Conceptual foundations for translating scenario-based cyber risk into investment decisions in SMEs
DOI:
https://doi.org/10.3846/bm.2026.2366Abstract
Small and medium-sized enterprises (SMEs) face increasing exposure to complex and high-impact cyber threats, while operating under significant financial and organizational resource constraints. Unlike large corporations, SMEs often lack the capacity to invest extensively in cybersecurity, making inefficient or poorly prioritized investments particularly costly. Prior research has highlighted scenario-based cyber stress testing as a method for capturing low-probability, high-impact cyber events, as well as exposure-based indices for assessing vulnerabilities of critical SME assets. Building on this line of research, the present study advances the conceptual development of a theoretical pathway that links scenario-based cyber risk assessment with investment-oriented decision logic. Drawing exclusively on the existing literature, the paper synthesizes key theoretical perspectives on cyber stress scenarios, asset criticality, risk exposure, and the economic interpretation of cyber risk in resource-constrained environments. It proposes a conceptual framework illustrating how scenario-based risk assessments and exposure indices can be translated into investment-relevant insights without relying on empirical case studies. Rather than introducing a fully operational investment model, the study represents a conceptual extension of prior work and establishes the theoretical foundations necessary for the future development of decision-support tools aimed at guiding SMEs in allocating scarce resources to strengthen cyber resilience under conditions of uncertainty.
Keywords:
cyber resilience, scenario-based cyber risk, cyber stress testing, risk exposure indices, investment prioritization, resource-constrained SMEs, conceptual frameworkHow to Cite
Bahmanova, A., & Lace, N. (2025a). Conceptual model of the company’s cyber resilience elements. In Proceedings of the International Multi-Conference on Complexity, Informatics and Cybernetics: IMCIC 2025 (pp. 172–183). International Institute of Informatics and Cybernetics. https://doi.org/10.54808/IMCIC2025.01.172
Bahmanova, A., & Lace, N. (2025b). Scenario-based stress testing for SME cyber resilience: A simulation-driven approach [Unpublished manuscript].
Cavallini, S., Soldani, J., & Venturi, A. (2022). A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs: The SMECRA tool. Decision Support Systems, 152, Article 13825.
Durst, S., Hinteregger, C., & Zieba, M. (2024). The effect of environmental turbulence on cyber security risk management and organizational resilience. Computers & Security, 137, Article 103591. https://doi.org/10.1016/j.cose.2023.103591
Erola, A., Agrafiotis, I., Nurse, J. R. C., Axon, L., Goldsmith, M., & Creese, S. (2022). A system to calculate cyber-value-at-risk. Computers & Security, 113, Article 102545. https://doi.org/10.1016/j.cose.2021.102545
European Union Agency for Cybersecurity. (2025). Handbook for cyber stress tests. Publications Office of the European Union. https://doi.org/10.2824/8248517
Khiaonarong, T., Korpinen, K. N., & Islam, E. (2025). Using simulations for cyber stress testing exercises (IMF Working Papers No. 2025(085). International Monetary Fund. https://doi.org/10.5089/9798229008952.001
Pettersen, S., & Grøtan, T. O. (2024). Exploring the grounds for cyber resilience in the hyper-connected oil and gas industry. Safety Science, 171, Article 106384. https://doi.org/10.1016/j.ssci.2023.106384
Saeed, S., Suayyid, S. A., Al-Ghamdi, M. S., Al-Muhaisen, H., & Almuhaideb, A. M. (2023). A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors, 23(16), Article 7273. https://doi.org/10.3390/s23167273
Sukumar, A., Mahdiraji, H. A., & Jafari-Sadeghi, V. (2023). Cyber risk assessment in small and medium-sized enterprises: A multilevel decision-making approach for small e-tailors. Risk Analysis, 43(10), 2082–2098. https://doi.org/10.1111/risa.14092
Taherdoost, H. (2024). A critical review on cybersecurity awareness frameworks and training models. Procedia Computer Science, 235, 1649–1663. https://doi.org/10.1016/j.procs.2024.04.156
van Haastrecht, M., Sarhan, I., Shojaifar, A., Baumgartner, L., Mallouli, W., & Spruit, M. (2021). A threat-based cybersecurity risk assessment approach addressing SME needs. In Proceedings of the 16th International Conference on Availability, Reliability and Security (pp. 1–12). Association for Computing Machinery. https://doi.org/10.1145/3465481.3469199
Downloads
Published
Conference Event
Section
Copyright
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
