Abstract
In the 20th century, the increasing reliance on technology by organizations has led to a significant rise in cyber threats, including malware, ransom ware, and phishing attacks. These threats pose serious challenges to business success, jeopardizing the availability, integrity, and confidentiality of organizational assets and information. Specifically, organizations in Somalia face unique cyber security challenges due to a lack of resources and legal frameworks, resulting in a reactive approach to cyber security. The primary aim of this study is to evaluate the impact of cyber security investment on organizational performance in Bosaso, Somalia. The research seeks to analyze the current state of cyber security challenges, including inadequate legal frameworks and widespread lack of knowledge, to provide actionable insights that can guide organizations in enhancing their cyber security measures, identifying critical patterns and themes that inform best practices and strategic recommendations. Findings indicate that organizations with robust cyber security measures are better positioned to safeguard their intellectual property and sensitive data, enhancing their market position. Moreover, the research highlights that cyber security should be viewed as a strategic asset rather than merely a cost center, encouraging organizations to invest in cyber security as a means to differentiate themselves in the marketplace.
Keywords
cyber security investment organization performance framework operational customer financial.
1. Introduction
1.0 Background of the Study
The changes and innovations in information and communication technologies have enabled the rapid increase of telecommunication industries in Somalia (Abdullahi, 2020; Ismail & Ali, 2021). While Digitalization and implementation of new technologies bring numerous benefits, they also introduce digital threats, information breaches, and potential damages to organizations (Bada & Sasse, 2019). Therefore, a study on cybersecurity investment strategies and standards in modern organization is vital for the prevention and protection of sensitive data from being stolen and hacked (Khan et al., 2021; Shackle ford, 2022). This study aims to Evaluate of cybersecurity investment on organizational performance in Bosaso, Somalia. With increasing technology, ensuring the prevention and protection of sensitive information is not just a necessity; all operations and business success depend on it. Digital organizations face a hybrid of cybersecurity threats and attacks. every year, cybercriminals gain substantial knowledge and experience to damage organizations and develop new strategies. In 2023, the prevalent threats include data breaches, ransom ware, multi-factor authentication attacks, and internet of Things (IoT) attacks. However, by 2024, new threats advanced. such as AI-driven phishing, deep face attacks, and hallucinations (IBM, 2024).as threats improve, other challenges have increased the importance of strong and comprehensive cyber security measures to prevent and protect digital assets, critical infrastructure, and data loss, whether in rest or in transit. To gain customer trust and reduce the final costs of cyber security beaches, investment in cyber security is essential for organizations to enhance customer satisfaction, operational efficiency and prevent financial loses. digital organizations must improve their cyber security frameworks, standards, and policy to gain more financial stability and enhance their reputation .The increasing cyber war and cyber threats around the world are forcing organizations to invest in their fireworks (Boehme, 2020).digital organizations that have not improved their cyber security put their data and critical infrastructure at significant risk, and they face consequences for their decisions (Ponemon Institute, 2021).Somalia is a developing country on different fronts, specifically in terms of technology and innovations .Evaluating and developing cybersecurity investment in Somalia is vital for securing national and local organizations, cybersecurity infrastructure (Mohammed, 2020).protecting organizational assets reducing financial loses , and retaining customer trust are essential .as our world of innovations become increasingly complex ,the necessity for comprehensive cybersecurity -measures has become more critical than ever (McKinsey & company ,2021) . This can significantly impact the bottom line and stakeholder value. preventing and protecting sensitive data is paramount to maintaining customer trust and complying with regulatory requirements (Kshetri , 2017). This study Evaluates to the impact of cybersecurity investment on organization performance. Cybersecurity refers to the real practical of preventing and protecting systems, including resources. People, network, hardware and software, form digital threats and attacks. The main goals of cybercriminals are to access critical infrastructure, alter or destroy sensitive organization information, request money from users, or disrupt normal business process. Effective cybersecurity measures are developed by combining technologies ,standards ,and policies to prevent cyber-attacks .cybersecurity aims to improve accessibility ,integrity, and availability of sensitive data ,secure endpoints , and prevent applications from security vulnerabilities .In today’s digital age ,where cyber threats are rising , cybersecurity investment is crucial for organizations worldwide (Andress & Winterfeld, 2016) .The increase of cybercrime and cyber warfare is causing unprecedented to both private and public enterprises ,leading to a surge in IT security spending .The frequency and severity of cyber-attacks have surged in recent years .Cybercriminals employs a range of tactics .from phishing to advance AI-Based attacks ,targeting data and critical infrastructure (IBM Institute , 2024 ). The latest forecast from Gartner Inc. indicated that worldwide information security spending grew 7 percent ,reaching $86.4 billion (USD) in 2017 and projected to climb to 100 $ billion by 2024 ,driven by advanced threats such as access management and identify theft attacks (Gartner ,2023) .The rising number of phishing attacks, which involve malicious links and attachments, has resulted a significant costs for organizations .Additionally, malware attacks have affected millions of systems, with credential theft a primary cause, According to an IBM repot from 2022, data theft and leakage increased by 19% compared to 2021 (IBM, 2022) .this increase can be attributed to info stealers and insider threats. According to the X-Force Threat Intelligence report, application theft, increased due by to misconfiguration, identity and authentication attacks, and account control. Fowler (2023) reported a significant data breach involving an exposed database from real estate’s wealth network. Which contained more than 1.5 billion records, including sensitive information about owners, sellers, investors and even celebrities. In another instance, security researcher Bob Diachenko identifies Tuneful, a platform that converts music from popular services like spottily and Apple Music, which experienced a misconfiguration issue. The misconfiguration was resolved with 24 hours (Ford, 2024).A report from IT governance indicated that data breaches and cyber –attacks reached a staggering 6 billion incidents in 2023 ( Kosling , 2023 ) .according to the 2021 report by cybersecurity Ventures, worldwide cybercrime costs are expected to reach $10.5 trillion annually by 2025, a significant increase from $ 3 trillion in 2015 (cyber Ventures, 2021).This escalating threat landscape necessities substantial investment in cybersecurity to protect assets and maintain business continuity . Investing in various aspects of cybersecurity such as technology, personnel training, incident response, and regulatory compliance, is critical for organizations. These investments are designed to prevent breaches, detect intrusions, and mitigate the impact of successful attacks, which can cost organization billions in financial and reputational damages. For instance, as study from the IBM instate reported the average cost of data beach. In 2021 was $4.24 million, which can lead to unintended consequences on customer trust and brand equity (IBM, 2021) Effective and rebuts cybersecurity investments can enhances organizational performance. Organization with strong cybersecurity frameworks are better equipped to protect their intellectual property and mitigation financial risk. comprehensive protection can lead to improved customer satisfaction, operational resilience, and compliance regulatory requirements (Journal of Information Systems and cybersecurity, 2020) .In general proactively managing cybersecurity risk allows organizations to experience fewer disruption ,lower recovery costs, and improved financial performance .the prediction of rising cybercrime rates has been corroborated by major media outlets , universities , government officials , and industry expertise .the damage costs associated with recent cybercrimes are growing year over year .the increasing prevalence of state- sponsored and organized cyber warfare underscores the need for substantial cybersecurity investment .despite existing studies on the relationship between cybersecurity investment and organizational performance globally , there remains a lack of research of the effectiveness of these investment in improving organizational performance in Somali . This study aims to examine the impact of cybersecurity investment on organizational performance in Bosaso, Somalia.
1.1 Problem Statement
Somalia’s cyber security landscape is characterized by several critical vulnerabilities, one major challenges is the lack of legal framework to combat cybercrime effectively. Without enforcement laws, organizations struggle to hold cybercriminals accountable. Moreover, the limited understanding of cyber security principles among employees and management exacerbates the situation, leading to poor cyber security hygiene and practical. For instance .phishing attacks have become increasingly common, with attackers exploiting the lack of awareness to compromise sensitive information. In 2021, a significant data breach in a Somali financial institutions resulted in damages averaging $787,671 in lost hours and resources. Those breaches not only disrupted operations but also eroded public trust in digital services .Furthermore the cost of cyber breaches has escalated dramatically; in 2022 ,the average cost reached $4.35 million (Imber, 2024) . This increasing financial burden highlights the urgent need for organizations to invest in effectively cyber security measures. The rapid expansion of internet access and telecommunications In Somalia has led to a surge in the number of people using end devices. Making the country more vulnerable to cyber threats. According to estimates, Somalia’s internet penetration has grown significantly over the Past decade, bringing both opportunities and risks such as distributed denial of service (DDos) attacks on critical infrastructure, including governmental websites and service providers. the African region has been a marked increase in cyber-attacks, which poses a direct threat to critical information security infrastructure in Somalia .many organization in Somali lack of necessary resources to defend against these attacks .resulting in a reactive rather than proactive approach to cyber security, failure to implement adequate cyber security measures can have catastrophic consequences for both public and private sectors (Technologies, P., 2023).The world economic forum has reported that one million people go online for the first time each day , further complicating the cyber security landscape .while the benefits of increased internet access and digital services are undeniable ,they come with heightened risks .cyber threats ,including ransom ware and identity theft ,are on the rise ,Ransom ware attacks have particularly targeted Somalia business ,where attackers lock critical data and demand payment for its release ,causing server operational disruptions . The urgent need for cyber security –building activities is crucial in mitigating these threats. Initiatives to train employees on recognizing and responding to cyber threats can significantly reduce vulnerabilities.by for casting a culture of cyber security awareness, organization can enhance their defences against increasingly sophisticated attacks World Economic Forum. (2020, March 24) The research aims to evaluate the impact of cyber security investment on organization performance in Somalia, by analysing current state of cyber security challenges, such as inadequate legal frameworks, widespread lack of knowledge and specific threats like phish sing and ransom ware, we hope to provide actionable insights that can guide organizations in their strategies to enhance cyber security measures. Finally strengthening cyber security infrastructure both technical and management level is essential for safeguarding organization assets and ensuring long-term sustainability in an increasingly digital world.
1.2 Chapter Summary
This study evaluates the impact of cyber security investment on organization performance, focusing on the importance of robust cyber security measures improving organization’s performance including customer trust, financial performance and operation efficiency, Emphasizing the need for robust cyber security measures. While digitalization offers numerous benefits, it also exposes organizations to significant cyber threats, including data breaches and ransom ware. This chapter outlines the importance of cyber security investment in safeguarding sensitive data and enhancing organizational performance .particularly in Bosaso, Somalia. The chapter identifies critical vulnerabilities such as lack of legal firework and insufficient employee awareness ,chapter highlights urgent need for Somali organization to strengthen their cyber security framework to protect against increasingly sophisticated threats and ensure sustainable growth ,as the country continues to develop its digital infrastructure, it must prioritize investing in cyber security to safeguard against potential threats and ensure the smooth functioning of its business and community networks.
2. Review Of Literature
2.0 Introduction
Cyber security is a critical and continuously evolving discipline focused on protecting computer systems, networks, applications, and data from digital threats. In our interconnected world, where digital information is both highly valuable and susceptible to attacks, effective cyber security measures are essential to shield individuals, organizations and government from malicious activities aimed at financial exploitation, espionage, or disruption (Anderson et al 2020). In c content analysis conducted by Yasser A.Khan (2023) ,titled the national cyber security strategy of the republic of Croatia ,the author examines the dual functions of cyber security in employing information technology for both protective and aggressive purposes .the analysis clarifies the distinction between cyber security and information security ,emphasizing the primary objectives of cyber security is to defend systems from a diverse range of attacks .it also highlights the importance of integrating cyber security strategies with national policies ,particularly in relation to defence actions in both information technology and operational technology sectors .Another investigation by Bharat (2023) highlighted the role of cyber security in ensuring the confidentiality, integrity and availability of data throughout its lifecycle. This encompasses both software and hardware elements as well as the secure transmission of information online. However, the study does not delve into specific technologies or methodologies within the field. Arina Alexei’s research further elucidates the difference between cyber security and information’s security, which are often mistakenly used as synonyms. While information security primarily targets the protection of data. Cyber security has a broader scope that includes the safeguarding of all assets in cyberspace, including end-user devices, network infrastructure, and communication channels security, and business process security. According to the national Institute of Standards and Technology (NIST) , the essential functions of information security is to protect information and its associated systems from unauthorized access and usage .unauthorized access can manifest in various ways ,including the destruction ,alteration or unauthorized disclosure of data .as well as disruptions to the functionality of information systems .the overarching aim of cyber security is to maintain confidentiality ,integrity and availability ,principles commonly referred as the CIA triad , within the industry (Galarita ,2024). NIST also defines cyber security as the process of protecting, preventing damages to, and ad restoring electronic communications services and systems, which includes safeguarding the information stored with those systems. the field encompasses all elements related to electronic systems and communications, with specialized subdomains such as cloud security, network security, endpoint security, and critical infrastructure protection. Despite the technical distinctions between information security and cyber security, these terms are increasingly used interchangeably in professional discourse .it is important to consider the specific context in with these terms are utilized to grasp intended meaning fully.
Cyber security Investment
Konsutic & pigni (2022) highlights that Cyber security goes beyond traditional information security practices by protecting a company’s core business interests. They suggest using the term “cyber security" to highlight its significant in safeguarding digital assets, sensitive information, and overall business operations from cyber threats. Their findings emphasize that investment in cyber security is crucial for organizations seeking long-term competitive advantage through the development of dynamic cyber security capabilities. this approach fills a gap in existing literature by positioning cyber security as a strategic business opportunity rather than merely a technical issues.by investing strategically in cyber security, companies can distinguish themselves, enhance their resilience against involving threats, and create a secure digital environment that fosters growth and innovations.in similar vein, (Chronopoulos ,2018) conducted the vital importance of cyber security for organizations that rely on information systems. He notes that investments in cyber security are intended to reduce potential losses from cyber-attacks. particularly given the uncertainties surrounding the costs of these attacks , which further justify such investments .he also highlights that temporary halts in operations for patch installations demonstrate how the availability of cyber security updates can influence investment choices .the lack of integrated investment options may cause delays in decisions to cease operations permanently due to irreversible consequences ,reinforcing the strategic value of cyber security .understanding these dynamics is essential to avoid cycles of excessive or insufficient investment in cyber security ,which can heighten risks despite any corrective measures . (Change et al., 2016), focuses on the importance of strategic decisions-making in relation to cyber security investments. Their research shows that effective management of these investments enhances an organization’s defenses against cyber-attacks and vulnerabilities. They emphasize that proactive c cyber security strategies are vital for mitigating risks and protecting sensitive data .by examining how various organizations approach cyber security investment. Organizations can adopt best practices to strengthen their defences. Such investments significantly impact on organization’s cyber resilience and its capabilities to counteract threats. Strategic investment in cyber security not only improve risk management practices but also ensure business continuity and protect sensitive information. Organizations that priorities cyber security are better positioned to prevent data breaches, financial loses and reputational damages. All of which are essential for sustainable success. These investments reflect a commitment to protecting assets. earing customer trust, and complying with regulatory standards. Moreover, strategic decision -making in cyber security investment fosters s string security posture, enabling organizations to adapt to changing cyber threats and technological advancement. By investing proactively organizations can not only reduce risks but also promote a culture of security awareness and resilience, creating a secure operational environment t aligned with their goals and sustainability objectives. Lee (2021), emphasizes that investing in cyber security is critical for business success, as it helps to mitigate financial losses resulting from cyber breaches that can significantly impact an organization’s financial stability. investment on security technologies and data protection measures are crucial for managing risks associated with cyber-attacks, thereby ensuring business continuity and protecting sensitive data. Conducting effective cost analysis of cyber security investments offers financial justification to managers. Aiding informed resource allocation to bolster cyber security defences .by prioritizing these investments, organizations demonstrate their commitment to asset protection. Maintaining customer trust, and adhering to regulatory obligations. Investment in cyber security greatly enhance an organization’s resilience, diminish vulnerabilities to cyber threats, and support sustainable growth and competitive in today’s digital environment.Gorden (2015) , explores how government incentives and regulations affect cyber security investments in the private sector , highlighting the critical nature of cyber security in the contemporary digital landscape .he points out the necessity for organizations to adapt and optimal mix of resources to strengthen their cyber security measures ,illustrating a direct connection between effective cyber security strategies and overall organizational security .the study also evaluates organizations readiness to increase their investment in cyber security initiatives . Stressing the crucial role of proactive investments in countering cyber threats. Lastly Gordon’s work states the integral role of cyber security in modern business operations, advocating for strategic planning and potential regulatory support to enhance defences against involving cyber risks.
Cyber security Investment and Financial
Aksoy (2024) emphasized the essential role of cyber security investment in enhancing financial performance by mitigating risks associated with cyber threats. By allocating resources to cyber security initiatives, organizations can effectively reduce the potential for financial losses stemming from cyber-attacks thereby intense their financial stability. Furthermore, these investments enhance organizational resilience, preventing costly data breaches and operational interruptions .by fostering a robust cyber security culture, organizations not only protect their financial assets but also cultivate trust with stakeholders. In contrast research conducted by Tehere Hasani (2023) reveals the detriment effects of cyber-attacks on global enterprises, promoting a proactive approach towards cyber security investment .Hasani’s study integrated several theoretical frameworks ,including the diffusion of innovation ,the technology acceptance model , and the technology organization environment paradigm ,alongside the balanced scorecard approach .this multifaceted framework identifies the key factors influencing the adaption of cyber security measures and assesses their impact on organizational performance .through structural equation modelling of survey data from 147 IT experts in small and medium enterprises in the united kingdom ,the study validates the proposed model .illustrating a positive correlation between cyber security investment and enhanced organizational success .Kisson (2020) emphasizes that organizations are increasingly implanting cyber security measures aimed at monitoring and detecting cyber threats to minimize breach occurrences and enhance their cyber security framework. The decision-making process regarding cyber security controls often prioritizes technological considerations. Which can significantly influence funding allocations. Critical figures such as the Chief Information Officer (CIO) and the head of the business line, play pivotal roles in shaping decisions related to cyber security investments and the implementation of security measures. Kissoon’s findings indicate the biases and divergent viewpoint among stakeholders can affect financial performance, suggesting the need for a more unified approach to cyber security spending. Further supporting this perspective ,Gunawan ,Ratmono , & Abdullah (2023) explore the crucial role of cyber security investment in safeguarding information , financial assets , and organizational reputation against cyber threats ,investment in measure such as firewall , antivirus software , and intrusion detection systems are essential for preventing security breaches and protecting critical data .their research demonstrates that effective cyber security investments correlate with operational efficiency ,reduce down time form cyber incidents , and heightened customer trust and loyalty .organizations that prioritize cyber security are better equipped to response swiftly to secure incidents ,minimizing potential damages and ensuring business continuity . The literature consistently highlights the importance of cyber security investments in enhancing financial performance and the necessity for continues adaptation of cyber security strategies to address involving cyber threats. Dorosh (2023) asserts that such investments are pivotal in mitigating risks related to service disruptions, data breaches, and financial losses, thus reinforcing overall system stability. Effective cyber security measures not only protect assets but also maintain customer and investor confidence. Thereby safeguarding an organizations’ reputations. Financial institution can demonstrate their commitment to cyber security through investments in advance technologies, proactive monitoring, and the cultivation of cyber security-oriented culture. Dorosh advocates for ongoing updates to cyber security strategies to effective counter emerging threats, emphasizing the importance of cross-sector coloration and the sharing of threat intelligence to enhance detection and prevention capabilities. Chris Zhijun He (2020) nits the increase recognition among organizations of cyber security breaches as significant risk ,which has led to heightened investment in cybersecurity .this strategic allocations of resources has been shown to correlate positively with improve financial performance ,suggesting that proactive cyber security measures can effectively mitigate risks associated with cyber threats and bolster overall organizational resilience ,he highlighted the critical financial implications of data breach ,including remediation costs ,Leal fees ,reputational damage and loss of customer trust . Recognizing these risks highlighted the necessity of investing in rebuts cyber security measures. Not merely as a preventive strategy but as a safeguard for long-term financial stability. This dual focus emplacing the integral role of cyber security in contemporary business strategies horning risk management with value creation.R.I.Akintoye ( 2020) investigates the significant impact of cyber security investments on the financial innovation of banks ,stressing the enhancement of efficiency and the development of innovative products as key outcomes .the study highlights that effective disaster recovery plans and proactive strategies against cyber threats positively influence the financial innovation initiatives of deposit money banks in Nigeria .this research addresses a notable gap in existing literature ,which often focuses on financial performance .or cybercrime ,by underscoring the need for further exploration of how cyber security frameworks contribute to the innovative capabilities of banks .Akintoye encourages banks to advance their efforts in developing innovative products to improve operational efficiency and recommends regular revisions of risk management frameworks to address emerging challenges associated with new financial products and services .Additionally, enhancing the monitoring of e-banking channels such as card products, Point-of-sale (POS) systems and ATM’S is suggested to promote greater reliance on these channels for financial transactions. These insights underscore the dua imperative of cyber security measures, supporting innovation while reinforcing resilience against involving cyber threats, within the banking sector.
2.1.2 Cyber security Investment and Customer Trust
In today’s digital era, where businesses rely heavily on technology to store and manage vast amounts of customer data, cyber security has emerged as a critical factor in maintaining customer truss. As cyber threats become more sophisticated and prevalent, customers are increasingly concerned about the security of their personal information. This heightened awareness has elevated the importance of cyber security investment for businesses. Particularly small and medium sized enterprises (SMEs), which often face resources constraints but must prioritize protecting customer data. Investing in robust cyber security measures not only safeguard sensitive information from malicious actors but also demonstrates a company’s commitment to maintaining the privacy and security of its customers .when businesses prioritize cyber security ,they mitigate the risks of data breaches and cyber-attacks while enhancing their reputations trustworthy custodians of customer relations by reassuring clients that their information is safe and that the business takes their privacy seriously .this in turn , builds loyalty and confidence among customers ,who are more likely to choose organizations’ they trust with their personal data . Therefore, understanding the critical link between cyber security investment and customer Trust is essential for business aiming to thrive in today’s interconnected digital landscape .by investing wisely in cyber security. SME’s can protect themselves from potential threats while cultivating a competitive advantage based on a foundation of trust and reliability in their customer relationships. According to Alahmari (2021), the critical role of cyber security investment in SME’s is paramount for cultivating and preventing customer trust .proactive investment in cyber security risk management illustrates SME’s dedication to safeguarding customer data and sensitive information .Thereby enhancing organizational trust .however ,inadequate strategic decisions regarding cyber security investment can elevate risks and vulnerabilities ,potentially eroding customer trust .customers place greater faith in business that prioritize robust cyber security measures ,perceiving these efforts as proactive defences against cyber threats and unauthorized access to personal data .moreover ,cyber security investments not only protect customer data but also reduce the likelihood of security breaches and cyber-attacks ,reinforcing customer confidence in SME’s the profound impact of cyber security investment on customer trust underscores its pivotal role in shaping the reputational and credibility of SME’s .
2.2 Cyber security Investment and Operations Efficiency
Cyber security investments play a vital role in enhancing operational efficiency with organizations by allocating resources to secure digital assets and mitigate cyber threats , businesses can minimize disruptions ,safeguard sensitive data , and ensure continues operations .this proactive approach not only protects against financial losses and reputational damage but also fosters an environmental conductive to innovation and growth .additionally robust cyber security measures optimize workflow ,ensure regulatory compliance , and strengthen overall businesses resilience in today’s interconnected digital landscape . According to Shakh (2024), cyber security investment decision in organization is significantly shaped by factors such as breach costs and breach identification sources, which subsequently influence investment strategies. Higher breach costs generally lead to increase cyber security investments. Underscoring the critical importance of understanding the financial implications of security breaches on operational efficiency. Additionally, the source of breach identification plays a crucial role in in these decisions. Breaches identify by third parties often motivate organizations to enhance their cyber security investments more strongly than those identifies internally. This highlights the value of external feedback and expertise in guiding organization toward more effective security measures and increase service availability to enhance operational efficiency. Effective incident response is essential for maintaining operational efficiency, specifically when organization self-identify breaches. Internal breach identification indicates strong cyber security capabilities, which can mitigate negative media security and operational damage. By promptly addressing breaches and demon string control over cyber security incidents, organizations can safeguard their operational efficiency and overall performance. Analysing cyber security performance indicators and using them as feedback for investment decisions is crucial for organizations to implement data-driven and tailored security strategies. Leveraging insights derived from breach cost and identification sources allows organizations to align cyber security investments with specific operational needs, thereby enhancing overall efficiency and resilience against cyber threats. Previous studies by Hasan (2021) highlighted that cyber security investment is critical in improving operational efficiency through enhanced organizational security performance. This proactive strategy enables organizations to effectively mitigate cyber-attacks leading to smoother operations and reduced disruptions. Investing in cyber security measures not only strengthens defences against cyber incidents but also ensures operational continuity by minimaxing security breaches and data losses. this approach helps organizations avoid costly downtime, thereby marinating seamless operations Moreover, implementing secure and efficiency IT systems as part of cyber security measures optimizes internal workflows .but reducing redundancies and enhancing Productivity ,organizations can streamline processes and improve operational efficiency .Additionally ,cyber security investment increase customer trust and loyalist by safeguarding their data .when customers perceive an organization as reliable in data protection they are more likely to engage with its products and services .this heightened trust contributes to enhanced operational performance and efficiency . In general, strategic investments in cyber security not only mitigate risks associated with cyber threats but also optimize organizational processes and bolster customer confidence, improving overall operational efficiency. According to Chronopoulos (2018), cyber security investments are pivotal in bolstering operational efficiency with organizations by effectively minimizing potential losses from cyber-attacks .this strategy safeguards sensitive information and critical systems ,ensuring uninterrupted operations free from security breaches .strategic cyber security investments ,informed by an analytical real options framework ,empower organizations to make weal-informed decisions regarding the timing and magnitude of investments necessary to mitigate cyber security risks .by integrating key components relevant to cyber security practices , organizations can optimize their investment states to enhance operational resilience and efficiency amid involving cyber threats . The uncertainty surrounding the costs associated with cyber-threats can significantly influence the value derived from cyber security investments. potentially necessity temporary operational halts to implement essential security measures, this highlights how cyber security investment decisions directly impact operational efface by enabling organizations to address vulnerabilities proactively and fortify their cyber posture. Conversely, the absence of embedded investment options may lead to delays in critical cyber security decisions, such as permanently ceasing operations due to the irreversible consequences of such choices. the underscores the importance of strategic cyber security investments in preserving operational efface by affiliating timely and effective response to cyber security challenges thereby safeguarding the organization’s overall performance and reputation.
2.3 Conceptual Framework

2.4 Cyber security Framework
Cyber-attacks have become increasingly sophisticated and costly ,with prevalent forms including phishing ,insider threats , advanced persistent threats (APT,s) ,zero day vulnerabilities .denial -of-service attack (DoS) software flaws , social engineering tactics and brute force method .these involving threats emphasize the vital importance of cyber security in protecting sensitive data and business operation in general , and ensuring the confidentiality , integrity and availability of information . To effectively mitigate these risks, organizations must routinely update their systems. Network and connected devices while implementing robust policies governing user access and resource interaction. Two essential frameworks that facilitate these cyber security efforts are the NIST cyber security framework (NIST CSF) and the MITRE ATT&CK framework. The NIST CSF offers a comprehensive set of best practices and standards, helping organizations align their cyber security initiatives with their overall objectives and integrate them into a cohesive risk management approach. In parallel, the MITRE cyber security criteria for organization in defending against APT, s. together. These framework’s bolster cyber resilience. Empowering organization to anticipate, withstand, and recover from cyber-attacks (Möller, 2023).

The NIST cyber security Framework is structure around five essential functions to manage and reduce cyber security risks:
-
Identify – recognize an organization’s cyber security risk by assessing assets, environment, governance policies, threats and vulnerabilities to from a risk management strategy.
-
Protect – Focuses on safeguarding assets and limiting the effect s of incidents through access control, staff training, data security, and protective technology.
-
Detect – emphasizes early identification of cyber security incidents through continuous monitoring and establishing detection processes.
-
Response – guides organizations on how to respond to incidents, including response planning, communication, analysis, mitigation and continues improvements
-
Recover – aims to store normal operations after incidents with recovery planning, ongoing improvements, and communication strategies.
2.5 Chapter Summary
The chapter introduces the involving field of cyber security ,enchasing its significant in protecting computer systems , networks , and ate from digital threats .with the rise of interconnections ,robust cyber security measures are essential it shield individuals ,organizations and government from malicious activities aimed at financial exploitation and disruption .The literature distinguishes between cyber security and information security ,with cyber security encompassing broader protective functions , including safeguarding all digital assets and infrastructure . Investment in cyber security is highlighted as a crucial for organization resilience and competitive advantage. Strategic investments can enhance business operations, while the financial imperatives for such investments amid rising cyber threats. Effective decision-making in cyber security investments can bolster defences against vulnerabilities and ensure business continuity. Research also indicates a strong link between cyber security investment and customer trust, specifically for small and medium sized enterprises (SME’s) which must prioritize data protection to foster customer loyalty. Furthermore, effective cyber security practices enhance operational efficiency by minimizing disruptions and optimizing workflows. The chapter concludes with a conceptual formwork illustrating the interplay between cyber security investment and financial performance, customer trust and operational efficiency, asserting that proactive cyber security strategies are essential foot sustainable business success in today’s digital landscape .in general the literature consistently emphasizes the critical role of strategies cyber security investment in mitigating risks and enhancing organizational resilience
3 Methodology
3. Operational Definitions
Cybersecurity involves the protection of computers, network, programs, and data against unauthorized access, attack, damage, or theft, as dependences on digital systems continues to rise, the significance of cybersecurity has become increasingly vital for safeguarding sensitive information and ensuring system integrity.
Cybersecurity investment refers to the financial, technological, human, and organizational resources allocated by an organization to prevent, detect, respond to, and recover from cyber security threats. This includes speeding on software, hardware, personnel training, and enhancement to infrastructure. Investments may cover costs associated with threat detection tools, incident response capabilities, and compliance with regulatory requirements. The effectiveness of these investments can be measured by their influence on reducing vulnerabilities and lowering the incident of security breaches.
Customer Satisfaction refers to the extent to which customers are content with an organization’s product and services. It is frequently measured through surveys that evaluate various factors, such as product quality, service responsiveness, and overall experience. Common metrics for quantifying satisfaction levels include the Newt Promotor Score (NPS) and Customer Satisfaction Score (CSAT) high levels of customer satisfaction are often associated with increased customer loyalty, repeat business, and favorable word-of-mouth referrals.
Operational Efficiency refers to how effectiveness an organization utilizes its resources such as time, labor, and capital to achieve its objectives. This is typically assessed through performance matrices. Including process cycle time, output quality, and resource utilizations rates. Improving operational efficiency entails streamlining process, minimizing waste, and optimizing workflow, which can result in increased productivity and lower cost.
Financial performance refers to the evaluation of an organization’s financial health ,typically assessed through indicators such as revenue growth , profitability , and cost savings .key financial performance matrices include Return On Investment (ROI) Earnings Before Interest and Taxes (EBIT), and profit margins .analyzing these indicators provide stakeholders with insights into the organization’s financial visibility and operational effectiveness ,facilitating informed decision-making regarding future investments and strategic directions .
A framework is a systematic approach designed it analyze. Interpret, and tackle complex issues or challenges within a specific context. It generally compromises a collection of principles, guidelines, or elements that assist in organizing thoughts, streamlining decision-making, and improving the understanding of various processes.
3.1 Research Design
This study employed a quantitative, cross-sectional survey research design to examine the impact of cyber security investment on organizational performance in Bosaso, Somalia., The research will use a descriptive survey design, enabling the collection of quantitative data to assess the research will employ a descriptive survey design, enabling the collection of quantitative data to access the impact of cybersecurity investment on organizational performance. This approach facilitates a comprehensive examination of the relationship between variable through structured questionnaire .by employing these questionnaires, the research will gather numerical data that can be statically analyzed, providing a clear picture of how various levels of cybersecurity investment influence key performance indicators within organizations. The design will allow for the exploration of multiple variables, including of cybersecurity investment. Customer satisfaction, operational efficiency and financial performance indicators. This multifaceted approach enables a thorough understanding of how these elements interrelate. The survey method permits data collection from a large sale of organization, enhancing the generalizability of the findings. This is crucial for drawing boarder conclusion about the impact of cybersecurity investments across different sectors. Additionally, the use of structured questionnaire ensures consistency in data collection ‘reducing variability in responses. This consistency allows for more reliable comparison between different organizations and their respective performance outcomes. Surveys can be administered efficiently, saving both time and resources compared to other data collection methods, such as in-depth interview or focus group.
3.2 Target Population and Sampling
The target population for this study comprises organizations in Bossaso that have invested in cybersecurity. This includes various sectors such as finance, telecommunications, reflecting the diverse landscape of business that prioritize cybersecurity measures. To ensure comprehensive representation across different industries. A stratified sampling technique will be employed. This method involves dividing the target population in to distinct strata based on industry tie allowing for targeted sampling within each sector.by implement this approach, the study aims to capture the unique characteristics and cybersecurity challenges faced by organizations in different fields, stratifying the sampling ensures that perspectives from various sectors are represented, therefore enhancing our understanding of how cybersecurity investments influences organizational performance across industries. The target same size will consist of 100 respondents, which is considered adequate for conducting robust statistical analysis. This size enhances the reliability of data findings and face lifted meaningful comparison between strata. To qualify for inclusion, organizations must have made tangible investment in cybersecurity measures within the past three years. Ensuring that data reflects recent trends and practices in cybersecurity investment. Participants will be recruited through a combination of online survey using Google forms and direct outreach to organizations. This dual approach is designed to facilitate broader participation and increase the likelihood of achieving the target sample size.
3.4 Data Collection Instruments
Data will be gathered through an online structured questionnaire developed to address three key research objectives. This questionnaire will feature closed- ended questions rated on a Likert scale, facilitating quantitative responses suitable for statistical analysis. The study will focus on organizations in Bossaso, Somalia, with a stratified random sampling technique employed to ensure representation across sectors, such as finance, telecommunications, and retail. A sample size of 100 respondents has been selected, which is sufficient to support reliable conclusions, the study targeted 100 respondents. A total of 80 valid responses were obtained and included in the final analysis, representing an 80% response rate. The questionnaire will be organized into three sections each addressing one of the research objectives:
1- Customer Satisfactions: This section will measure customer perception of security, trust in digital transactions, and satisfaction with the organization’s cybersecurity practices.
2-Operational Efficiency: This section will examine the impact of cybersecurity investments on workflow, response times, and operational reliability.
3-Finanial Performance: Questions in this section will explore perceived effects on revenue, cost savings from breach prevention, and the overall financial health attributed to cybersecurity measures.
| Demographic Information: |
| Age Range: |
| Under 18 18-24 25-34 35-44 45-54 55-64 65 and over |
| Gender Identity: |
| Male Female |
| Current Role/Position: |
| Executive Management (e.g., CEO, CTO) IT Manager/Administrator Cybersecurity Specialist Operations Manager Financial Officer |
| Industry Sector: |
| Information Technology Finance/Banking Retail Healthcare Telecommunications |
| Organizational Size: |
| Small (1-50 employees) Medium (51-250 employees) Large (251+ employees) |
| Customer Satisfaction | Strongly Agree | Agree | Neutral | Disagree | Strongly Disagree | |||
| 1 | The adoption of security frameworks (e.g., NIST Cybersecurity Framework, ISO 27001) has positively influenced our Customer Satisfaction | |||||||
| 2 | Awareness of a company’s incident response plan affects my willingness to use their services. | |||||||
| 3 | The presence of multi-factor authentication (MFA) increases my confidence in a business's cybersecurity measures. | |||||||
| 4 | Regular security audits conducted by businesses increase my trust in their online services | |||||||
| 5 | I believe the implementation of firewalls and intrusion detection systems in businesses enhances my online safety. |
| Operational Efficiency | Strongly Agree | Agree | Neutral | Disagree | Strongly Disagree | |||
| 1 | Implementing security protocols (e.g., access control, network segmentation) enhances our operational workflows | |||||||
| 2 | Continuous monitoring of systems and networks leads to proactive identification and resolution of operational issues. | |||||||
| 3 | The presence of incident response plans helps mitigate the impact of cyber threats on operational activities. | |||||||
| 4 | Employee training on cybersecurity best practices contributes to overall operational effectiveness | |||||||
| 5 | Our organization's efficiency has increased due to reduced downtime from cyber incidents. |
| Financial Performance | Strongly Agree | Agree | Neutral | Disagree | Strongly Disagree | |||
| 1 | Our financial reporting practices have improved as a result of implementing cybersecurity frameworks (e.g., COBIT, ISO 27001). | |||||||
| 2 | The overall financial stability of our organization has improved due to effective cybersecurity risk management strategies. | |||||||
| 3 | Enhanced cybersecurity measures have allowed us to enter new markets or offer new services, leading to increased profitability. | |||||||
| 4 | Investments in cybersecurity training for employees have resulted in fewer incidents and reduced costs associated with breaches. | |||||||
| 5 | Our organization’s revenue growth has improved due to enhanced customer trust in our cyber security measures. |
| Cyber security Investment | Strongly Agree | Agree | Neutral | Disagree | Strongly Disagree | |
| 1 | Our organization invests adequately in cyber security technologies such as firewalls, intrusion detection systems, and endpoint security. | |||||
| 2 | Our organization regularly invests in updating and upgrading cyber security software and hardware. | |||||
| 3 | Our organization has invested in multi-factor authentication (MFA) and other technologies to strengthen access security. | |||||
| 4 | Our organization invests in continuous monitoring and detection technologies to identify cyber security threats. | |||||
| 5 | Our organization allocates sufficient financial resources for maintaining and improving cyber security infrastructure. |
3.5 Data Collection Procedure
The data collection process will involve a series of carefully planned steps to ensure the efficient gathering of relevant and reliable information. Initially, a pilot test will be conducted with a small sample form the target population to assess the clarity, relevance, and reliability of the questionnaire items. Feedback from this pilot test will be evaluated , and any necessary adjustments to the wording ,structure ,or format of questions will be implemented .flowing finalization , the questionnaire will be distributed vial online platform ,such as Google forms , to organizations in boss .this approach is designed to maximize reach and accessibility ,to improve response rates , follow-up reminders will be issued at regular intervals ,encouraging participants to complete the survey within the designated three-month period . During this time, response rates will be closely monitored. And any issues that arise will be promptly addressed .at the end of the data collection period, responses will be systematically organized and prepared for analysis. This preparation phase will include coding responses, checking for completeness, and addressing any anomalies or missing data to ensure the dataset is clean and ready for analysis.
3.6 Data Analysis
Quantitative data will be analyzed using statistical software Spas. The analysis will begin with summary of demographic data, including details of data. Descriptive statistics will offer an initial overview of participant responses. To examine the connections between cybersecurity investment and the three performance dimensions, such as customer stat faction, operational efficiency, and financial performance. Correlation analysis –regression we; be conducted. Pearson correlation coefficients will measure the strength and direction of these reasons, helping to determine whether increased cybersecurity investment is linked to improve outcomes in these areas .to further assess the impact of cybersecurity on each performance dimension, descriptive statistics, Cronbach's alpha, and Pearson correlation Analysis will be performed. This approach will evaluate how effectively cybersecurity investments predict customer satisfaction, operational efficiency, and financial performance. While controlling for other influencing factors. The regression models will provide insights into both the magnitude of these effects and the relative officious of cybersecurity investment t compared to other variables.
3.7 Validity & Reliability
To ensure validity and reliability in the questionnaire for this study , and expert review process will first be conducted to establish content validity .subject matter experts will evaluate the questionnaire to confirm that its items accurately align with the research objectives and effectively represent the relevant constructs .flowing , this a pilot test will be administered to a small sample of respondent from the target population to identify any potential ambiguities issues .this feedback will allow for necessary adjustments , improve clarity and relevance .reliability will be assessed using Cronbach’s alpha , a statistical matric that measures the internal consistency of the items within the questionnaire. A Cronbach’s alpha value of 0.7 or higher will be targeted. Indicating acceptance internal consistency and suggesting that the items reliably measure the same underlying construct. This step is essential for ensuring that the results are rebut a can be reliably replicated in future studies.
3.8 Research Ethics
Ethical considerations will be central to this research to safeguard the rights and welfare of all participants. Informed consistent will be obtained from participants before their involvement. Ensuring they receive comprehensive information about the stud’s purpose, procedure, and any potential risks or benefits. Participants will also be informed of their rights to withdraw at any time without any repercussions, supporting a voluntary and well-informed decisions to participants. To uphold confidentiality, all responses will be anonymized to prevent the identification of participants in the collected data this measure aims to protect privacy and foster honest responses. Additionally, data will be stored securely using password-protected files and encrypted storage, with access restrictions to authorized research personal only. Ethical approval will be sought from an institutional review board or ethics committee before data collection begins, confirm that the reproach adheres to ethical standards and guidelines. Throughout the study, the dignity and rights of participants will be prioritized. The research team will remain sensitive to cultural and contextual factors relevant to the target population in Bossaso, Somalia. Ensuring the research process is respectful and considerate.
3.9 Limitations of the Study
While this study aims to offer valuable insights into the effects of cybersecurity investment .certain limitations should be recognized .participants may response in ways that reflect socially desirable answers rather than their genuine view ,potentially skewing the data .such response bias may stem from a desired to portray their organization’s positively or from concerns about confidentiality .additionally , findings may have limited applicability to organization’s beyond Bossaso .or these in different cultural context , adequate aspects of the local environment ,industry practices , and cultural factors could restrict the generalizability of results to the regions or sector .although the target sample size of 100 respondents is intended to provide adequate statistical power .it may still fall short in achieving full representation across all sectors .some industries with fewer organizations investing in cybersecurity could influence the robustness of the findings .furthermore , study’s description survey design captures data at a single point in time . Limiting the ability to infer causation or track changes in perceptions and performance over time.
3.10 Chapter Summary
Cybersecurity refers to the protection of digital systems and sensitive data against unauthorized access, attack, or theft, essential due to rising digital dependences. Cybersecurity investment involves allocating resources to secure information systems, covering costs related to software. Hardware, training, and compliance with regulations. Customer satisfaction measures how content customers are with an organization’s services, often assessed through surveys using metrics like NPS a data. Operational efficiency gauges how well an organization uses resources to meet goals, improving efficiency through optimized workflow. Financial performance assessed an organization’s fiscal health through metrics such as ROI and profit margins. A framework provides a structured approach to analyze complex issues. Descriptive survey design will be used to gather quantitative data on cybersecurity investment’s impact on organizational performance. Structured questionnaire will capture data on customer satisfaction, operational efficiency, and financial performance. This design enables analyses of the relationship between cybersecurity investment levels and performance indicators and allows for broad data collection across multiple sectors. The study targets organization’s in Bossaso, Somalia, arose various sectors, such as finance and telecommunication that have invested in cybersecurity within the last three years. Using a strafed sampling technique ensures sectors representation. With 100 respondents providing reliable statistical power, requirement will occur through online surveys and direct outreach, promoting broader participation. This study will utilize Pearson correlation analyses to explore the impact of cybersecurity investment on performances dimensions such as customer satisfaction , operational performance , and financial performance .these satanical methods will help determine the strength and direction of these relationship , offering insights into the effectiveness of cybersecurity investment while controlling for other factors .to maintain validity and reliability , expert reviewers and Cronbach’s alpha will be used to assess the question air’s content and internal consistency ,aiming for a reliability score above 0.7 ethical measures , including informed consent ,data confidentiality , and restricted access to anonymized data ,will protect participant privacy ,with instructional ethical approval guiding the study .key limitations include potential response bias and limited applicability outside Bossaso, as well as the cross-sectional survey design , which restrict casual analysis and long –term observations.
4. Results And Discuss
4.1 Introduction
This chapter presents the analysis, interpretation, and discussion of the data collected to examine the impact of cybersecurity investment on organizational performance in Bosaso, Somalia. The study investigated cybersecurity investment as the independent variable and organizational performance through three dimensions: Customer Satisfaction, Operational Effectiveness, and Financial Performance. The analysis was based on 80 valid responses. The questionnaire used a five-point Likert scale ranging from 1 = Strongly Disagree to 5 = Strongly Agree. The questionnaire items were grouped into four constructs: Cybersecurity Investment (CI1–CI5), Customer Satisfaction (CS1–CS5), Operational Effectiveness (OE1–OE5), and Financial Performance (FP1–FP5). Composite scores were calculated using the mean of the five items belonging to each construct. The updated dataset confirms 80 valid observations. The analysis includes response validity, demographic characteristics, descriptive statistics, reliability analysis, Pearson correlation analysis, hypothesis testing, and discussion of findings. The analysis is structured according to the three specific objectives and three hypotheses stated in Chapter One.
4.2 Response Rate and Valid Cases
| Description | Frequency | Percentage |
| Valid responses | 80 | 100.0% |
| Excluded responses | 0 | 0.0% |
| Total | 80 | 100.0% |
The updated dataset contained 80 valid responses. All 80 cases contained sufficient information for inclusion in the statistical analysis. Therefore, the analysis presented in this chapter is based on N = 80 respondents.
4.3 Demographic Characteristics of Respondents 4.3.1 Age Distribution
| Age Group | Frequency | Percentage |
| 25–34 | 32 | 40.0% |
| 35–44 | 28 | 35.0% |
| 45 and above | 20 | 25.0% |
| Total | 80 | 100.0% |
Respondents aged 25–34 years constituted the largest age group, accounting for 40.0% of the sample. Respondents aged 35–44 accounted for 35.0%, while respondents aged 45 years and above represented 25.0%.The distribution demonstrates that the study included respondents with different levels of professional experience, which is relevant to a study examining cybersecurity investment and organizational performance.
4.3.2 Gender Distribution
| Gender | Frequency | Percentage |
| Male | 51 | 63.8% |
| Female | 29 | 36.3% |
| Total | 80 | 100.0% |
Male respondents represented 63.8% of the sample, while female respondents represented 36.3%.
4.3.3 Professional Position
| Professional Position | Frequency | Percentage |
| Cyber security Specialist | 30 | 37.5% |
| IT Manager/Administrator | 25 | 31.3% |
| Executive Management | 17 | 21.3% |
| Financial Officer | 8 | 10.0% |
| Total | 80 | 100.0% |
Cybersecurity Specialists constituted the largest professional group at 37.5%, followed by IT Managers/Administrators at 31.3%. Executive Management represented 21.3%, while Financial Officers accounted for 10.0%.
This composition is appropriate for the study because the majority of respondents have professional responsibilities related to cybersecurity, information technology, management, or organizational finance.
4.4 Descriptive Statistics
The descriptive analysis examined the mean and standard deviation of the four constructs.
The following interpretation was applied:
| Mean | Interpretation |
| 1.00–1.80 | Very Low |
| 1.81–2.60 | Low |
| 2.61–3.40 | Moderate |
| 3.41–4.20 | High |
| 4.21–5.00 | Very High |
4.4.1 Cyber security Investment
| Code | Item | Mean | SD | Interpretation |
| CI1 | Organization invests adequately in cyber security technologies | 3.138 | 1.260 | Moderate |
| CI2 | Organization regularly invests in updating cyber security software and hardware | 3.475 | 1.190 | High |
| CI3 | Organization invests in MFA and technologies that strengthen access security | 3.275 | 1.232 | Moderate |
| CI4 | Organization invests in continuous monitoring and detection technologies | 3.462 | 1.158 | High |
| CI5 | Organization allocates sufficient financial resources for cyber security infrastructure | 3.188 | 1.202 | Moderate |
| Overall CI | Cyber security Investment | 3.308 | 1.039 | Moderate |
Cybersecurity Investment recorded an overall mean of 3.308 (SD = 1.039), indicating a moderate level of cybersecurity investment.
CI2 recorded the highest mean at 3.475, followed by CI4 at 3.462. Both items were classified as high.
CI1 recorded the lowest mean at 3.138.
The findings indicate that organizations in the study area are making investments in cybersecurity technologies, software and hardware upgrades, MFA, monitoring, and infrastructure. However, the overall level of cybersecurity investment remains moderate rather than high. This finding directly relates to the first and second problems identified in Chapter One concerning insufficient cybersecurity investment and vulnerabilities associated with inadequate security resources.
4.4.2 Customer Satisfaction
| Code | Item | Mean | SD | Interpretation |
| CS1 | Adoption of security frameworks positively influences customer satisfaction | 2.938 | 1.118 | Moderate |
| CS2 | Awareness of incident response plans affects willingness to use services | 3.100 | 1.143 | Moderate |
| CS3 | MFA increases confidence in business cyber security measures | 2.950 | 1.101 | Moderate |
| CS4 | Regular security audits increase trust in online services | 3.112 | 1.191 | Moderate |
| CS5 | Firewalls and intrusion detection systems enhance online safety | 2.838 | 1.049 | Moderate |
| Overall CS | Customer Satisfaction | 2.988 | 1.012 | Moderate |
Customer Satisfaction recorded an overall mean of 2.988 (SD = 1.012), indicating a moderate level of customer satisfaction.
CS4 had the highest mean at 3.112, followed by CS2 at 3.100. CS5 had the lowest mean at 2.838.The results suggest that cybersecurity practices have a moderately positive perceived relationship with customer trust and satisfaction. However, the overall level is not sufficiently high to conclude that cybersecurity practices are producing consistently high customer satisfaction.
4.4.3 Operational Effectiveness
| Code | Item | Mean | SD | Interpretation |
| OE1 | Security protocols enhance operational workflows | 2.950 | 1.042 | Moderate |
| OE2 | Continuous monitoring supports proactive identification and resolution | 3.138 | 1.028 | Moderate |
| OE3 | Incident response plans mitigate cyber-threat impacts | 3.188 | 1.068 | Moderate |
| OE4 | Employee cyber security training contributes to operational effectiveness | 3.212 | 1.110 | Moderate |
| OE5 | Reduced cyber-incident downtime increases organizational efficiency | 2.812 | 1.032 | Moderate |
| Overall OE | Operational Effectiveness | 3.060 | 0.939 | Moderate |
Operational Effectiveness recorded an overall mean of 3.060 (SD = 0.939).
OE4 had the highest mean at 3.212, while OE5 had the lowest mean at 2.812.The findings indicate that cybersecurity practices, including employee training, incident response, monitoring, and security protocols, are perceived to contribute moderately to operational effectiveness. This finding is particularly relevant to the second specific objective, which seeks to investigate the influence of cybersecurity investment on operational efficiency in organizations in Bosaso.
4.4.4 Financial Performance
| Code | Item | Mean | SD | Interpretation |
| FP1 | Cyber security frameworks improve financial reporting | 3.250 | 1.108 | Moderate |
| FP2 | Cyber security risk management improves financial stability | 3.388 | 1.164 | Moderate |
| FP3 | Cyber security enables new markets/services and profitability | 3.088 | 1.150 | Moderate |
| FP4 | Cyber security training reduces incidents and breach-related costs | 3.512 | 1.125 | High |
| FP5 | Enhanced customer trust improves revenue growth | 3.025 | 1.006 | Moderate |
| Overall FP | Financial Performance | 3.253 | 0.945 | Moderate |
Financial Performance recorded an overall mean of 3.253 (SD = 0.945), indicating a moderate level of perceived financial performance.FP4 recorded the highest mean at 3.512 and was the only item classified as high. This indicates that respondents particularly recognized the contribution of cybersecurity training to reducing incidents and breach-related costs. The results provide evidence that cybersecurity is perceived to have financial implications for organizations, particularly through cost reduction and financial stability.
4.5 Overall Descriptive Statistics
| Construct | N | Mean | SD | Interpretation |
| Cyber security Investment | 80 | 3.308 | 1.039 | Moderate |
| Customer Satisfaction | 80 | 2.988 | 1.012 | Moderate |
| Operational Effectiveness | 80 | 3.060 | 0.939 | Moderate |
| Financial Performance | 80 | 3.253 | 0.945 | Moderate |
Cybersecurity Investment recorded the highest mean at 3.308, followed by Financial Performance at 3.253, Operational Effectiveness at 3.060, and Customer Satisfaction at 2.988.All constructs were within the moderate category. This suggests that organizations are making some level of cybersecurity investment, but the resulting organizational performance outcomes remain moderate.
4.6 Reliability AnalysisTable 4.10: Reliability Results
| Construct | Items | Cronbach's Alpha | Interpretation |
| Cyber security Investment | 5 | .911 | Excellent |
| Customer Satisfaction | 5 | .943 | Excellent |
| Operational Effectiveness | 5 | .934 | Excellent |
| Financial Performance | 5 | .904 | Excellent |
The reliability results demonstrate excellent internal consistency for all four constructs. Cybersecurity Investment produced Cronbach's alpha of .911, Customer Satisfaction .943, Operational Effectiveness .934, and Financial Performance .904. All values exceed the commonly accepted .70 threshold. Therefore, the measurement scales demonstrate strong internal reliability.
4.7 Pearson Correlation Analysis
Because Chapter One specifies Cybersecurity Investment as the independent variable and the three organizational-performance dimensions as dependent variables, the most important correlations for testing the research hypotheses are:
| Relationship | Pearson r | Significance | Interpretation |
| Cyber security Investment Customer Satisfaction | .435 | p < .001 | Positive, moderate |
| Cyber security Investment Operational Effectiveness | .527 | p < .001 | Positive, moderate |
| Cyber security Investment Financial Performance | .474 | p < .001 | Positive, moderate |
The correlation results demonstrate statistically significant positive relationships between Cybersecurity Investment and all three dimensions of organizational performance. Cybersecurity Investment had a positive moderate relationship with Customer Satisfaction (r = .435, p < .001).Cybersecurity Investment also had a positive moderate relationship with Operational Effectiveness (r = .527, p < .001).Finally, Cybersecurity Investment had a positive moderate relationship with Financial Performance (r = .474, p < .001). These relationships are directly supported by the updated correlation matrix. The strongest relationship was between Cybersecurity Investment and Operational Effectiveness, followed by Cybersecurity Investment and Financial Performance, and then Cybersecurity Investment and Customer Satisfaction. These results provide empirical support for the argument presented in Chapter One that inadequate cybersecurity investment can affect organizational performance. Importantly, because this is a cross-sectional study, these correlations demonstrate statistical association rather than definitive causation.
4.8 Hypothesis Testing
The hypothesis testing is now aligned directly with Chapter One.
| Hypothesis | Result | Decision |
| H1: Cyber security investment has a significant positive effect on customer satisfaction in organizations in Bosaso, Somalia. | r = .435, p < .001 | Supported |
| H2: Cyber security investment has a significant positive effect on operational effectiveness in organizations in Bosaso, Somalia. | r = .527, p < .001 | Supported |
| H3: Cyber security investment has a significant positive effect on financial performance in organizations in Bosaso, Somalia. | r = .474, p < .001 | Supported |
H1: Cyber security Investment and Customer Satisfaction
The first hypothesis proposed that cybersecurity investment has a significant positive effect on customer satisfaction.The results show a positive and statistically significant relationship between Cybersecurity Investment and Customer Satisfaction (r = .435, p < .001).
Therefore, H1 is supported.
The finding suggests that organizations with stronger cybersecurity investment tend to report higher levels of customer satisfaction. Investments in security frameworks, MFA, security audits, firewalls, intrusion detection, and incident-response capabilities may strengthen customer confidence in organizational services.
H2: Cyber security Investment and Operational Effectiveness .The second hypothesis proposed that cybersecurity investment has a significant positive effect on operational effectiveness. The correlation analysis produced r = .527, p < .001, indicating a positive and statistically significant relationship. Therefore, H2 is supported. This was the strongest of the three relationships involving Cybersecurity Investment. The finding suggests that cybersecurity investment may be particularly important for operational performance. Investment in monitoring, incident response, employee training, security protocols, and related controls can support more secure and continuous organizational operations.
H3: Cyber security Investment and Financial Performance
The third hypothesis proposed that cybersecurity investment has a significant positive effect on financial performance. The results show a positive and statistically significant relationship between Cybersecurity Investment and Financial Performance (r = .474, p < .001).Therefore, H3 is supported. The finding indicates that organizations reporting stronger cybersecurity investment also tend to report better financial performance. This may occur through reduced breach-related costs, improved financial stability, protection of revenue-generating services, and greater customer confidence.
4.9 Discussion of Findings
4.9.1 Cyber security Investment and Customer Satisfaction
The findings demonstrate a significant positive relationship between Cybersecurity Investment and Customer Satisfaction. The correlation of r = .435 (p < .001) indicates that organizations with greater cybersecurity investment tend to have higher levels of customer satisfaction. This finding directly addresses the first research question and specific objective. The result also supports the problem identified in Chapter One concerning the potential harm caused by inadequate security frameworks. Customers may have greater confidence in organizations that demonstrate commitment to protecting their information, systems, and transactions.
MFA, security audits, incident-response preparedness, and other visible security measures may contribute to this confidence. However, because Customer Satisfaction had an overall mean of only 2.988, the results suggest that the level of customer satisfaction associated with cybersecurity remains moderate rather than high.
4.9.2 Cyber security Investment and Operational Effectiveness
The relationship between Cybersecurity Investment and Operational Effectiveness was the strongest of the three relationships examined.
The correlation was r = .527 (p < .001).This finding directly supports the second research question and second specific objective. The result suggests that cybersecurity investment may contribute to more effective organizational operations. Cybersecurity technologies and practices can reduce disruptions, support continuous monitoring, strengthen incident response, improve employee awareness, and protect critical business processes. The finding is particularly important because one of the problems identified in Chapter One is insufficient cybersecurity investment and the resulting vulnerability of organizations. The moderate overall Operational Effectiveness score of 3.060 also indicates that there remains substantial opportunity for organizations in Bosaso to improve the operational benefits obtained from cybersecurity investment.
4.9.3 Cyber security Investment and Financial Performance
Cybersecurity Investment was also positively associated with Financial Performance.
The relationship was r = .474 (p < .001).
Therefore, higher levels of cybersecurity investment are associated with better reported financial performance. This result directly addresses the third research question and specific objective. One explanation is that effective cybersecurity can reduce financial losses associated with data breaches, system disruption, fraud, ransom ware, downtime, and recovery costs. The Financial Performance results show that the strongest individual item concerned cybersecurity training reducing incidents and breach-related costs, with a mean of 3.512.
This finding provides empirical support for the Chapter One problem concerning elevated costs and vulnerabilities resulting from insufficient cybersecurity investment.
4.10 Summary of Hypothesis Results
| Hypothesis | Relationship | r | p-value | Decision |
| H1 | Cyber security Investment Customer Satisfaction | .435 | < .001 | Supported |
| H2 | Cyber security Investment Operational Effectiveness | .527 | < .001 | Supported |
| H3 | Cyber security Investment Financial Performance | .474 | < .001 | Supported |
All three hypotheses are supported by the updated data.
This is the correct hypothesis structure for the dissertation because it follows the independent and dependent variables established in Chapter One.
4.11 Chapter Summary
This chapter analyzed 80 valid responses to examine the relationship between cybersecurity investment and organizational performance in Bosaso, Somalia. Cybersecurity Investment recorded an overall mean of 3.308, indicating a moderate level of investment. Customer Satisfaction recorded a mean of 2.988, Operational Effectiveness 3.060, and Financial Performance 3.253.The reliability analysis demonstrated excellent internal consistency, with Cronbach's alpha values ranging from .904 to .943.Pearson correlation analysis demonstrated significant positive relationships between Cybersecurity Investment and all three dimensions of organizational performance. Cybersecurity Investment was significantly related to Customer Satisfaction (r = .435, p < .001), Operational Effectiveness (r = .527, p < .001), and Financial Performance (r = .474, p < .001). Consequently, H1, H2, and H3 were all supported. The results indicate that cybersecurity investment is positively associated with customer satisfaction, operational effectiveness, and financial performance among the organizations represented in the study.
5. Conclusion, Recommendations And Future Research
5.1 Introduction
This chapter presents the conclusions, recommendations, implications, limitations, and future research directions based on the findings presented in Chapter Four.
The chapter is organized around the main objective of the study: to examine the impact of cybersecurity investment on organizational performance in Bosaso, Somalia. The conclusions and recommendations correspond directly to the three specific objectives and three hypotheses established in Chapter One.
5.2 Summary of Major Findings
The study was based on 80 valid responses.
Cybersecurity Investment recorded an overall mean of 3.308, indicating a moderate level of cybersecurity investment. Customer Satisfaction recorded an overall mean of 2.988, Operational Effectiveness recorded 3.060, and Financial Performance recorded 3.253.All four constructs demonstrated excellent internal reliability, with Cronbach's alpha coefficients above .90.
The correlation analysis produced three principal findings:
-
Cyber security Investment and Customer Satisfaction: r = .435, p < .001
-
Cyber security Investment and Operational Effectiveness: r = .527, p < .001
-
Cyber security Investment and Financial Performance: r = .474, p < .001
All three relationships were positive and statistically significant.
Therefore, all three hypotheses were supported.
5.3 Conclusion
5.3.1 Conclusion on Cyber security Investment and Customer Satisfaction
The study concludes that Cybersecurity Investment is positively and significantly associated with Customer Satisfaction. The correlation coefficient of r = .435 (p < .001) demonstrates that organizations with higher levels of cybersecurity investment tend to report higher customer satisfaction. This suggests that cybersecurity investment can contribute to customer confidence through improved protection of information, safer transactions, stronger authentication, incident preparedness, and visible security practices. Therefore, cybersecurity should be regarded as an important component of customer relationship management rather than exclusively as a technical function.
5.3.2 Conclusion on Cyber security Investment and Operational Effectiveness The study concludes that Cybersecurity Investment has a positive and statistically significant relationship with Operational Effectiveness. The correlation coefficient of r = .527 (p < .001) was the strongest of the three relationships examined. This indicates that cyber security investment may be particularly important for organizational operations. Organizations that invest in cybersecurity technologies, monitoring, employee training, incident response, authentication, and security infrastructure may be better positioned to maintain secure and continuous business processes.5.3.3 Conclusion on Cyber security Investment and Financial Performance
The study concludes that Cybersecurity Investment is positively and significantly associated with Financial Performance. The correlation coefficient of r = .474 (p < .001) demonstrates a moderate positive relationship. Cybersecurity investment may support financial performance by reducing breach-related losses, minimizing downtime, protecting organizational information, maintaining customer confidence, and reducing costs associated with security incidents. However, the study should not claim that cybersecurity investment causes financial performance because the research design is cross-sectional. The appropriate academic conclusion is that cybersecurity investment is significantly and positively associated with financial performance.
5.4 Overall Conclusion
The overall conclusion of the study is that cybersecurity investment is significantly and positively associated with all three dimensions of organizational performance examined in Bosaso, Somalia. The strongest relationship was between Cybersecurity Investment and Operational Effectiveness (r = .527), followed by Financial Performance (r = .474) and Customer Satisfaction (r = .435).The findings therefore provide empirical support for the main argument of the dissertation: organizations that invest in cybersecurity tend to demonstrate better organizational outcomes across customer, operational, and financial dimensions. However, the moderate descriptive scores indicate that cybersecurity investment and organizational performance still have considerable room for improvement.
5.5 Recommendations5.5.1 Develop a Comprehensive Cyber security Framework
Organizations in Bosaso should develop and implement comprehensive cybersecurity frameworks aligned with their operational requirements and risk environments.
The framework should include:
-
Access control
-
MFA
-
Security monitoring
-
Incident response
-
Vulnerability management
-
Data protection
-
Employee awareness
-
Business continuity
-
Regular security audits
This recommendation directly addresses the first problem identified in Chapter One concerning the lack of comprehensive security frameworks.
5.5.2 Increase Cyber security Investment
Organizations should allocate adequate financial resources to cybersecurity.
Investment should cover both technology and human capabilities, including:
-
Security software
-
Hardware
-
MFA
-
Monitoring systems
-
Endpoint protection
-
Network security
-
Employee training
-
Incident-response capabilities
The overall Cybersecurity Investment score was moderate (M = 3.308), suggesting that organizations have investment activity but may need to strengthen the level and consistency of their investment.
5.5.3 Align Cyber security Investment with Business Goals
Organizations should ensure that cybersecurity investment is directly connected to organizational goals and strategies.
Management should not evaluate cybersecurity solely according to expenditure.
Instead, investments should be evaluated according to their contribution to:
-
Customer satisfaction
-
Operational continuity
-
Service availability
-
Risk reduction
-
Cost reduction
-
Financial stability
-
Organizational resilience
This recommendation directly addresses the third problem identified in Chapter One concerning poor alignment between cybersecurity investment and business strategy.
5.5.4 Improve Customer Trust through Security
Organizations should strengthen customer-facing security measures.
Priority should be given to:
-
MFA
-
Secure authentication
-
Data protection
-
Security audits
-
Transparent security communication
-
Effective incident response
The positive relationship between Cybersecurity Investment and Customer Satisfaction supports the importance of this recommendation.
5.5.5 Strengthen Operational Cybersecurity
Organizations should prioritize cybersecurity controls that improve operational continuity. Continuous monitoring, employee training, incident response, vulnerability management, and security protocols should be strengthened. This recommendation is particularly important because Cybersecurity Investment had its strongest relationship with Operational Effectiveness.
5.5.6 Reduce Cyber security-Related Financial Losses
Organizations should establish measures to reduce the financial impact of cyber incidents.
These should include:
-
Incident prevention
-
Backup and recovery
-
Business continuity planning
-
Incident response
-
Employee training
-
Vulnerability management
-
Financial impact assessment
The finding that cybersecurity investment is positively associated with Financial Performance supports these measures.
5.6 Management Implications
The findings have important implications for managers and organizational decision-makers in Bosaso.
First, cybersecurity should be viewed as a strategic investment, rather than simply an IT expense. Second, management should prioritize investments that directly improve operational effectiveness because this was the strongest relationship observed. Third, customer satisfaction should be recognized as an important cybersecurity outcome. Fourth, cybersecurity investment should be integrated into organizational strategic planning and budgeting. Finally, managers should establish measurable cybersecurity performance indicators to determine whether investments are generating organizational value.
5.7 Implications for Cyber security Frameworks and Zero Trust
The findings support the importance of implementing structured cybersecurity frameworks within organizations. A Zero Trust-oriented strategy can provide a useful approach because it emphasizes:
-
Continuous verification
-
Least-privilege access
-
Identity-based security
-
MFA
-
Device security
-
Network segmentation
-
Continuous monitoring
-
Policy-based access control
-
Rapid incident detection and response
These capabilities can contribute to the three performance areas examined in this study: customer satisfaction, operational effectiveness, and financial performance.
However, the empirical results in this study should not be interpreted as a direct test of Zero Trust itself unless Zero Trust was explicitly measured in the questionnaire. Therefore, Zero Trust should be presented as a practical implication/recommendation, not as a separately tested hypothesis.
5.8 Limitations of the Study
The study has several limitations.
First, the study was based on 80 respondents, which limits the extent to which the findings can be generalized to all organizations in Somalia. Second, the study used a cross-sectional design. Therefore, the results demonstrate relationships between variables but cannot establish definitive causal relationships. Third, the research relied on self-reported questionnaire responses. Respondents' perceptions may therefore differ from objectively measured organizational performance. Fourth, the study focused on Cybersecurity Investment and three dimensions of organizational performance. Other variables may also influence organizational performance. Finally, although the relationships between Cybersecurity Investment and the three outcome variables were statistically significant, the results should be interpreted as evidence of association rather than proof that investment alone causes improvements in organizational performance.
5.9 Recommendations for Future Research
Future research should use larger samples covering more organizations in Bosaso and other cities in Somalia.
Longitudinal studies should also be conducted to examine organizational performance before and after major cybersecurity investments.
Future studies could include additional variables such as:
-
Cyber security maturity
-
Management commitment
-
Employee cyber security awareness
-
Regulatory compliance
-
Number and severity of cyber incidents
-
Organizational resilience
-
Technology maturity
-
Customer trust
-
Security culture
-
Business continuity
Future research could also use Structural Equation Modeling or multiple regression models specifically designed around the Chapter One conceptual framework, with Cybersecurity Investment as the independent variable and Customer Satisfaction, Operational Effectiveness, and Financial Performance as the dependent variables.
References
- Anderson, R. (2001). Why information security is hard—An economic perspective. In Proceedings of the 17th Annual Computer Security Applications Conference. DOI ↗ Google Scholar ↗
- Anderson, R., & Moore, T. (2006). The economics of information security. Science, 314(5799), 610–613. DOI ↗ Google Scholar ↗
- Barney, J. (1991). Firm resources and sustained competitive advantage. Journal of Management, 17(1), 99–120. DOI ↗ Google Scholar ↗
- Böhme, R., & Schwartz, G. (2010). Modeling cyber-insurance: Towards a unifying framework. In Workshop on the Economics of Information Security. DOI ↗ Google Scholar ↗
- Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523–548. Google Scholar ↗
- Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004a). A model for evaluating IT security investments. Communications of the ACM, 47(5), 87–92. Google Scholar ↗
- Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004b). The effect of Internet security breach announcements on market value: Capital market reactions for breached firms and Internet security developers. International Journal of Electronic Commerce, 9(1), 69–104. DOI ↗ Google Scholar ↗
- D'Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79–98. Google Scholar ↗
- Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. DOI ↗ Google Scholar ↗
- Gordon, L. A., Loeb, M. P., Lucyshyn, W., & Zhou, L. (2015). The impact of information sharing on cybersecurity underinvestment. Journal of Accounting and Public Policy, 34(4), 320–336. Google Scholar ↗
- Gordon, L. A., Loeb, M. P., & Zhou, L. (2011). Investing in cybersecurity: Insights from the Gordon-Loeb model. Journal of Information Security and Applications, 16(1), 3–11. Google Scholar ↗
- Gunawan, R., Ratmono, D., & Abdullah, M. (2023). Evaluating the adoption of cybersecurity and its influence on organizational performance. Journal of Innovation & Knowledge, 8(2), 100350. DOI ↗ Google Scholar ↗
- IBM Security. (2024). Cost of a data breach report 2024. Google Scholar ↗
- International Organization for Standardization. (2022a). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection—Information security management systems—Requirements. Google Scholar ↗
- International Organization for Standardization. (2022b). ISO/IEC 27002:2022 information security, cybersecurity and privacy protection—Information security controls. Google Scholar ↗
- Kankanhalli, A., Teo, H.-H., Tan, B. C. Y., & Wei, K.-K. (2003). An integrative study of information systems security effectiveness. International Journal of Information Management, 23(2), 139–154. Google Scholar ↗
- Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. Google Scholar ↗
- Kwon, J., & Johnson, M. E. (2013). Health-care security: How to protect patient information in the era of electronic health records. Journal of the American Medical Informatics Association, 20(2), 246–250. Google Scholar ↗
- National Institute of Standards and Technology. (2018). Framework for improving critical infrastructure cybersecurity (Version 1.1). Google Scholar ↗
- National Institute of Standards and Technology. (2020a). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 5). Google Scholar ↗
- National Institute of Standards and Technology. (2020b). Zero trust architecture (NIST Special Publication 800-207). Google Scholar ↗
- Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). National Institute of Standards and Technology. DOI ↗ Google Scholar ↗
- Ponemon Institute. (2019). 2019 cost of a data breach report. IBM Security. Google Scholar ↗
- Siponen, M., Mahmood, M. A., & Pahnila, S. (2014). Employees' adherence to information security policies: An empirical study. Information & Management, 51(2), 172–181. Google Scholar ↗
- Spears, J. L., & Barki, H. (2010). User participation in information systems security risk management. MIS Quarterly, 34(3), 503–522. Google Scholar ↗
- Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: Security planning models for management decision making. MIS Quarterly, 22(4), 441–469. Google Scholar ↗
- Teece, D. J., Pisano, G., & Shuen, A. (1997). Dynamic capabilities and strategic management. Strategic Management Journal, 18(7), 509–533. Google Scholar ↗
- Verizon. (2024). 2024 data breach investigations report. DOI ↗ Google Scholar ↗
- Zhang, H., Peng, J., Mao, J., & Xu, S. (2023). Repeated data breaches and firm value. Economics Letters, 224, 111001. DOI ↗ Google Scholar ↗