1 of 19

Creating business value

in unpredictable times

Moving towards antifragility

through organizational learning by application

of a cyber resilience maturity model

Edzo A. Botjes�Doctoral Consortium �2026-06-07 @ Bled Econference

2 of 19

Problem Knowledge

Business Continuity is at risk.

2026-06-07 @ DC eBled slide 2

People

Corona, People Walkout, Silent Quitting, People feeling isolated, …

Environmental

Extreme weather, shortage of fuels, power and resources, …

Controdictionairy Legislation

European law (Data Act, GDPR, CRA, NIS2), US Cloud Act, FISA Sec 702, Chinese law, ...

Supply chain

Hormuz, Green Horizon, Colonial Pipeline, Solarwinds, Axios, Aqua, …

Data breaches

Odido, Clinical Diagnostics, Dutch chain of Justice (OM, JDI, etc), …

https://www.ransomware.live/map/nlhttps://scatteredsecrets.com/#dataleaks https://haveibeenpwned.com/PwnedWebsites

Data access

Microsoft tokens CN, Entra-id failure, Data Bricks tokens, SecureSend, …

Zero-days vulnerabilities

Used by governmental, commercial and/or criminal organisations identified by for example Claude Mythos, and NSO.

https://www.cve.orghttps://euvd.enisa.europa.eu

Complexity Science and Critical Realism

3 of 19

Problem Knowledge

Business Continuity is at risk.

2026-06-07 @ DC eBled slide 3

The Challenge

The Problem

Law of Requisite Variety

Navigating this context requires integrating these core constructs.

Complexity Science

Critical Realism

The organizational reality is characterized by VUCA.

Adaptive Cycle

Adaptive Cycle�Dynamic Capabilities, �Ambidexterity,

Exploiting Opportunities, �Opportunity Management

VUCA�Volatile�Uncertain, �Complex and �Ambigu

4 of 19

Solution Knowledge

Achieving Cyber Resilience 1/2

2026-06-07 @ DC eBled slide 4

The Challenge

The Ambition

The Solution

The Application

The Problem

Law of Requisite Variety

Sensemaking

Antifragile

Learning Organization

Navigating this context requires integrating these core constructs.

Viability in this context necessitates antifragile behavior.

Maintaining relevance

requires tools to structure �and govern the organization.

Successful design, implementation and realisation, depend on:

Complexity Science

Critical Realism

The organizational reality is characterized by VUCA.

Resilience

Maturity Models

by applying a specific tool

Adaptive Cycle

Cyber Security

Risk Management

Cyber Resilience

Combining

Adaptive Cycle�Dynamic Capabilities, �Ambidexterity,

Exploiting Opportunities, �Opportunity Management

Cyber Security �Security, Socio-Technical Systems, Cyber-Physical Systems, �Cyber Security Management, Operational Security,Information Security, Application Security, Data Security,

Cloud Security, Endpoint Security, Network Security, �Physical Security, Infrastructure Security,

Risk Management�Business Continuity Management,

Enterprise Continuity Management,

Enterprise Risk Management,

Enterprise Design, Enterprise Governance,�Enterprise Architecture, Cyber Risk Management,

VUCA�Volatile�Uncertain, �Complex and �Ambigu

5 of 19

problem Knowledge

Achieving Cyber Resilience 2/2

2026-06-07 @ DC eBled slide 5

Central Research Question:

  • How can organizations exploit a chaotic context to generate more business value?

We formulated the following research questions:

  • RQ1: What is a Cyber Resilience Maturity Model (CRMM) that adequately addresses the exploitation of unforeseen events?
  • RQ2: How does the (extended) Cyber Resilience Maturity Model (CRMM) offer guidance and value when applied by organizations?
  • RQ3: What are the key lessons learned from the application of the Cyber Resilience Maturity Model (CRMM) and how can these lessons be incorporated into a refined version of the CRMM?

6 of 19

Solution Knowledge

Methodology - eADR & eDSR

2026-06-07 @ DC eBled slide 6

  1. Mullarkey, Matthew T., and Alan R. Hevner. 2019. “An Elaborated Action Design Research Process Model” edited by P. Ågerfalk. European Journal of Information Systems 28(1):6–20. doi:10.1080/0960085X.2018.1451811.
  2. Tuunanen, Tuure, Robert Winter, and Jan Vom Brocke. 2024. “Dealing with Complexity in Design Science Research: A Methodology Using Design Echelons.” MIS Quarterly 48(2):427–58. doi:10.25300/MISQ/2023/16700.

In each iteration of each phase

  1. Problem Formulation
  2. Artifact Creation
  3. Evaluation
  4. Reflection
  5. Formalisation of Learning

Evolution

Implementation

Design�Objectives and Requirements

Diagnosis

Design & �Development

Adhering to Open Science by transparency on processes and tools used for:

Search & Discover

- Exploratory Literature Research

- Reference Management

- Open Note-taking

- Video Conferencing

- Computer Operating System

Design Study

- Project Management

- Project Proposal

- Local LaTeX processing

Collect & Analyze Data

Publish Report

  1. DSR supports sense-making and emancipation of the actors.
  2. DSR acknowledges wicked problems.�DSR supports via recursion validation of intermediate steps.
  3. DSR integrates well with Open Science.
  4. We will use Design Theory (Gregor, 2006 et al.) to formulate Design Goals as and Requirements as summary of the diagnose and in support of the design, development and evolution.

7 of 19

Solution Knowledge

Current State

2026-06-07 @ DC eBled slide 7

  1. We have defined 12 design principles based on multiple iterations of the diagnosis phase.
  2. We have selected 16 models 9 most cited: AUMMCS, C2M2, NICE-CMM, NIST CSF, NIST 800-53, NIST 800-37,ISO 27001, ISO 27005, COSO ERMF� 1 specific to the problem domain: MMOR � 6 models advised by experts: EAAL, Progress-CCMM, RMC, SCMM, ISO 28000, ISO 15408

8 of 19

Solution Knowledge

Vision for an improved model

2026-06-07 @ DC eBled slide 8

  • We have defined 12 design principles based on multiple iterations of the diagnosis phase.
  • We have selected 16 models 9 most cited: AUMMCS, C2M2, NICE-CMM, NIST CSF, NIST 800-53, NIST 800-37,ISO 27001, ISO 27005, COSO ERMF� 1 specific to the problem domain: MMOR � 6 models advised by experts: EAAL, Progress-CCMM, RMC, SCMM, ISO 28000, ISO 15408

Vision - The target artifact should address

  1. The recursion and layered resilience of the Adaptive Cycle.�

This includes [1] fragile, [2] stable, [3] resilient, and [4] antifragile.� This will cover NIST CSF and Cyber Defence Matrix and other frameworks.

  • The recursion and control of Viable Systems Model.�

This includes the recognition of doing the things right, doing the right things.� This will cover Learning Organisation, Cyber Security Venn diagram, Requisite Variety � and sense-making.

9 of 19

Solution Knowledge

Future State

2026-06-07 @ DC eBled slide 9

  • We have defined 12 design principles based on multiple iterations of the diagnosis phase.
  • We have selected 16 models 9 most cited: AUMMCS, C2M2, NICE-CMM, NIST CSF, NIST 800-53, NIST 800-37,ISO 27001, ISO 27005, COSO ERMF� 1 specific to the problem domain: MMOR � 6 models advised by experts: EAAL, Progress-CCMM, RMC, SCMM, ISO 28000, ISO 15408

Way Forward - next steps in development of the artifact

    • Extent an Existing model
      1. Why : New models take time to get adopted by a large population and existing models are not perse wrong.
      2. How : Define gap between 12 DP and extend each of the 16 Models with at least one missing DP.
      3. Critique : Little experts on function and construction of the models, until now.
      4. Advantage : Extending existing stories is more impactful than widespread adoption of a new way of thinking.
    • Create a new model
      • Why : Use the 12 DP in the design phase. It tackles a few foundational issues with frameworks and Maturity Models (subjective reality sensemaking).
      • How : Experiment with minimal knowledge in an artifact, enabling iterative personal exploration (grounded theory, emergence etc).
      • Critique : Very challenging with mental models and beliefs within scientific bubble.

10 of 19

Solution Knowledge

Extent an existing model challenge

2026-06-07 @ DC eBled slide 10

  • We have defined 12 design principles based on multiple iterations of the diagnosis phase.
  • We have selected 16 models 9 most cited: AUMMCS, C2M2, NICE-CMM, NIST CSF, NIST 800-53, NIST 800-37,ISO 27001, ISO 27005, COSO ERMF� 1 specific to the problem domain: MMOR � 6 models advised by experts: EAAL, Progress-CCMM, RMC, SCMM, ISO 28000, ISO 15408

Hypothesis based on observations - in my search experts on function and construction

  1. Until now, experts on ISO 27001 mostly do not consider themselves experts on 27005. I find this strange.
  2. Application of frameworks (discourse) appears to be bounded to sector, country and other variables.
  3. I think that it will be difficult to find experts on the most cited frameworks.
  4. I think that it will be only the creators of the other frameworks to function as experts.
  5. I think that practitioners do not know and do not apply multiple frameworks if any (in name only).

11 of 19

Solution Knowledge

Questions

2026-06-07 @ DC eBled slide 11

  • We have defined 12 design principles based on multiple iterations of the diagnosis phase.
  • We have selected 16 models 9 most cited: AUMMCS, C2M2, NICE-CMM, NIST CSF, NIST 800-53, NIST 800-37,ISO 27001, ISO 27005, COSO ERMF� 1 specific to the problem domain: MMOR � 6 models advised by experts: EAAL, Progress-CCMM, RMC, SCMM, ISO 28000, ISO 15408

Questions

    • What to do when I can not find experts for all 16 models?
    • What to do when I can not find enough experts for function/construction and gap analysis as experts and with a focus group?
    • How “out there” can I be for the new model (I am doing some examples).

12 of 19

APPENDIX

slide 12 2026-06-07 �OU Antifragility & Cyber Resilience

13 of 19

Solution Knowledge

Research Design

2026-06-07 @ DC eBled slide 13

What can we know?�ontology

Why does this happen?�aetiology

How do we gain knowledge?epistemology

What is the value?�axiology

How do we find out?�methodology

What is the purpose?�teleology

  1. To achieve Research Quality
    1. Replicable
    2. Independence
    3. Precision
    4. Falsification
  2. We embrace Open Science (OSF & UNESCO)
    • Search & Discover
    • Design Study
    • Collect & Analyze Data
    • Publish Report
    • Open Access, Open Research Infrastructure, Open Source, Open Note Taking etc.
    • FAIR (Findable, Accessible, Interoperable, and Reusable)
  3. In regards to the research design we take into account that Critical Realism (subjective & Objective reality) and Complexity Science demand an iterative approach and restraint in generalisability. Finding a balance between subjective, inter-subjective, objective reality and emancipation of the actors and incremental adjustment of the personal reality of each individual.
  • Hevner, Alan R., Jeffrey Parsons, Alfred Benedikt Brendel, Roman Lukyanenko, Verena Tiefenbeck, Monica Chiarini Tremblay, and Jan Vom Brocke. 2024. “Transparency in Design Science Research.” Decision Support Systems 182:114236. doi:10.1016/j.dss.2024.114236.
  • Floridi, Luciano. 2024. The Keyhole Model: Some Advice on How to Develop a Research Project (Revised Version 6). Research Paper. Centre for Digital Ethics (CEDE). https://ssrn.com/abstract=4730258.
  • Maedche, Alexander, Edona Elshan, Hartmut Höhle, Christiane Lehrer, Jan Recker, Ali Sunyaev, Benjamin Sturm, and Oliver Werth. 2024. “Open Science: Towards Greater Transparency and Openness in Science.” Business & Information Systems Engineering. doi:10.1007/s12599-024-00858-7.
  • Brinkman, Loek, Elly Dijk, Hans De Jonge, Nicole Loorbach, and Daan Rutten. 2023. “Open Science: A Practical Guide for Early-Career Researchers.”
  • UNESCO and Canadian National Commission for UNESCO. 2022. An Introduction to the UNESCO Recommendation on Open Science. UNESCO. doi:10.54677/XOIR1696

Skip Slide

14 of 19

Solution Knowledge

Methodology - Design Science Research

2026-06-07 @ DC eBled slide 14

  1. Vom Brocke, Jan, Robert Winter, Alan Hevner, and Alexander Maedche. 2020. “Special Issue Editorial – Accumulation and Evolution of Design Knowledge �in Design Science Research: A Journey Through Time and Space.” Journal of the Association for Information Systems 21(3):520–44. doi:10.17705/1jais.00611
  2. Tuunanen, Tuure, Robert Winter, and Jan Vom Brocke. 2024. “Dealing with Complexity in Design Science Research: A Methodology Using Design Echelons.” MIS Quarterly 48(2):427–58. doi:10.25300/MISQ/2023/16700.

Skip Slide

15 of 19

Solution Knowledge

Methodology - eDSR

2026-06-07 @ DC eBled slide 15

  • Tuunanen, Tuure, Robert Winter, and Jan Vom Brocke. 2024. “Dealing with Complexity in Design Science Research: A Methodology Using Design Echelons.” MIS Quarterly 48(2):427–58. doi:10.25300/MISQ/2023/16700.

Skip Slide

16 of 19

Solution Knowledge

Methodology - Action Design Research & eADR

2026-06-07 @ DC eBled slide 16

  1. Sein, Maung K., Ola Henfridsson, Sandeep Purao, Matti Rossi, and Rikard Lindgren. 2011. “Action Design Research.” MIS Quarterly 35(1):37–56. doi:10.2307/23043488.
  2. Mullarkey, Matthew T., and Alan R. Hevner. 2019. “An Elaborated Action Design Research Process Model” edited by P. Ågerfalk. European Journal of Information Systems 28(1):6–20. doi:10.1080/0960085X.2018.1451811.

Skip Slide

17 of 19

Solution Knowledge

Appendix - Open Science Framework

2026-06-07 @ DC eBled slide 17

18 of 19

Solution Knowledge

Appendix - Open Science UNESCO

2026-06-07 @ DC eBled slide 18

  • UNESCO and Canadian National Commission for UNESCO. 2022. An Introduction to the UNESCO Recommendation on Open Science. UNESCO. doi:10.54677/XOIR1696.

19 of 19

Solution Knowledge

Appendix - Design Principles

2026-06-07 @ DC eBled slide 19

  • Support the user to envision how to uphold business continuity.
    • prepare their organization to deal with the known, known unknown and the unknown unknown (01 & 02)
  • Support the user in conserving the current situation.
    • Minimize the impact of downside risks (03 & 04)
  • Support the user in improving the current situation.
    • Make use of opportunities (05 & 06)
  • Support the user in improving sensemaking
    • Determine the next steps as individual and as group (07, 08 & 09)
  • Support the user in improving learning
    • Learn as an individual and as a group (10 & 11)
  • Support the user in becoming antifragile
    • Embrace exposure to the unknown unknown as way to gain value (12)