Small and Medium Enterprises (SMEs) face increasing cybersecurity risks while often having limited resources and low readiness to implement ISO/IEC 27001. This research aims to design a user-centered risk management framework to improve security posture and enhance the effectiveness of security control implementation. The study employs the Design Science Research Methodology (DSRM) by integrating ISO/IEC 27005 as an operational risk management standard and ISO 31000 as strategic guidance, supported by a Multi-Criteria Decision Analysis (MCDA) approach for security control prioritization. The framework was demonstrated through a case study at PT Pulsabayar and evaluated using Focus Group Discussions (FGDs) and expert validation. Risk analysis identified 20 cybersecurity risks, consisting of 9 medium risks and 11 low risks, with the three highest-priority risks being application account takeover, phishing attacks, and malware infections. Security control prioritization generated priority scores ranging from 0.36 to 0.64, enabling systematic resource allocation for risk mitigation. The framework received positive evaluations from internal stakeholders and external experts, confirming its clarity, usability, and alignment with organizational needs. This research concludes that a user-centered and standards-aligned framework can strengthen cybersecurity governance and support SMEs in achieving incremental compliance and sustainable security improvements.
Copyrights © 2026