Cyber Insurance and Small to Medium Sized Enterprises in Sweden
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesisAlternative title
Cyberförsäkringar och små till medelstora företag i Sverige (Swedish)
Abstract [en]
The modern society is completely surrounded by IT regardless of sector, branch of business, whether it is school or a normal day job. IT is a cornerstone of the new and improved world and much depends on it. Companies and organizations of different sizes need to be able to make sure that IT equipment, services, and processes always work, and if they stop working, regardless of what affects it, they need to make sure that they can recover them to operational capacity again. With cyber insurance, companies can insure their IT, but this is not a silver bullet solution. Companies with less than 250 employees are considered small to medium-sized, and the literature suggests that cyber insurance was not made with them in mind, even though SMEs are 99% of all businesses in Sweden. Through semi-structured interviews with people from SMEs, this study aimed to understand the attitude towards cyber insurance as well as identifying the reasons to have or not have one. The results showed that the main obstacles with cyber insurance were cost, level of trust between parties, and unclear terms. Awareness was identified as an issue on the customer’s side and was rooted in insurance awareness, false sense of security, and their perception of future development for cyber insurance. Lastly, the results present the perceived value of the insurance by highlighting the advantages of having one, what the customer wanted and needed from their insurance, and alternative solutions to the insurance. The study concludes that obstacles and awareness contribute to a mixed attitude toward cyber insurance and that there are different reasons for having, or not having it, cyber insurance was identified as a great way to handle residual risk through risk transfer, but it should be noted that there are other acceptable ways of managing it.
Place, publisher, year, edition, pages
2025. , p. 21
Keywords [en]
Cyber Insurance, Cybersecurity, SMEs, Information Security, Risk Management
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:hj:diva-68965OAI: oai:DiVA.org:hj-68965DiVA, id: diva2:1976051
Subject / course
JTH, Computer Engineering
Supervisors
Examiners
2025-06-242025-06-242025-10-13Bibliographically approved