoT) technologies within Small and Medium Enterprises (SMEs) has introduced new operational efficiencies while simultaneously expanding the cybersecurity threat landscape. However, most SMEs lack the resources, technical expertise, and institutional maturity required to adopt existing security frameworks, which are often designed with large enterprises in mind. This paper proposes a risk-based framework specifically developed to help SMEs identify, assess, and mitigate IoT-related security risks in a structured and scalable manner. The framework integrates key components such as asset classification, STRIDE-based threat modeling, CVSS-driven vulnerability assessment, and dynamic risk prioritization through Bayesian inference. Emphasis is placed on cost-effective mitigation strategies that are feasible within SME resource constraints and aligned with regulatory requirements. The framework was validated through a real-world case study involving a digitally enabled retail SME. Results demonstrate tangible improvements in vulnerability management, security control implementation, and organizational readiness. Additionally, qualitative feedback from stakeholders highlights the framework’s usability, adaptability, and minimal disruption to operations. This research bridges a critical gap in the current literature by contextualizing established cybersecurity methodologies for the SME sector and providing a practical toolset for managing IoT risks. The proposed framework offers SMEs a viable path toward improving cybersecurity resilience in increasingly connected business environments.
扫码关注我们
求助内容:
应助结果提醒方式:
