Development and Validation of a Cybersecurity Model for Ransomware Mitigation Based on NIST CSF 2.0: The Case Study of a Peruvian Micro-Small Enterprise

  • Lorenzo Biggi
  • , Jorge Rioja
  • , Pedro Castaneda
  • , Juan Mansilla-Lopez
  • , Alberto Daniel Garcia-Nunez

Research output: Contribution to journalArticlepeer-review

Abstract

This study proposes a pragmatic cybersecurity model grounded in the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0 to mitigate ransomware in Peruvian Micro and Small Enterprises (MSEs). Through a single-case study of a transportation-sector MSE and a case study methodology proposed in a previous study, the research advances in three stages: (1) cybersecurity posture diagnosis, (2) model design, and (3) expert validation. The model’s five-phase structure, Organizational Profile Scope Definition, Critical Assets Identification, Risk Analysis, Cybersecurity Control Selection, and Action Plan Development, addresses MSEs’ resource constraints while aligning with NIST CSF 2.0 functions. Expert evaluation yielded an average score of 3.74 out of 5 across nine assessment categories, with a Standard Deviation (SD) of 0.21, and with categories such as "Risk Assessment" and "Sustainability and Adaptability" achieving the highest given scores of 4 out of 5. This modular, cost-free approach bridges the framework adoption gap in resource-constrained enterprises and presents a feasible alternative to existing cybersecurity standards. Although validated through a single case, the proposed framework provides practical guidance for MSEs and establishes a foundation for future research across diverse sectors and geographic locations.

Original languageEnglish
Pages (from-to)30015-30025
Number of pages11
JournalEngineering, Technology and Applied Science Research
Volume15
Issue number6
DOIs
StatePublished - 2025
Externally publishedYes

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 8 - Decent Work and Economic Growth
    SDG 8 Decent Work and Economic Growth
  2. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Keywords

  • Micro
  • National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
  • Small Enterprises (MSEs)
  • cybersecurity
  • ransomware
  • risk management

Fingerprint

Dive into the research topics of 'Development and Validation of a Cybersecurity Model for Ransomware Mitigation Based on NIST CSF 2.0: The Case Study of a Peruvian Micro-Small Enterprise'. Together they form a unique fingerprint.

Cite this