Cyber risk management in SMEs: insights from industry surveys
Felicitas Hoppe,
Nadine Gatzert and
Petra Gruner
Journal of Risk Finance, 2021, vol. 22, issue 3/4, 240-260
Abstract:
Purpose - This article aims to gain insights on the current state of small- and medium-sized enterprises’ (SMEs’) cyber risk management process and to derive future research directions. Design/methodology/approach - This is done by collecting market insights from 37 recent industry surveys and structuring them based on the steps of the risk management process. From this analysis, major challenges are derived and future fields of research identified. Findings - The results indicate that deficiencies in risk culture as well as the strained market for IT experts are the major obstacles with respect to the implementation of cyber risk management in SMEs, and that these challenges are similar across countries. The findings suggest that especially the relationship between cyber security culture and cyber risk management should be investigated further, and that a stronger link between the research streams on enterprise risk management and cyber risk management would be desirable. Originality/value - This paper contributes to the literature by providing a systematic overview on the current state of SMEs' cyber risk management from a market perspective. The findings provide support for the existing academic literature by emphasizing the central role of cyber security culture (perception, knowledge, attitude) for a successful cyber risk management, which however should be addressed in more depth in future (empirical) research.
Keywords: Cyber risk management; Risk culture; Cyber security culture; Cyber insurance; SMEs (search for similar items in EconPapers)
Date: 2021
References: Add references at CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
https://www.emerald.com/insight/content/doi/10.110 ... d&utm_campaign=repec (text/html)
https://www.emerald.com/insight/content/doi/10.110 ... d&utm_campaign=repec (application/pdf)
Access to full text is restricted to subscribers
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eme:jrfpps:jrf-02-2020-0024
DOI: 10.1108/JRF-02-2020-0024
Access Statistics for this article
Journal of Risk Finance is currently edited by Nawazish Mirza
More articles in Journal of Risk Finance from Emerald Group Publishing Limited
Bibliographic data for series maintained by Emerald Support ().