Small and medium-sized enterprises (SMEs) increasingly rely on digital technologies in everyday operations, often without having sufficient resources or structured mechanisms to manage the cyber risks that accompany this dependence. As digitalization deepens, cyber incidents in SMEs are shaped not only by technical vulnerabilities but also by human behavior and organizational practices. However, much of the existing research still approaches cyber resilience through fragmented technological or managerial lenses. This study takes a conceptual and theory-driven approach to examine cyber resilience in SMEs as a socio-technical system. Building on systems theory and adaptive management, the analysis draws on a structured synthesis of interdisciplinary literature to develop a systemic model of adaptive digital risk management. The model is developed through a structured conceptual process combining systematic exploration of interdisciplinary literature, analytical synthesis of recurring conceptual patterns, and system-level model construction informed by systems theory and adaptive management principles. Cyber resilience is therefore interpreted as a dynamic capability that develops over time, especially in digital environments characterized by increasing automation and evolving forms of human–technology interaction. The study contributes to cyber resilience research by offering a system-oriented perspective and provides SMEs with a conceptual basis for strengthening adaptive approaches to digital risk management.
Bahmanova et al. (Sat,) studied this question.