<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">11</article-id>
      <title-group>
        <article-title>Theoretical framework for three-level information security budgeting in small and medium-sized enterprises</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Теоретическое обоснование трехуровневого каркаса бюджетирования информационной безопасности для организаций малого и среднего бизнеса</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-9911-1584</contrib-id>
          <name>
            <surname>Mandritsa</surname>
            <given-names>Igor</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>d_artman@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-4293-7013</contrib-id>
          <name>
            <surname>Petrenko</surname>
            <given-names>Vyacheslav</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>vipetrenko@ncfu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-0364-1239</contrib-id>
          <name>
            <surname>Mandritsa</surname>
            <given-names>Olga</given-names>
          </name>
          <xref ref-type="aff" rid="aff3"/>
          <email>man_olga@mail.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">North-Caucasus Federal University; MIREA – Russian Technological University (Stavropol branch)</aff>
      <aff id="aff2">North-Caucasus Federal University</aff>
      <aff id="aff3">MIREA – Russian Technological University (Stavropol branch)</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-10-09">
        <day>09</day>
        <month>10</month>
        <year>2026</year>
      </pub-date>
      <issue>3</issue>
      <fpage>145</fpage>
      <lpage>161</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/images/oblozhki/3_2026.png"/>
      <abstract xml:lang="en">
        <p>This paper develops a theoretical three-level information security budgeting framework for small and medium-sized enterprises, integrating: a previously validated 16-factor threat taxonomy based on the Toxicity Index TDI and the Fisher – Jenks method; a threedimensional threat space with axes ‘toxicity × budget load × attack frequency’; cluster-dependent convolution functions – Expected Annual Loss (EAL) for mass threats (Opportunist), Conditional Value-at-Risk (CVaR) for catastrophic threats (Apex Predator), and the budgetary anticipation function B_AI for the emerging class of AI-threats. The vertical compatibility theorem is proven: level I results are a special case of level III functions under degenerate parameters. The Delphi method is applied exclusively for AHP weight calibration. Empirical validation is based on 94 small and mediumsized enterprises of the Southern Federal District, 347 incidents, 2022–2025.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Information security budgeting</kwd>
        <kwd>clustering of cyber threats</kwd>
        <kwd>expected annual losses</kwd>
        <kwd>notional value at risk</kwd>
        <kwd>theory of extreme values</kwd>
        <kwd>small and medium-sized businesses</kwd>
        <kwd>analytical hierarchy method</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
