Investigating industry norms of cyber security: a critical content analysis of PwC's annual reports
Purpose Industry reports are the cornerstone of the cyber security landscape, providing relevant implicit insight into the current cyber security norms and expectations. Analysis of these reports from a critical perspective is missing, meaning the role that they play and the implicit insights they contain are unexplored. Design/methodology/approach In our study, we address this research gap through studying the annual PwC industry reports relating to cyber security using a content analysis approach. Findings We identify that PwC reports have continually emphasised strategy and leadership, contrasting with the more recent inclusion of strategy in cyber security. Furthermore, we observed that though norms have changed, cyber security and what it encompasses have not fully changed despite tools and threats evolving. Cyber security is also positioned as a benchmarkable concept, which can be both motivating and demotivating considering the inevitable occurrence of cyber incidents. Research limitations/implications Our study demonstrates the value of industry reports by showing the difference in industry and research perspectives. Future research can then use and incorporate these reports to supplement analysis. In addition, our description of how cyber security's norms and beliefs have changed over time provides researchers with a context when analysing historical and current practices extending their analysis. Practical implications Our study contributes to practice by identifying patterns useful for providing guidance to organisations. Furthermore, our study demonstrates the importance of industry encouraging their involvement. Originality/value Studies incorporating industry reports with such analysis are novel, at the time of writing.
Authors
- Elinor Tsen (ORCID: https://orcid.org/0000-0003-0630-6951)
Institutions
- University of Auckland (NZ)
Publication Details
- Journal
- Organizational Cybersecurity Journal Practice Process and People
- Published
- 2026-10-06
- DOI
- https://doi.org/10.1108/ocj-05-2025-0018
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00