Please use this identifier to cite or link to this item: http://hdl.handle.net/1893/37988
Appears in Collections:Accounting and Finance Journal Articles
Peer Review Status: Refereed
Title: The Role of CEO Power and Audit Committees in Cybersecurity Risk Management
Author(s): Al-Shaer, Habiba
Albitar, Khaldoon
Derouiche, Imen
Hussainey, Khaled
Contact Email: habiba.al-shaer@stir.ac.uk
Keywords: cybersecurity
cybersecurity risk management
CEO power
audit committees.
Date Deposited: 19-Jan-2025
Citation: Al-Shaer H, Albitar K, Derouiche I & Hussainey K (2025) The Role of CEO Power and Audit Committees in Cybersecurity Risk Management. <i>The International Journal of Accounting</i>. https://doi.org/10.1142/S1094406025420041
Abstract: The research problem Considering cybersecurity as a strategic ethical decision rather than a technical concern, the study explores how CEO power and audit committees (ACs) impact cybersecurity risk management (CRM) and what role other CEO attributes play in shaping this nexus. Previous research has provided limited insight into the possible factors influencing CRM. This study addresses this research gap. Motivation or theoretical reasoning We are motivated by the lack of empirical evidence on the role of CEO power and ACs in CRM. The study uses stewardship and resource dependence theories to explain how CEO power and ACs influence CRM. The test hypotheses H1: CEO power is positively associated with CRM. H2: AC characteristics are positively associated with CRM. Target population The study is based on a sample of non-financial companies listed on the London Stock Exchange (FTSE-All-Share) from 2014 to 2020, totalling 1,036 firm-year observations. Adopted methodology. The study uses the Probit model. Analyses The paper uses different measures of CEO power and ACs. It also undertakes additional analyses that control for CEO attributes, such as tenure, age, and nationality, as well as firm-specific characteristics, including firm size, firm risk, and financial health. Findings Our findings show that powerful CEOs are more likely to be associated with CRM. Furthermore, effective ACs are more likely to exercise greater oversight over cybersecurity risk. These effects are stronger in firms with younger CEOs, CEOs with shorter tenure, or CEOs of diverse nationalities. Powerful CEOs and ACs are more likely to be associated with CRM in large, risky, and financially healthy firms. This study calls for CEOs and ACs to take on a broader remit and provides original evidence of their role in CRM.
DOI Link: 10.1142/S1094406025420041
Rights: © 2026 World Scientific Publishing Co Pte Ltd
Notes: Output Status: Forthcoming
Licence URL(s): https://storre.stir.ac.uk/STORREEndUserLicence.pdf

Files in This Item:
File Description SizeFormat 
Cyberpaper_acceptedversion.pdfFulltext - Accepted Version778.07 kBAdobe PDFUnder Embargo until 2028-01-14    Request a copy

Note: If any of the files in this item are currently embargoed, you can request a copy directly from the author by clicking the padlock icon above. However, this facility is dependent on the depositor still being contactable at their original email address.



This item is protected by original copyright



Items in the Repository are protected by copyright, with all rights reserved, unless otherwise indicated.

The metadata of the records in the Repository are available under the CC0 public domain dedication: No Rights Reserved https://creativecommons.org/publicdomain/zero/1.0/

If you believe that any material held in STORRE infringes copyright, please contact library@stir.ac.uk providing details and we will remove the Work from public display in STORRE and investigate your claim.