scieee AI-readable full text Open interactive document viewer

Risk governance and cybercrime: The hierarchical regression approach

Erin, Olayinka Adedayo,Kolawole, Adebola Daniel,Noah, Abdurafiu Olaiya

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Erin, Olayinka Adedayo; Kolawole, Adebola Daniel; Noah, Abdurafiu Olaiya Article Risk governance and cybercrime: The hierarchical regression approach Future Business Journal Provided in Cooperation with: Faculty of Commerce and Business Administration, Future University Suggested Citation: Erin, Olayinka Adedayo; Kolawole, Adebola Daniel; Noah, Abdurafiu Olaiya (2020) : Risk governance and cybercrime: The hierarchical regression approach, Future Business Journal, ISSN 2314-7210, Springer, Heidelberg, Vol. 6, Iss. 1, pp. 1-15, https://doi.org/10.1186/s43093-020-00020-1 This Version is available at: https://hdl.handle.net/10419/246627 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/ Erinetal. Futur Bus J (2020) 6:12 https://doi.org/10.1186/s43093-020-00020-1 RESEARCH Risk governance andcybercrime: thehierarchical regression approach Olayinka Adedayo Erin1*, Adebola Daniel Kolawole2 and Abdurafiu Olaiya Noah3 Abstract This study examines the impact of risk governance on cybercrime of selected listed firms in the Nigerian financial institutions. To achieve this, a sample size of 50 listed companies from the Nigerian financial sector was selected for the years 2013–2017, resulting in 250 observations. The study employed the use of hierarchical regression analysis to test the impact of risk governance variables (Chief Risk Officer_centrality, Enterprise Risk Management_index, Chief Risk Officer_presence, Board Risk Committee_size, Board Risk Committee_activism, and Board Risk Committee_independence) and other control variables such as corporate governance variables (Board Size and Board of Directors_ independence) and firm characteristics variables (Firm size and firm age) on cybercrime. The study observed from the findings that almost all the explanatory variables present a positive and significant relationship with cybercrime, except the Chief Risk Officer_presence, firm age and Board Risk Committee_size which revealed an insignificant relationship with cybercrime. The study concludes that risk governance variables and other variables are likely to reduce and minimize the impact of cybercrime on the sampled firms used in this study. Keywords: Cybercrime, Chief Risk Officer, Enterprise Risk Management, Financial loss, Nigerian financial sector, Risk governance © The Author(s) 2020. This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creat iveco mmons .org/licen ses/by/4.0/. Introduction The issue of cyber risk and crime cannot be overemphasized in today’s risk governance framework [1]. Recent high profile cases of cyber-attacks on financial institutions have drawn the attention of board executives, regulators, risk professionals, and academia in global discourse. Cybercrimes are becoming a global challenge facing most organizations in recent times especially, the financial organizations [2]. Regulators, board members, and stakeholders are seeking new ways to respond and detect material threats of cyber-attack on their organizations [3]. Regulators continue to issue guidelines on the risk management framework and board oversight functions on how to tackle emerging cybercrimes [4]. Evidence from the literature also shows that most financial institutions have devoted time and resources on their IT infrastructure in order to curb the menace of cybercrimes. For instance, PricewaterhouseCoopers (PwC) [5] opined that the evolving role of the board in risk governance is the major bedrock on which cybercrimes could be tackled in any organization. In support of this view, Soliman and Adam [6] posited that the governance structure of risk architecture is one of the most important factors to curb cybercrimes. However, due to the increase in migration of financial transactions to alternative channels such mobile money, internet banking, Point-of-Sales (POS), and others, the issue of cybercrime has become a global and major challenge for financial institutions [7, 8]. This global challenge led to the International Risk Governance Council (IRGC) in 2005 developed a risk governance framework to curb the scourge of cyber threats in financial institutions. The framework viewed risk governance as a governance process effected by the entity’s board to oversee risk management issues in organizations. The whole essence of risk governance is that board members are directly involved in the risk process, risk implementation, risk reporting, and disclosure [9–11]. Open Access Future Business Journal *Correspondence: [email protected] 1 Department of Accounting, Covenant University, Ota, Nigeria Full list of author information is available at the end of the article Page 2 of 15 Erinetal. Futur Bus J (2020) 6:12 Nigeria’s financial sector is of interest to this study because it has proven that the financial sector operates in a more volatile environment. Several studies argued [5, 12, 13] that firms in the Nigerian financial industry face a growing number of new and interrelated risks compared to their peers in other sectors. Nigerian financial industry risks are becoming increasingly difficult to quantify; hence, there is need to find an innovative way of reducing these risks and exposure [1]. KPMG [14] reported that financial institutions in Nigeria lose averagely about 10 billion naira yearly due to avoidable and unsystematic risk. They advocated for a more integrated and holistic approach to tackling risk issues in the Nigerian financial industry. There are fifty-seven (57) companies operating in the financial sector listed on the Nigerian Stock Exchange as at the end of 2017. Therefore, it is important for this study to focus on risk governance process as it relates to the financial sector in Nigeria. Marjolein etal. [15] argued that due to the regulatory pressure and the effect of cyber threats, it has become necessary for the institutionalization of risk governance both in the developed and emerging countries. Several authors [10, 13, 16, 17] found that effective risk governance framework is a major step toward prevention of cybercrimes while creating sustainable future for stakeholders. These authors believed that risk governance is linked to wealth maximization of shareholders. This means the risk governance framework has the potential impact to reduce cyber-attacks that might affect the organization’s bottom line. The resultant negative effect of cybercrime on financial institutions especially in the Sub-Saharan African countries is enormous [18, 19]. Many depositors’ funds and savings were lost due to the impact of cybercrimes. Estimates of about 500 million dollars in Sub-Saharan African countries are lost annually due to cyber-attacks [14]. This bad incidence has necessitated the different regulatory agencies in charge of financial institutions to strengthen the risk governance process in order to tackle fraudulent practices and cybercrimes. The purpose of risk governance is to institutionalize risk culture, strengthen risk management practices, reduce the incidence of cybercrimes, align strategic objectives with risk framework, and avoid the risk of systemic failure in financial institutions. Recent studies [4, 6, 13, 14, 20] on cybercrime in emerging economies especially African countries revealed that lack of risk oversight, poor attitude of board members, and ineffective cyber risk management have escalated the incidence of cybercrimes. The motivation for embarking on this study in Nigeria is that the issue of cybercrime has been on the increase especially in financial institutions in recent times. Therefore, it is critical to examine the impact of risk governance on cybercrime in emerging economies with a special focus on Nigeria. Most studies on cybercrimes are from the perspectives of the audit committee, corporate governance, and e-commerce without due consideration on the subject of risk governance in Nigeria. However, few studies [6, 9, 21] on risk management framework were limited to the subject of enterprise risk management and credit risk management without holistically considering risk governance vis-à-vis its impact on cybercrimes in Nigeria. Due to the timely importance of this study on Nigerian financial institutions and other emerging economies, we are motivated to examine this study and present our findings that could help solve the menace of cybercrimes, cyberfraud, and cyber-theft in financial institutions in Nigeria. The important question to consider is does risk governance actually impact cybercrime in financial institutions? Against this backdrop, this study seeks to examine the impact of risk governance on cybercrimes of financial institutions in Nigeria using the hierarchical regression approach. This study also recognizes other factors other than risk governance structure that could impact cybercrime. This study proposed contribution to knowledge is in twofold. First, this study adds to the existing literature in the area of risk governance, risk management, and fraud prevention and how it affects cybersecurity issues, especially in emerging economies with Nigeria as a focus. This study provides original insight on how effective risk governance impact cybercrimes of financial institutions in emerging economies with Nigeria as a focus. Secondly, this study provides relevant information on the expanded purpose of risk governance framework within risk management research and its transformative impact on fraud and crime prevention in financial institutions. The structure of the paper is organized as follows. “Literature review” section discusses the review of the literature on risk governance and cybercrime, also the theoretical framework that underpins the study. “Research methods” section discusses the methodology adopted as well as research design. Also, the models were specified. “Results” section presents information regarding the empirical results, and discussion was made, while “Discussion” section concludes the paper, presents recommendation and areas for further studies. Literature review Risk governance andcybercrime According to the Institute of Risk Management [22], digital technologies, devices, and media have brought us great benefits as well as enormous opportunities, but their use also exposes us to significant risks. The incidences of cyber-attack have continued to be on Page 3 of 15 Erinetal. Futur Bus J (2020) 6:12 the increase which has now made the issue of security and resilience of IT systems; their governance and management a must to improve upon by boards and top management of businesses [7]. Imperatively, it is required by those charged with risk management within a business organization to have a full understanding of the nature of its risks exposure including the available practical tools and techniques that can be deployed to mitigate those risks. Risks exposures of business cannot be divulged from various strategies evolved by senior management and the robustness of its information technology (IT), but cyber risk as asserted by IRM [22] is not purely a matter for the IT team. Cybersecurity and cyberspace are considered as the virtual world since they are abstract in nature and as such led to an increase in cybercrime activities [23]. Risk governance is the effective protective measures that can be applied in increasingly complex cybercrime landscape [24]. Risk governance advocates the use of a preventive mechanism in safeguarding vulnerable assets of an organization. Robinson [24] noted that the use of policy guided by the principle of risk management could be employed, to help prevent security breaches and minimize losses from attacks that do get through. Klinle and Renn [4] opined that risk governance combines the institutional structure and corporate policies that help organization mitigate and reduce risk problems, especially, cyber risks. IRGC [25] believed that risk governance plays a major role in the reduction in cybercrimes in today’s contemporary risk environment. Therefore, it is imperative to examine the link between risk governance and cybercrime in today’s financial landscape. Risk governance determinants Chief risk officer centrality Liebenberg and Hoyt [26] stated that a key function of Chief Risk Officer (CRO) is to communicate risk management objectives and strategies to investors thereby ensuring greater value for firms having opaque financial health. Erin etal. [21] argued that the supervising role of a CRO ensures an effective risk governance structure. According to Erin etal. [21], all financial institutions are statutorily required to hire a CRO who will be saddled with the responsibility of overseeing risk management affairs within the organization. The study carried out by Dickinson [27] found that riskier financial institutions that have a Chief Risk Officer are more likely to form a risk management committee. Also, it is believed that the role of Chief Financial Officer (CFO) is in no way better than the CRO and that the position of CRO should not be undermined in any way [28]. Enterprise risk management Enterprise risk management (ERM) has emerged as a construct that ostensibly overcomes limitations of silobased traditional risk management (TRM) [9, 29]. The emergence of Enterprise Risk Management (ERM) in recent times has resulted in a new paradigm for managing the portfolio of risks that face organizations thereby making policymakers focus on mechanisms that help to improve corporate governance and risk management [27, 30]. McShane etal. [29] posited that the purpose of ERM is to gain a systematic understanding of the interdependencies and correlations among risks aggregated into portfolios, then hedging the residual risk, which is more efficient and value maximizing than dealing with each risk independently. The study used five categories of the Standard and Poor’s (S&P) [31] ERM insurance rating to assess the impact of management activities on firm value for a dataset of 82 worldwide insurance companies. They found the existence of a positive relationship between an increasing level of risk management and firm value, while a change from traditional risk management to ERM does not lead to an increase in shareholder value. Risk management function and technique is largely examined using a measure called the Risk Management Index (RMI). The study of Nocco and Stulz [32] described ERM at both macroand micro-level stating that it enables senior management to identify, measure, and limit to acceptable levels the net exposures faced by the firm while ensuring that all material risks are “owned,” and risk‐return trade-offs carefully evaluated, by operating managers and employees throughout the firm. ERM gives the board and senior management the enabled capacity to effectively implement risk management framework [21]. Arumona etal. [33] in their study emphasized that the board and relevant committees should work with management to promote and actively cultivate a corporate culture and environment that understands and implements enterprise-wide risk management while recommending that risk management should be tailored to a specific company. The findings of Yong [34] showed that the successful implementation of ERM relies on corporate governance, especially periodic monitoring. Board risk committee size The board is charged with the overall responsibility for the oversight function of risk and risk management [33]. Going by the recent trends in corporate governance and risk management, companies have increased the proportion of independent directors and the diversity of those directors in order to enhance board performance [35]. This underscores the need to institute an independent committee within the board that will be responsible for Page 4 of 15 Erinetal. Futur Bus J (2020) 6:12 risk management policies and framework. Financial companies covered by the Dodd-Frank Act must have dedicated risk management committees. The risk appetite and governance structure of an entity will assist in the composition of the risk committee. PwC [5] noted that risk committees provide a good way to improve board oversight of risk but not the only way to respond to the challenges. Board risk committee activism Board activism is the extent of involvement of a company’s board of directors in the affairs of an organization while measuring the scope of a board’s activities [30]. Activism promotes boardroom independence [36], and board activism increases as the proportion of outside board members increases [30]. Impliedly, it can be argued that board risk committee activism is enhanced by the proportion of independent board member in the committee. In the same vein, Boholm etal. [37] opined that board risk committee activism is intensified by the number of times the board meets in a year or quarter to discuss risk-related issues. Consistent with the view of [14, 37] revealed that board risk committee activism is indispensable in order to strengthen risk institution and governance. Chief risk officer presence Several studies have discussed the importance of chief risk officer [26, 35, 36] ranging from the appointment of a CRO as a part of ERM program to the influence of risk manager in driving and facilitating the ERM process in companies. Hoyt and Liebenberg [38] developed an analysis that evaluated the effects of Chief Risk Officer Presence and the board on the performance and risk of banks during the financial crisis with a specific focus on the European banks. Findings from the study showed that the sole presence of the CRO is not sufficient to reduce the riskiness of the bank but seems to increase risk. Although findings from the study of [13, 30] did not indicate any financial benefit for the shareholders in those companies that hired CRO. Board risk committee independence The independence of the risk committee is pivotal to risk management activities of any organization [39]. It is expected that the risk governance process is founded on sound corporate governance principles. Studies of [12, 13] argued that the inclusion of independent persons in the risk committee will further strengthen the risk culture, risk architecture, and risk disclosure. Also, the study of Peters etal. [40] revealed that independent directors that are knowledgeable in risk and financial matters are skilled in financial models in evaluating projects that have a positive and significant impact on the organization. Other factors Corporate governance determinants Board of directors independence Board independence is a central issue in risk governance practice. Board independence is to ensure that the board is objective enough to act in the best interests of the company’s stakeholders [41]. It is the responsibility of the board to provide oversight function regarding risk strategy, risk implementation, risk compliance, and risk disclosure [30]. However, the board of directors in many organizations are unaware of their responsibility in developing and providing management guidance regarding risk management strategy within the organization. Decker and Galer [42] revealed that the board of director independence is a crucial factor in risk governance in any organization. The independence of the board should be clearly distinct from the management’s responsibility of implementing the risk strategies developed by the board of directors. The study of Beasley etal. [30] found that the board of director independence positively influenced ERM implementation among firms. Board size The size of the board is one of the major determining factors in corporate governance principle [43]. Similarly, Rochette [44] argued that firms with high board size have a greater tendency to adopt a holistic risk management system and follow the risk governance process. Also, Pagach and Warr [13] revealed that board size plays a determining factor in risk governance, risk implementation, and risk disclosure. Consistent with the view of Rochette [44] and Beasley etal. [30] found that most financial institutions with diverse board members are likely to adopt a holistic approach in tackling the issue of cybercrimes and ensure strict risk governance process. Firm characteristics determinants Firm age The subject of firm age appeared in most empirical research in finance. It is mostly used as a control variable in studies on firm performance [45], corporate diversification [46], ownership structure [47], and risk management research [13]. Firm age is viewed as the number of years of incorporation [48], even though some authors argued that firm age starts when it is listed [29]. The subject of firm age is contentious in research; however, studies opined that the age of a firm is a key determinant in firm’s sustainability, performance, and survival [49–51]. Firm size It is believed that when organization size increases, it is bound to experience different threatening events (risk) that could affect the business sustainability. Page 5 of 15 Erinetal. Futur Bus J (2020) 6:12 Beasley etal. [30] found that larger firms are more likely to commit greater resources to their risk management activities. The study of Ilaboya and Ohiokha [48] found that larger firms are more likely to take the issue of risk governance more serious than smaller firms. In tandem with this view, [7] revealed that larger firms have higher risk exposure and greater financial distress and as a result, they are more likely to implement integrated risk management and put more attention on risk governance process. Previous studies [30, 52] found a positive correlation between firm size and risk management activities. It thus means that larger firms are more willing to allocate more resources to tackle the issue of risks affecting their business operations. Based on the above issues, the study hypothesized is developed: H0 Risk governance has no significant impact on cybercrime of firms operating in the Nigerian financial sector. Conceptual model The conceptual model depicts the various variables or factors that affect cybercrime (Fig.1). The conceptual framework forms the basis on which this study is anchored and is linked to the research hypothesis. Literature gaps Previous research has been limited in empirically showing the relevance of risk management in financial institutions in Nigeria [6, 9, 49, 53–55]. The research gap identified with these previous studies only examined risk management from the perspective of firm performance and firm value without holistically considering the impact of risk governance on cybercrime. Also, previous studies have only been limited to the banking sector without researching the financial sector as a whole. Against this backdrop, this study seeks to extend the frontier of knowledge by filling the identified gap. Theoretical consideration The theory of legitimacy has been a popular theory in the field of management and accounting in recent times. It is important due to its ability in analyzing the relationship between companies and their environment. Dowling and Pfeffer [56] opined that legitimation is a process where the organization has the right to transform, import, and export information within the organizational context. Legitimacy theory is derived organizational legitimacy which means a firm’s value system is congruent within the large social system of which the firm is a part. Deegan [57] considered the legitimacy theory as a social contract between the organization and the society in which it operates. They argued that values and norms within the society are not fixed but continuously changing over time. The continuous societal value has heightened social expectation; therefore, for the organization to be successful, it has to be attentive to societal (environmental, human, and social) needs. Risk management and governance are considered as a legitimate function the organization has to fulfill in order to create value for its stakeholders [58, 59]. Many researchers argued that risk management and governance must meet the societal needs in order to be considered relevant and successful especially in mitigating cybercrimes [30, 60, 61]. Most studies viewed legitimacy theory with respect to organizational dynamics and value creation in determining risk governance process [6, 62]. These authors argued that societal pressure was heightened after the corporate scandals experienced in recent times. These corporate failures increased regulatory and stakeholders’ pressure on the need for organizations to adopt more rigorous corporate governance and risk management framework in creating value and performance. Some studies revealed that is legitimate for the organization to adopt a risk process that will facilitate the firm’s performance, growth and reduce cybercrimes. Mikes and Kaplan [63] considered legitimacy has an important resource in which organization is dependent for its survival. Their study claimed that legitimacy as a resource can be achieved through disclosure strategies. Also, Bromiley etal. [12] and Shima etal. [64] explained that in recent times, corporate legitimation strategies have increased focus on risk management practices with regard to firm’s reputation. Reputation risk studies emphasized the importance of legitimacy theory for financial growth of the organization. It is considered a good resource for future profit which invariably affects the firm’s long-term sustainability. 9 Cybercrime BRC Independence BRC Acvism BRC Size CRO Centrality CRO Presence ERM Implemen taon BOD Independence Board Size Firm Size Firm Age Fig. 1 Conceptual model. Source: Developed by Authors Page 6 of 15 Erinetal. Futur Bus J (2020) 6:12 Research methods Research design This study employed panel data to examine the impact of risk governance on cybercrime of listed firms operating in financial institutions in Nigeria. This study covers the period of 2013–2017. Data were gathered across the firms over a period of five (5) years (2013–2017). The reason for the choice of the period was that the regulatory authority (Central Bank of Nigeria) in Nigeria to develop holistic risk governance framework in the Nigerian financial institutions in the year 2012 to tackle the problem of cybercrime. The CBN risk governance framework placed more emphasis on the function of the risk management committee, risk governance process, the role of the board of directors as well as developing a holistic risk management framework. Therefore, it is important to critically investigate the impact of risk governance system on cybercrimes in the Nigerian financial institutions for the period of 2013–2017. The study population consists of fifty-seven (57) firms listed on the Nigerian Stock Exchange (NSE) for the specified period. Based on Taro Yamane sampling formula, the sample size was limited to fifty (50) firms (see “Appendix1” section). We gathered our data from the annual reports of selected firms and from African financial report. This study focused on financial institutions because of its stabilizing role in the economy and its ability to prevent a systemic collapse of the entire economic system. The data were analyzed through descriptive statistics, Pearson correlation, and hierarchical regression method. Measurement ofvariables In this section, we examined the variables used in this study ranging from the dependent variable to independent variables; however, the same set of variables were used in all the study periods, respectively (Table1). ERM_Index This is derived from both corporate governance measure and risk assessment procedure. The first three variables from corporate governance (CG) measure are: Presence of CRO-1 Table 1 Measurement andoperationalization ofvariables. Source: Developed by Authors Variable(s) Symbols Operationalization Prior studies Dependent variable Financial loss (cybercrime) FINLoss Proxy by the total financial loss suffered due to cybercrime disclosed in the annual reports Baxter et al. [23] and Okoye et al. [65] Independent variables (risk gov. variables) Chief risk officer presence CRO_presence CRO is dummy variable, set equal to 1 for firms with CRO designation, and 0 otherwise McShane et al. [29] Chief risk officer centrality CRO_centrality CRO remuneration divided by CFO remuneration. Note CFO means Chief Financial Officer Cavezzali, and Garddenal [66] Board risk committee size BRC_size The total number of members on the risk committee Erin et al. [21] and [33] Board risk committee activism BRC_activism BRC activism is the number of times meeting was held in a financial year Aebi et al. [67] and Li et al. [20] Enterprise risk management index ERM_index ERM index is measured through the combination of corporate governance and risk variables Hoyt and Liebenberg [38] and Arnold et al. [68] Board risk committee independence BRC_independence The proportion of non-executive directors divided by total numbers of directors Gordon et al. [16] and Soliman and Adam [6] Corporate governance variables Board of director independence BOD_independence The proportion of non-executive directors divided by total numbers of directors Ellul and Yerramilli [41]; Board size BSIZE The actual number of directors on the firm’s board Ame, Arumona and Erin [45] Firm characteristics variables Firm Age FAGE The number of years of a firm’s existence since incorporation Baxter et al. [23] and Okoye et al. [43] Firm size FSIZE Proxy by the natural logarithm of Total Assets Uwuigbe et al. [47] Page 7 of 15 Erinetal. Futur Bus J (2020) 6:12 Risk Committee-2 Reporting frequency between Risk Committee (RC) and board of directors (BOD)—3 The other three variables from risk assessment procedure measure are: Risk Assessment frequency (RA_frequency)-4 Risk Assessment Level (RA_level)-5 Risk Assessment Methodology (RA_Method)-6 The comprehensive ERM_Index is the sum of all the six variables that ranges from 1 to 6. ERM_Index rates firms from numbers 1 to 6 depending on the level of their ERM implementation. Model specification We developed our models based on the conceptual issues reviewed in the literature. This model captured the risk governance variables (main predictor variables) examined in the literature in this study. The estimated econometric model is expressed in the following equations: Model 1 where FINLoss = Financial Loss, CRO_centrality = Chief Risk Officer Centrality, ERM_index = Enterprise Risk Management Index, BRC_size = Board Risk Committee Size, BRC_activism = Board Risk Committee Activism, CRO_presence = Chief Risk Officer Presence, BRC_independence = Board Risk Committee independence, i = 1, 2, 3,…,50 indicating the number of firms that were used for the study, t = 1, 2,…,5 indicating the time period that was used for this study (2013–2017), β1–6 = coefficient or slope of the regression line or independent variables. μit = The error term which accounts for other possible factors that could affect the dependent variable not captured in the model (the stochastic error term is assumed to be identically and independently distributed). Model 2 In order to use the hierarchical regression method, there are other corporate governance variables (other than the main predictor variables) that were added to know if it has more impact on the dependent variable. The econometric model is stated below: (1) FINLoss =f  CRO_centrality,ERM_index, BRC_size,BRC_activism, CRO _ presence , BRC _ independence) (2) FINLoss it = β 0+ β 1 CRO_centrality it +β2ERM_indexit +β3BRC_size it +β4BRC_activismit +β5CRO_presenceit +β 6BRC _ independenceit µ it where BOD_independence = Board of Directors Independence, BSIZE = Board Size, i = 1, 2, 3,…,50 indicating the number of firms that were used for the study, t = 1, 2,…,5 indicating the time period that was used for this study (2013–2017), β1–8 = Coefficient or slope of the regression line or independent variables. μit = The error term which accounts for other possible factors that could affect the dependent variable not captured in the model (the stochastic error term is assumed to be identically and independently distributed). Model 3 In order to further test the impact of risk governance on cybercrime, there are two firm characteristics variables that were added. The econometric model is stated below: where FAGE = Firm Age, FSIZE = Firm Size, i = 1, 2, 3,…,50 indicating the number of firms that were used for the study, t = 1, 2,…,5 indicating the time period that was used for this study (2013–2017), β1–10 = Coefficient or slope of the regression line or independent variables. μit = The error term which accounts for other possible factors that could affect the dependent variable not captured in the model (the stochastic error term is assumed to be identically and independently distributed). Data analysis techniques This study employed the hierarchical regression method to measure the impact of risk governance on cybercrime. The essence of hierarchical regression is to show if variables examined explain statistically significant variance in the dependent variable. Since hierarchical regression is a model comparison analysis, therefore, there is a need to account for other variables other than the main predictor variables. The study also conducted preliminary statistical analysis like descriptive statistics and correlation matrix, measurement of variables’ normality, and their relationship, respectively. (3) FINLoss it = β 0+ β 1 CRO_centrality it +β2ERM_indexit +β3BRC_sizeit +β4BRC_activismit +β5CRO_presence it +β6BRC_independenceit +β7BOD_independenceit + β8BSIZEit + µit (4) FINLoss =it=β0+β1 CRO_centrality it +β2ERM_indexit +β3BRC_sizeit +β4BRC_activismit +β5CRO_presenceit +β6BRC_independenceit +β7BOD_independenceit+β8BSIZEit + β9FAGEit + β10FSIZEit + µit Page 8 of 15 Erinetal. Futur Bus J (2020) 6:12 Table 2 Descriptive statistics FinLoss CRO_centrality ERM_index BRC_size BRC_activism CRO_presence BRC_indp BOD_indp BSIZE FAGE FSIZE Mean 23.9681 0.3126 4.3400 3.8245 3.8729 0.8100 2.1220 3.4199 8.8560 38.4600 124.3737 Median 22.7770 0.2845 4.0000 3.2347 3.4596 0.7800 2.0000 3.1223 7.5954 31.0000 114.9870 Maximum 42.7625 0.5375 6.0000 5.0000 6.0000 1.0000 3.0000 4.0000 10.0000 73.0000 252.3875 Minimum 2.2780 0.1157 3.0000 3.0000 2.0000 0.0000 1.0000 2.0000 6.0000 17.0000 39.9011 SD 10.8646 0.8829 0.8829 0.1071 0.8653 0.4499 0.1120 0.1050 2.3257 23.5973 5.7355 Skewness 1.3306 0.9783 0.1589 0.1685 1.4253 -0.9854 0.5022 0.1463 1.1901 1.3471 0.7499 Kurtosis 2.5150 2.7663 2.3095 1.6551 2.1168 1.9603 2.1929 2.6278 2.6886 2.1013 1.9961 Jarque–Bera 76.5431 45.3903 6.0188 20.0239 97.6401 51.2732 17.2959 2.3357 63.9628 121.6178 33.9307 Probability 0.0000 0.0687 0.0493 0.0000 0.0045 0.0000 0.0001 0.3110 0.0000 0.0000 0.3217 Sum 274.2035 17.8637 108.5000 56.1250 93.2401 18.0000 30.5000 104.9931 22.1400 96.1500 25.9343 Sum Sq. Dev. 23.9212 19.4100 15.5328 2.8593 34.7433 50.4000 3.1290 2.7473 13.4681 13.6521 81.9359 Observations 250 250 250 250 250 250 250 250 250 250 250 Page 15 of 15 Erinetal. Futur Bus J (2020) 6:12 44. Rochette M (2009) From risk management to enterprise risk management (ERM). J Risk Manag Financ Inst 2(4):394–408 45. Ame J, Arumona J, Erin O (2017) The impact of ownership structure on firm performance: evidence from listed manufacturing companies in Nigeria. Int J Account Finance Inf Syst 1(1):293–305 46. Campa J, Kedia S (2002) Explaining the diversification discount. J Finance 57(4):1731–1762. https ://doi.org/10.1111/1540-6261.00476 47. Uwuigbe U, Erin O, Uwuigbe O, Igbinoba E, Jafaru J (2017) Ownership structure and financial disclosure quality: evidence from listed firms in Nigeria. J Internet Bank Commerce 22(8):1–12. https ://doi.org/10.22495 / cocv1 4i4ar t8 48. Ilaboya O, Ohiokha I (2016) Firm age, size and profitability dynamics: a test of learning by doing and structural inertia hypotheses. Bus Manag Res 5(1):29–39. https ://doi.org/10.5430/bmr.v5n1p 29 49. Erin O, Ogueyungbo O, Ogundele I, Ogundele O (2017) Effect of the business model and strategic growth factors on organization value creation. J Knowl Manag Econ Inf Technol 7(4):1–17 50. Majumdar SK (1997) Impact of size and age on firm-level performance: some evidence from India. Rev Ind Organ 12:231–241. https ://doi. org/10.1023/A:10077 66324 749 51. Papatogonas E (2007) Financial performance of large and small firms: evidence from Greece. Int J Financ Serv Manag 2(1):14–20. https ://doi. org/10.1504/IJFSM .2007.01166 8 52. Golshan N, Rasid S (2012) Determinants of enterprise risk management (ERM) adoption: an empirical analysis of Malaysian Public Listed Firms. Int J Soc Hum Sci 6(1):119–126. https ://doi.org/10.5281/zenod o.10797 00 53. Dabari J, Saidin S (2015) Determinants influencing the implementation of enterprise risk management in the Nigerian banking sector. Int J Asian Soc Sci 5(12):740–754. https ://doi.org/10.18488 /journ al.1/2015.5.12/1.12.740.75 54. Obalola M, Akpan T, Abass O (2014) The relationship between enterprise risk management (ERM) and organisational performance: evidence from Nigerian Insurance Industry. Res J Finance Account 5(14):102–126 55. Ugwuanyi U, Imo G (2014) Enterprise risk management and performance of Nigeria’s brewery industry. Dev Country Stud 2(10):60–67 56. Dowling J, Pfeffer J (1975) Organizational legitimacy: social values and organizational behavior. Pac Soc Rev 18(1):122–136. https ://doi. org/10.2307/13882 26 57. Deegan C (2002) The legitimising effect of social and environmental disclosures—a theoretical foundation. Account Audit Account J 15(3):282–311. https ://doi.org/10.1108/09513 57021 04358 52 58. Andersen T (2009) Effective risk management outcomes: exploring effects of innovation and capital structure. J Strategy Manag 2(4):352– 379. https ://doi.org/10.1108/17554 25091 10038 45 59. Flora C, Leoni G (2016) Enterprise risk management (ERM) and firm performance: the Italian Case. Br Account Rev 3(1):36–50. https ://doi. org/10.1016/j.bar.2016.08.003 60. Corbett C, Kirsch D (2001) International diffusion of ISO 14000 certification. Prod Oper Manag 10(3):327–342. https ://doi. org/10.1111/j.1937-5956.2001.tb003 78.x 61. Sharma U, Lawrence S, Lowe A (2010) Institutional contradiction and management control innovation. A field study of total quality management practices in a privatized telecommunication company. Manag Account Res 21(4):251–264. https ://doi.org/10.1016/j.mar.2010.03.005 62. Arena M, Arnaboldi M, Azzone G (2012) The organizational dynamics of enterprise risk management. Account Organ Soc 35(7):659–675. https :// doi.org/10.1016/j.aos.2010.07.003 63. Mikes A, Kaplan R (2014) Managing risks: towards a contingency theory of enterprise risk management. Working paper, Harvard Business School. https ://www.hbs.edu/facul ty/Publi catio n%20Fil es/13-063_5e67d ffeaa5e-4fac-a746-7b3c0 79025 20.pdf 64. Shima N, Mahmood Z, Happy M, Akbar A (2013) Enterprise risk management and performance in Malaysia. Interdiscip J Contemp Res Bus 5(1):670–707 65. Okoye L, Adetiloye K, Erin O, Evbuomwan G (2016) Impact of banking consolidation on the performance of the banking sector in Nigeria. In: Proceedings of the 28th international business information management association conference, IBIMA 2016: Innovation Management, Development Sustainability and Competitive Economic Growth Through Vision 2020. https ://ibima .org/confe rence /28th-ibima -confe rence / 66. Cavezzali E, Garddenal G (2015) Risk governance and performance of the Italian banks: an empirical analysis. Working paper 8. Department of Management, Università Ca’ Foscari Venezia 67. Aebi V, Sabato G, Schmid M (2011) Risk management, corporate governance, and bank performance in the financial crisis. J Bank Finance 32(2):3213–3226. https ://doi.org/10.1016/j.jbank fin.2011.10.020 68. Arnold V, Benford T, Canada J, Sutton S (2011) The role of strategic enterprise risk management and organizational flexibility in easing new regulatory compliance. Int J Account Inf Syst 12(3):171–188. https ://doi. org/10.1016/j.accin f.2011.02.002 69. Securities and Exchange Commission (SEC) (2015) Corporate governance code for financial institutions. Retrieved from https ://sec.gov.ng/regul ation /rules -codes / 70. Creswell J (2014) Research design: qualitative, quantitative and mixed method approaches, 2nd edn. Sage Publications, California 71. Ojeka S, Ben-Caleb E, Ekpe E (2017) Cybersecurity in the Nigerian banking sector: an appraisal of audit committee effectiveness. Int Rev Manag Market 7(2):340–346 Publisher’s Note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.