PURPOSE: The primary objective of this study is to identify institutional environments (institutional-level factors) and corporate characteristics (organizational-level factors) associated with cybersecurity performance, and to assess their importance in explaining differences in cybersecurity performance across organizations. METHODOLOGY: We apply binary logistic regression to firm-level data from the Orbis database to examine how institutional- and organizational-level factors are associated with cybersecurity performance. The dataset covers companies operating in the United States, Europe, and China in 2022, comprising 1,211 observations. FINDINGS: Companies in China, Northern Europe and Southern Europe underperform those in the United States in terms of cybersecurity performance. Firms in the financial and healthcare sectors exhibit stronger cybersecurity performance, while higher financial leverage, larger firm size, and greater profitability (ROE) are associated with lower cybersecurity performance levels. IMPLICATIONS: From a theoretical perspective, our study supports the usefulness of an institutional approach to cyber risk, complementing and extending the investment-oriented perspective that currently dominates the literature. Our findings also offer insights for investors seeking to reassess asset allocation strategies in light of cybersecurity-related risk exposure. They inform managers aiming to identify best practices for safeguarding corporate value against cyber threats, and support policymakers in identifying where voluntary business cybersecurity practices underperform and may require complementary regulatory or policy measures. ORIGINALITY & VALUE: This study is the first to analyze multi-level patterns of cybersecurity performance on an international scale. It contributes to the existing literature by revealing the regional and sectoral distribution of cybersecurity performance and demonstrating that firms with greater financial risk exposure may also be more susceptible to cyber risks, thereby amplifying potential adverse outcomes.

Patterns of cybersecurity performance in corporations: International evidence / Doś, A., Flori, E., Łasak, P., Pattarin, F.. - In: JOURNAL OF ENTREPRENEURSHIP, MANAGEMENT AND INNOVATION. - ISSN 2299-7075. - 22:3(2026), pp. 130-162. [10.7341/20262237]

Patterns of cybersecurity performance in corporations: International evidence

Flori, Elisa
Secondo
;
2026-01-01

Abstract

PURPOSE: The primary objective of this study is to identify institutional environments (institutional-level factors) and corporate characteristics (organizational-level factors) associated with cybersecurity performance, and to assess their importance in explaining differences in cybersecurity performance across organizations. METHODOLOGY: We apply binary logistic regression to firm-level data from the Orbis database to examine how institutional- and organizational-level factors are associated with cybersecurity performance. The dataset covers companies operating in the United States, Europe, and China in 2022, comprising 1,211 observations. FINDINGS: Companies in China, Northern Europe and Southern Europe underperform those in the United States in terms of cybersecurity performance. Firms in the financial and healthcare sectors exhibit stronger cybersecurity performance, while higher financial leverage, larger firm size, and greater profitability (ROE) are associated with lower cybersecurity performance levels. IMPLICATIONS: From a theoretical perspective, our study supports the usefulness of an institutional approach to cyber risk, complementing and extending the investment-oriented perspective that currently dominates the literature. Our findings also offer insights for investors seeking to reassess asset allocation strategies in light of cybersecurity-related risk exposure. They inform managers aiming to identify best practices for safeguarding corporate value against cyber threats, and support policymakers in identifying where voluntary business cybersecurity practices underperform and may require complementary regulatory or policy measures. ORIGINALITY & VALUE: This study is the first to analyze multi-level patterns of cybersecurity performance on an international scale. It contributes to the existing literature by revealing the regional and sectoral distribution of cybersecurity performance and demonstrating that firms with greater financial risk exposure may also be more susceptible to cyber risks, thereby amplifying potential adverse outcomes.
2026
3
Doś, Anna; Flori, Elisa; Łasak, Piotr; Pattarin, Francesco
Patterns of cybersecurity performance in corporations: International evidence / Doś, A., Flori, E., Łasak, P., Pattarin, F.. - In: JOURNAL OF ENTREPRENEURSHIP, MANAGEMENT AND INNOVATION. - ISSN 2299-7075. - 22:3(2026), pp. 130-162. [10.7341/20262237]
File in questo prodotto:
File Dimensione Formato  
JEMI_Vol22_Issue3_2026_Article7.pdf

accesso aperto

Tipologia: Versione editoriale (Publisher’s layout)
Licenza: Creative commons
Dimensione 764.53 kB
Formato Adobe PDF
764.53 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/500091
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 0
  • OpenAlex ND
social impact