Cyber Resilience: An Exploration of the Limits of Professional Training and the Need to Outsource Cybersecurity Strategies
Abstract
The expansion of digitalization and increasingly difficult to manage cyber risks represent the reality of our days and the near future. In this context, our study aims to distinguish the determinants of cyber resilience of companies, with a focus on the role of professional training and the importance of outsourcing security strategies. Supported by institutional theory, our research distinguishes between the two possible roles of professional training, that of a legitimacy factor or a determinant of technical efficiency. The research hypotheses were verified with the help of a sample of 12916 companies and using a mediation model in which binary and multinomial logistic regressions were estimated, which link the perceived cyber resilience to the priority of security through professional training. The estimation results confirmed the hypothesis H1 according to which the high priority given to security increases the probability of carrying out training programs. Moreover, professional training allows to pass from perceived higher cyber risk to low risk (hypothesis H2a), but does not facilitate the transition to no risk (hypothesis H2b), thus there is a saturation point, when other factors should intervene. In addition, the research results indicate that a significant factor for strengthening perceived cyber resilience is the outsourcing of IT security services (hypothesis H3). Validation of the research hypotheses brings arguments regarding the need for a dual cyber risk management strategy, in which the continuous development of skills is accompanied by the responsible outsourcing of security services.
© 2026 Gina Cristina DIMIAN, Maria Denisa VASILESCU, Anastasia COSMA, Luminița STANCU (BROASCĂ), published by Bucharest University of Economic Studies
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.