Strategic Selection of SOC Architectures in Financial SMEs: Applying CRITIC and WASPAS to Support Cybersecurity Decisions
Erik Etsushi Miyashita, Luis Hernan Contreras Pinochet · Procedia Computer Science · 2025
Small and medium-sized enterprises (SMEs) in the financial sector face increasing cybersecurity challenges due to accelerated digitalization combined with limited technical and financial resources. This study proposes a structured multi-criteria decision-making model to support the selection of the most appropriate Security Operations Center (SOC) architecture for financial SMEs. The approach integrates the CRITIC method to objectively determine the weights of decision criteria and the WASPAS method to rank alternatives using a hybrid compensatory evaluation. Seven SOC operational models were evaluated based on seven technical, organizational, and compliance-related criteria, supported by a survey of experienced professionals working in SOC implementation for Brazilian financial SMEs. The results indicate a clear preference for hybrid SOC models that combine outsourced first-level response with internal second-level management, offering an optimal balance between operational control, technical capability, and cost efficiency. The criteria of Cost, Professional Qualifications, and Company Experience emerged as the most influential factors in the decision-making process. This study contributes both methodologically and practically by demonstrating the application of CRITIC and WASPAS in cybersecurity decision-making and by providing SMEs with a replicable, objective, and efficient tool to support SOC model selection. The outcomes are aligned with Sustainable Development Goal (SDG) 8.3 by fostering digital resilience and operational sustainability for SMEs.