Paper Type

ERF

Abstract

This study examines the impact of Top Management Team (TMT) involvement on cybersecurity performance, distinguishing between two critical outcomes: prevention (incident occurrence) and recovery (restoration time). Grounded in Upper Echelons Theory and the attention-based view, we deconstruct TMT involvement into two dimensions: breadth (cross-functional participation) and depth (intensity of engagement). Using a pooled cross-sectional dataset of 8,352 firm-year observations from the UK Cyber Security Breaches Survey (2018–2021), we propose that TMT breadth primarily enhances preventive vigilance, while TMT depth is more effective at accelerating post-incident recovery. Furthermore, we investigate how external stakeholder feedback moderates these relationships by amplifying executive accountability and information quality. By bridging the gap between ex ante governance and ex post response, this research provides a nuanced framework for building organizational cyber resilience and offers strategic insights for executives navigating an increasingly complex digital threat landscape.

Paper Number

1558

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Prevention or Recovery? Untangling the Effects of Top Management Team Governance on Cybersecurity Incidents

This study examines the impact of Top Management Team (TMT) involvement on cybersecurity performance, distinguishing between two critical outcomes: prevention (incident occurrence) and recovery (restoration time). Grounded in Upper Echelons Theory and the attention-based view, we deconstruct TMT involvement into two dimensions: breadth (cross-functional participation) and depth (intensity of engagement). Using a pooled cross-sectional dataset of 8,352 firm-year observations from the UK Cyber Security Breaches Survey (2018–2021), we propose that TMT breadth primarily enhances preventive vigilance, while TMT depth is more effective at accelerating post-incident recovery. Furthermore, we investigate how external stakeholder feedback moderates these relationships by amplifying executive accountability and information quality. By bridging the gap between ex ante governance and ex post response, this research provides a nuanced framework for building organizational cyber resilience and offers strategic insights for executives navigating an increasingly complex digital threat landscape.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.