Risk-Based Cybersecurity Assessment for an SME

Most small companies believe they are too small to be a target. That assumption is exactly what makes them vulnerable. This thesis asked a simple question: how can a small enterprise protect itself in a way that actually fits its size, its budget, and its reality?

Sittampalam, Ranaya, 2026

Type of Thesis Bachelor Thesis
Client Swiss Energy Partner GmbH
Supervisor Siddhanti, Pragati
Views: 1
Swiss Energy Partner, a small renewable-energy consulting company, runs almost entirely on cloud services. As the company grew, its digital dependence increased faster than its security. It had no documented security policy, no one formally responsible for cybersecurity, and no structured way of assessing risk. This left it exposed to threats such as phishing, data loss, and unauthorised access, a situation shared by many small and medium-sized enterprises that lack dedicated security resources and expertise.
The thesis followed a qualitative single-case study built on three sources of evidence: interviews with internal staff, interviews with four external cybersecurity experts, and a technical review of the company's systems. The material was examined through thematic analysis and assessed against two recognised frameworks, ISO/IEC 27001 and the NIST Cybersecurity Framework. Each risk was rated by likelihood and impact, and the resulting gaps were translated into prioritised, proportionate recommendations designed for a small company.
The assessment identified six key risks, four of them critical, including phishing, unauthorised access, data loss without recovery, and the absence of any incident detection. Looking across both frameworks revealed a common root: the company lacked a basic security governance foundation, with no policies, no clear responsibility, and no risk process. The technical weaknesses were largely symptoms of this deeper gap. From this, nine prioritised and proportionate recommendations were developed, sequenced so the company starts with low-cost foundational measures before technical ones. The central outcome is a reusable cybersecurity assessment toolkit that automatically calculates risk priorities, a readiness score, and an implementation roadmap from the user's own inputs. It allows the company, and comparable small enterprises, to assess and strengthen their cybersecurity posture independently and repeatedly over time. The thesis shows that meaningful security does not require a large budget. It requires structure, priorities, and a strong foundation.
Studyprogram: Business Information Technology (Bachelor)
Keywords cybersecurity; SME; risk assessment; ISO 27001; NIST CSF; gap analysis; cloud security
Confidentiality: vertraulich
Type of Thesis
Bachelor Thesis
Client
Swiss Energy Partner GmbH, Laufen
Authors
Sittampalam, Ranaya
Supervisor
Siddhanti, Pragati
Publication Year
2026
Thesis Language
English
Confidentiality
Confidential
Studyprogram
Business Information Technology (Bachelor)
Location
Basel
Keywords
cybersecurity; SME; risk assessment; ISO 27001; NIST CSF; gap analysis; cloud security