Paper Type
ERF
Abstract
Organizations continue to suffer personally identifiable information (PII) breaches despite heavy investment in security technology and compliance programs. Research on PII protection remains fragmented across technical safeguards, threat taxonomies, and privacy governance, leaving a limited understanding of how organizations integrate these elements into sustained protection capabilities. Grounded in the dynamic capabilities framework, this study develops and will empirically test an integrative moderated-mediation model in which Safeguard Portfolio Sophistication mediates the relationship between PII Threat Taxonomy Use and PII Protection Capability, and Governance and Security-Privacy Climate moderates both the first-stage and second-stage paths. The model maps sensing, seizing, and transforming onto the core dimensions of dynamic capabilities. Hypotheses will be tested using partial least squares structural equation modeling on a cross-sectional survey of senior security and privacy managers. Procedural and statistical remedies for common method bias, as well as planned robustness checks, are fully specified.
Paper Number
1451
Recommended Citation
Toffey, Paul Ackah, "Building Organizational Capabilities for PII Protection: A Dynamic Capabilities on Threat Taxonomies and Safeguard Portfolios" (2026). AMCIS 2026 Proceedings. 12.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/12
Building Organizational Capabilities for PII Protection: A Dynamic Capabilities on Threat Taxonomies and Safeguard Portfolios
Organizations continue to suffer personally identifiable information (PII) breaches despite heavy investment in security technology and compliance programs. Research on PII protection remains fragmented across technical safeguards, threat taxonomies, and privacy governance, leaving a limited understanding of how organizations integrate these elements into sustained protection capabilities. Grounded in the dynamic capabilities framework, this study develops and will empirically test an integrative moderated-mediation model in which Safeguard Portfolio Sophistication mediates the relationship between PII Threat Taxonomy Use and PII Protection Capability, and Governance and Security-Privacy Climate moderates both the first-stage and second-stage paths. The model maps sensing, seizing, and transforming onto the core dimensions of dynamic capabilities. Hypotheses will be tested using partial least squares structural equation modeling on a cross-sectional survey of senior security and privacy managers. Procedural and statistical remedies for common method bias, as well as planned robustness checks, are fully specified.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC