Exploratory empirical evaluation of the cyber-resistivity maturity and scoring framework (CRMSF): a multi-sector pilot study
Abstract Cybersecurity maturity models are widely used to assess and improve organizational security posture. However, many existing frameworks remain control-centric, static, and insufficiently adaptive to organizational scale and sector-specific constraints. These limitations are particularly evident in small and medium-sized enterprises and public-sector environments, where resource and governance challenges hinder effective implementation. The Cyber-Resistivity Maturity and Scoring Framework (CRMSF) is developed as a modular, scalable, and business-aligned framework that integrates maturity progression with explicit weighting, complexity, criticality, and benchmarking mechanisms. It combines technical and organizational practices within a unified self-assessment and scoring architecture designed to support risk-informed and actionable decision-making. This paper presents an initial empirical evaluation of CRMSF through a mixed-methods pilot study involving 26 cybersecurity professionals from multiple industry sectors. Data were collected through structured self-assessments across seven domains and twenty-four security categories, supplemented by surveys and expert interviews. Both quantitative and qualitative data were collected to evaluate usability, completeness, and contextual relevance. Based on structured practitioner evaluations, the results indicate meaningful perceived relationships between cybersecurity and cyber-resilience domains and suggest that practitioners regarded the framework as supportive for prioritizing initiatives and informing strategic investment decisions, while complementing established standards such as ISO/IEC 27001 and the NIST Cybersecurity Framework. The findings suggest strong perceived coherence and practical applicability of the framework, while identifying opportunities for refinement and further evaluation of scalability. The results provide initial, exploratory evidence that CRMSF is perceived as supporting adaptive, context-aware cybersecurity maturity assessment aligned with strategic governance and operational realities.
Authors
- Konstantinos Vavousis (ORCID: https://orcid.org/0000-0001-8625-6290)
- Yianna Danidou (ORCID: https://orcid.org/0000-0003-1722-9701)
- Costas Iordanou (ORCID: https://orcid.org/0000-0002-7424-7482)
- Georgios Vardoulias
- Konstantinos Papachristofis (ORCID: https://orcid.org/0009-0003-5462-2489)
Institutions
- Hellenic Naval Academy (GR)
- Cyprus University of Technology (CY)
- European University Cyprus (CY)
- The American College of Greece (GR)
Publication Details
- Journal
- International Journal of Information Security
- Published
- 2026-10-09
- DOI
- https://doi.org/10.1007/s10207-026-01329-8
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00