Paper Type

Complete

Abstract

Organizations’ ability to sustain operations during crises increasingly depends on digital governance infrastructures that enable preparedness, coordination, and accountability. Yet firms differ in whether they institutionalize cybersecurity readiness through formal cybersecurity policies, an important marker for supply chains, financial stability, and service continuity. Drawing on ICT4D and crisis-resilience perspectives, we examine whether digitally enabled monitoring mechanisms, crisis management systems, internal audit reporting to the board, whistleblower protection, and a composite monitoring architecture predict cybersecurity policy presence among listed firms. Using firm-year panel data with separate estimates for the United States and Europe, we find that crisis management systems and the bundled monitoring architecture are associated with policy adoption, with the strongest and most stable effects for the composite bundle. A Mundlak within-between decomposition indicates that these relationships reflect both within-firm capability strengthening over time and persistent cross-firm differences, especially in Europe. Results position integrated monitoring as foundational crisis infrastructure.

Paper Number

1362

Comments

SIG GLOB DEV

Share

COinS
Top 25 Paper Badge
 
Aug 15th, 12:00 AM

What Drives Cyber Policy? Crisis Readiness and Resilience Across Companies

Organizations’ ability to sustain operations during crises increasingly depends on digital governance infrastructures that enable preparedness, coordination, and accountability. Yet firms differ in whether they institutionalize cybersecurity readiness through formal cybersecurity policies, an important marker for supply chains, financial stability, and service continuity. Drawing on ICT4D and crisis-resilience perspectives, we examine whether digitally enabled monitoring mechanisms, crisis management systems, internal audit reporting to the board, whistleblower protection, and a composite monitoring architecture predict cybersecurity policy presence among listed firms. Using firm-year panel data with separate estimates for the United States and Europe, we find that crisis management systems and the bundled monitoring architecture are associated with policy adoption, with the strongest and most stable effects for the composite bundle. A Mundlak within-between decomposition indicates that these relationships reflect both within-firm capability strengthening over time and persistent cross-firm differences, especially in Europe. Results position integrated monitoring as foundational crisis infrastructure.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.