Doctoral defence: Mari Seeba "A Multi-Stakeholder Framework for Comparable and Repeatable Security Level Evaluation in Organizations“

Mari Seeba
  • 04 Sep 2026
  • 10:15–13:15
  • Delta Study Building (Narva mnt 18–1018), and online
  • UT Institute of Computer Science
Doctoral defence

On 4 September at 10:15, Mari Seeba will defend her doctoral thesis "A Multi-Stakeholder Framework for Comparable and Repeatable Security Level Evaluation in Organizations“ to obtain the degree of Doctor of Philosophy (in Computer Science).

Supervisor:
Prof. Raimundas Matulevičius, University of Tartu

Opponents:
Prof. Audun Jøsang, University of Oslo (Norway)
Assoc. Prof. Simon Hacks, Stockholm University (Sweden)

Summary
In today’s digital society, everything is interconnected. A security incident at a single service provider can cascade and disrupt society and the economy. To prevent such crises, the European Union introduced the NIS2 Directive, requiring a high common level of cybersecurity across all member states.

Thousands of service providers with varying levels of digital maturity must now implement the risk management measures required by the NIS2 Directive. Simultaneously, state authorities, supervisors, policy-makers, suppliers, and consultants all need an up-to-date overview of the security situation to perform their duties. This has created a situation where security data is collected from organizations multiple times by different stakeholders. This repetitive data collection increases the administrative burden on both service providers, their partners, and state agencies.

The doctoral thesis provides a solution by developing the Framework for Security Level Evaluation (F4SLE). Beyond evaluating an organization’s security level, F4SLE enables sector-based comparison and addresses the diverse needs of NIS2 stakeholders. Its low entry barrier, compliance with standards, and hierarchical structure make self-assessment accessible even for organizations with low digital maturity, while ensuring compliance with privacy requirements. Furthermore, to ensure results remain comparable as threats and standards evolve, the thesis introduces MUSE, a method for updating evaluation instruments without losing the ability to compare new results with previous versions.

The usability of F4SLE was validated by nearly 300 service providers from the EU and Central America. Additionally, the framework’s ability to satisfy NIS2-based user stories for various stakeholders was tested, proving the principle of “collect data once, use it many times.

  • 04 Sep 2026
  • 10:15–13:15
  • Delta Study Building (Narva mnt 18–1018), and online
  • UT Institute of Computer Science
Doctoral defence