Building Cyber Resilient Organisations Through Strategic Risk Management and Digital Preparedness
Abstract
The increasing dependence of organisations on digital technologies has created significant opportunities for operational efficiency, connectivity, and business growth while simultaneously increasing exposure to complex cyber risks. This article examines how strategic risk management and digital preparedness can strengthen cyber resilience and support organisational continuity in increasingly interconnected business environments. The analysis focuses on four important dimensions comprising strategic cyber risk management and governance, digital preparedness and human cybersecurity capability, cyber resilience and business continuity, and cyber risk across digital ecosystems and supply chains. The article identifies several challenges that can weaken organisational cyber resilience, including limited integration of cyber risk into strategic decision making, inadequate employee and organisational preparedness, difficulties in maintaining critical operations during cyber incidents, and vulnerabilities arising from external digital dependencies. These challenges demonstrate that cybersecurity should not be treated solely as a technical responsibility because cyber incidents can generate operational, financial, reputational, and strategic consequences. The article proposes stronger cyber risk governance, continuous development of human and digital capabilities, closer integration between cybersecurity and business continuity, and improved coordination across digital supply chains. Overall, effective cyber resilience requires organisations to combine technological protection with strategic governance, organisational learning, preparedness, response capability, and adaptive capacity. This integrated approach can enable organisations to manage evolving cyber threats more effectively, protect critical business activities, and strengthen long term organisational resilience in increasingly digital business environments.
Full text article
References
Abdullah, F. I., Yusof, M. S., & Abu Seman, S. (2020). Strategic Warehouse Management and Supply Chain Performance in a Changing Business Environment. The Asian Journal of Professional & Business Studies, 1(2), 73–89. https://doi.org/10.61688/ajpbs.v1i2.155
Abd Wahab, N. S., & Yusof, M. S. (2020). Ergonomic Work Design and Its Influence on Healthcare Professionals’ Well-being and Performance. The Asian Journal of Professional & Business Studies, 1(2), 90–107. https://doi.org/10.61688/ajpbs.v1i2.298
AlGhamdi, S., Win, K. T., & Vlahu Gjorgievska, E. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, 102030. https://doi.org/10.1016/j.cose.2020.102030
Anderson, R., & Moore, T. (2006). The economics of information security. Science, 314(5799), 610–613. https://doi.org/10.1126/science.1130992
Andersson, J., de Lemos, R., Malek, S., & Weyns, D. (2021). Software engineering for self adaptive systems: Research challenges in the provision of assurances. In R. de Lemos et al. (Eds.), Software engineering for self adaptive systems III: Assurances (pp. 3–30). Springer.
Annarelli, A., Nonino, F., & Palombi, G. (2020). Understanding the management of cyber resilient systems. Computers & Industrial Engineering, 149, 106829. https://doi.org/10.1016/j.cie.2020.106829
Benz, M., & Chatterjee, D. (2020). Calculated risk? A cybersecurity evaluation tool for SMEs. Business Horizons, 63(4), 531–540. https://doi.org/10.1016/j.bushor.2020.03.010
Boyson, S. (2014). Cyber supply chain risk management: Revolutionizing the strategic control of critical IT systems. Technovation, 34(7), 342–353. https://doi.org/10.1016/j.technovation.2014.02.001
Bromiley, P., McShane, M., Nair, A., & Rustambekov, E. (2015). Enterprise risk management: Review, critique, and research directions. Long Range Planning, 48(4), 265–276. https://doi.org/10.1016/j.lrp.2014.07.005
Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. https://doi.org/10.2307/25750690
Callahan, C., & Soileau, J. (2017). Does enterprise risk management enhance operating performance? Advances in Accounting, 37, 122–139. https://doi.org/10.1016/j.adiac.2017.01.001
Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). The effect of Internet security breach announcements on market value: Capital market reactions for breached firms and Internet security developers. International Journal of Electronic Commerce, 9(1), 70–104. https://doi.org/10.1080/10864415.2004.11044320
Colicchia, C., Creazza, A., & Menachof, D. A. (2019). Managing cyber and information risks in supply chains: Insights from an exploratory analysis. Supply Chain Management: An International Journal, 24(2), 215–240. https://doi.org/10.1108/SCM-09-2017-0289
D'Arcy, J., & Teh, P. L. (2019). Predicting employee information security policy compliance on a daily basis: The interplay of security related stress, emotions, and neutralization. Information & Management, 56(7), 103151. https://doi.org/10.1016/j.im.2019.02.006
Da Veiga, A., & Eloff, J. H. P. (2010). A framework and assessment instrument for information security culture. Computers & Security, 29(2), 196–207. https://doi.org/10.1016/j.cose.2009.09.002
Duchek, S. (2020). Organizational resilience: A capability based conceptualization. Business Research, 13, 215–246. https://doi.org/10.1007/s40685-019-0085-7
Dupont, B. (2019). The cyber resilience of financial institutions: Significance and applicability. Journal of Cybersecurity, 5(1), tyz013. https://doi.org/10.1093/cybsec/tyz013
Florio, C., & Leoni, G. (2017). Enterprise risk management and firm performance: The Italian case. The British Accounting Review, 49(1), 56–74. https://doi.org/10.1016/j.bar.2016.08.003
Ghadge, A., Weiß, M., Caldwell, N. D., & Wilding, R. (2020). Managing cyber risk in supply chains: A review and research agenda. Supply Chain Management: An International Journal, 25(2), 223–240. https://doi.org/10.1108/SCM-10-2018-0357
Goel, S., Williams, K., & Dincelli, E. (2020). Got phished? Internet security and human vulnerability. Journal of the Association for Information Systems, 21(1), 22–44.
Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274
Gordon, L. A., Loeb, M. P., & Lucyshyn, W. (2003). Sharing information on computer systems security: An economic analysis. Journal of Accounting and Public Policy, 22(6), 461–485. https://doi.org/10.1016/j.jaccpubpol.2003.09.001
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726. https://doi.org/10.1016/j.jisa.2020.102726
Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments. Information Systems Frontiers, 21, 1285–1305. https://doi.org/10.1007/s10796-019-09959-1
Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106–125. https://doi.org/10.1057/ejis.2009.6
Hillmann, J., & Guenther, E. (2021). Organizational resilience: A valuable construct for management research? International Journal of Management Reviews, 23(1), 7–44. https://doi.org/10.1111/ijmr.12239
Ifinedo, P. (2012). Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers & Security, 31(1), 83–95. https://doi.org/10.1016/j.cose.2011.10.007
Linkov, I., & Kott, A. (2019). Fundamental concepts of cyber resilience: Introduction and overview. In I. Linkov & A. Kott (Eds.), Cyber resilience of systems and networks (pp. 1–25). Springer. https://doi.org/10.1007/978-3-319-77492-3_1
Malik, M. F., Zaman, M., & Buckby, S. (2020). Enterprise risk management and firm performance: Role of the risk committee. Journal of Contemporary Accounting & Economics, 16(1), 100178. https://doi.org/10.1016/j.jcae.2019.100178
Masip Bruin, X., Marín Tordera, E., Ruiz, J., Jukan, A., Ren, G. J., Zhu, J., & Farré, J. (2021). Cybersecurity in ICT supply chains: Key challenges and a relevant architecture. Sensors, 21(18), 6057. https://doi.org/10.3390/s21186057
Mikes, A., & Kaplan, R. S. (2015). When one size doesn't fit all: Evolving directions in the research and practice of enterprise risk management. Journal of Applied Corporate Finance, 27(1), 37–40. https://doi.org/10.1111/jacf.12102
Nurse, J. R. C., Buckley, O., Legg, P. A., Goldsmith, M., Creese, S., Wright, G. R. T., & Whitty, M. (2014). Understanding insider threat: A framework for characterising attacks. In 2014 IEEE Security and Privacy Workshops (pp. 214–228). IEEE. https://doi.org/10.1109/SPW.2014.38
Pandey, S., Singh, R. K., Gunasekaran, A., & Kaushik, A. (2020). Cyber security risks in globalized supply chains: Conceptual framework. Journal of Global Operations and Strategic Sourcing, 13(1), 103–128. https://doi.org/10.1108/JGOSS-05-2019-0042
Puhakainen, P., & Siponen, M. (2010). Improving employees' compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757–778. https://doi.org/10.2307/25750704
Radanliev, P., De Roure, D., Nurse, J. R. C., Montalvo, R. M., Cannady, S., Santos, O., Maddox, L. T., & Burnap, P. (2020). Future developments in cyber risk assessment for the Internet of Things. Computers in Industry, 117, 103172. https://doi.org/10.1016/j.compind.2020.103172
Schinagl, S., & Shahim, A. (2020). What do we know about information security governance? From the basement to the boardroom: Towards digital security governance. Information & Computer Security, 28(2), 261–292. https://doi.org/10.1108/ICS-02-2019-0033
Scholz, R. W., Czichos, R., Parycek, P., & Lampoltshammer, T. J. (2020). Organizational vulnerability of digital threats: A first validation of an assessment method. European Journal of Operational Research, 282(2), 627–643. https://doi.org/10.1016/j.ejor.2019.09.020
Sepúlveda Estay, D. A., Sahay, R., Barfod, M. B., & Jensen, C. D. (2020). A systematic review of cyber resilience assessment frameworks. Computers & Security, 97, 101996. https://doi.org/10.1016/j.cose.2020.101996
Shojaei, A., Wang, J., & Fenner, A. (2020). Exploring the feasibility of blockchain technology as an infrastructure for improving built asset sustainability. Built Environment Project and Asset Management, 10(2), 184–199.
Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502. https://doi.org/10.2307/25750688
Sobb, T., Turnbull, B., & Moustafa, N. (2020). Supply Chain 4.0: A survey of cyber security challenges, solutions and future directions. Electronics, 9(11), 1864. https://doi.org/10.3390/electronics9111864
Soomro, Z. A., Shah, M. H., & Ahmed, J. (2016). Information security management needs more holistic approach: A literature review. International Journal of Information Management, 36(2), 215–225. https://doi.org/10.1016/j.ijinfomgt.2015.11.009
Torten, R., Reaiche, C., & Boyle, S. (2018). The impact of security awareness on information technology professionals’ behaviour. Computers & Security, 79, 68–79.
Wiley, A., McCormac, A., & Calic, D. (2020). More than the individual: Examining the relationship between culture and information security awareness. Computers & Security, 88, 101640. https://doi.org/10.1016/j.cose.2019.101640
Yusof, M. S. (2022). Strengthening warehouse operations through Integrated Safety Management Practices: bi. The Asian Journal of Professional & Business Studies, 1(2), 56–72. https://doi.org/10.61688/ajpbs.v1i2.150
Yusof, M. S., & Abd Wahab, N. S. (2020). Advancing Sustainable Healthcare Workplaces Through Human Centred Ergonomic Work Design. The Asian Journal of Professional & Business Studies, 1(2), 108–126. https://doi.org/10.61688/ajpbs.v1i2.330
Yusof, M. S., & Abd Wahab, N. S. (2020). Transforming Healthcare Work Systems Through Human-Centred Ergonomic Innovation. The Asian Journal of Professional & Business Studies, 1(1), 93–110. https://doi.org/10.61688/ajpbs.v1i1.134
Yusof, M. S., & Abd Wahab, N. S. (2020). Strengthening Hospital Management Through Ethical Leadership and Professional Integrity. The Asian Journal of Professional & Business Studies, 1(1), 59–75. https://doi.org/10.61688/ajpbs.v1i1.8
Yusof, M. S., & Abd Wahab, N. S. (2021). Balancing technology and ethics in the transformation of modern hospital healthcare. The Asian Journal of Professional & Business Studies, 2(1), 16–34. https://doi.org/10.61688/ajpbs.v2i1.146
Yusof, M. S., & Razali, H. (2020). Navigating Organisational Uncertainty Through Risk Perception and Managerial Judgement. The Asian Journal of Professional & Business Studies, 1(1), 76–92. https://doi.org/10.61688/ajpbs.v1i1.69
Yusof, M. S., Salleh, M. N., & Zahari, F. M. (2020). The Relationship between Information Technology Capability and New Product Development Success: A Conceptual Framework. International Journal of Business and Technology Management, 2(1), 98-112.
Yusof, M. S., Salleh, M. N., & Zahari, F. M. (2020). The Relationship between NPD Process and NPD Strategy toward NPD Success in Malaysian Automotive Industry. Asian Journal of Research in Business and Management, 2(1), 11-26.
Yusof, M. S., & Salleh, M. N. (2021). Beyond manufacturing towards innovation-driven new product development in Malaysia’s automotive industry. The Asian Journal of Professional & Business Studies, 2(1), 35–52. https://doi.org/10.61688/ajpbs.v2i1.152
Zhang, J., & He, W. (2019). Enterprise cybersecurity training and awareness programs: Recommendations for success. Journal of Organizational and End User Computing, 31(4), 1–18.
Zhang, T., Tao, D., Qu, X., Zhang, X., Zeng, J., Zhu, H., & Zhu, H. (2020). Automated vehicle acceptance in China: Social influence and initial trust are key determinants. Transportation Research Part C: Emerging Technologies, 112, 220–233.
Zwilling, M., Klien, G., Lesjak, D., Wiechetek, Ł., Çetin, F., & Basim, H. N. (2020). Cyber security awareness, knowledge and behavior: A comparative study. Journal of Computer Information Systems, 62(1), 82–97. https://doi.org/10.1080/08874417.2020.1712269
Authors
Copyright (c) 2025 MUHAMMAD SHAHID KAMARUDIN, AHMAD IQHWAN AHMAD NADZRI, MUHAMMAD HAKIMI SHAHARUDIN, ZULAKMAL AMIRUDDIN

This work is licensed under a Creative Commons Attribution 4.0 International License.
https://www.explorationpub.com/ueditor/php/upload/image/20220407/1649295240380692.png