Enhanced National Institute of Standards and Technology Cybersecurity Awareness Framework for Small and Medium Enterprises in Nigeria
Ebiesuwa Seun, Okedare Fiyinfolu
Asian Journal of Research in Computer Science · pp. 106–127 · Published 29 Jun 2026
10.9734/ajrcos/2026/v19i6872Abstract
Aims: The study aimed to develop an enhanced cybersecurity awareness framework tailored specifically for Small and Medium-sized Enterprises (SMEs) in Nigeria, addressing their limited resources and unique challenges. Study Design: A framework development study using secondary data analysis and practical testing on SMEs. Place and Duration of Study: Conducted in Nigeria, using a dataset from the Small and Medium Enterprises Development Agency of Nigeria (SMEDAN) covering cybersecurity challenges over a five-year period (2021-2025). Methodology: To prepare the data for analysis, the ETL (Extract, Transform, and Load) approach was employed, involving data cleaning and transformation processes carried out with OpenRefine and Tableau. The identified cybersecurity challenges were systematically analyzed and categorized into three major groups: technical vulnerabilities, human-related risks, and operational gaps. Building on these insights, an enhanced cybersecurity awareness framework was developed by adapting the five core functions of the NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, Recover, and adding a sixth function, Govern with respect to Education. This adaptation simplified the framework into practical, scalable, and cost-effective measures suitable for SMEs with limited resources. The framework was tested under SME network conditions using NS‑3 simulations and practical deployment in ten SMEs. Scenarios included TLS/IPsec sessions, VPNs, encrypted backups, and simulated DoS attacks. Results: Compliance percentages were derived from structured assessments across the ten SMEs, with results analyzed using risk matrices and performance metrics. Compliance levels ranged from 37.9% to 92.7%. Beyond compliance, quantitative findings showed reduced latency during encrypted sessions, improved throughput under VPN conditions, lower CPU load during cryptographic operations, and faster recovery times following simulated attacks. Conclusion: The framework proved scalable, cost-effective, and practical for SMEs with limited resources. It highlighted the importance of awareness training and building a strong security culture. Improving cybersecurity awareness and adopting structured practices significantly reduces SME vulnerability to cyber threats. The framework offers a practical roadmap for Nigerian SMEs to enhance cybersecurity, protect sensitive information, and ensure business continuity in the digital economy.
Cited by 0
No indexed citations yet.
Related research
- First Trimester Fasting Blood Glucose as a Screening Tool for Diabetes Mellitus in a Teaching Hospital Setting in Nigeria — shares topic coverage
- The Nature and Complications of Acute Traumatic Cervical Spinal Cord Injury in a University Hospital in Nigeria — shares topic coverage
- Musculoskeletal Complications of Sickle Cell Anaemia and Their Management Approaches in Makurdi, Nigeria — shares topic coverage
- Work-related Musculoskeletal Disorders among Radiologists in Nigeria — shares topic coverage
- The Skills of Cardiopulmonary Resuscitation in Some Professional and Student Teachers Compared — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.