article وصول مفتوح

Cyber risk management: an illusion of a risk-based approach

  • Journal of Management Control
  • Springer Science+Business Media
Research footprint

At a glance

الاستشهادات
7
المراجع
86
Comments
0
Paper overview

Abstract

Abstract In this study, we investigate how organizations align qualitative and quantitative approaches to measure and manage cyber risk effectively. Cyber risk involves the potential compromise of data integrity, availability, or confidentiality due to attacks or incidents. We draw on the theoretical framework of calculative cultures, describing the qualitative and quantitative organizational approaches to risk management. We conducted twenty-seven in-depth interviews with individuals involved in cyber risk management from five multi-billion-dollar organizations. We find that while organizations claim to rely on risk-based (quantitative) management, they measure cyber risk qualitatively with a ‘quantitative veneer’ - that is, merely giving the appearance of using quantitative methods. This mismatch creates the illusion of a risk-based approach. We extend the literature of calculative cultures with the concept of 'qualculation'. It combines qualitative and quantitative approaches and suggests that 'qualculation', not quantification, is the highest standard that could be attained in aligning measurement and management of cyber risk.

Record transparency

Publication details

DOI
10.1007/s00187-025-00401-z
OpenAlex
W4414345534
Document type
article
Language
EN
Source
Journal of Management Control
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.