Building Cyber Resilient Organisations Through Strategic Risk Management and Digital Preparedness

Shahri Abu Seman (1) , Aza Jamaludin (1) , Ahmad Fauzi Ahmad Zaini (1)
(1) Institute of Graduate Studies, Universiti Poly-Tech Malaysia, 56100 Kuala Lumpur, Malaysia, Malaysia

Abstract

The increasing dependence of organisations on digital technologies has created significant opportunities for operational efficiency, connectivity, and business growth while simultaneously increasing exposure to complex cyber risks. This article examines how strategic risk management and digital preparedness can strengthen cyber resilience and support organisational continuity in increasingly interconnected business environments. The analysis focuses on four important dimensions comprising strategic cyber risk management and governance, digital preparedness and human cybersecurity capability, cyber resilience and business continuity, and cyber risk across digital ecosystems and supply chains. The article identifies several challenges that can weaken organisational cyber resilience, including limited integration of cyber risk into strategic decision making, inadequate employee and organisational preparedness, difficulties in maintaining critical operations during cyber incidents, and vulnerabilities arising from external digital dependencies. These challenges demonstrate that cybersecurity should not be treated solely as a technical responsibility because cyber incidents can generate operational, financial, reputational, and strategic consequences. The article proposes stronger cyber risk governance, continuous development of human and digital capabilities, closer integration between cybersecurity and business continuity, and improved coordination across digital supply chains. Overall, effective cyber resilience requires organisations to combine technological protection with strategic governance, organisational learning, preparedness, response capability, and adaptive capacity. This integrated approach can enable organisations to manage evolving cyber threats more effectively, protect critical business activities, and strengthen long term organisational resilience in increasingly digital business environments.


                                                                          

Full text article

Generated from XML file

References

Abdullah, F. I., Yusof, M. S., & Abu Seman, S. (2020). Strategic Warehouse Management and Supply Chain Performance in a Changing Business Environment. The Asian Journal of Professional & Business Studies, 1(2), 73–89. https://doi.org/10.61688/ajpbs.v1i2.155

Abd Wahab, N. S., & Yusof, M. S. (2020). Ergonomic Work Design and Its Influence on Healthcare Professionals’ Well-being and Performance. The Asian Journal of Professional & Business Studies, 1(2), 90–107. https://doi.org/10.61688/ajpbs.v1i2.298

AlGhamdi, S., Win, K. T., & Vlahu Gjorgievska, E. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, 102030. https://doi.org/10.1016/j.cose.2020.102030

Anderson, R., & Moore, T. (2006). The economics of information security. Science, 314(5799), 610–613. https://doi.org/10.1126/science.1130992

Andersson, J., de Lemos, R., Malek, S., & Weyns, D. (2021). Software engineering for self adaptive systems: Research challenges in the provision of assurances. In R. de Lemos et al. (Eds.), Software engineering for self adaptive systems III: Assurances (pp. 3–30). Springer.

Annarelli, A., Nonino, F., & Palombi, G. (2020). Understanding the management of cyber resilient systems. Computers & Industrial Engineering, 149, 106829. https://doi.org/10.1016/j.cie.2020.106829

Benz, M., & Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63(4), 531–540. https://doi.org/10.1016/j.bushor.2020.03.010

Boyson, S. (2014). Cyber supply chain risk management: Revolutionizing the strategic control of critical IT systems. Technovation, 34(7), 342–353. https://doi.org/10.1016/j.technovation.2014.02.001

Bromiley, P., McShane, M., Nair, A., & Rustambekov, E. (2015). Enterprise risk management: Review, critique, and research directions. Long Range Planning, 48(4), 265–276. https://doi.org/10.1016/j.lrp.2014.07.005

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. https://doi.org/10.2307/25750690

Callahan, C., & Soileau, J. (2017). Does enterprise risk management enhance operating performance? Advances in Accounting, 37, 122–139. https://doi.org/10.1016/j.adiac.2017.01.001

Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). The effect of Internet security breach announcements on market value: Capital market reactions for breached firms and Internet security developers. International Journal of Electronic Commerce, 9(1), 70–104. https://doi.org/10.1080/10864415.2004.11044320

Colicchia, C., Creazza, A., & Menachof, D. A. (2019). Managing cyber and information risks in supply chains: Insights from an exploratory analysis. Supply Chain Management: An International Journal, 24(2), 215–240. https://doi.org/10.1108/SCM-09-2017-0289

D'Arcy, J., & Teh, P. L. (2019). Predicting employee information security policy compliance on a daily basis: The interplay of security related stress, emotions, and neutralization. Information & Management, 56(7), 103151. https://doi.org/10.1016/j.im.2019.02.006

Da Veiga, A., & Eloff, J. H. P. (2010). A framework and assessment instrument for information security culture. Computers & Security, 29(2), 196–207. https://doi.org/10.1016/j.cose.2009.09.002

Duchek, S. (2020). Organizational resilience: A capability based conceptualization. Business Research, 13, 215–246. https://doi.org/10.1007/s40685-019-0085-7

Dupont, B. (2019). The cyber resilience of financial institutions: Significance and applicability. Journal of Cybersecurity, 5(1), tyz013. https://doi.org/10.1093/cybsec/tyz013

Florio, C., & Leoni, G. (2017). Enterprise risk management and firm performance: The Italian case. The British Accounting Review, 49(1), 56–74. https://doi.org/10.1016/j.bar.2016.08.003

Ghadge, A., Weiß, M., Caldwell, N. D., & Wilding, R. (2020). Managing cyber risk in supply chains: A review and research agenda. Supply Chain Management: An International Journal, 25(2), 223–240. https://doi.org/10.1108/SCM-10-2018-0357

Goel, S., Williams, K., & Dincelli, E. (2020). Got phished? Internet security and human vulnerability. Journal of the Association for Information Systems, 21(1), 22–44.

Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274

Gordon, L. A., Loeb, M. P., & Lucyshyn, W. (2003). Sharing information on computer systems security: An economic analysis. Journal of Accounting and Public Policy, 22(6), 461–485. https://doi.org/10.1016/j.jaccpubpol.2003.09.001

Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726. https://doi.org/10.1016/j.jisa.2020.102726

Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments. Information Systems Frontiers, 21, 1285–1305. https://doi.org/10.1007/s10796-019-09959-1

Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106–125. https://doi.org/10.1057/ejis.2009.6

Hillmann, J., & Guenther, E. (2021). Organizational resilience: A valuable construct for management research? International Journal of Management Reviews, 23(1), 7–44. https://doi.org/10.1111/ijmr.12239

Ifinedo, P. (2012). Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers & Security, 31(1), 83–95. https://doi.org/10.1016/j.cose.2011.10.007

Linkov, I., & Kott, A. (2019). Fundamental concepts of cyber resilience: Introduction and overview. In I. Linkov & A. Kott (Eds.), Cyber resilience of systems and networks (pp. 1–25). Springer. https://doi.org/10.1007/978-3-319-77492-3_1

Malik, M. F., Zaman, M., & Buckby, S. (2020). Enterprise risk management and firm performance: Role of the risk committee. Journal of Contemporary Accounting & Economics, 16(1), 100178. https://doi.org/10.1016/j.jcae.2019.100178

Masip Bruin, X., Marín Tordera, E., Ruiz, J., Jukan, A., Ren, G. J., Zhu, J., & Farré, J. (2021). Cybersecurity in ICT supply chains: Key challenges and a relevant architecture. Sensors, 21(18), 6057. https://doi.org/10.3390/s21186057

Mikes, A., & Kaplan, R. S. (2015). When one size doesn't fit all: Evolving directions in the research and practice of enterprise risk management. Journal of Applied Corporate Finance, 27(1), 37–40. https://doi.org/10.1111/jacf.12102

Nurse, J. R. C., Buckley, O., Legg, P. A., Goldsmith, M., Creese, S., Wright, G. R. T., & Whitty, M. (2014). Understanding insider threat: A framework for characterising attacks. In 2014 IEEE Security and Privacy Workshops (pp. 214–228). IEEE. https://doi.org/10.1109/SPW.2014.38

Pandey, S., Singh, R. K., Gunasekaran, A., & Kaushik, A. (2020). Cyber security risks in globalized supply chains: Conceptual framework. Journal of Global Operations and Strategic Sourcing, 13(1), 103–128. https://doi.org/10.1108/JGOSS-05-2019-0042

Puhakainen, P., & Siponen, M. (2010). Improving employees' compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757–778. https://doi.org/10.2307/25750704

Radanliev, P., De Roure, D., Nurse, J. R. C., Montalvo, R. M., Cannady, S., Santos, O., Maddox, L. T., & Burnap, P. (2020). Future developments in cyber risk assessment for the Internet of Things. Computers in Industry, 117, 103172. https://doi.org/10.1016/j.compind.2020.103172

Schinagl, S., & Shahim, A. (2020). What do we know about information security governance? From the basement to the boardroom: Towards digital security governance. Information & Computer Security, 28(2), 261–292. https://doi.org/10.1108/ICS-02-2019-0033

Scholz, R. W., Czichos, R., Parycek, P., & Lampoltshammer, T. J. (2020). Organizational vulnerability of digital threats: A first validation of an assessment method. European Journal of Operational Research, 282(2), 627–643. https://doi.org/10.1016/j.ejor.2019.09.020

Sepúlveda Estay, D. A., Sahay, R., Barfod, M. B., & Jensen, C. D. (2020). A systematic review of cyber resilience assessment frameworks. Computers & Security, 97, 101996. https://doi.org/10.1016/j.cose.2020.101996

Shojaei, A., Wang, J., & Fenner, A. (2020). Exploring the feasibility of blockchain technology as an infrastructure for improving built asset sustainability. Built Environment Project and Asset Management, 10(2), 184–199.

Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502. https://doi.org/10.2307/25750688

Sobb, T., Turnbull, B., & Moustafa, N. (2020). Supply Chain 4.0: A survey of cyber security challenges, solutions and future directions. Electronics, 9(11), 1864. https://doi.org/10.3390/electronics9111864

Soomro, Z. A., Shah, M. H., & Ahmed, J. (2016). Information security management needs more holistic approach: A literature review. International Journal of Information Management, 36(2), 215–225. https://doi.org/10.1016/j.ijinfomgt.2015.11.009

Torten, R., Reaiche, C., & Boyle, S. (2018). The impact of security awareness on information technology professionals’ behaviour. Computers & Security, 79, 68–79.

Wiley, A., McCormac, A., & Calic, D. (2020). More than the individual: Examining the relationship between culture and information security awareness. Computers & Security, 88, 101640. https://doi.org/10.1016/j.cose.2019.101640

Yusof, M. S. (2022). Strengthening warehouse operations through Integrated Safety Management Practices: bi. The Asian Journal of Professional & Business Studies, 1(2), 56–72. https://doi.org/10.61688/ajpbs.v1i2.150

Yusof, M. S., & Abd Wahab, N. S. (2020). Advancing Sustainable Healthcare Workplaces Through Human Centred Ergonomic Work Design. The Asian Journal of Professional & Business Studies, 1(2), 108–126. https://doi.org/10.61688/ajpbs.v1i2.330

Yusof, M. S., & Abd Wahab, N. S. (2020). Transforming Healthcare Work Systems Through Human-Centred Ergonomic Innovation. The Asian Journal of Professional & Business Studies, 1(1), 93–110. https://doi.org/10.61688/ajpbs.v1i1.134

Yusof, M. S., & Abd Wahab, N. S. (2020). Strengthening Hospital Management Through Ethical Leadership and Professional Integrity. The Asian Journal of Professional & Business Studies, 1(1), 59–75. https://doi.org/10.61688/ajpbs.v1i1.8

Yusof, M. S., & Abd Wahab, N. S. (2021). Balancing technology and ethics in the transformation of modern hospital healthcare. The Asian Journal of Professional & Business Studies, 2(1), 16–34. https://doi.org/10.61688/ajpbs.v2i1.146

Yusof, M. S., & Razali, H. (2020). Navigating Organisational Uncertainty Through Risk Perception and Managerial Judgement. The Asian Journal of Professional & Business Studies, 1(1), 76–92. https://doi.org/10.61688/ajpbs.v1i1.69

Yusof, M. S., Salleh, M. N., & Zahari, F. M. (2020). The Relationship between Information Technology Capability and New Product Development Success: A Conceptual Framework. International Journal of Business and Technology Management, 2(1), 98-112.

Yusof, M. S., Salleh, M. N., & Zahari, F. M. (2020). The Relationship between NPD Process and NPD Strategy toward NPD Success in Malaysian Automotive Industry. Asian Journal of Research in Business and Management, 2(1), 11-26.

Yusof, M. S., & Salleh, M. N. (2021). Beyond manufacturing towards innovation-driven new product development in Malaysia’s automotive industry. The Asian Journal of Professional & Business Studies, 2(1), 35–52. https://doi.org/10.61688/ajpbs.v2i1.152

Zhang, J., & He, W. (2019). Enterprise cybersecurity training and awareness programs: Recommendations for success. Journal of Organizational and End User Computing, 31(4), 1–18.

Zhang, T., Tao, D., Qu, X., Zhang, X., Zeng, J., Zhu, H., & Zhu, H. (2020). Automated vehicle acceptance in China: Social influence and initial trust are key determinants. Transportation Research Part C: Emerging Technologies, 112, 220–233.

Zwilling, M., Klien, G., Lesjak, D., Wiechetek, Ł., Çetin, F., & Basim, H. N. (2020). Cyber security awareness, knowledge and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82–97. https://doi.org/10.1080/08874417.2020.1712269

Authors

Shahri Abu Seman
Aza Jamaludin
Ahmad Fauzi Ahmad Zaini
ahmadfauzi@uptm.edu.my (Primary Contact)
Abu Seman, S., Jamaludin, A., & Ahmad Zaini, A. F. (2021). Building Cyber Resilient Organisations Through Strategic Risk Management and Digital Preparedness. The Asian Journal of Professional & Business Studies, 2(2), 85–103. https://doi.org/10.61688/ajpbs.v2i2.378

Article Details

Most read articles by the same author(s)

Similar Articles

You may also start an advanced similarity search for this article.