Title: Artificial intelligence method for extracting knowledge from security experts to assess SMEs' information systems

Authors: Ines Saad; Wafa Bouaynaya

Addresses: MIS Laboratory, Amiens Business School and University of Picardie Jules Verne, Amiens, France ' Excelia Business School, La Rochelle, France

Abstract: This research investigates the possibility of utilising the implicit and explicit knowledge of cybersecurity professionals in order to help small and medium-sized businesses (SMEs) in assessing the level of security that their information and knowledge systems possess. A dominance-based rough set approach serves as the foundation for the proposed strategy, which consists of two primary stages. In order to generate three ordered decision classes, the first phase requires the construction of a set of criteria and preference models, which are guided by seasoned security specialists. Validation of this preference model is performed with the help of test data during the second step. Forty-three small and medium-sized enterprises (SMEs) and 15 cybersecurity specialists participated in the testing of the method. By taking this method, firm managers are able to better anticipate cybersecurity risks, provide a comprehensive review of information system security, and reduce the likelihood of cyberattacks.

Keywords: knowledge of security experts; knowledge classification; multicriteria classification; security of information systems; decision rules; service continuity plan; traceability; encryption; interoperability; availability; authentication; access authorisation.

DOI: 10.1504/IJKMS.2026.152469

International Journal of Knowledge Management Studies, 2026 Vol.17 No.1, pp.1 - 19

Received: 07 Jul 2024
Accepted: 11 Dec 2024

Published online: 23 Mar 2026 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article