ORGANIZATIONAL DETERMINANTS OF CYBER RISK OCCURRENCE IN MALAYSIAN LOCAL AUTHORITIES

Authors

DOI:

https://doi.org/10.35631/AIJBES.829024

Keywords:

Cyber Risk Management, Cyber Risk Occurrence, Cybersecurity Policies, Cybersecurity Training, Leadership Commitment, Majlis Bandaraya Shah Alam (MBSA)

Abstract

The increasing dependence on digital infrastructure has intensified the need for effective cyber risk management, particularly within public sector organizations such as local authorities. Within the context of Majlis Bandaraya Shah Alam (MBSA), the extent to which organizational factors, including cybersecurity policies, cybersecurity training, and leadership commitment, influence Cyber Risk Occurrence (CRO) requires empirical investigation. Although these factors have been recognised as important elements of cybersecurity governance, limited context-specific evidence is available regarding their relative contribution to CRO within Malaysian local authorities. Therefore, this study examines how organizational factors, namely cybersecurity policies, cybersecurity training, and leadership commitment, influence Cyber Risk Occurrence (CRO) within MBSA.  A quantitative research design was adopted using a structured online questionnaire. Stratified random sampling was employed to ensure proportional representation of senior management (Officer A) and operational staff (Officer B). A total of 242 respondents participated in the study. Pearson correlation analysis revealed that Cybersecurity Policies (CP), Cybersecurity Training (CT), and Leadership Commitment (LC) were significantly associated with Cyber Risk Occurrence (CRO). However, multiple regression analysis identified cybersecurity training as the only significant predictor of CRO after controlling for the other organizational factors. The findings highlight the critical role of continuous employee training in strengthening organizational resilience against cyber threats. This study contributes to the cybersecurity literature by integrating Risk Management Theory, Human Capital Theory, and Transformational Leadership Theory to explain cyber risk occurrence in Malaysian local authorities. The findings also provide practical insights for policymakers, practitioners, and public sector organizations in strengthening cybersecurity governance, enhancing employee capabilities, and improving organizational cyber resilience.

 

Downloads

Download data is not yet available.

References

Aliane, N., & Zakariya, A. (2023). Enhancing cyber security resilience in the industrial sector: A comprehensive framework for third-party risk management. International Journal of Cyber Criminology, 17(2), 262–283. https://doi.org/10.5281/zenodo.4766716.

Alshaikh, M. (2020). Developing cybersecurity culture to influence employee compliance behavior. Computers & Security, 98, 101734. https://doi.org/10.1016/j.cose.2020.101734

Alshaikh, M., Maynard, S. B., Ahmad, A., & Chang, S. (2021). Policy communication & employee compliance. Section: Information security policy effectiveness, pp. 1–9. https://doi.org/10.1016/j.cose.2021.102202

Avast Business (2025). City of Atlanta Ransomware Attack. Gen Digital Inc. https://www.avast.com/en-my/business/resources/atlanta-ransomware#pc.

Bass, B. M., & Avolio, B. J. (1994). Improving organizational effectiveness through transformational leadership. Sage Publications.

Becker, G. S. (1993). Human capital: A theoretical and empirical analysis with special reference to education (3rd ed.). The University of Chicago Press.

Chong, W. F., Feng, R., Hu, H., & Zhang, L. (2025). Cyber risk assessment for capital management. Journal of Risk and Insurance, 92(2), 424–471. https://doi.org/10.1111/jori.12504

Cook, R. D. (1979). Influential observations in linear regression. Journal of the American Statistical Association, 74(365), 169-174. https://doi.org/10.1080/01621459.1979.10481634

Cortina, J. M. (1993). What is coefficient alpha? An examination of theory and applications. Journal of Applied Psychology, 78(1), 98. https://doi.org/10.1037/0021-9010.78.1.98

Cyber Security Agency of Singapore. (2021). Singapore cybersecurity strategy, pp. 18–25.

https://www.csa.gov.sg/Strategy/singapore-cybersecurity-strategy

Cyber Security Agency of Singapore. (2021). The Singapore Cybersecurity Strategy 2021 (Policy document). Government of Singapore. https://www.csa.gov.sg/resources/publications/the-singapore-cybersecurity-strategy-2021/

Daoud, J. I. (2017, December). Multicollinearity and regression analysis. Journal of Physics: Conference Series, 949(1). https://doi.org/10.1088/1742-6596/949/1/012009

Das, K. R., & Imon, A. H. M. R. (2016). A brief review of tests for normality. American Journal of Theoretical and Applied Statistics, 5(1), 5-12. https://doi.org/10.11648/j.ajtas.20160501.12

Equifax Inc. (2017). Equifax announces cybersecurity incident involving consumer information, pp. 4–7.

https://www.equifax.com/personal/education/identity-theft/articles/-/learn/equifax-data-breach/

European Union Agency for Cybersecurity (ENISA),2022. Cybersecurity training, skills development, phishing and credential misuse in public sector organisations. Pages 22–35.

European Union Agency for Cybersecurity. (2026). Cybersecurity certification framework. ENISA. https://www.enisa.europa.eu/topics/product-security-and-certification/cybersecurity-certification-framework

Fabritius, P. (2019). Baltimore ransomware attack costs city over $18 million. Government Technology.

https://www.govtech.com/security/Baltimore-Ransomware-Attack-Costs-City-Over-18M.html

Fabritius, W. (2019). July 25). Ransomware attack shows Baltimore’s lack of organizational resilience. https://www.route-fifty.com/digital-government/2019/07/ransomware-baltimore-organizational-resilience/158314/

Goswami, S. S., Sarkar, S., Gupta, K. K., & Mondal, S. (2023). The role of cyber security in advancing sustainable digitalization: Opportunities and challenges. Journal of Decision Analytics and Intelligent Computing, 3(1), 270–285. https://doi.org/10.31181/jdaic10018122023g

Goswami, S., Dey, S., & Mukherjee, S. (2023). Human factors in cybersecurity risk management: A systematic review. Computers & Security, 124, 102973, pp. 6–12.

https://doi.org/10.1016/j.cose.2022.102973

Gupta, A., & Remella, S. (2025). Building resilience in hybrid cloud systems: Security frameworks for mission‑critical applications — A systematic literature review. International Journal of Computer Science and Mobile Computing, 14(9), 52–62. https://doi.org/10.47760/ijcsmc.2025.v14i09.008

Hair, J. F., Hult, G. T. M., Ringle, C. M., Sarstedt, M., & Thiele, K. O. (2017). Mirror, mirror on the wall: A comparative evaluation of composite-based structural equation modeling methods. Journal of the Academy of Marketing Science, 45(5), 616-632. https://doi.org/10.1007/s11747-017-0517-x

Heal, R., & Twycross, A. (2015). Validity and reliability in quantitative research. Evidence-Based Nursing, 66-67. https://doi.org/10.1136/eb-2015-102129

Herath, T., & Rao, H. R. (2009). Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness. Decision Support Systems, 47(2),154–165.

https://doi.org/10.1016/j.dss.2009.02.005

Herath, T., & Rao, H. R. (2009). Protection motivation and deterrence: A framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106–125. https://doi.org/10.1057/ejis.2009.6

https://www.enisa.europa.eu/publications/cybersecurity-skills-development

https://www.iso.org/standard/27001

InfoMSP. (2025, May 30). Definition of cyber risk management. InfoMSP. https://www.infomsp.com/whatis/definition/cyber-risk-management/

Insurica (2025, April 25). Cyber case study: Colonial Pipeline ransomware attack. Insurica. https://insurica.com/blog/colonial-pipeline-ransomware-attack/

International Organization for Standardization. (2018). ISO/IEC 27005:2018 — Information technology — Security techniques — Information security risk management. ISO, Clauses 6–8.

https://www.iso.org/standard/75281.html

International Organization for Standardization. (2022). ISO/IEC 27001:2022 — Information security management systems — Requirements. https://www.iso.org/standard/27001

ISO/IEC (2022), Information Security Management governance. ISO/IEC 27001:2022 – Clause 5 (Leadership), Clause 6 (Planning), Annex A.5 (Information Security Policies)

Jackson, S. L. (2012). Research methods and statistics: A critical thinking approach (4th ed.). Wadsworth Publishing.

Kenton, W. (2025, October). Durbin Watson Test explained: Understanding autocorrelation in regression analysis. Investopedia. https://www.investopedia.com/terms/d/durbin-watson-statistic.asp

Kline, R. B. (2011). Principles and practice of structural equation modeling (5th ed.). The Guilford Press.

Masson, V. L. (2025, June 26). The magic number: How to optimize and improve your survey response rate. Kantar.

Mohajan, H. K. (2017). Two criteria for good measurements in research: Validity and reliability. Economic Series, 17(4), 59-82.

National Audit Office – NAO (2018), National Health Service – WannaCry ransomware attack, Part Two: Why the attack succeeded, pp. 18–27. https://www.nao.org.uk/reports/investigation-wannacry-cyber-attack-and-the-nhs/

National Audit Office (NAO), United Kingdom, 2018. National Health Service – WannaCry ransomware attack, Staff awareness, outdated training, organisational preparedness, Pages 18–27. https://www.nao.org.uk/reports/investigation-wannacry-cyber-attack-and-the-nhs/

National Audit Office. (2018). Investigation: WannaCry cyber attack and the NHS. https://www.nao.org.uk/reports/investigation-wannacry-cyber-attack-and-the-nhs/

Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., & Jerram, C. (2017). Human behaviour, phishing awareness, password practices, cybersecurity training effectiveness. Pages 165–172. https://doi.org/10.1016/j.cose.2017.01.002

Ponemon Institute. (2020). Cost of a data breach report 2020 (Research report). IBM Security & Ponemon Institute. https://www.capita.com/sites/g/files/nginej291/files/2020-08/Ponemon-Global-Cost-of-Data-Breach-Study-2020.pd

Puhakainen, P., & Siponen, M. (2010). Improving employees’ compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757–778.

https://doi.org/10.2307/25750704

Puhakainen, P., & Siponen, M. T. (2010). Improving employees’ compliance through information systems security training: An action research study. MIS Quarterly, 34(4), 757–778. https://doi.org/10.2307/25750704

Saccenti, E., Hendriks, M. H., & Smilde, A. K. (2020). Corruption of the Pearson correlation coefficient by measurement error and its estimation, bias, and correction under different error models. Scientific Reports, 10(1), 438. https://doi.org/10.1038/s41598-019-57247-4

Sarumi, A. O., & Abdul-Raheem, I. (2022). Leadership commitment and cybersecurity governance in public organizations. Journal of Information Security and Applications, 67, 103176, pp. 5–9.

https://doi.org/10.1016/j.jisa.2022.103176

Sarumi, J., & Abdul-Raheem, I. (2022). Ethical hacking and cyber security in Nigerian telecommunication industry. Advances in Multidisciplinary & Scientific Research Journal Publication, 10(1), 1–36.

Schmitt, N. (1996). Uses and abuses of coefficient alpha. Psychological Assessment, 8(4), 350. https://doi.org/10.1037/1040-3590.8.4.350

Siponen, M., & Willison, R. (2009). Information security management standards: Problems and solutions. Information & Management, 46(5), 267–270. https://doi.org/10.1016/j.im.2008.12.007

Traynor, O. (2025, March 24). NIST Cybersecurity Framework 2.0: An Overview. https://cybelangel.com/blog/guide_nist_2/

U.S. Department of Justice (DOJ), 2018. City of Atlanta ransomware attack / Employee preparedness, cybersecurity training gaps, incident escalation, Pages 4–9. https://www.justice.gov/criminal-ccips/file/1096976/download

U.S. Government Accountability Office – GAO (2021). SolarWinds supply-chain cyberattack. GAO-21-105325, pp. 9–18 (Root causes & governance gaps). https://www.gao.gov/products/gao-21-105325

U.S. House Committee on Oversight and Reform. (2018). The Equifax data breach (Majority staff report). https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf

United Nations Department of Economic and Social Affairs. (2022). United Nations E‑Government Survey 2022: The future of digital government (Report). United Nations. https://unpan.un.org/sites/unpan.org/files/Full%20report%20and%20annexes%20%28English%29.pdf

Downloads

Published

2026-09-14

How to Cite

Paino, H., Rahmat, M., Puteh, M. S., & Rashid, M. Z. A. (2026). ORGANIZATIONAL DETERMINANTS OF CYBER RISK OCCURRENCE IN MALAYSIAN LOCAL AUTHORITIES. ADVANCED INTERNATIONAL JOURNAL OF BUSINESS, ENTREPRENEURSHIP AND SME’S (AIJBES), 8(29), 435–456. https://doi.org/10.35631/AIJBES.829024