Main Article Content
Abstract
Purpose – This study aims to develop a vulnerability management model to enhance security capability in small and medium-sized enterprises (SMEs), particularly in safeguarding accounting data under resource constraints
Design/Methodology/Approach – This study employs a qualitative multi-case research design involving six SMEs in Surakarta, Indonesia. Data were collected through in-depth interviews, direct observations, and document analysis. Using inductive comparative logic and cross-case thematic analysis, the study identifies recurring governance patterns and develops a context-sensitive vulnerability management model grounded in empirical evidence across varying levels of resource constraints.
Findings – The findings reveal that vulnerability management effectiveness in SMEs is shaped by the integration of governance structures, managerial coordination, and organizational learning rather than by technological capability alone. The study identifies three distinct governance configurations across SMEs under varying levels of resource constraints: reactive centralization, vendor-dependent compliance, and institutionalized adaptive governance. The proposed model consists of four interconnected components: identification and detection, evaluation and prioritization, managerial decision integration, and HR awareness and continuous learning. These components operate through a continuous feedback mechanism that strengthens adaptive security governance and organizational resilience.
Research Limitations and Implications – This study is limited to six SME cases in Surakarta, Indonesia, which may restrict broader generalizability across industries and regions. Future research may apply quantitative or mixed-method approaches to validate and extend the proposed model across different organizational and institutional contexts.
Practical implications – The study provides a practical and cost-efficient framework for SMEs to strengthen accounting data security through structured vulnerability management, risk-based prioritization, internal governance coordination, and continuous security awareness practices.
Originality/Value – This study positions vulnerability management as a governance-oriented and learning-based organizational capability shaped by resource conditions, managerial integration, and adaptive organizational practices. The proposed model offers a context-sensitive approach for strengthening sustainable accounting data security governance in SMEs.
Keywords
Article Details
Copyright (c) 2026 Anita Wijayanti, Massila Kamalrudin, Kartika Hendra Titisari, Werner R Murhadi

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
- Adejumo, A. P., & Ogburie, C. P. (2025). Strengthening Finance with Cybersecurity: Ensuring Safer Digital Transactions. World Journal of Advance Reserach and Review, 25(March), 1527–1541. https://doi.org/10.30574/wjarr.2025.25.3.0908
- Bennouk, K., & Aali. (2024). A Comprehensive Review and Assessment of Cybersecurity Vulnerability Detection Methodologies. Journal of Cybersecuryty and Privacy, 853–908. https://doi.org/10.3390/jcp4040040
- Bouncken, R. B., Czakon, W., & Schmitt, F. (2025). Purposeful Sampling and Saturation in Qualitative Research. Review of Managerial Science, 1–64. https://doi.org/10.1007/s11846-025-00881-2
- Chotia, V., Khoualdi, K., Broccardo, L., & Zafar, M. (2025). Technology in Society The Role of Cyber Security and Digital Transformation in Gaining Competitive Advantage Through Strategic Management Accounting. Technology in Society, 81(February), 102851. https://doi.org/10.1016/j.techsoc.2025.102851
- Eisenhardt, K. M., & Bourgeois, L. J. (1988). Politics of Strategic Decision Making in High-Velocity Environments: Toward a Midrange Theory. Academy of Management Journal, 31(4), 737–770. https://doi.org/10.5465/256337
- Eisenhardt, K. M., Graebner, M. E., Eisenhardt, K. M., & Graebner, M. E. (2007). Theory Building from Cases: Opportunities and Challenges. The Academyof Management Journal, 50(1), 25–32.
- https://psycnet.apa.org/doi/10.5465/AMJ.2007.24160888
- Giudiece. (2024). Methodologies and tools for a vulnerability management process with an integrated risk evaluation framework Author: Fortunato Gabriele Lo Giudice.
- Hollweck, T. (2016). Case Study Research Design and Methods. The Canadian Journal of Program Evaluation, 30(2016), 1–5. https://doi.org/10.3138/cjpe.30.1.108
- Isa, M., Praswati, A. N., & Zulaekah, S. (2024). Vulnerability Analysis: A Tool for SMEs ’ Business Resilience. Journal of Integrated Disaster Risk Management, 14, 157–175. https://doi.org/10.5595/001c.125616
- Jiang, W., Almaayah, M., & Shehab, R. (2025). Natural Language Processing-Driven Communication for Improved Citizen Alignment in Smart Cities. 21–28.
- https://doi.org/10.70470/ESTIDAMAA/2025/003
- Jiang, Y., Nay, Meng, Q., Lim, H. W., & Sikdar, B. (2025). A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges. Cryptography and Security, 1(1), 1–32. https://doi.org/10.48550/arXiv.2502.11070
- Mazzano. (2025). CyberESP An Integrated Cybersecurity Framework for SMEs. Journal of Software: Evolution and Process, 37, 1–23. https://doi.org/10.1002/smr.70050
- Morshed, A. (2025). Cybersecurity in Digital Accounting Systems: Challenges and Solutions in the Arab Gulf Region. Journal of Risk and Financial Management, 18(41), 1–24. https://doi.org/10.3390/jrfm18010041
- Neri, M., Niccolini, F., & Pugliese, R. (2022). Assessing SMEs ’ Cybersecurity Organizational Readiness: Findings From an Italian Survey. Journal of Applied Knowledge Management, 10(September), 1–22. https://doi.org/10.36965/OJAKM.2022.10(2)1-22
- Nurwanah. (2024). Advances in Applied Accounting Research Cybersecurity in Accounting Information Systems: Challenges and Solutions. Advance in Apllied Accounting Reserach, 2(3), 157–168. https://doi.org/10.60079/aaar.v2i3.336%20Advances
- Ridder. (2017). The Theory Contribution of case Study Research Designs. Business Research, 10(2), 281–305. https://doi.org/10.1007/s40685-017-0045-z
- Roup, A., & Effendy, M. (2025). Risk Analysis of Accounting Information System Security Based on Vulnerability Data From OPENVAS, OWASP ZAP, And NMAP Tools: A Cybersecurity Perspective. Jurnal Ilmiah Akuntansi Kesatuan, 13(3), 433–438. https://doi.org/10.37641/jiakes.v13i3.3590
- Rusu, D., & Mantulescu, M. (2025). Development of an Application-Based Framework for Information Security Management in SMEs. Sustainability, 17(8314), 1–22. https://doi.org/10.3390/su17188314
- Schilirò. (2024). Digital Transformation and its Impact on Organizations. International Journal of Business and Management, 19(6), 71–81. https://doi.org/10.5539/ijbm.v19n6p71
- Shimizu, N., & Hashimoto, M. (2025). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. Cryptography and Security, 1–16. https://doi.org/10.48550/arXiv.2506.01220
- Thomann, & Maggetti, M. (2020). With Qualitative Comparative Analysis ( QCA ): Approaches , Challenges, and Tools. Sociological Method & Reserach, 49(2). https://doi.org/10.1177/0049124117729700
- Waweru, E., Karume, S. M., & Kibet, A. (2025). A Review of Human Vulnerabilities in Cyber Security: Challenges and Solutions for Microfinance Institutions. Journal of Information Security, 16(1), 114–130. https://doi.org/10.4236/jis.2025.161006
- Wijayanti, A. (2018). Factors Contributing Online Family Business To Enhance The Sustainability of Family Business. The Turkish Online Journal of Design, Art and Communication, (September), 3114–3120.
- Yin, R. K. (2007). Case study research: Design and methods (3. ed., [Nachdr.]). Sage.
- Yin, R. K. (2011). How to Know Whether and When to Use The Case Study as A Reserach Method.
- Zlati, M. L., Ionescu, R. V., & Antohi, V. M. (2022). Modelling the Vulnerability of Financial Accounting Systems during Global Challenges: A Comparative Analysis. Mathematics, 10(1462), 1–21. https://doi.org/10.3390/math10091462.
References
Adejumo, A. P., & Ogburie, C. P. (2025). Strengthening Finance with Cybersecurity: Ensuring Safer Digital Transactions. World Journal of Advance Reserach and Review, 25(March), 1527–1541. https://doi.org/10.30574/wjarr.2025.25.3.0908
Bennouk, K., & Aali. (2024). A Comprehensive Review and Assessment of Cybersecurity Vulnerability Detection Methodologies. Journal of Cybersecuryty and Privacy, 853–908. https://doi.org/10.3390/jcp4040040
Bouncken, R. B., Czakon, W., & Schmitt, F. (2025). Purposeful Sampling and Saturation in Qualitative Research. Review of Managerial Science, 1–64. https://doi.org/10.1007/s11846-025-00881-2
Chotia, V., Khoualdi, K., Broccardo, L., & Zafar, M. (2025). Technology in Society The Role of Cyber Security and Digital Transformation in Gaining Competitive Advantage Through Strategic Management Accounting. Technology in Society, 81(February), 102851. https://doi.org/10.1016/j.techsoc.2025.102851
Eisenhardt, K. M., & Bourgeois, L. J. (1988). Politics of Strategic Decision Making in High-Velocity Environments: Toward a Midrange Theory. Academy of Management Journal, 31(4), 737–770. https://doi.org/10.5465/256337
Eisenhardt, K. M., Graebner, M. E., Eisenhardt, K. M., & Graebner, M. E. (2007). Theory Building from Cases: Opportunities and Challenges. The Academyof Management Journal, 50(1), 25–32.
https://psycnet.apa.org/doi/10.5465/AMJ.2007.24160888
Giudiece. (2024). Methodologies and tools for a vulnerability management process with an integrated risk evaluation framework Author: Fortunato Gabriele Lo Giudice.
Hollweck, T. (2016). Case Study Research Design and Methods. The Canadian Journal of Program Evaluation, 30(2016), 1–5. https://doi.org/10.3138/cjpe.30.1.108
Isa, M., Praswati, A. N., & Zulaekah, S. (2024). Vulnerability Analysis: A Tool for SMEs ’ Business Resilience. Journal of Integrated Disaster Risk Management, 14, 157–175. https://doi.org/10.5595/001c.125616
Jiang, W., Almaayah, M., & Shehab, R. (2025). Natural Language Processing-Driven Communication for Improved Citizen Alignment in Smart Cities. 21–28.
https://doi.org/10.70470/ESTIDAMAA/2025/003
Jiang, Y., Nay, Meng, Q., Lim, H. W., & Sikdar, B. (2025). A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges. Cryptography and Security, 1(1), 1–32. https://doi.org/10.48550/arXiv.2502.11070
Mazzano. (2025). CyberESP An Integrated Cybersecurity Framework for SMEs. Journal of Software: Evolution and Process, 37, 1–23. https://doi.org/10.1002/smr.70050
Morshed, A. (2025). Cybersecurity in Digital Accounting Systems: Challenges and Solutions in the Arab Gulf Region. Journal of Risk and Financial Management, 18(41), 1–24. https://doi.org/10.3390/jrfm18010041
Neri, M., Niccolini, F., & Pugliese, R. (2022). Assessing SMEs ’ Cybersecurity Organizational Readiness: Findings From an Italian Survey. Journal of Applied Knowledge Management, 10(September), 1–22. https://doi.org/10.36965/OJAKM.2022.10(2)1-22
Nurwanah. (2024). Advances in Applied Accounting Research Cybersecurity in Accounting Information Systems: Challenges and Solutions. Advance in Apllied Accounting Reserach, 2(3), 157–168. https://doi.org/10.60079/aaar.v2i3.336%20Advances
Ridder. (2017). The Theory Contribution of case Study Research Designs. Business Research, 10(2), 281–305. https://doi.org/10.1007/s40685-017-0045-z
Roup, A., & Effendy, M. (2025). Risk Analysis of Accounting Information System Security Based on Vulnerability Data From OPENVAS, OWASP ZAP, And NMAP Tools: A Cybersecurity Perspective. Jurnal Ilmiah Akuntansi Kesatuan, 13(3), 433–438. https://doi.org/10.37641/jiakes.v13i3.3590
Rusu, D., & Mantulescu, M. (2025). Development of an Application-Based Framework for Information Security Management in SMEs. Sustainability, 17(8314), 1–22. https://doi.org/10.3390/su17188314
Schilirò. (2024). Digital Transformation and its Impact on Organizations. International Journal of Business and Management, 19(6), 71–81. https://doi.org/10.5539/ijbm.v19n6p71
Shimizu, N., & Hashimoto, M. (2025). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. Cryptography and Security, 1–16. https://doi.org/10.48550/arXiv.2506.01220
Thomann, & Maggetti, M. (2020). With Qualitative Comparative Analysis ( QCA ): Approaches , Challenges, and Tools. Sociological Method & Reserach, 49(2). https://doi.org/10.1177/0049124117729700
Waweru, E., Karume, S. M., & Kibet, A. (2025). A Review of Human Vulnerabilities in Cyber Security: Challenges and Solutions for Microfinance Institutions. Journal of Information Security, 16(1), 114–130. https://doi.org/10.4236/jis.2025.161006
Wijayanti, A. (2018). Factors Contributing Online Family Business To Enhance The Sustainability of Family Business. The Turkish Online Journal of Design, Art and Communication, (September), 3114–3120.
Yin, R. K. (2007). Case study research: Design and methods (3. ed., [Nachdr.]). Sage.
Yin, R. K. (2011). How to Know Whether and When to Use The Case Study as A Reserach Method.
Zlati, M. L., Ionescu, R. V., & Antohi, V. M. (2022). Modelling the Vulnerability of Financial Accounting Systems during Global Challenges: A Comparative Analysis. Mathematics, 10(1462), 1–21. https://doi.org/10.3390/math10091462.