As Industry 4.0 advances, organizations must embrace digital transformation (DT) to remain competitive. However, inadequate IT Governance (ITG) often leads to DT failures. While ambidextrous ITG models, combining traditional and agile approaches, have proven effective for large banks, their applicability to small and medium enterprises (SMEs) remains unexplored. This study aims to recommend prioritized ITG solutions for SMEs and estimate improvements in capability maturity levels to ensure successful DT. Employing Design Science Research (DSR) across five stages—problem identification, requirement specification, design, demonstration, and evaluation—data were collected through semi-structured interviews and document analysis. Using COBIT 2019’s SME focus area, the analysis identified three key Information Technology Governance and Management (ITGM) objectives: EDM03 (Ensured Risk Optimization), APO12 (Managed Risk), and MEA03 (Compliance with External Requirements), with an average capability maturity level of 3.38. Sixteen solutions, based on seven ITGM components, were developed and compiled into a roadmap to elevate the maturity level to 3.84. This research enriches COBIT 2019 literature, proposes a hybrid ITG framework for SMEs, and enhances web-based information systems, fostering operational efficiency, risk mitigation, regulatory compliance, and sustainable competitiveness for SMEs undergoing DT.