침해사고 경험이 보안 투자 의사결정에 미치는 영향 : 조직학습이론 기반 단계적 학습과 결정 요인의 재편
The Effect of Cyber Incident Experience on Security Investment Decisions : Staged Learning and the Reconfiguration of Determinants from an Organizational Learning Theory Perspective
Security investment has become a decision-making task as the threat of cyber incidents increases due to artificial intelligence technology. However, existing studies have not explained the staged learning structure by dealing with incidents and security investment in a single reactive relationship. This study analyzed how security investment determinants worked by classifying the security budget rise for the incident year and the next year from the single-loop-double-loop learning perspective of organizational learning theory. Hierarchical binary logistic regression was performed on 347 incident-experienced companies in the Korean Information Security Survey from 2022 to 2024. Incident response duration was the dominant predictor in the reactive stage, and an inverted U-shaped relationship was confirmed for severity. At the strategic stage, the nonlinear effect of severity disappeared, and management's perception of security importance acted as the dominant predictor. In moderation, third-party identification of incidents reinforced the reactive stage effect, and a formal security policy strengthened the strategic stage effect. This asymmetry shows that the weight of the determinants is reconfigured according to the learning stage. This study expands learning from incidents into qualitatively distinct staged learning, and offers companies and governments implications for staged security enhancement and policy support.
한국어
최근 인공지능 기술이 기업 전반으로 확산되면서 침해사고 위협도 함께 커졌다. 이에 보안 투자는 위협에 대응하기 위한 기업의 중요한 의사결정 과제가 되었다. 그러나 그간의 연구는 침해사고와 보안 투자를 주로 단일한 반응적 관계로만 보아 단계적 학습 구조를 충분히 조명하지 못하고 있다. 본 연구는 조직학습이론의 단일 루프-이중 루프 학습 측면에서 침해사고 발생연도의 보안 예산 증가를 반응적 단계, 차년도의 보안 예산 증가를 전략적 단계로 구분하고, 각 보안 투자 결정 요인들이 어떻게 작동하는지 살펴보았다. 연구 분석은 2022년부터 2024년까지 정보보호실태조사에서 침해사고를 경험한 347개 기업의 데이터를 활용하여 위계적 이분형 로지스틱 회귀분석을 하였다. 분석 결과, 반응적 단계에서는 침해사고 대응 소요시간이 지배적 예측 변수였으며, 침해사고 심각도는 역U자형 관계가 확인되었다. 전략적 단계에서는 심각도의 비선형 효과는 소멸되고, 경영진의 보안 중요도 인식이 지배적 예측 변수로 작용하였다. 조절효과는 제3자의 침해사고 식별이 반응적 단계 효과를, 조직의 공식 보안 정책이 전략적 단계 효과를 강화하였다. 이처럼 단계별로 다른 결과는 보안 투자가 학습 단계에 따라 결정 요인의 비중이 재편됨을 보여준다. 본 연구는 침해사고에서 비롯된 학습을 질적으로 구별되는 단계적 학습으로 확장하고, 기업에는 단계별 보안 강화를, 정부에는 정책적 지원 방향을 제시한다.
목차
요약 Ⅰ. 서론 Ⅱ. 이론적 배경 2.1 조직학습이론(OLT): 반응적 보안 예산과 전략적 보안 예산 2.2 심각도와 보안 투자의 비선형 관계 2.3 대응 소요시간과 조직 보안 역량 2.4 보안 관심도 변화와 경영진의 보안 중요도 인식 2.5 침해사고 식별 주체와 공식 보안 정책의 조절 효과 Ⅲ. 연구 방법 3.1 연구모형 3.2 데이터 및 표본 3.3 변수 측정 3.4 분석 방법 및 타당성 검토 Ⅳ. 분석 결과 4.1 기술통계 및 상관관계 4.2 반응적 단계(Stage 1): 반응적 보안예산 증가(t시점) 4.3 전략적 단계(Stage 2): 전략적 보안 예산 증가(t+1시점) Ⅴ. 논의 5.1 단계별 보안 투자 결정 요인의 재편 5.2 침해사고 심각도와 IRD의 단계적 작동 5.3 조직의 인지 기반과 제도적 통로 Ⅵ. 결론 6.1 연구 결과 및 의의 6.2 실무 및 정책적 시사점 참고문헌 Abstract