You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
π Cybersecurity Risk Assessment Framework for SMEs
A structured, quantitative Cybersecurity Risk Assessment Framework for Small and Medium Enterprises (SMEs) β identifying top threats, scoring risks using Likelihood Γ Impact, and recommending NIST-aligned mitigation strategies.
Small and Medium Enterprises (SMEs) are increasingly targeted by cybercriminals due to limited security budgets and lack of dedicated IT teams. This project develops a practical, reusable risk assessment framework that any SME can adopt to:
Identify and rank cyber threats
Quantify risk using a scoring model
Apply targeted mitigation controls
Align with industry standards (NIST CSF v2.0)
π― Objectives
Identify the most prevalent cybersecurity risks facing SMEs
Develop a quantitative Risk Assessment Model (Risk Score = Likelihood Γ Impact)
Propose cost-effective mitigation strategies aligned with NIST CSF
Validate the framework through 3 real-world SME case studies
π₯οΈ Critical SME Assets
Employee Accounts
Customer Data
Financial Records
Business Applications
Email Systems
Cloud Services
Network Infrastructure
β οΈ Top 5 Threats Identified
#
Threat
Description
01
Phishing Attacks
Fake emails/websites used to steal credentials
02
Ransomware
Malware that encrypts files and demands ransom
03
Insider Threats
Employees exposing data intentionally or accidentally
04
Weak Passwords
Poor practices enabling unauthorized access
05
Unpatched Software
Outdated systems with exploitable vulnerabilities
π¬ Methodology
Identify SME assets and critical business processes.
Analyze common cyber threats and vulnerabilities.
Assign Likelihood (1β5) and Impact (1β5) values.
Calculate Risk Score = Likelihood Γ Impact.
Rank risks by severity.
Recommend mitigation controls aligned with NIST CSF.
Validate results using SME case studies.
π Risk Assessment Model
Formula
Risk Score = Likelihood (1β5) Γ Impact (1β5)
Risk Matrix
Risk / Threat
Likelihood
Impact
Risk Score
Level
Phishing Attacks
5
4
20
π΄ High
Ransomware
4
5
20
π΄ High
Insider Threats
3
5
15
π High
Weak Passwords
5
4
20
π΄ High
Unpatched Software
4
4
16
π΄ High
Risk Level Scale
Score
Level
Action
1 β 5
π’ Low
Monitor
6 β 10
π‘ Medium
Plan
11 β 15
π High
Respond within 30 days
16 β 25
π΄ Critical
Immediate action
π‘οΈ NIST Framework Alignment
Function
Activities
IDENTIFY
Asset Management, Risk Assessment, Governance
PROTECT
Access Control, MFA, Data Security, Training
DETECT
Continuous Monitoring, Anomaly Detection
RESPOND
Incident Response Planning, Communications
RECOVER
Recovery Planning, Backup & Restoration
π’ Case Studies
1. π Retail Store β Phishing Attack
Severity: High
Scenario: Phishing email compromised POS system credentials
Controls Applied: MFA + Employee Security Training
Outcome: Reduced credential theft; staff trained to identify phishing
This project is licensed under the MIT License β feel free to use, adapt, and share with attribution.
Cybersecurity Β· Risk Management Β· 2025β2026
Made with β€οΈ by Himanshu Soni | Naviotech Solution Pvt Ltd
About
π A Cybersecurity Risk Assessment Framework for SMEs β Likelihood Γ Impact scoring, NIST CSF aligned, with real-world case studies. Minor Project I | 2025β2026