Blockchain Use, Cyber Risk, and Firm Value: The Mediating Role of Internal Control
DOI:
https://doi.org/10.63544/jbii.v5i7.108Keywords:
Blockchain Use, Cyber Risk, Internal Control, Firm Value, Agency TheoryAbstract
This study examines the impact of blockchain use and cyber risk on firm value, with internal control serving as a mediating mechanism, among non-financial firms listed on the Pakistan Stock Exchange. Grounded in agency theory, the research employs a quantitative explanatory design, analysing survey responses from senior financial and assurance professionals alongside secondary financial data using partial least squares structural equation modelling (PLS-SEM). The findings reveal that blockchain use significantly and positively influences internal control effectiveness (β = 0.555, p < 0.001), while cyber risk exerts a significant negative effect on internal control (β = -0.486, p < 0.001). Internal control demonstrates a strong positive relationship with firm value (β = 0.794, p < 0.001) and serves as a significant mediator in both the blockchain use–firm value relationship (β = 0.441, p < 0.001) and the cyber risk–firm value relationship (β = -0.386, p < 0.001). The model exhibits substantial explanatory power, accounting for 66.1% of the variance in internal control and 63.1% of the variance in firm value. These results underscore that the value derived from blockchain technology and the mitigation of cyber risk are contingent upon robust internal control environments. For emerging market firms, effective governance, risk assessment, monitoring procedures, and control activities are essential to translate digital technology investments into tangible firm value. The study extends agency theory by demonstrating how technological conditions—both enabling and threatening—influence economic outcomes through organizational control mechanisms. Practical implications for boards, financial executives, risk managers, auditors, and regulators are discussed.
Akter, M., Kummer, T.-F., & Yigitbasioglu, O. (2024). Looking beyond the hype: The challenges of blockchain adoption in accounting. International Journal of Accounting Information Systems, 53, Article 100681. https://doi.org/10.1016/j.accinf.2024.100681
Baatwah, S. R., Asiri, M., Bajaher, M. S., Alyafai, A., & Baajajah, S. (2026). Thriving post-cyberattacks: The power of control, disclosure, and IT maturity. Electronic Commerce Research, 26, 1705–1743. https://doi.org/10.1007/s10660-025-09958-2
Baita, A. J., Umar, U. H., & Masyita, D. (2026). Sukuk, banking attributes and Islamic financial development. International Journal of Social Economics, 53(7), 1122–1135. https://doi.org/10.1108/IJSE-12-2024-0998
Billah, M., Hadhri, S., Balli, F., & Sahabuddin, M. (2024). Exploring the dynamic links and implications for hedging and investment strategies between sukuk and commodity-market volatility: Evidence from country-level analysis. International Review of Economics & Finance, 93, 350–371. https://doi.org/10.1016/j.iref.2024.03.011
Cao, H., Phan, H. V., & Silveri, S. (2024). Data breach disclosures and stock price crash risk: Evidence from data breach notification laws. International Review of Financial Analysis, 93, Article 103164. https://doi.org/10.1016/j.irfa.2024.103164
Chen, H., Yang, D., Zhang, J. H., & Zhou, H. (2020). Internal controls, risk management, and cash holdings. Journal of Corporate Finance, 64, Article 101695. https://doi.org/10.1016/j.jcorpfin.2020.101695
Chen, W., Li, X., Wu, H., & Zhang, L. (2024). The impact of managerial myopia on cybersecurity: Evidence from data breaches. Journal of Banking & Finance, 166, Article 107254. https://doi.org/10.1016/j.jbankfin.2024.107254
Committee of Sponsoring Organizations of the Treadway Commission. (2013). Internal control—Integrated framework. COSO.
Demek, K. C., & Kaplan, S. E. (2023). Cybersecurity breaches and investors' interest in the firm as an investment. International Journal of Accounting Information Systems, 49, Article 100616. https://doi.org/10.1016/j.accinf.2023.100616
Hair, J. F., Hult, G. T. M., Ringle, C. M., & Sarstedt, M. (2022). A primer on partial least squares structural equation modeling (PLS-SEM) (3rd ed.). Sage.
Han, S., Mei, J., & Deng, J. (2025). Does internal compliance auditing increase corporate value? The influence of accounting information quality and agency problems. Finance Research Letters, 86, Article 108897. https://doi.org/10.1016/j.frl.2025.108897
Henseler, J., Ringle, C. M., & Sarstedt, M. (2015). A new criterion for assessing discriminant validity in variance-based structural equation modeling. Journal of the Academy of Marketing Science, 43(1), 115–135. https://doi.org/10.1007/s11747-014-0403-8
Jensen, M. C., & Meckling, W. H. (1976). Theory of the firm: Managerial behaviour, agency costs and ownership structure. Journal of Financial Economics, 3(4), 305–360. https://doi.org/10.1016/0304-405X(76)90026-X
Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019
Le, A.-T., Huang, H. H., & Do, T. K. (2024). Navigating through cyberattacks: The role of tax aggressiveness. Journal of Corporate Finance, 88, Article 102649. https://doi.org/10.1016/j.jcorpfin.2024.102649
Ledhem, M. A. (2022). The financial stability of Islamic banks and sukuk market development: Is the effect complementary or competitive? Borsa Istanbul Review, 22(Suppl. 1), S79–S91. https://doi.org/10.1016/j.bir.2022.09.009
Liao, K., Lin, L., & Sun, Y. (2025). Blockchain adoption and corporate financial reporting quality. Journal of Accounting and Public Policy, 49, Article 107265. https://doi.org/10.1016/j.jaccpubpol.2024.107265
Liu, Y., Liu, Q., & Wei, Y. (2025). Digital finance, internal control, and audit quality. Finance Research Letters, 76, Article 107033. https://doi.org/10.1016/j.frl.2025.107033
Muktadir-Al-Mukit, D., & Ali, M. H. (2025). The dynamics of stock market responses following cyberattack news: Evidence from an event study. Information Systems Frontiers. Advance online publication. https://doi.org/10.1007/s10796-025-10639-6
Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioural research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879–903. https://doi.org/10.1037/0021-9010.88.5.879
Rosati, P., Gogolin, F., & Lynn, T. (2022). Cyber-security incidents and audit quality. European Accounting Review, 31(3), 701–728. https://doi.org/10.1080/09638180.2021.1904575
Slapničar, S., Axelsen, M., & Eulerich, M. (2026). Cyber risk management: An illusion of a risk-based approach. Journal of Management Control, 37, 359–394. https://doi.org/10.1007/s00187-025-00401-z
Smaoui, H., & Nechi, S. (2017). Does sukuk market development spur economic growth? Research in International Business and Finance, 41, 136–147. https://doi.org/10.1016/j.ribaf.2017.04.018
Wang, J., Ho, C. Y., & Shan, Y. G. (2024). Does cybersecurity risk stifle corporate innovation activities? International Review of Financial Analysis, 91, Article 103028. https://doi.org/10.1016/j.irfa.2024.103028
Zaheer, S., & van Wijnbergen, S. (2025). Sukuk defaults: On distress resolution in Islamic finance. Qualitative Research in Financial Markets, 17(2), 292–311. https://doi.org/10.1108/QRFM-08-2023-0203
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Imran Abdul Aziz , Syed Muhammad Shoaib Wasim, Yusra Shehzadi

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.