Anna Doś, Ph.D. Hab., Associate Professor, Department of Financial Markets, Krakow University of Economics, ul. Rakowicka 27, 31-510 Kraków, Poland, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.. *Any views, interpretations, or conclusions expressed in this article are exclusively those of the authors and do not represent the official position of the journal, its editorial board, the publisher, or the authors’ affiliated institutions.
Elisa Flori, Ph.D., Department of Economics and Management, University of Trento, Via Vigilio Inama, 5, 38122 Trento, Italy, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
Piotr Łasak, Ph.D. Hab., Associate Professor, Institute of Economics, Finance and Management, Jagiellonian University, ul. Prof. S. Łojasiewicza 4, 30-348 Kraków, Poland, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it., corresponding author.
Francesco Pattarin, Prof. Dr., ‘Marco Biagi’ Department of Economics via Jacopo Berengario, 51, 41121, Modena, Italy, e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

Abstract

PURPOSE: The primary objective of this study is to identify institutional environments (institutional-level factors) and corporate characteristics (organizational-level factors) associated with cybersecurity performance, and to assess their importance in explaining differences in cybersecurity performance across organizations. METHODOLOGY: We apply binary logistic regression to firm-level data from the Orbis database to examine how institutional- and organizational-level factors are associated with cybersecurity performance. The dataset covers companies operating in the United States, Europe, and China in 2022, comprising 1,211 observations. FINDINGS: Companies in China, Northern Europe and Southern Europe underperform those in the United States in terms of cybersecurity performance. Firms in the financial and healthcare sectors exhibit stronger cybersecurity performance, while higher financial leverage, larger firm size, and greater profitability (ROE) are associated with lower cybersecurity performance levels. IMPLICATIONS: From a theoretical perspective, our study supports the usefulness of an institutional approach to cyber risk, complementing and extending the investment-oriented perspective that currently dominates the literature. Our findings also offer insights for investors seeking to reassess asset allocation strategies in light of cybersecurity-related risk exposure. They inform managers aiming to identify best practices for safeguarding corporate value against cyber threats, and support policymakers in identifying where voluntary business cybersecurity practices underperform and may require complementary regulatory or policy measures. ORIGINALITY & VALUE: This study is the first to analyze multi-level patterns of cybersecurity performance on an international scale. It contributes to the existing literature by revealing the regional and sectoral distribution of cybersecurity performance and demonstrating that firms with greater financial risk exposure may also be more susceptible to cyber risks, thereby amplifying potential adverse outcomes.

Keywords: cybersecurity performance, corporate cybersecurity, cyber risk, cyber risk management, cybersecurity ratings, institutional theory, institutional determinants, firm-level determinants, financial leverage, operational risk