An Empirical Analysis of Cybersecurity Practices in Small and Medium Enterprises (SMEs)
This is an empirical study that measures the cybersecurity position of Small and Medium Enterprises (SMEs) in terms of capability maturity, control deficit adoption, and operational resilience. Based on simulated incident data from consolidated industry reporting (2020-2025) and current structured threat data, Cybersecurity Capability Maturity Index (CMI) and Mean Time to Resolution (MTTR) are estimated. The comparison reveals that the median SME is operating in a CMI of 2.1 (Minimal maturity), which is directly linked to critically low Multi-Factor Authentication (MFA) enforcement (13% mandatory usage) and acute behavioral risk factors (an 83% training gap). Findings indicate that the operation is very fragile, with an MTTR that is always greater than 48 hours. The study provides a technical foundation for strategically focused, quantitative policy interventions that focus on organizational governance rather than resource acquisition
