Thesis etd-04022024-163746

Thesis type
Tesi di dottorato di ricerca
Thesis title
Uncovering the cyber side of organizational resilience. A conceptual development and a Small and Medium Enterprises investigation
Academic discipline
Course of study
tutor Prof. Niccolini, Federico
supervisore Prof. Virili, Francesco
  • cyber organizational resilience
  • cybersecurity
  • organizational resilience
  • small and medium enterprises.
Graduation session start date
Release date
Understanding and investigating organizational resilience (OR) should be interpreted as an essential facet of nowadays research. This is particularly true when confronted with the array of high-impact, even disruptive, events that organizations experience worldwide (e.g., COVID-19). Thus, a capacity for resilience is needed for organizations that want to overcome challenging conditions (Bouaziz and Hachicha, 2018).
Although been widely discussed, unresolved gaps surround the concept of organizational resilience. As an example, a missing univocal conceptual development and the “resilience to what?” debate (Hepfer and Lawrence, 2022). Nowadays, a new research domain is intended to focus on the cyber side of OR. The cyber organizational resilience (cyber-OR) challenge is a growing and evolving issue due to the large number of cyber threats affecting organizations of all sizes (WEF, 2022; Verizon Report, 2022). The current research on cyber resilience (CR), is mainly discussed in the engineering research domain and the technical focus is prevalent. However, since cybersecurity nowadays involves almost every organizational dimension, organization science is a new, yet promising field (Telay and Klein, 2021).
This dissertation focuses on cyber-OR as a construct that allows organizations, especially the small ones, to adopt a proactive approach when confronted with a cyber-attack. The research context of this dissertation is that of Italian and Swiss Small and Medium Enterprises (SMEs).
From a practical perspective, the SME count worldwide leads to a predicted approximated amount of 332.99 million SMEs worldwide in 2021 (Statista, 2023). Indeed, most enterprises in Italy and Switzerland are small ones (respectively 95.2% and 99.7 %) (ISTAT, 2023; OECD, 2022). This opens a ground for the analysis and discussion of a critical component of these country’s economic structure.
From the cybersecurity perspective, “small businesses are three times more likely to be targeted by cybercriminals than larger companies” (Segal, 2021, p. 1). The Italian and Swiss landscape has no exception with a rise in cyber-attacks, especially those included in the social engineering categories (CLUSIT, 2023; SRI, 2022). Additionally, SMEs are widely recognized for their limited access to resources, lack of cybersecurity specialists and training, and an optimistic risk appraisal (Gafni and Levy, 2023; Renaud and Weir, 2016).
However, the SME context is under-researched and various scholars have pointed it as a fruitful and necessary research avenue (Annarelli and Nonino, 2016; Pal et al., 2014), especially in the cyber domain (Sukumar et al., 2023; Wilson et al., 2022). An investigation of SMEs thus fits into a research gap in both OR and cybersecurity.
Both the Italian and Switzerland context stands as useful to understanding the cyber-OR concept due to the above-mentioned factors. Moreover, the Switzerland context stands as a contribute of the visiting period at the “Centre Universitaire d’Informatique” at the University of Geneva.
According to the above discussion, the main research question of this dissertation is: What is the current level of cyber-OR in SMEs?

Cyber-OR is a new, yet promising construct that is however highly fragmented and a consensus is far from being reached. In this sense, there is a need to extend and complement the existing literature on OR considering the cyber-attack as a triggering event.
Thus, a systematic literature review was developed following Jesson et al. (2011) prescriptions to ensure methodological rigor, transparency, and reproducibility. The analysis focused on a final set of 127 papers, of which 45 dealt with cyber-OR and 82 with OR. The analysis leads to the identification of OR and CR key features thus to the identification of both redundant and inconsistent themes in the literature. Overall, the results informed the development of an integrative conceptual framework on cyber-OR, thus adopting a complementarity-oriented approach. Moreover, the analysis leads to a novel and comprehensive conceptualization of cyber-OR (i.e., organizational resilience in the context of cyber-attacks and cybersecurity). Consistent with the literature review results, cyber-OR is defined in this research as a multifaceted concept that includes three stages, namely anticipation and preparation, response and withstand, and recover and learn. All three stages and related constructs and features are causally linked, thus emerging as functional to an effective overall level of cyber-OR. This perspective reinforces the idea of cyber-OR as a feedback process.

Based on the systematic literature review, qualitative exploratory research has been performed on the cyber-OR tools and practices implemented by Italian SMEs. Moreover, consistent with the above-mentioned SME discussion, this investigation focuses on the hindering factors faced while dealing with cybersecurity and how this affects them while implementing cyber-OR features. This study employed semi-structured interviews as a research methodology. Interviews took place during 2022 in a time range of 4 months. Each interview was administered to SMEs key informants upon permission to participate in the research and lasted an average time of 45 minutes. Theoretical saturation and information redundancy (Glaser and Strauss, 1967; Onwuegbuzie and Collins, 2007) have been reached leading to 31 interviews.
Semi-structured interviews have been then analyzed by thematic analysis following Braun and Clarke’s (2006) prescriptions alongside provisional and open coding (Boyatzis, 1998; Miles et al., 2014; Saldaña, 2021). This investigation allows for an initial assessment of cyber-OR tools and practices implemented by SMEs, as well as an understanding of whether hindering factors affect them from engaging in a cyber-OR approach and related implementation. All results considered, Italian SMEs lack in implementing cyber-OR tools and practices, especially the learning ones. Moreover, three main hindering factors have been identified (i.e., lack of awareness, budget and resource scarcity, and small organization size) as affecting cyber-OR.

Driven by the main research question, the literature review, and qualitative investigation results, a quantitative study was performed. The working hypothesis behind this proposal assumes that the organizational learning capabilities (OLCs) impact both OR and cyber-OR. Moreover, this study aimed at assessing the scores obtained in OR and cyber-OR, additionally dividing the sample into two categories, namely organizations that suffered a cyber-attack and those that had not.
An online distributed survey was disseminated via institutional contact to Swiss SMEs. The survey was based on previous studies and employed validated measures. The survey was back-translated (Brislin, 1970) from English to French language. Additionally, the survey was sent out to an expert panel to assess content validity. A five-point Likert scale (Likert, 1932) was employed for each item, which allows to stay consistent with previous literature on the employed measurement (Prayag et al., 2018; Shuaib et al., 2022; Sobaih et al., 2021; Camison and Puig-Denia, 2016).
Data analysis was based on partial least square structural equation modeling (PLS-SEM) which has been depicted as flexible in handling different model setups and dealing with relatively small sample sizes (Hair et al., 2022). Additionally, using PLS-SEM allows one to stay consistent with previous research which involved the same variables employed in this study (Jerez-Gómez et al., 2019; Prayag et al., 2018; Wang et al., 2022; Yahia Marzouk and Jin, 2022).
Results demonstrate a higher score in the evaluation of the OR measurement. However, a higher score was obtained from SMEs that suffered a cyber-attack, thus suggesting a change in their attitude after being victims of cybercrime. The hypothesis testing confirms the theoretically acknowledged (Duchek, 2020; Pal et al., 2014; Trim and Lee, 2022; Tsen et al., 2022) role of OLC in prompting OR and its cyber side.

All results considered, SMEs lack in implanting cyber-OR tools and practices. This is especially true for the learning ones. The results from the quantitative and qualitative analysis align in several aspects. The lack of post-event practices displayed by Italian SMEs and the higher score obtained from SMEs who suffered a cyber-attack, further reinforce the idea of undergoing a cyber-incident as a stimulus to practice implementation. The lack of a cybersecurity expert in Italian SMEs aligns with the lowest score obtained from Swiss SMEs in the cyber-OR governance section.

All considered the focus on cyber-OR, the SME context, and the OLCs hypothesis testing stands as a contribution in the knowledge domain since the concepts are still under-researched and an empirical validation is in need. The conceptual development of the cyber-OR concept is offered as a knowledge advancement, thus addressing the need for a thorough examination of the cyber side of OR (Bagheri and Ridley, 2017; Dalal et al., 2022). From a theoretical perspective, this study enriches the literature concerning OR and the newly established construct of cyber-OR.
The low research focus on the SME context constitutes a valuable contribution to the research domain. The emphasis on SMEs allows proposing that, in light of the results and analysis of the hindering factors, SMEs need a specific path to achieve resilience, especially its cyber side.
The quantitative contribution further confirms the fundamental role of OLCs in shaping OR and its cyber counterpart (i.e., cyber-OR). Although being widely discussed from a theoretical perspective (Vogus and Sutcliffe, 2003; Vogus and Sutcliffe, 2007) its empirical investigation is still under-researched (Orth and Schuldis, 2020). Additionally, it contributes to theory via the use of the WEF index to assess cyber-OR. Indeed, this measure has been proven statistically valuable in assessing cyber-OR. The “resilience to what?” issue in OR conceptualizations also reflect on measurement instruments which according to Cutter (2016) are still in need of properly differentiating the to what and for whom issues of resilience.
From a managerial perspective, this dissertation sheds light on the specific cyber-OR features that could be employed by managers as a roadmap. Additionally, the hindering factors identification could allow effective countermeasures to mitigate their effect. The OLCs investigations serve as a solid base for the development of enhancing practices.

