“…Accordingly, the presence of such resources in any firm could earn the organization an advantage over its competing organization and also attain an upgrade in general firm operations. Earlier studies have looked at IT threats (Safa et al , 2018; McDermott et al , 2019; Siddiqui et al , 2020), Information Systems (IS) development policies (Hina and Dominic, 2017, 2018; Temel and Karimov, 2019) and IS security (Niemimaa and Niemimaa, 2017; Boiko and Shendryk, 2017; Siponen and Baskerville, 2018; Merhi and Ahluwalia, 2019; Svyd et al , 2019; Berdik et al , 2021) and IT security culture (Mahfuth et al , 2017; Nævestad et al , 2018; Nasir et al , 2019; Asamoah et al , 2021). These studies seldom explored the moderated-mediated role of OC and IT strategy on the relationship between ERM and IT security especially within the financial sector in emerging economies where cyberattacks keeps increasing.…”