Concepedia

Publication | Closed Access

Information technology governance and cybersecurity at the board level

170

Citations

0

References

2020

Year

TLDR

Security breaches are costly in the USA and Middle East, prompting shareholders to demand risk mitigation, so MENA firms must embed a cybersecurity culture at the board level. The study examines the relationship between information technology governance and cybersecurity levels in MENA listed firms. Data were collected via a checklist from 94 MENA‑listed firms for the year ended 2018. The analysis reveals a significant direct link between IT governance and cybersecurity, underscoring that board IT expertise leads to better cyber‑threat decisions and enables scrutiny of IT leadership.

Abstract

Security breaches are very costly in the USA, followed very closely by the Middle East. Shareholders and investors demand that their firms mitigate all kinds of risks, and it is the responsibility of the BOD to gain and maintain their confidence. In view of this scenario, MENA companies need to protect their data, while the BODs need to embed a culture of cybersecurity in the firm. The aim of this paper is to examine the relationship between information technology governance (ITG) and the level of cybersecurity by MENA listed firms. The study used a checklist to collect data from a sample of 94 firms listed in the financial stock markets of the MENA countries for the year ended 2018. The study found that there is a significant and direct relationship between ITG and the level of a firm's cybersecurity. This indicates the importance of appointing board members with IT knowledge and experience. This leads to better decisions taken by the BODs when faced with cyber-threats and challenges. In addition, IT expertise on the BODs can be important to understand what the Heads of IT are doing on the inside and, thus being knowledgeable enough to challenge their actions.