Search results

1 – 10 of 10
Content available
Article
Publication date: 19 June 2007

103

Abstract

Details

Industrial and Commercial Training, vol. 39 no. 4
Type: Research Article
ISSN: 0019-7858

Content available

Abstract

Details

Journal of Health Organization and Management, vol. 27 no. 3
Type: Research Article
ISSN: 1477-7266

Content available
Article
Publication date: 8 August 2008

Sara Nolan

864

Abstract

Details

Strategic HR Review, vol. 7 no. 5
Type: Research Article
ISSN: 1475-4398

Content available
Article
Publication date: 15 June 2012

Sara Nolan

686

Abstract

Details

Strategic HR Review, vol. 11 no. 4
Type: Research Article
ISSN: 1475-4398

Content available
778

Abstract

Details

European Journal of Training and Development, vol. 38 no. 1/2
Type: Research Article
ISSN: 2046-9012

Open Access
Article
Publication date: 26 May 2023

Sasha Romanosky and Elizabeth L. Petrun Sayers

The purpose of this study is to examine how companies integrate cyber risk into their enterprise risk management practices. Data breaches have become commonplace, with thousands…

2650

Abstract

Purpose

The purpose of this study is to examine how companies integrate cyber risk into their enterprise risk management practices. Data breaches have become commonplace, with thousands occurring each year, and some costing hundreds of millions of dollars. Consequently, cyber risk has become one of the gravest risks facing organizations, and has attracted boardroom-level attention. On the other hand, companies already manage many kinds of difficult and growing risks, and that firms lose less than 1% of annual revenues as a result of cyber incidents. Therefore, how should firms appropriately address cyber risk? Is it indeed a materially different kind of risk area, or is it simply just one more risk that can seamlessly be integrated into existing enterprise risk management (ERM) practices?

Design/methodology/approach

The authors performed thematic analysis based on semi-structured interviews, with non-probabilistic, purposive sampling, to answer two main questions. First, how do firms manage enterprise risks, generally? And second, how are they integrating cyber risk into these existing processes?

Findings

The authors find that there is considerable variation in the approach and sophistication in ERM practices, such as whether they are driven more like an auditing function, or as a risk champion. The authors also find that despite the novelty of cyber risk, it can be integrated like other enterprise risks, and that cyber risk is most often seen as an operational risk (similar to workplace accidents or fraud), rather than a strategic risk, emerging from, for example, technology innovation and R&D.

Research limitations/implications

The generalization of the results is limited by the sample size and variation of firms interviewed. While the authors attempted to interview enterprise risk managers across a wide variation of firms, there were clear limitations in the scope. That being said, the authors were fortunate to be able to examine ERM and cyber risk practices across small and large, private and publicly traded companies, from a variety of business sectors.

Practical implications

The authors believe these finding are important because they present evidence that while cyber risk may be new, it does not require specialized handling or processes to track it at the enterprise level. While some firms may choose to provide special accommodations or attention because of their data collection or business practices, this approach is neither necessary nor required of all firms in all situations.

Originality/value

This research is one of the only papers that, to the best of the authors’ knowledge, examines how cyber risk is integrated at an enterprise level.

Details

Management Research Review, vol. 47 no. 1
Type: Research Article
ISSN: 2040-8269

Keywords

Content available
Book part
Publication date: 20 August 1996

Abstract

Details

The Peace Dividend
Type: Book
ISBN: 978-0-44482-482-0

Content available
Book part
Publication date: 1 November 2016

Abstract

Details

Governing for the Future: Designing Democratic Institutions for a Better Tomorrow
Type: Book
ISBN: 978-1-78635-056-5

Content available
Book part
Publication date: 26 October 2020

Lee Barron

Abstract

Details

Tattoos and Popular Culture
Type: Book
ISBN: 978-1-83909-215-2

Content available
Book part
Publication date: 6 September 2021

Christian Fuchs

Abstract

Details

Communicating COVID-19
Type: Book
ISBN: 978-1-80117-720-7

Access

Only content I have access to

Year

Content type

1 – 10 of 10