Main Article Content

Abstract

Purpose – This study aims to develop a vulnerability management model to enhance security capability in small and medium-sized enterprises (SMEs), particularly in safeguarding accounting data under resource constraints
Design/Methodology/Approach – This study employs a qualitative multi-case research design involving six SMEs in Surakarta, Indonesia. Data were collected through in-depth interviews, direct observations, and document analysis. Using inductive comparative logic and cross-case thematic analysis, the study identifies recurring governance patterns and develops a context-sensitive vulnerability management model grounded in empirical evidence across varying levels of resource constraints.
Findings – The findings reveal that vulnerability management effectiveness in SMEs is shaped by the integration of governance structures, managerial coordination, and organizational learning rather than by technological capability alone. The study identifies three distinct governance configurations across SMEs under varying levels of resource constraints: reactive centralization, vendor-dependent compliance, and institutionalized adaptive governance. The proposed model consists of four interconnected components: identification and detection, evaluation and prioritization, managerial decision integration, and HR awareness and continuous learning. These components operate through a continuous feedback mechanism that strengthens adaptive security governance and organizational resilience.
Research Limitations and Implications – This study is limited to six SME cases in Surakarta, Indonesia, which may restrict broader generalizability across industries and regions. Future research may apply quantitative or mixed-method approaches to validate and extend the proposed model across different organizational and institutional contexts.
Practical implications – The study provides a practical and cost-efficient framework for SMEs to strengthen accounting data security through structured vulnerability management, risk-based prioritization, internal governance coordination, and continuous security awareness practices.
Originality/Value – This study positions vulnerability management as a governance-oriented and learning-based organizational capability shaped by resource conditions, managerial integration, and adaptive organizational practices. The proposed model offers a context-sensitive approach for strengthening sustainable accounting data security governance in SMEs.

Keywords

Vulnerability Management Accounting Information Security SME Governance Resource Constraints Cybersecurity Capability

Article Details

Author Biographies

Massila Kamalrudin, Universiti Teknikal Malaysia Melaka (UTeM), Melaka, Malaysia

Professor Datuk Ts. Dr. Massila Kamalrudin is a distinguished academic leader and software engineering scholar at Universiti Teknikal Malaysia Melaka (UTeM), Malaysia. She holds the ORCID ID 0000-0003-4804-2042, which attests to her international research identity and publication record.

Since joining UTeM in April 2004, she has held the rank of Professor of Software Engineering, and in March 2022 she was appointed the fifth Vice-Chancellor of the university. Her career spans over two decades of academic and administrative leadership, including roles such as Deputy Dean, research coordinator, and Centre of Advanced Computing Technology manager, underscoring her broad experience in both teaching and institutional strategy.

Professor Kamalrudin’s research expertise lies primarily in software engineering—particularly in requirements engineering, software security readiness, global software development, and human-centric design of socio-technical systems. Her publications demonstrate rigorous methodological work and contribute significantly to both theory and practice. As a leader of a technical university, she is noted for her visionary and transformational approach emphasizing industry-university collaboration, postgraduate curriculum innovation, and aligning institutional strategies with Malaysia’s national aspirations in Industry 4.0 and sustainable development.  She is committed to mentoring the next generation of scholars and practitioners and continues to engage actively in research, governance, and educational reform. Her holistic approach combines academic excellence, strategic insight, and a passion for advancing applied technology education.

 

Kartika Hendra Titisari, Universitas Islam Batik Surakarta, Surakarta, Indonesia

Kartika Hendra Titisari, SE, M.Si, Akt, CA, CSRS, CSRA, is a senior lecturer and researcher at the Faculty of Economics, Universitas Islam Batik Surakarta (UNIBA), Indonesia. She is an active member of the Indonesian Institute of Accountants (IAI) and holds professional certifications in sustainability reporting and corporate responsibility (CSRS, CSRA). Her research interests lie in corporate governance, financial management, entrepreneurship, and sustainable business transformation.

Over the years, she has published and co-authored several academic papers focusing on the relationship between financial structure, corporate performance, and the implementation of sustainable and ethical business models among small and medium enterprises (SMEs) in Indonesia. Her work emphasizes the strategic integration of financial reporting, governance practices, and organizational sustainability in emerging market contexts.

Through her teaching, research, and community engagement, she actively contributes to strengthening financial literacy, corporate accountability, and entrepreneurial resilience in local business communities. Kartika is also committed to advancing the academic development of young scholars in accounting and management education, in alignment with UNIBA’s mission to promote research-based, ethical, and globally competitive education.

Werner R Murhadi, Universitas Surabaya, Surabaya, Indonesia

Dr. Werner R. Murhadi, SE, M.M., CSA, is a lecturer and researcher specializing in Financial Management, Strategic Leadership, and Business Transformation. He is affiliated with higher education institutions in Indonesia and is recognized for his research contributions in corporate governance, strategic decision-making, and organizational resilience.

His academic work primarily examines how financial structures, leadership strategies, and governance mechanisms influence business performance and sustainability, particularly in emerging markets. Through both quantitative and qualitative approaches, he has explored issues related to capital structure optimization, managerial decision effectiveness, and strategic adaptability in small and medium-sized enterprises (SMEs) and service-based industries.

Werner’s research emphasizes bridging theoretical insights and managerial practices, contributing to a deeper understanding of how strategic management and financial governance can support long-term competitiveness and value creation. Beyond research, he is actively engaged in academic mentoring and curriculum development, promoting innovation in management education and encouraging young scholars to integrate ethics, data-driven decision-making, and sustainability principles into business leadership.

His scholarly work aligns with Indonesia’s vision to strengthen entrepreneurial capacity, digital transformation, and transparency in governance in the business sector, reflecting a commitment to impactful and responsible research.

How to Cite
Wijayanti, A., Kamalrudin, M., Titisari, K. H., & Murhadi, W. R. (2026). A vulnerability management model for enhancing security governance capability in SMEs. Jurnal Siasat Bisnis, 30(2), 156–171. https://doi.org/10.20885/jsb.vol30.iss2.art2

References

  1. Adejumo, A. P., & Ogburie, C. P. (2025). Strengthening Finance with Cybersecurity: Ensuring Safer Digital Transactions. World Journal of Advance Reserach and Review, 25(March), 1527–1541. https://doi.org/10.30574/wjarr.2025.25.3.0908
  2. Bennouk, K., & Aali. (2024). A Comprehensive Review and Assessment of Cybersecurity Vulnerability Detection Methodologies. Journal of Cybersecuryty and Privacy, 853–908. https://doi.org/10.3390/jcp4040040
  3. Bouncken, R. B., Czakon, W., & Schmitt, F. (2025). Purposeful Sampling and Saturation in Qualitative Research. Review of Managerial Science, 1–64. https://doi.org/10.1007/s11846-025-00881-2
  4. Chotia, V., Khoualdi, K., Broccardo, L., & Zafar, M. (2025). Technology in Society The Role of Cyber Security and Digital Transformation in Gaining Competitive Advantage Through Strategic Management Accounting. Technology in Society, 81(February), 102851. https://doi.org/10.1016/j.techsoc.2025.102851
  5. Eisenhardt, K. M., & Bourgeois, L. J. (1988). Politics of Strategic Decision Making in High-Velocity Environments: Toward a Midrange Theory. Academy of Management Journal, 31(4), 737–770. https://doi.org/10.5465/256337
  6. Eisenhardt, K. M., Graebner, M. E., Eisenhardt, K. M., & Graebner, M. E. (2007). Theory Building from Cases: Opportunities and Challenges. The Academyof Management Journal, 50(1), 25–32.
  7. https://psycnet.apa.org/doi/10.5465/AMJ.2007.24160888
  8. Giudiece. (2024). Methodologies and tools for a vulnerability management process with an integrated risk evaluation framework Author: Fortunato Gabriele Lo Giudice.
  9. Hollweck, T. (2016). Case Study Research Design and Methods. The Canadian Journal of Program Evaluation, 30(2016), 1–5. https://doi.org/10.3138/cjpe.30.1.108
  10. Isa, M., Praswati, A. N., & Zulaekah, S. (2024). Vulnerability Analysis: A Tool for SMEs ’ Business Resilience. Journal of Integrated Disaster Risk Management, 14, 157–175. https://doi.org/10.5595/001c.125616
  11. Jiang, W., Almaayah, M., & Shehab, R. (2025). Natural Language Processing-Driven Communication for Improved Citizen Alignment in Smart Cities. 21–28.
  12. https://doi.org/10.70470/ESTIDAMAA/2025/003
  13. Jiang, Y., Nay, Meng, Q., Lim, H. W., & Sikdar, B. (2025). A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges. Cryptography and Security, 1(1), 1–32. https://doi.org/10.48550/arXiv.2502.11070
  14. Mazzano. (2025). CyberESP An Integrated Cybersecurity Framework for SMEs. Journal of Software: Evolution and Process, 37, 1–23. https://doi.org/10.1002/smr.70050
  15. Morshed, A. (2025). Cybersecurity in Digital Accounting Systems: Challenges and Solutions in the Arab Gulf Region. Journal of Risk and Financial Management, 18(41), 1–24. https://doi.org/10.3390/jrfm18010041
  16. Neri, M., Niccolini, F., & Pugliese, R. (2022). Assessing SMEs ’ Cybersecurity Organizational Readiness: Findings From an Italian Survey. Journal of Applied Knowledge Management, 10(September), 1–22. https://doi.org/10.36965/OJAKM.2022.10(2)1-22
  17. Nurwanah. (2024). Advances in Applied Accounting Research Cybersecurity in Accounting Information Systems: Challenges and Solutions. Advance in Apllied Accounting Reserach, 2(3), 157–168. https://doi.org/10.60079/aaar.v2i3.336%20Advances
  18. Ridder. (2017). The Theory Contribution of case Study Research Designs. Business Research, 10(2), 281–305. https://doi.org/10.1007/s40685-017-0045-z
  19. Roup, A., & Effendy, M. (2025). Risk Analysis of Accounting Information System Security Based on Vulnerability Data From OPENVAS, OWASP ZAP, And NMAP Tools: A Cybersecurity Perspective. Jurnal Ilmiah Akuntansi Kesatuan, 13(3), 433–438. https://doi.org/10.37641/jiakes.v13i3.3590
  20. Rusu, D., & Mantulescu, M. (2025). Development of an Application-Based Framework for Information Security Management in SMEs. Sustainability, 17(8314), 1–22. https://doi.org/10.3390/su17188314
  21. Schilirò. (2024). Digital Transformation and its Impact on Organizations. International Journal of Business and Management, 19(6), 71–81. https://doi.org/10.5539/ijbm.v19n6p71
  22. Shimizu, N., & Hashimoto, M. (2025). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. Cryptography and Security, 1–16. https://doi.org/10.48550/arXiv.2506.01220
  23. Thomann, & Maggetti, M. (2020). With Qualitative Comparative Analysis ( QCA ): Approaches , Challenges, and Tools. Sociological Method & Reserach, 49(2). https://doi.org/10.1177/0049124117729700
  24. Waweru, E., Karume, S. M., & Kibet, A. (2025). A Review of Human Vulnerabilities in Cyber Security: Challenges and Solutions for Microfinance Institutions. Journal of Information Security, 16(1), 114–130. https://doi.org/10.4236/jis.2025.161006
  25. Wijayanti, A. (2018). Factors Contributing Online Family Business To Enhance The Sustainability of Family Business. The Turkish Online Journal of Design, Art and Communication, (September), 3114–3120.
  26. Yin, R. K. (2007). Case study research: Design and methods (3. ed., [Nachdr.]). Sage.
  27. Yin, R. K. (2011). How to Know Whether and When to Use The Case Study as A Reserach Method.
  28. Zlati, M. L., Ionescu, R. V., & Antohi, V. M. (2022). Modelling the Vulnerability of Financial Accounting Systems during Global Challenges: A Comparative Analysis. Mathematics, 10(1462), 1–21. https://doi.org/10.3390/math10091462.