1. Cyber-Resiliency for Digital Enterprises: A Strategic Leadership Perspective
- Author
-
Jeremy Zwiegelaar, Charles Booth, Vikas Kumar, and John Loonam
- Subjects
business.industry ,Business process ,Strategy and Management ,Corporate governance ,media_common.quotation_subject ,Cyber Security ,Leadership ,CIO ,CISO ,Qualitative inquiry ,Interviews ,05 social sciences ,Mindset ,Information security ,Public relations ,Management ,Officer ,Strategic leadership ,Transformational leadership ,0502 economics and business ,Psychological resilience ,Electrical and Electronic Engineering ,business ,050203 business & management ,media_common - Abstract
As organizations increasingly view information as one of their most valuable assets, which supports the creation and distribution of their products and services, information security will be an integral part of the design and operation of organizational business processes. Yet, risks associated with cyber attacks are on the rise. Organizations that are subjected to attacks can suffer significant reputational damage as well as loss of information and knowledge. As a consequence, effective leadership is cited as a critical factor for ensuring corporate level attention for information security. However, there is a lack of empirical understanding as to the roles strategic leaders play in shaping and supporting the cyber security strategy. This study seeks to address this gap in the literature by focusing on how senior leaders support the cyber security strategy. The authors conducted a series of exploratory interviews with leaders in the positions of Chief Information Officer, Chief Security Information Officer, and Chief Technology Officer. The findings revealed that leaders are engaged in both transitional, where the focus is on improving governance and integration, and transformational support, which involves fostering a new cultural mindset for cyber resiliency and the development of an ecosystem approach to security thinking. Managerial relevance statement Our findings provide interesting insights for managers particularly those in the role of Chief Information Officers (CIOs), Chief Security Information Officers (CSIOs), and Chief Technology Officers (CTOs). We propose a Cyber Security Strategy Framework (CSSF) which can be used by these information/technology managers to design an effective organizational strategy to develop cyber resilience in their organization. Our framework suggests that managers should focus on transitional and transformational support. The transitional support focuses on improving governance and integration whereas transformational support focuses on the emphasis of fostering a new cultural mindset for cyber resiliency and the development of an ecosystem approach to security thinking. Our findings provide good evidence showing how leaders can support more effective cyber security initiatives.
- Published
- 2022
- Full Text
- View/download PDF