In the digital era of the Industrial Revolution 4.0, organizations such as BPRDCo must undergo Digital Transformation (DT) to remain competitive. A significant obstacle in this process is often the inadequacy of information security controls, which can lead to DT failure. Previous research has highlighted the necessity of ambidextrous information security management—integrating both traditional and agile approaches—as a crucial mechanism for DT success in large banks, particularly in data management and information security. However, this strategy has not been proven effective for smaller banks like BPRDCo. Therefore, this study aims to develop and propose priority information security management solutions specifically tailored for SMEs, while also estimating the improvement in maturity level capabilities to boost DT success. The research follows five stages in Design Science Research (DSR): problem identification, requirements specification, design and development, demonstration, and evaluation. Data were collected through interviews and document analysis, and analyzed using the ISO 27001:2022 Information Security Management System (ISMS) framework. Six priority PDCA and Annex controls were identified for BPRDCo as the case study. Based on the identified gaps, six essential solutions were designed using ISMS controls. These recommendations were compiled into an implementation roadmap to enhance BPRDCo's readiness for full ISMS implementation and certification, ultimately supporting DT success in small banks.