Theoretical framework for three-level information security budgeting in small and medium-sized enterprises
This paper develops a theoretical three-level information security budgeting framework for small and medium-sized enterprises, integrating: a previously validated 16-factor threat taxonomy based on the Toxicity Index TDI and the Fisher — Jenks method; a threedimensional threat space with axes «toxicity x budget load x attack frequency'; cluster-dependent convolution functions — Expected Annual Loss (EAL) for mass threats (Opportunist), Conditional Value-at-Risk (CVaR) for catastrophic threats (Apex Predator), and the budgetary anticipation function B_AI for the emerging class of AI-threats. The vertical compatibility theorem is proven: level I results are a special case of level III functions under degenerate parameters. The Delphi method is applied exclusively for AHP weight calibration. Empirical validation is based on 94 small and mediumsized enterprises of the Southern Federal District, 347 incidents, 2022−2025.


