Underinvestment in cyber security: Quantifying cyber security behavior in UK businesses

1Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Many businesses, particularly small businesses, are underinvesting in cyber security. This exposes them to the risk of costly cyber attack. To address the challenge of cyber security in small businesses a greater understanding is needed of why businesses are underinvesting. To address this challenge, we propose a novel framework to distinguish five behavioral types and quantify the proportion of businesses fitting each type. The types are overconfident, procrastinator, risk accepting, defer responsibility, and optimal. We apply our framework using data from the UK Government’s Cyber Security Breaches Survey from 2018–2024. We find that procrastination and overconfidence are the main reasons for underinvestment in cyber security in small businesses. We also find that small businesses with cyber insurance and/or cyber outsourcing are more likely to be classified as optimal. These results can inform policy interventions that better target the root cause of underinvestment in cyber security.

Cite

CITATION STYLE

APA

Cartwright, A., & Cartwright, E. (2026). Underinvestment in cyber security: Quantifying cyber security behavior in UK businesses. Journal of Small Business Management, 64(4), 1438–1473. https://doi.org/10.1080/00472778.2025.2549068

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free