Adriko, Rodney, Nurse, Jason R. C. (2026) Cybersecurity and cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamics. Computers & Security, 153 . Article Number 104818. ISSN 0167-4048. (doi:10.1016/j.cose.2025.104818) (KAR id:112661)
|
PDF
Publisher pdf
Language: English
This work is licensed under a Creative Commons Attribution 4.0 International License.
|
|
|
Download this file (PDF/806kB) |
Preview |
| Request a format suitable for use with assistive technology e.g. a screenreader | |
| Official URL: https://doi.org/10.1016/j.cose.2025.104818 |
|
Abstract
Cyber insurance is increasingly positioned as a complementary tool for managing cyber risk, yet Small to Medium-Sized Enterprises (SMEs) remain underrepresented in its adoption. This study investigates the perceptions, decision-making dynamics, and support needs of SMEs regarding cyber insurance, drawing on 38 semistructured interviews with SMEs, insurers, brokers, and other relevant stakeholders. The findings reveal that many SMEs deprioritise cyber insurance; not because they dismiss its importance outright, but due to a combination of limited awareness, concerns over cost, and a perception that its value is minimal unless required by clients or regulators. This hesitation is further shaped by several key barriers: complex policy language, a lack of trust in insurers, and unclear internal ownership of cybersecurity responsibilities. Despite these challenges, the study identifies promising strategies to boost adoption. These include simplifying policy structures, fostering trust through collaborative awareness efforts, introducing financial incentives tailored to SME budgets, and offering accessible, user-friendly tools that help businesses assess their cyber risks and insurance needs. By identifying actionable strategies and addressing both cultural and structural barriers, this study contributes to efforts to enhance cybersecurity resilience in the SME sector.
| Item Type: | Article |
|---|---|
| DOI/Identification number: | 10.1016/j.cose.2025.104818 |
| Uncontrolled keywords: | cybersecurity; SMEs; SMBs; Information security; cyber insurance; risk management; standards and controls; decision-making; psychology; Risk perception |
| Subjects: |
Q Science > QA Mathematics (inc Computing science) > QA 75 Electronic computers. Computer science T Technology |
| Institutional Unit: | Schools > School of Computing |
| Former Institutional Unit: |
There are no former institutional units.
|
| Depositing User: | Rodney Adriko |
| Date Deposited: | 08 Jan 2026 16:30 UTC |
| Last Modified: | 09 Jan 2026 09:23 UTC |
| Resource URI: | https://kar.kent.ac.uk/id/eprint/112661 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):

https://orcid.org/0000-0003-2642-877X
Altmetric
Altmetric