Cybersecurity Risk Management and Organisational Performance
The Moderating Role of Cybersecurity Mitigation Strategies in Saudi Insurance Companies
DOI:
https://doi.org/10.19139/soic-2310-5070-3927Keywords:
: Digital insurance, User- Interface design, Transaction swiftness, Competitiveness of insurance premiums, Information Quality, Policyholders, securityAbstract
Cybersecurity has become a strategic enterprise risk for insurers as digital transformation increases dependence on interconnected technologies and sensitive data. This study examines the relationships between cybersecurity risks and the perceived financial and operational performance of Saudi insurance companies and tests the moderating role of cybersecurity mitigation strategies. A quantitative cross-sectional survey was conducted among 150 professionals working in risk management, information technology, cybersecurity, internal audit, and related organisational functions. The proposed model was analysed using Partial Least Squares Structural Equation Modelling with SmartPLS 4.0. The results show that cybersecurity risks are negatively associated with perceived financial performance (β = −0.620, p < 0.001) and perceived operational performance (β = −0.580, p < 0.001). Cybersecurity mitigation strategies also significantly moderate both relationships. The positive interaction effects for perceived financial performance (β = 0.271, p < 0.001) and perceived operational performance (β = 0.298, p < 0.001) indicate that stronger governance, technological controls, employee awareness, regulatory compliance, and incident-response capabilities weaken the adverse performance consequences ofcybersecurity risks. The study contributes to Enterprise Risk Management and organisational resilience research by conceptualising cybersecurity mitigation strategies as integrated organisational capabilities rather than isolated technical controls. It also extends empirical cybersecurity research to the Saudi insurance sector. The findings highlight the importance of embedding cybersecurity governance, preparedness, and recovery capabilities within enterprise risk-management and business-continuity systems to support secure digital transformation.Downloads
Published
2026-08-28
How to Cite
Mosa, H. A. H., & Husin, M. M. (2026). Cybersecurity Risk Management and Organisational Performance: The Moderating Role of Cybersecurity Mitigation Strategies in Saudi Insurance Companies. Statistics, Optimization & Information Computing, 16(4), 3014–3029. https://doi.org/10.19139/soic-2310-5070-3927
License
Copyright (c) 2026 Hamed Abdallah Hamed Mosa, Maizaitulaidawati Md Husin

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).