Project history
The project with the strong contribution of Poste was developed in Unindustria from the work carried out and promoted by the Information Technology Section and was part of the activities of Unindustria’s Cyber Security Technical Group, in collaboration with the Cyber 4.0 Competence Center and with the sponsorship and collaboration of ACN.
Cyber Security Readiness is a project that involves different entities with the common intent of providing the useful tools for all types of organizations, with particular reference to SMEs, to better deal with cyber threats.
Expanding the goals
We want to reach out to SMEs, entities, PAC/PALs, and all stakeholders to assess their level of cybersecurity, identify any gaps, and consequently increase awareness and ability to protect corporate assets.
A structured method
Administration of questionnaires
Analysis of results with AHP methodology
Identification of solutions
Training workshops and seminars
Methods of questionnaire analysis
What methodology?
Questionnaire analysis is carried out through a procedure based on the Analytic Hierarchy Process (AHP) and the adoption of pairwise comparison matrices.
AHP, the approach, defined by Thomas L. Saaty in the late 1970s, represents one of the most widely used methodologies in multicriteria analysis or in general decision-making processes in which a procedure is required to evaluate data on the basis of subjective judgments made by multiple evaluators and according to multiple criteria.
Why AHP in this context?
The four proposed questionnaires, "Remote Working," "Ransomware," "Third Parties," and "Cyber Security," represent four complementary areas to be analyzed for a process to assess the degree of corporate Cybersecurity Readiness.
Each questionnaire also collects questions belonging to different domains: "Governance & Asset," "Security Infrastructure," "Data Protection, Backup and DR" , "Awareness and Communications," and "Security Update and Monitoring."
Each questionnaire and each domain can be viewed as different evaluation criteria necessary for the definition of an overall Cybersecurity Readiness index. Experts in the field of cybersecurity will be interviewed in order to assess how high a score for a particular questionnaire/domain is more relevant than a high score obtained on every other questionnaire/domain.
Such an interview, based on the compilation of a pairwise comparison matrix, will make it possible to generate weights that, combined with the results of the questionnaires, will characterize the overall assessment of the sample that will undergo the test.
What benefits does the chosen evaluation process introduce?
The evaluation process allows intrinsic control over the consistency or coherence of the experts involved.
The use of pairwise comparison matrices makes it possible to analyze relative judgments and not absolute evaluations about the relevance of one questionnaire/domain to the others. In this way, it is possible to assess the degree of consistency of the interviewed expert in order to weigh his or her judgment based on the inconsistency shown during the interview.
How to participate
Fast
Participating in the project takes just a few minutes to fill out one or more questionnaires, also called Surveys, designed as a self-assessment of your company’s level of cybersecurity.
Easy
The surveys consist of general questions about the company’s organization followed by technical/organizational questions or aimed at investigating the level of exposure to a specific cyber risk.
Anonymous
The surveys consist of general questions about the company’s organization followed by technical/organizational questions or aimed at investigating the level of exposure to a specific cyber risk.