Conceptual foundations for translating scenario-based cyber risk into investment decisions in SMEs
Abstract
Small and medium-sized enterprises (SMEs) face increasing exposure to complex and high-impact cyber threats, while operating under significant financial and organizational resource constraints. Unlike large corporations, SMEs often lack the capacity to invest extensively in cybersecurity, making inefficient or poorly prioritized investments particularly costly. Prior research has highlighted scenario-based cyber stress testing as a method for capturing low-probability, high-impact cyber events, as well as exposure-based indices for assessing vulnerabilities of critical SME assets. Building on this line of research, the present study advances the conceptual development of a theoretical pathway that links scenario-based cyber risk assessment with investment-oriented decision logic. Drawing exclusively on the existing literature, the paper synthesizes key theoretical perspectives on cyber stress scenarios, asset criticality, risk exposure, and the economic interpretation of cyber risk in resource-constrained environments. It proposes a conceptual framework illustrating how scenario-based risk assessments and exposure indices can be translated into investment-relevant insights without relying on empirical case studies. Rather than introducing a fully operational investment model, the study represents a conceptual extension of prior work and establishes the theoretical foundations necessary for the future development of decision-support tools aimed at guiding SMEs in allocating scarce resources to strengthen cyber resilience under conditions of uncertainty.