Javascript must be enabled to continue!
Necessary but Not Sufficient? Human Factors in Internal Auditors' Cybersecurity Risk Judgment
View through CrossRef
Effective cybersecurity assurance depends on the ability of assurance providers to accurately evaluate cybersecurity risks. Despite growing investments in cybersecurity technologies, governance frameworks, and assurance mechanisms, organizations continue to experience cybersecurity incidents, raising concerns about the quality and consistency of cybersecurity risk judgments. Drawing on Social Cognitive Theory, this study examines the influence of cybersecurity skills, self-efficacy, experience, and conflict management style on cybersecurity risk judgment performance among internal auditors. Survey data from Malaysian internal auditors were analysed using Partial Least Squares Structural Equation Modelling (PLS-SEM) and Necessary Condition Analysis (NCA) to examine both sufficiency and necessity relationships. The results show that cybersecurity skills and experience positively influence cybersecurity risk judgment performance, whereas conflict management style has a significant negative effect. Self-efficacy does not directly influence performance but emerges as a necessary condition for achieving high cybersecurity risk judgment performance. Cybersecurity skills also demonstrate partial evidence of serving as an enabling condition for superior performance. The findings demonstrate that factors influencing cybersecurity risk judgment differ from those required to achieve superior performance. By integrating sufficiency and necessity perspectives, this study advances cybersecurity assurance research and highlights the complementary roles of cybersecurity skills and auditor self-efficacy in supporting effective cybersecurity assurance.
Title: Necessary but Not Sufficient? Human Factors in Internal Auditors' Cybersecurity Risk Judgment
Description:
Effective cybersecurity assurance depends on the ability of assurance providers to accurately evaluate cybersecurity risks.
Despite growing investments in cybersecurity technologies, governance frameworks, and assurance mechanisms, organizations continue to experience cybersecurity incidents, raising concerns about the quality and consistency of cybersecurity risk judgments.
Drawing on Social Cognitive Theory, this study examines the influence of cybersecurity skills, self-efficacy, experience, and conflict management style on cybersecurity risk judgment performance among internal auditors.
Survey data from Malaysian internal auditors were analysed using Partial Least Squares Structural Equation Modelling (PLS-SEM) and Necessary Condition Analysis (NCA) to examine both sufficiency and necessity relationships.
The results show that cybersecurity skills and experience positively influence cybersecurity risk judgment performance, whereas conflict management style has a significant negative effect.
Self-efficacy does not directly influence performance but emerges as a necessary condition for achieving high cybersecurity risk judgment performance.
Cybersecurity skills also demonstrate partial evidence of serving as an enabling condition for superior performance.
The findings demonstrate that factors influencing cybersecurity risk judgment differ from those required to achieve superior performance.
By integrating sufficiency and necessity perspectives, this study advances cybersecurity assurance research and highlights the complementary roles of cybersecurity skills and auditor self-efficacy in supporting effective cybersecurity assurance.
Related Results
Cybersecurity and Organisational Performance – the Interplay
Cybersecurity and Organisational Performance – the Interplay
The interplay between cybersecurity and organisational performance is multifaceted in nature, as it is related to how cybersecurity impacts and is impacted by various organisationa...
CONCEPTUALISING A FIDUCIARY DUTY ON AUDITORS
CONCEPTUALISING A FIDUCIARY DUTY ON AUDITORS
Auditors are a key feature of a company. They perform an important role as they report on a company’s financial affairs. The report is presented at the company’s general meeting fo...
Cybersecurity Knowledge Deterioration and the role of Gamification Intervention
Cybersecurity Knowledge Deterioration and the role of Gamification Intervention
Cybersecurity is becoming an overly critical issue in contemporary times. Cyberspace safety is declining, and this covers all categories of persons, businesses, institutions, and e...
Audit management, need for closure and detection of misstatements
Audit management, need for closure and detection of misstatements
Purpose
The purpose of this paper is to study whether diverting auditors to erroneous accounts leads to higher effectiveness and detection of errors. Also, this paper investigates ...
Cultivating self-efficacy to empower professionals’ re-up skilling in cybersecurity
Cultivating self-efficacy to empower professionals’ re-up skilling in cybersecurity
Purpose
The accelerated digital transformation and the growing emphasis on privacy, safety and security present ongoing challenges for cybersecurity experts. Alongside these challe...
Cybersecurity Startup Founders in Greater Washington, DC: Prior Experience Required
Cybersecurity Startup Founders in Greater Washington, DC: Prior Experience Required
The Greater Washington region is one of three leading cybersecurity industry clusters in the world. The proximity of this region to federal agencies, particularly in national secu...
The effects of computer assurance specialist competence and auditor accounting information system expertise on auditor planning judgments
The effects of computer assurance specialist competence and auditor accounting information system expertise on auditor planning judgments
While auditors' interactions with complex accounting information systems (AIS) and computer assurance specialists (CAS) play a critical role in determining audit quality (POB 2000)...
The Status Quo and Effects of Undergraduate Students’ Cybersecurity Judgment: A study in China
The Status Quo and Effects of Undergraduate Students’ Cybersecurity Judgment: A study in China
Abstract
Internet users’ cybersecurity psychology and cognition play an important role in their cybersecurity behavior. Taking 347 Chinese undergraduate students for...

