Uppsats

The cost of cyber attacks on attaining organizational goals

Magister-uppsats

Blekinge Tekniska Högskola/Institutionen för industriell ekonomi

Publicerad: 2026

Språk: Engelska

Sammanfattning

IT organizations are not standalone entities. They are interconnected across a multitude of interfaces, with the internet at the backbone, leaving them vulnerable to cyberattacks. Current events and recent history show that cyberattacks are an increasing threat, preventing organizations from achieving their goals. Our study aims to highlight the direct and indirect impacts of cyberattacks, the key factors that influence these financial implications, and what some organizations are doing to mitigate them. The study is qualitative, and we collected data through interviews. We interviewed 11 cybersecurity professionals with diverse experience from multiple organizations. We used NVivo to facilitate analysis of the transcribed interviews. We derived five themes for each research question and interpreted them in the TOE framework. This study's findings underscore the multifaceted financial repercussions of cyberattacks on IT firms, including direct costs such as IT recovery, legal fines, and insurance spikes, as well as indirect impacts such as operational disruption and brand devaluation. The TOE framework highlights how technological vulnerabilities, organizational preparedness, and regulatory pressures collectively shape outcomes, reframing human factors as strategic assets when supported by training and leadership commitment. Practical insights advocate proactive measures, including zero-trust architectures, incident response planning, and integrating cyber insurance, while emphasizing sector-specific risks in reputation-sensitive industries. The findings call on organizations to balance technical defenses with cultural shifts toward cybersecurity awareness. This work lays a foundation for more resilient, adaptive cybersecurity strategies in an evolving threat landscape by addressing methodological gaps in quantifying intangible losses and advancing interdisciplinary research. Future research directions should address the gaps in our understanding of cyberattack impacts, including developing sophisticated and robust methodologies to quantify the indirect costs of cyberattacks, such as reputational damage and customer trust erosion, which remain challenging to measure despite their profound financial implications. Large-scale, interdisciplinary studies leveraging real-world data and AI-driven analytics could enhance predictive models of cyber risks while addressing privacy and data accessibility challenges. Comparative analyses across industries and regions are needed to uncover contextual vulnerabilities, particularly for SMEs and sectors like healthcare, where impacts diverge significantly. Additionally, exploring the interplay between organizational culture, leadership, and cybersecurity investment strategies will be critical to fostering resilience. Future work can advance the development of standardized metrics for cybersecurity ROI and holistic mitigation frameworks by integrating technical, behavioral, and governance perspectives.

Information

Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för industriell ekonomi
Publiceringsdatum
2026
Uppsatstyp
Magister-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.