Leverage the COBIT 2019 Design Toolkit in an SME Context: A Multiple Case Study


Organizations today exploit IT to achieve business value and competitive advantages; it is the disruptive effect of digital transformation. However, investing in IT without proper control and governance over enterprise IT (GEIT) can expose organizations to cyber-risks and IT project failures. This problem affects both multinationals and small organizations. In particular, small and medium-sized enterprises (SMEs) struggle to implement IT-governance also due to the complexity of the standard IT-governance frameworks. In this study, five case studies were conducted with five manufacturing companies in Italy whose headquarters are located in the Lombardy region to investigate the potential benefits for IT practitioners of using the COBIT 2019 Design Toolkit, an Excel spreadsheet that facilitates the development of a governance system. The results are encouraging, the IT practitioners appreciated the COBIT 2019 Design Toolkit to map the IT resources and issues, prioritize the most important governance and management objectives, and align business and IT strategy. However, some criticalities emerged, for instance, the limited prescriptive power of the tool and the language, which is sometimes difficult to understand for IT practitioners. It should also be noted that current IT-governance implementation in Italian manufacturing SMEs appears to be very limited. Further, it should be highlighted that this study was using COBIT 2019 before ISACA issued “COBIT for Small and Medium Enterprises Using COBIT 2019” which could already have a positive impact on the level of comprehension.

Keywords: COBIT 2019, IT-governance, IT-governance frameworks, multiple case study

