Skip to main content
Kent Academic Repository

Cybersecurity and cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamics

Adriko, Rodney, Nurse, Jason R. C. (2026) Cybersecurity and cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamics. Computers & Security, 153 . Article Number 104818. ISSN 0167-4048. (doi:10.1016/j.cose.2025.104818) (KAR id:112661)

Abstract

Cyber insurance is increasingly positioned as a complementary tool for managing cyber risk, yet Small to Medium-Sized Enterprises (SMEs) remain underrepresented in its adoption. This study investigates the perceptions, decision-making dynamics, and support needs of SMEs regarding cyber insurance, drawing on 38 semistructured interviews with SMEs, insurers, brokers, and other relevant stakeholders. The findings reveal that many SMEs deprioritise cyber insurance; not because they dismiss its importance outright, but due to a combination of limited awareness, concerns over cost, and a perception that its value is minimal unless required by clients or regulators. This hesitation is further shaped by several key barriers: complex policy language, a lack of trust in insurers, and unclear internal ownership of cybersecurity responsibilities. Despite these challenges, the study identifies promising strategies to boost adoption. These include simplifying policy structures, fostering trust through collaborative awareness efforts, introducing financial incentives tailored to SME budgets, and offering accessible, user-friendly tools that help businesses assess their cyber risks and insurance needs. By identifying actionable strategies and addressing both cultural and structural barriers, this study contributes to efforts to enhance cybersecurity resilience in the SME sector.

Item Type: Article
DOI/Identification number: 10.1016/j.cose.2025.104818
Uncontrolled keywords: cybersecurity; SMEs; SMBs; Information security; cyber insurance; risk management; standards and controls; decision-making; psychology; Risk perception
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 75 Electronic computers. Computer science
T Technology
Institutional Unit: Schools > School of Computing
Former Institutional Unit:
There are no former institutional units.
Depositing User: Rodney Adriko
Date Deposited: 08 Jan 2026 16:30 UTC
Last Modified: 09 Jan 2026 09:23 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/112661 (The current URI for this page, for reference purposes)

University of Kent Author Information

Adriko, Rodney.

Creator's ORCID: https://orcid.org/0000-0003-2642-877X
CReDIT Contributor Roles: Writing - review and editing, Project administration, Conceptualisation, Writing - original draft, Data curation, Formal analysis, Investigation, Methodology

Nurse, Jason R. C..

Creator's ORCID: https://orcid.org/0000-0003-4118-1680
CReDIT Contributor Roles: Supervision, Formal analysis, Project administration, Conceptualisation, Writing - review and editing
  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.