Security in small and medium-sized enterprises (SMEs) is now largely approached through the lens of cybersecurity, which is frequently assimilated to information security as a whole. However, cyber threats have not replaced traditional threats affecting people, physical infrastructures, or information itself. Rather, they have been added to an already complex security environment. Despite this reality, the different domains of security, notably cybersecurity, physical security, and personnel security screening, continue to be managed independently within organizations. This siloed approach promotes the implementation of fragmented, reactive, and sometimes inconsistent security measures in their overall deployment.
Existing standards and methodologies are generally specialized in a specific security domain and often remain complex or difficult to apply in the context of SMEs. Furthermore, there are few tools capable of holistically evaluating whether implemented security mechanisms are globally balanced and coherent, both in terms of security domains and with respect to the families and operational functions of security controls.
This research aims to develop a multidimensional analytical framework designed to assess the overall security posture of SMEs through an integrated and accessible approach. Unlike traditional approaches primarily focused on risk analysis or regulatory compliance, the proposed method seeks to identify organizational imbalances between different security functions and components. The framework developed is based on a matrix structured around four security functions, namely prevent, detect, delay, and respond, as well as three intervention axes: technologies, equipment and services, procedures, and the human factor.
This research adopts a qualitative and applied methodology based on a literature review, interviews conducted with eight recognized security experts in Quebec, field validations carried out in different organizational contexts, and a survey conducted among security professionals. An exploratory complementary analysis using Multiple Correspondence Analysis (MCA) and Hierarchical Ascending Classification (HAC) was also performed to explore certain perception structures observed among respondents.
The results highlight several recurring imbalances in current organizational security practices. The analyses notably suggest a strong dominance of technological approaches, weak integration between different security domains, and underutilization of human and procedural dimensions. The validations conducted also tend to demonstrate that the proposed visual representation facilitates the rapid identification of organizational strengths, weaknesses, and asymmetries while supporting strategic discussions among stakeholders.
This research therefore contributes to the development of a structured, accessible, and multidimensional analytical tool intended to support SMEs in progressively improving their overall security posture through an integrated approach adapted to their operational realities and organizational constraints.
| Date | 24 Jul 2026 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Michel Rioux (Supervisor) |
|---|
Coats, F. (Author),
Rioux (Supervisor),
24 Jul 2026Student thesis: Master's thesis › Master in Engineering: Engineering