Logo image
EMPIRICAL ASSESSMENT AND VALIDATION OF CYBERSECURITY POSTURE IN SMALL‑TO‑MEDIUM ENTERPRISES: A CASE STUDY OF WESTERN AUSTRALIA
Doctoral Thesis   Open access

EMPIRICAL ASSESSMENT AND VALIDATION OF CYBERSECURITY POSTURE IN SMALL‑TO‑MEDIUM ENTERPRISES: A CASE STUDY OF WESTERN AUSTRALIA

Alladean Chidukwani
Doctor of Philosophy (PhD), Murdoch University
2026
DOI:
https://doi.org/10.60867/00000136
pdf
Whole Thesis7.88 MBDownloadView
Open Access

Abstract

This thesis examines the cybersecurity posture of small-to-medium enterprises (SMEs) in Western Australia, addressing a critical gap in empirical evidence and assurance mechanisms for this sector. Using a publication-based approach, the research progresses through three phases: a systematic literature review, a NIST CSF aligned survey, and a mixed-methods validation study. The literature review exposed an imbalance in research emphasis on the Identify and Protect functions of the NIST CSF, with limited attention to Detect, Respond, and Recover. It also highlighted the dominance of qualitative methodologies and the need for more quantitative approaches. The subsequent survey measured awareness, perceived risk, and NIST CSF control adoption among SMEs, revealing gaps in legislative compliance and reliance on informal guidance. It also highlighted the inherent limitation of social desirability bias in SME cybersecurity self-assessments. To address these limitations, the final phase introduced the Validated Cybersecurity Posture Assessment Framework (VCPAF), combining expert interviews, technical scans, and artefact reviews. This validation uncovered systemic overestimation of maturity and recurring weaknesses in controls such as patching, access control, monitoring, and incident response. The thesis advances SME cybersecurity by providing empirical evidence of the limitations of self-assessment in SME cybersecurity, introducing VCPAF as a validated framework for posture assessment and assurance mechanism, and proposing two conceptual contributions, the Operational Validity of Self-Assessment (OVSA) and the Perception–Practice Gap Drivers Theory (PPGDT) to explain misalignment between perceived and actual security. OVSA demonstrates that unaudited self-reports systematically overstate maturity for controls requiring continuous governance and resilience rehearsal, advocating for measurement-anchored approaches using triangulated evidence. PPGDT explains misalignment through cognitive biases, governance failures, resource constraints, and ecosystem dependencies. This research enhances SME cybersecurity by providing evidence‑based, validated assessment methods that move beyond self‑reported maturity, integrating behavioural, organisational, and technical factors to deliver a practical posture evaluation approach.

Details

Metrics

1 Record Views
Logo image