Skip to content
Conference

Adapting NIST CSF 2.0 Framework to Enhance Cybersecurity Readiness Against Phishing in SMEs in Yemen

Aug 2026 · 2026 6th International Conference on Emerging Smart Technologies and Applications (eSmarTA) · pp. 1-8 · 0 citations · 32 references

Abstract

Small and medium-sized educational institutions in Yemen face significant challenges in building cybersecurity readiness, particularly against phishing attacks, which serve as a primary gateway to more sophisticated threats given the absence of formal policies and weak behavioral awareness. This study proposes a practical model for adapting the NIST CSF 2.0 framework to this resource-constrained context. A quasi-experimental methodology was conducted across four sequential stages: risk assessment, framework adaptation using low-cost administrative and technical controls, expert validation of the model's validity and acceptability, and final effectiveness evaluation through phishing simulations along with measurement of perceived awareness before and after the intervention. The results showed statistically significant improvements: the click rate on suspicious links decreased from 30% to 10%, while the reporting rate increased from 10% to 45%. Expert evaluation yielded a mean total score of 3.9 out of 5, with a standard deviation of 0.41, reflecting good model acceptance and consensus among experts. The study demonstrates that flexible adaptation of global frameworks using affordable technologies and simplified procedures can achieve tangible cybersecurity improvements for such institutions, thereby enhancing cybersecurity as an indispensable pillar for sustainability in the digital age.

View source

Similar papers

Review Open access Aug 2026

CONVINCED BUT UNPREPARED: A PILOT MEASUREMENT OF CYBERSECURITY PREPAREDNESS IN SLOVAK SMES

Small and medium-sized enterprises (SMEs) are increasingly becoming targets of cyberattacks. Their preparedness in Slovakia, however, is rarely measured. This study develops and pilots a survey instrument for assessing the cybersecurity preparedness of SMEs. The questionnaire has six parts. Four of them contain an atti...

J. Sopko, Leoš Šafár · 0 citations
Open access Aug 2026

Network Infrastructure Security Audit at a Vocational School Teaching Factory Using the NIST Cybersecurity Framework

Background: The increasing dependence on public-facing network services exposes educational institutions to growing cybersecurity threats, highlighting the need for structured security evaluations. This study evaluates cybersecurity maturity in a vocational school Teaching Factory (TEFA) environment using the NIST Cybe...

Maya Destriani, Bintang Najarul Haq Mulyadi, T. Ardan · 0 citations
Review Open access Aug 2026

Patching the Invisible Gap: A Comparative Analysis of Cyber Defense Strategies in Indonesian Digital Enterprises

Over the past five years, hacking incidents targeting Indonesia’s digital business ecosystem have increased significantly. The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara [BSSN]) recorded more than 1.6 billion cyberattacks throughout 2021, while 311 data breach incidents affecting 248 stakeholders we...

Aditya Akbar, Rafael Verdyansyah Pratama, Cahyo Purnomo et al. · 0 citations
Review Open access Sep 2026

A Risk-Based Framework for Assessing Cybersecurity Maturity Levels of Savings and Credit Cooperative Societies (SACCOS) in Tanzania

Savings and Credit Cooperative Societies (SACCOS) are central to financial inclusion in Tanzania; however, their digital transformation has advanced faster than their cybersecurity capabilities. National instruments, including the Cybercrimes Act (CAP 443), the Government Cyber Security Strategy 2022–2027, and the TCDC...

Ayoub Jonathan Kitomari, Gustaph Sanga, S. Wambura · 0 citations
Review Open access Sep 2026

Cybersecurity Awareness and Practices Among Teachers in Mahendranagar, Kanchanpur, Nepal: An Exploratory Protection Motivation Perspective

This study examined cybersecurity awareness and practices among 165 school and higher education teachers in Mahendranagar, Kanchanpur, Nepal, using Protection Motivation Theory (PMT) as its theoretical framework. The study investigated teachers’ perceptions of cyber threats, online security behaviors, and cybersecurity...

S. Bhatt · 0 citations
Open access Aug 2026

Assessment of Information Gathering, Footprinting, and Vulnerability Assessment Competencies Among BSIT Students: Basis for a Cybersecurity Training Framework

The increasing prevalence of cybersecurity threats has emphasized the need for Information Technology (IT) graduates to possess essential cybersecurity competencies. This study assessed the competencies of fourth-year Bachelor of Science in Information Technology (BSIT) students of Bohol Northern Star College in the ar...

Roseline B. Lorican, Jomar C. Igloso, Judelyn C. Felicia et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.