Previous Article in Journal
City-Level Road Traffic CO2 Emission Modeling with a Spatial Random Forest Method
Previous Article in Special Issue
Banking on the Metaverse: Systemic Disruption or Techno-Financial Mirage?
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

Impact of Security Management Activities on Corporate Performance

1
Graduate School of Management of Technology, Sungkyunkwan University, Suwon 16419, Republic of Korea
2
Department of Systems Management Engineering, Sungkyunkwan University, 2066 Seobu-ro, Jangan-gu, Suwon 16419, Republic of Korea
*
Author to whom correspondence should be addressed.
Systems 2025, 13(8), 633; https://doi.org/10.3390/systems13080633
Submission received: 17 June 2025 / Revised: 13 July 2025 / Accepted: 21 July 2025 / Published: 28 July 2025

Abstract

The digital business environment is rapidly evolving with advancements in information technology (IT), increasing the risk of information security incidents. Grounded in the resource-based view and in contingency theory, this study adopts a different approach from prior research by conceptualizing security management activities not as mere risk control mechanisms, but as strategic innovation drivers that can enhance corporate performance (sales revenue and operating profit). The authors develop a research model with six independent variables, including internal and external security management activities, CISO role configuration (independent or dual-role with CIO), and investment levels in IT and information security. The dependent variables include sales revenue and operating profit, with ISMS or ISO certification as a moderating variable. Using information security (IS) disclosures and financial data from 545 Korean firms that have reported their security management activities to the Ministry of Science and ICT, multiple regression and moderation analyses reveal that high IT investment negatively impacts performance, but this effect is mitigated when formal security systems, like ISMS or ISO, are in place. The results suggest that integrating recognized security frameworks into management strategies can enhance both innovation and financial outcomes, encouraging a proactive approach to security management.
Keywords: resource-based view (RBV); contingency theory; security management activities; CISO (Chief Information Security Officer); CIO (Chief Information Officer); multiple regression analysis; moderation effect analysis; ISMS (Information Security Management System); ISO (International Organization for Standardization) resource-based view (RBV); contingency theory; security management activities; CISO (Chief Information Security Officer); CIO (Chief Information Officer); multiple regression analysis; moderation effect analysis; ISMS (Information Security Management System); ISO (International Organization for Standardization)

Share and Cite

MDPI and ACS Style

Cho, H.; Cho, K. Impact of Security Management Activities on Corporate Performance. Systems 2025, 13, 633. https://doi.org/10.3390/systems13080633

AMA Style

Cho H, Cho K. Impact of Security Management Activities on Corporate Performance. Systems. 2025; 13(8):633. https://doi.org/10.3390/systems13080633

Chicago/Turabian Style

Cho, Hyunwoo, and Keuntae Cho. 2025. "Impact of Security Management Activities on Corporate Performance" Systems 13, no. 8: 633. https://doi.org/10.3390/systems13080633

APA Style

Cho, H., & Cho, K. (2025). Impact of Security Management Activities on Corporate Performance. Systems, 13(8), 633. https://doi.org/10.3390/systems13080633

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop