As Thailand’s financial sector accelerates its digital transformation, cybersecurity has transitioned from a mere technical support function to a strategic imperative that governs operational risk and financial stability. This study empirically examines the efficacy of cyber risk controls and their correlation with perceived
[...] Read more.
As Thailand’s financial sector accelerates its digital transformation, cybersecurity has transitioned from a mere technical support function to a strategic imperative that governs operational risk and financial stability. This study empirically examines the efficacy of cyber risk controls and their correlation with perceived organizational readiness. Utilizing a quantitative survey of 53 specialized practitioners (
N = 53), we assessed maturity across the six dimensions of the Bank of Thailand’s Cyber Resilience Assessment regulatory framework: Governance, Identification, Protection, Detection, Response, and Third-Party Risk Management. While descriptive statistics indicate high overall maturity (
= 4.19, S.D. = 0.37), multiple regression analysis uncovers a critical “Protection Paradox”. Specifically, the “Protection” dimension exhibits a statistically significant negative impact on readiness (β = −0.432,
p = 0.01), suggesting that over-engineered technical controls induce operational friction. In contrast, “Identification” emerged as the primary positive driver of readiness (β = 0.627,
p < 0.01), highlighting visibility as a superior strategic lever. Furthermore, a structural disconnect was identified between strategic “Governance” and “Third-Party Risk Management” (
r = 0.46), highlighting a “Silo Effect” where board-level policy fails to effectively mitigate supply chain risks. These findings suggest that financial institutions must pivot from volume-based compliance to risk-optimized integration to bridge these strategic and operational gaps.
Full article