Cybersecurity Assurance for SMEs: A Conceptual Framework Integrating Organizational Culture, Fraud Risk Management and Forensic Accounting
Ifedapo Francis Awolowo et al.
Canadian Journal of Administrative Sciences / Revue Canadienne des Sciences de l Administration2026https://doi.org/10.1002/cjas.70051article
AJG 2ABDC B
Weight
0.50
Abstract
As digitalization accelerates across the global economy, small and medium enterprises (SMEs) face increasing exposure to cybersecurity threats, not due to flaws in external platforms, but because of internal organizational vulnerabilities. This paper presents a conceptual framework that integrates the resource‐based view (RBV) and dynamic capabilities theory (DCT) to explore how SMEs can strategically enhance their cyber resilience. We reconceptualize fraud risk management (FRM), forensic accounting (FA) and cyber‐aware organizational culture as strategic resources that, when systematically integrated, enable dynamic capabilities for cyber resilience. These resources support organizational processes to sense emerging threats, seize response opportunities and reconfigure defencive capabilities in resource‐constrained environments. By shifting the focus from technology‐centric models to capability‐driven strategies, this framework positions cybersecurity as a strategic asset, essential for sustaining operational continuity, safeguarding reputation and enhancing competitive advantage. The framework offers theoretical insights and practical guidance for SME leaders, policymakers and practitioners navigating cybersecurity challenges in resource‐constrained environments.