Skip to content
Open access

Development of the Risk-Weighted Cybersecurity Maturity Index (RWCMI) Based on the NIST Cybersecurity Framework 2.0 for Multi-Entity Organizations

Jul 2026 · Eduvest - Journal Of Universal Studies · Vol 6, pp. 8227-8243 · 0 citations · 26 references

TL;DR

The RWCMI provides a more risk-sensitive cybersecurity maturity measurement framework that supports strategic decision-making, investment prioritization, and continuous improvement of cybersecurity governance in multi-entity organizations.

Abstract

The rapid growth of digital transformation has increased organizational dependence on interconnected technologies while simultaneously expanding cybersecurity risks, particularly in multi-entity organizations with diverse operational characteristics and information system environments. Conventional cybersecurity maturity assessments often provide general capability measurements but have limitations in representing variations in risk exposure across security domains. This study aims to develop the Risk-Weighted Cybersecurity Maturity Index (RWCMI) based on the NIST Cybersecurity Framework (CSF) 2.0 to provide a more contextual measurement of cybersecurity maturity by integrating risk weighting into the maturity assessment process. This research employed a quantitative, model-based evaluation approach using a case study of PTPN Group, consisting of one holding company and ten subsidiaries. Data were collected through cybersecurity maturity questionnaires, expert-based risk assessments, and supporting organizational documents. The RWCMI model integrates maturity scores from 22 NIST CSF 2.0 categories with normalized risk weights derived from expert judgments. The results indicate variations in cybersecurity maturity levels among entities, with several organizations achieving targeted maturity levels while others requiring fundamental improvements. The RWCMI approach successfully identified priority improvement areas, particularly in asset management, data security, identity management, and cybersecurity governance. In conclusion, RWCMI provides a more risk-sensitive cybersecurity maturity measurement framework that supports strategic decision-making, investment prioritization, and continuous improvement of cybersecurity governance in multi-entity organizations.

Read PDF

Similar papers

Review Open access Sep 2026

A Risk-Based Framework for Assessing Cybersecurity Maturity Levels of Savings and Credit Cooperative Societies (SACCOS) in Tanzania

Savings and Credit Cooperative Societies (SACCOS) are central to financial inclusion in Tanzania; however, their digital transformation has advanced faster than their cybersecurity capabilities. National instruments, including the Cybercrimes Act (CAP 443), the Government Cyber Security Strategy 2022–2027, and the TCDC...

Ayoub Jonathan Kitomari, Gustaph Sanga, S. Wambura · 0 citations
Review Open access Sep 2026

Cyber Risk Maturity Assessment Model Based on SeMS for Aircraft Operations: A Systematic Literature Review

Aviation cybersecurity governance rests on a three-document RTCA/EUROCAE airworthiness security family; DO-355A/ED-204A provides operational-phase compliance guidance, but no validated, scored maturity layer aligned with Security Management System (SeMS) principles exists above it. This study mapped evidence on cyber r...

Agoes Soebagio, Dwi Afriyanto, Girinoto Girinoto et al. · 0 citations
Open access Sep 2026

A Multi-Stage Framework for Examining the Internal Activity and Refinement of the Cybersecurity Risk Mitigation System in Financial-Banking Environments

The rapid digitalization of financial banking services has increased the need for effective cybersecurity risk mitigation as institutions rely on interconnected digital infrastructures. Understanding how technological, organizational, and human-related factors interact is important for supporting cybersecurity planning...

Laurențiu-Constrantin Stama, R. Nechita, D. Deselnicu et al. · 0 citations
Open access Sep 2026

An Organizational Decision-Support System for Cybersecurity Risk Management: Classifying Breach Types Using XGBoost and Real-World Incident Data

Financial institutions face an escalating volume of cybersecurity threats, yet existing decision frameworks rarely link predictive analytics to operational security priorities. Drawing on Task-Technology Fit theory, this study develops a machine learning-based decision-support framework to classify cybersecurity breach...

Muhammed Samancı, Emrah Noyan, Nuri Avşarlıgil · 0 citations
Open access Aug 2026

Assessment of Information Gathering, Footprinting, and Vulnerability Assessment Competencies Among BSIT Students: Basis for a Cybersecurity Training Framework

The increasing prevalence of cybersecurity threats has emphasized the need for Information Technology (IT) graduates to possess essential cybersecurity competencies. This study assessed the competencies of fourth-year Bachelor of Science in Information Technology (BSIT) students of Bohol Northern Star College in the ar...

Roseline B. Lorican, Jomar C. Igloso, Judelyn C. Felicia et al. · 0 citations
Open access Aug 2026

NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking

The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.

M. B. Legowo, Budi Indiarto, Adzrani Haura Badzlinaya Novianto et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.