Informing cybersecurity strategic commitment through top management perceptions: The role of institutional pressures

被引:29
作者
Ogbanufe, Obi [1 ]
Kim, Dan J. [1 ]
Jones, Mary C. [1 ]
机构
[1] Univ North Texas, G Brint Ryan Coll Business, Dept Informat Technol & Decis Sci, 1307 West Highland St, Denton, TX 76201 USA
基金
美国国家科学基金会;
关键词
Risk management; Cybersecurity strategy; Cyberinsurance; Top management; Upper echelons theory; Institutional theory; INFORMATION-SYSTEMS SECURITY; CYBER-RISK; REGULATORY OVERSIGHT; SENIOR EXECUTIVES; POLICY COMPLIANCE; JOB INSECURITY; UPPER ECHELONS; E-COMMERCE; DECISION; ASSIMILATION;
D O I
10.1016/j.im.2021.103507
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Given the financial consequences of security breaches, security risk management has gained more attention in board rooms and garnered more involvement from top management. We undertake a study to understand the top managers' role in cybersecurity strategy, specifically with cyberinsurance. This study draws from institutional and upper echelons theories to explain how top managers' values and perceptions mediate the impact of external institutional pressures on the commitment to use cyberinsurance as a risk management strategy. We empirically test proposed hypotheses using data collected from executive-level managers of various firms and perform semi structured interviews of six case sites as post hoc analysis. The results suggest that institutional pressures positively affect top managers' perceptions of job security, breach risk, financial risk, transaction cost, and regulatory oversight. In turn, these perceptions influence their commitment to cyberinsurance. We find that values and perceptions of personal relevance have a significant impact on their strategic decisions. The findings emphasize the critical role that top management plays in mediating the influence of institutional pressures on cybersecurity strategy. Implications for research and practice, along with limitations and future directions, are discussed.
引用
收藏
页数:18
相关论文
共 139 条
[1]  
Absolute, 2016, IT CONF STAT SEC CON
[2]   CHIEF EXECUTIVE OFFICER INCENTIVES, MONITORING, AND CORPORATE RISK MANAGEMENT: EVIDENCE FROM INSURANCE USE [J].
Adams, Mike ;
Lin, Chen ;
Zou, Hong .
JOURNAL OF RISK AND INSURANCE, 2011, 78 (03) :551-582
[3]   Production and transaction economies and IS outsourcing: A study of the US banking industry [J].
Ang, S ;
Straub, DW .
MIS QUARTERLY, 1998, 22 (04) :535-552
[4]  
Angst C.M., 2017, MIS Quarterly, V41, P1, DOI [10.25300/MISQ/2017/41.4, DOI 10.25300/MISQ/2017/41.4]
[5]  
Angst CM, 2017, MIS QUART, V41, P893
[6]  
[Anonymous], 2015, Experian
[7]   CONTENT, CAUSES, AND CONSEQUENCES OF JOB INSECURITY - A THEORY-BASED MEASURE AND SUBSTANTIVE TEST [J].
ASHFORD, SJ ;
LEE, C ;
BOBKO, P .
ACADEMY OF MANAGEMENT JOURNAL, 1989, 32 (04) :803-829
[8]   The effect of management commitment to service quality on employees' affective and performance outcomes [J].
Babakus, E ;
Yavas, U ;
Karatepe, OM ;
Avci, T .
JOURNAL OF THE ACADEMY OF MARKETING SCIENCE, 2003, 31 (03) :272-286
[9]  
Bagchi K., 2003, COMMUN ASSOC INF SYS, V12, P684
[10]   Assimilation of interorganizational business process standards [J].
Bala, Hillol ;
Venkatesh, Viswanath .
INFORMATION SYSTEMS RESEARCH, 2007, 18 (03) :340-362