{"id":6919,"date":"2023-09-25T10:31:16","date_gmt":"2023-09-25T08:31:16","guid":{"rendered":"https:\/\/frjournal.eu\/journal\/?p=6919"},"modified":"2023-09-28T09:54:35","modified_gmt":"2023-09-28T07:54:35","slug":"managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study","status":"publish","type":"post","link":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/","title":{"rendered":"Managing cyber risk in the financial sector: Insights from a case study"},"content":{"rendered":"<p>Chiara Crovini, Pier Luigi Marchini\/ Financial Reporting \/ 1-2023<\/p>\n<hr \/>\n<p class=\"fs-7\">Purpose: This article focuses on cyber risk as an emerging issue within the risk management process and the internal control system in the financial sector. It in-vestigates whether cyber risk management (CRM) is (dis)integrated into traditional enterprise risk management (ERM) and analyzes the external dynamics affecting the CRM design. Design\/methodology\/approach: This article draws upon institutional theory and the concept of boundary objects. The research examines a listed Italian bank and gathers the data from semi-structured interviews, direct observations, meet-ings, and archival sources. Findings: The findings underline that cyber risk rationale plays a crucial role in the CRM process. The interplay between institutional complexity and the need to manage cyber risk is critical for a bank to have a stable and flexible infrastructure. The knowledge boundaries related to the cyber risk culture require further cyber risk talk. Originality\/value: This research furthers the understanding of cyber risk and CRM as an integral part of the ERM and internal control systems in the financial sector, in which there is a shortage of case studies. The financial sector is highly regulated, and managing cyber risk has become crucial as banks usually deal with enormous amounts of personal and sensitive data stored on networks and in the cloud. Practical implications: This case study emphasizes the crucial role of CRM in the identification and reporting of cyber risk information in annual reports.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<div class=\"fusion-button-wrapper fusion-aligncenter\"><style type=\"text\/css\" scoped=\"scoped\">.fusion-button.button-1 .fusion-button-text, .fusion-button.button-1 i {color:#ffffff;}.fusion-button.button-1 {border-width:0px;border-color:#ffffff;}.fusion-button.button-1 .fusion-button-icon-divider{border-color:#ffffff;}.fusion-button.button-1:hover .fusion-button-text, .fusion-button.button-1:hover i,.fusion-button.button-1:focus .fusion-button-text, .fusion-button.button-1:focus i,.fusion-button.button-1:active .fusion-button-text, .fusion-button.button-1:active{color:#ffffff;}.fusion-button.button-1:hover, .fusion-button.button-1:focus, .fusion-button.button-1:active{border-width:0px;border-color:#ffffff;}.fusion-button.button-1:hover .fusion-button-icon-divider, .fusion-button.button-1:hover .fusion-button-icon-divider, .fusion-button.button-1:active .fusion-button-icon-divider{border-color:#ffffff;}.fusion-button.button-1{width:auto;}<\/style><a class=\"fusion-button button-flat fusion-button-round button-large button-default button-1\" target=\"_blank\" rel=\"noopener noreferrer\" href=\"https:\/\/www.francoangeli.it\/riviste\/articolo\/73588\"><span class=\"fusion-button-text\">Read Article<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Chiara Crovini, Pier Luigi Marchini\/ Financial Reporting \/ 1-2023 Purpose: This article focuses on cyber risk as an emerging issue within the risk management process and the internal control system in the financial sector. It in-vestigates whether cyber risk management (CRM) is (dis)integrated into traditional enterprise risk management (ERM) and analyzes the external dynamics affecting [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"quote","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[30,1],"tags":[493,489,491,267,490,492],"class_list":["post-6919","post","type-post","status-publish","format-quote","hentry","category-browse-the-journal","category-financial-reporting","tag-case-study","tag-cyber-risk-management","tag-financial-sector","tag-internal-control-system","tag-multi-perspective-approach","tag-risk-information","post_format-post-format-quote"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal\" \/>\n<meta property=\"og:description\" content=\"Chiara Crovini, Pier Luigi Marchini\/ Financial Reporting \/ 1-2023 Purpose: This article focuses on cyber risk as an emerging issue within the risk management process and the internal control system in the financial sector. It in-vestigates whether cyber risk management (CRM) is (dis)integrated into traditional enterprise risk management (ERM) and analyzes the external dynamics affecting [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/\" \/>\n<meta property=\"og:site_name\" content=\"Financial Reporting Journal\" \/>\n<meta property=\"article:published_time\" content=\"2023-09-25T08:31:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-28T07:54:35+00:00\" \/>\n<meta name=\"author\" content=\"Laura Bini\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Laura Bini\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/\"},\"author\":{\"name\":\"Laura Bini\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#\\\/schema\\\/person\\\/d92fb46103bc536c63f8000f2cb595ac\"},\"headline\":\"Managing cyber risk in the financial sector: Insights from a case study\",\"datePublished\":\"2023-09-25T08:31:16+00:00\",\"dateModified\":\"2023-09-28T07:54:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/\"},\"wordCount\":328,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#organization\"},\"keywords\":[\"case study\",\"cyber risk management\",\"financial sector\",\"internal control system\",\"multi-perspective approach\",\"risk information\"],\"articleSection\":[\"Browse the Journal\",\"Financial Reporting\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/\",\"url\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/\",\"name\":\"Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#website\"},\"datePublished\":\"2023-09-25T08:31:16+00:00\",\"dateModified\":\"2023-09-28T07:54:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/2023\\\/09\\\/25\\\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Managing cyber risk in the financial sector: Insights from a case study\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#website\",\"url\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/\",\"name\":\"Financial Reporting Journal\",\"description\":\"Half-yearly journal of Financial Communication\",\"publisher\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#organization\",\"name\":\"Financial Reporting Journal\",\"url\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2017\\\/12\\\/logofr-b-e1513959052920.png\",\"contentUrl\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2017\\\/12\\\/logofr-b-e1513959052920.png\",\"width\":166,\"height\":84,\"caption\":\"Financial Reporting Journal\"},\"image\":{\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/#\\\/schema\\\/person\\\/d92fb46103bc536c63f8000f2cb595ac\",\"name\":\"Laura Bini\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g\",\"caption\":\"Laura Bini\"},\"url\":\"https:\\\/\\\/frjournal.eu\\\/journal\\\/author\\\/laurabini\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/","og_locale":"en_GB","og_type":"article","og_title":"Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal","og_description":"Chiara Crovini, Pier Luigi Marchini\/ Financial Reporting \/ 1-2023 Purpose: This article focuses on cyber risk as an emerging issue within the risk management process and the internal control system in the financial sector. It in-vestigates whether cyber risk management (CRM) is (dis)integrated into traditional enterprise risk management (ERM) and analyzes the external dynamics affecting [&hellip;]","og_url":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/","og_site_name":"Financial Reporting Journal","article_published_time":"2023-09-25T08:31:16+00:00","article_modified_time":"2023-09-28T07:54:35+00:00","author":"Laura Bini","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Laura Bini","Estimated reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/#article","isPartOf":{"@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/"},"author":{"name":"Laura Bini","@id":"https:\/\/frjournal.eu\/journal\/#\/schema\/person\/d92fb46103bc536c63f8000f2cb595ac"},"headline":"Managing cyber risk in the financial sector: Insights from a case study","datePublished":"2023-09-25T08:31:16+00:00","dateModified":"2023-09-28T07:54:35+00:00","mainEntityOfPage":{"@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/"},"wordCount":328,"commentCount":0,"publisher":{"@id":"https:\/\/frjournal.eu\/journal\/#organization"},"keywords":["case study","cyber risk management","financial sector","internal control system","multi-perspective approach","risk information"],"articleSection":["Browse the Journal","Financial Reporting"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/","url":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/","name":"Managing cyber risk in the financial sector: Insights from a case study | Financial Reporting Journal","isPartOf":{"@id":"https:\/\/frjournal.eu\/journal\/#website"},"datePublished":"2023-09-25T08:31:16+00:00","dateModified":"2023-09-28T07:54:35+00:00","breadcrumb":{"@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/frjournal.eu\/journal\/2023\/09\/25\/managing-cyber-risk-in-the-financial-sector-insights-from-a-case-study\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/frjournal.eu\/journal\/"},{"@type":"ListItem","position":2,"name":"Managing cyber risk in the financial sector: Insights from a case study"}]},{"@type":"WebSite","@id":"https:\/\/frjournal.eu\/journal\/#website","url":"https:\/\/frjournal.eu\/journal\/","name":"Financial Reporting Journal","description":"Half-yearly journal of Financial Communication","publisher":{"@id":"https:\/\/frjournal.eu\/journal\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/frjournal.eu\/journal\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/frjournal.eu\/journal\/#organization","name":"Financial Reporting Journal","url":"https:\/\/frjournal.eu\/journal\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/frjournal.eu\/journal\/#\/schema\/logo\/image\/","url":"https:\/\/frjournal.eu\/journal\/wp-content\/uploads\/sites\/3\/2017\/12\/logofr-b-e1513959052920.png","contentUrl":"https:\/\/frjournal.eu\/journal\/wp-content\/uploads\/sites\/3\/2017\/12\/logofr-b-e1513959052920.png","width":166,"height":84,"caption":"Financial Reporting Journal"},"image":{"@id":"https:\/\/frjournal.eu\/journal\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/frjournal.eu\/journal\/#\/schema\/person\/d92fb46103bc536c63f8000f2cb595ac","name":"Laura Bini","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0107beac750eab99e3a0d6bccffb462af0675bc9367851d6a7db3251fb66d5f5?s=96&d=mm&r=g","caption":"Laura Bini"},"url":"https:\/\/frjournal.eu\/journal\/author\/laurabini\/"}]}},"_links":{"self":[{"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/posts\/6919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/comments?post=6919"}],"version-history":[{"count":4,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/posts\/6919\/revisions"}],"predecessor-version":[{"id":6974,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/posts\/6919\/revisions\/6974"}],"wp:attachment":[{"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/media?parent=6919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/categories?post=6919"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/frjournal.eu\/journal\/wp-json\/wp\/v2\/tags?post=6919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}