Frontline perceptions of middle management as a bottleneck in cybersecurity escalation and risk communication
Purpose This study examines how frontline cybersecurity professionals perceive middle management's role in the escalation and communication of cyber risk within large organizations, and identifies the communication failures they associate with delayed or incomplete reporting of critical security issues to senior leadership. Design/methodology/approach Semi-structured interviews were conducted with 20 frontline cybersecurity professionals across multiple industries. Thematic analysis identified patterns in how participants perceived middle management's handling of security information to shape the reporting and resolution of security threats. Findings Participants perceived three interconnected failure modes: structural barriers that delay escalation, procedural gaps that limit tracking and accountability, and behavioral dynamics in which the severity of security issues was perceived to be minimized or suppressed before reaching senior leadership. Participants attributed these patterns variously to impression management and controllability concerns and to resource constraints, competing priorities, immature escalation processes, unclear ownership and misunderstanding of technical severity. Where these dynamics occur, organizations risk exposure to preventable threats and senior leaders may lack the accurate information needed for risk-based decisions. Originality/value While prior work has examined organizational communication, governance and coordination failures in cybersecurity incidents, relatively little research has examined middle-management communication dynamics in the escalation of cyber risk. This study addresses that gap from the frontline perspective and proposes interventions including direct reporting mechanisms, interdisciplinary technical advisory councils and targeted middle-management training.
Authors
- Brian Scavotto (ORCID: https://orcid.org/0000-0001-7966-8705)
Institutions
- Eastern Oregon University (US)
Publication Details
- Journal
- Organizational Cybersecurity Journal Practice Process and People
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1108/ocj-02-2026-0006
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00