Cybersecurity Awareness and Intention to Adopt Cloud-Based Financial Systems Among Small and Medium-Sized Enterprises: An Extended Technology Acceptance Model Evidence Synthesis
DOI:
https://doi.org/10.66687/JMRISKeywords:
Cloud-based financial systems, cybersecurity, Awareness, SMEAbstract
Background: Cloud-based financial systems can provide small and medium-sized enterprises (SMEs) with lower infrastructure costs, real-time access to accounting information, scalability and improved financial visibility. Adoption decisions, however, are influenced not only by perceived usefulness and ease of use but also by concerns about cybersecurity, privacy, trust and organizational preparedness.
Objective: To synthesize evidence available on SME adoption of cloud-based financial systems and to evaluate cybersecurity awareness as an extension to the Technology Acceptance Model (TAM).
Methods: A structured evidence synthesis was conducted using peer-reviewed literature from high-ranking journals in accounting information systems, information systems, cybersecurity, innovation and management. Studies were eligible when they examined cloud accounting, cloud ERP or cloud-computing adoption in SMEs, or when they directly assessed SME cybersecurity awareness, preparedness or risk perception. Because no eligible pre-2026 study identified in the review directly estimated the complete extended-TAM model proposed here, no synthetic path coefficients were generated.
Results: The evidence consistently supported perceived benefit or relative advantage as an important adoption driver, while ease of use, organizational readiness, compatibility, external support and security factors showed context-dependent effects. A 2024 cloud-accounting study in SMEs found that employee capability, organizational resources, management support and technological factors influenced willingness to adopt cloud-based accounting. A 2025 study of 172 Vietnamese companies found security/privacy and system integration to be significant predictors of cloud-accounting adoption. In parallel, cybersecurity studies showed substantial SME knowledge gaps: UK SMEs often perceived attack probability as low despite expecting high impact, while Western Australian SMEs reported lack of funding and uncertainty about where to begin as major barriers to preparedness.
Conclusion: Cybersecurity awareness is a credible extension to TAM because it changes how decision-makers interpret perceived risk, trust and the effort required to use cloud financial systems safely. The most defensible model is not that awareness simply increases adoption; rather, adequate awareness converts undifferentiated fear into informed trust and makes organizational readiness more actionable. SMEs should therefore combine usability and business-value evaluation with targeted cybersecurity capability development before adoption.
References
Davis FD. Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS Q. 1989;13(3):319-340. doi:10.2307/249008.
Venkatesh V, Morris MG, Davis GB, Davis FD. User acceptance of information technology: toward a unified view. MIS Q. 2003;27(3):425-478. doi:10.2307/30036540.
Ma D, Fisher R, Nesbit T. Cloud-based client accounting and small and medium accounting practices: adoption and impact. Int J Account Inf Syst. 2021;41:100513. doi:10.1016/j.accinf.2021.100513.
Mujalli A, Wani MJG, Almgrashi A, Khormi T, Qahtani M. Investigating the factors affecting the adoption of cloud-based accounting in SMEs. J Open Innov Technol Mark Complex. 2024;10(2):100314. doi:10.1016/j.joitmc.2024.100314.
Nguyen Phu G, Hoang Thi T, Tran Nguyen Bich H. The impact of cloud computing technology on cloud accounting adoption and financial management of businesses. Humanit Soc Sci Commun. 2025;12:851. doi:10.1057/s41599-025-05190-3.
Kumar J, Rani V, Rani G, Rani M. Is cloud computing a game-changer for SME financial performance? Unveiling the mediating role of organizational agility through PLS-SEM. Bus Process Manag J. 2025;31(6):2433-2452. doi:10.1108/BPMJ-10-2024-1004.
Wilson M, McDonald S, Button D, McGarry K. It won't happen to me: surveying SME attitudes to cyber-security. J Comput Inf Syst. 2023;63(2):397-409. doi:10.1080/08874417.2022.2067791.
Chidukwani A, Zander S, Koutsakis P. Cybersecurity preparedness of small-to-medium businesses: a Western Australia study with broader implications. Comput Secur. 2024;145:104026. doi:10.1016/j.cose.2024.104026.
Arroyabe MF, Arranz CFA, Fernandez De Arroyabe I, Fernandez de Arroyabe JC. Exploring the economic role of cybersecurity in SMEs: a case study of the UK. Technol Soc. 2024;78:102670. doi:10.1016/j.techsoc.2024.102670.
Bada M, Nurse JRC. Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Inf Comput Secur. 2019;27(3):393-410. doi:10.1108/ICS-07-2018-0080.
Al Hadwer A, Tavana M, Gillis D, Rezania D. A systematic review of organizational factors impacting cloud-based technology adoption using Technology-Organization-Environment framework. Internet Things. 2021;15:100407. doi:10.1016/j.iot.2021.100407.
Oliveira T, Thomas M, Espadanal M. Assessing the determinants of cloud computing adoption: an analysis of the manufacturing and services sectors. Inf Manag. 2014;51(5):497-510. doi:10.1016/j.im.2014.03.006.
Hoong Y, Rezania D. Balancing talent and technology: navigating cybersecurity and privacy in SMEs. Telemat Inform Rep. 2024;15:100151. doi:10.1016/j.teler.2024.100151.