Purpose – This study aims to develop a vulnerability management model to enhance security capability in small and medium-sized enterprises (SMEs), particularly in safeguarding accounting data under resource constraintsDesign/Methodology/Approach – This study employs a qualitative multi-case research design involving six SMEs in Surakarta, Indonesia. Data were collected through in-depth interviews, direct observations, and document analysis. Using inductive comparative logic and cross-case thematic analysis, the study identifies recurring governance patterns and develops a context-sensitive vulnerability management model grounded in empirical evidence across varying levels of resource constraints.Findings – The findings reveal that vulnerability management effectiveness in SMEs is shaped by the integration of governance structures, managerial coordination, and organizational learning rather than by technological capability alone. The study identifies three distinct governance configurations across SMEs under varying levels of resource constraints: reactive centralization, vendor-dependent compliance, and institutionalized adaptive governance. The proposed model consists of four interconnected components: identification and detection, evaluation and prioritization, managerial decision integration, and HR awareness and continuous learning. These components operate through a continuous feedback mechanism that strengthens adaptive security governance and organizational resilience.Research Limitations and Implications – This study is limited to six SME cases in Surakarta, Indonesia, which may restrict broader generalizability across industries and regions. Future research may apply quantitative or mixed-method approaches to validate and extend the proposed model across different organizational and institutional contexts.Practical implications – The study provides a practical and cost-efficient framework for SMEs to strengthen accounting data security through structured vulnerability management, risk-based prioritization, internal governance coordination, and continuous security awareness practices.Originality/Value – This study positions vulnerability management as a governance-oriented and learning-based organizational capability shaped by resource conditions, managerial integration, and adaptive organizational practices. The proposed model offers a context-sensitive approach for strengthening sustainable accounting data security governance in SMEs.