AI-CyberDoSpeRT: assessing managerial awareness of AI-driven cyber risks
Yevgen Bogodistov, Lyubov Stafyeyeva, Christoph Steiner, Petar DespotovicPurpose
This study explores risk awareness within the domain of cybercrime, focusing on the ability to apply an appropriate risk management strategy (RMS). We identify the primary determinants of managerial cyber risk awareness and assess their influence on losses of a firm due to cybercrimes and preference for a RMS.
Design/methodology/approach
This study develops a new survey for AI-related cyber risks based on CyberDoSpeRT–AI-CyberDoSpeRT. Through a series of studies, we legitimize the measurement tools (exploratory factor analysis and confirmatory factor analysis) and apply them to predict losses due to cyberattacks and preferences for RMSs.
Findings
Cyber risk awareness emerged as a multidimensional construct. The “Awareness of Behavioral Profiles for Security Design” had a strong correlation with predicted financial losses caused by cybercrimes and was a significant predictor of the neglect of risk avoidance strategies. “Awareness of the Attack Profiles of Cybercriminals” did not have an observable impact on a firm's financial loss. However, it demonstrated a strong preference for adopting risk avoidance strategies and a weakly significant tendency toward risk mitigation strategies. Previous losses of a firm due to cyberattacks strengthened all types of risk management, particularly risk mitigation and risk acceptance.
Originality/value
This study measures managerial cybersecurity risk awareness based on various factors and reveals the relationship between managerial risk awareness and business losses suffered, as well as the preference for a RMS. We developed and tested the AI-CyberDoSpeRT scale for measuring risk awareness in the digital space and its impact on RMS selection.