Jul 2026· Asian journal of current research· Vol 11, pp. 233-248· 0 citations
TL;DR
It is argued that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics.
Abstract
Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.
A multilayered regulatory model is proposed that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing, essential for protecting investors, preserving market continuity, and containing systemic cyber risk.
Akomolehin F. Olugbenga· International journal of res...· 0 citations
This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations
This study develops an integrated explanation of cybersecurity disclosure by synthesizing accounting, governance, finance, and information-systems research published between 2019 and 2026. A structured integrative literature review was applied to a curated corpus of 44 publications, identified through searches of Scopus and Google Scholar and screened against topical-relevance criteria. The studies were coded according to disclosure type, measurement attributes, governance and institutional determinants, stakeholder group, outcome, and contextual condition. The evidence shows that cybersecurity reporting includes risk, governance, preventive, incident, and mitigative information, which should not be treated as interchangeable constructs. Board independence,information technology expertise, dedicated cyber committees, gender diversity, internal controls, breach history, regulation, and sectoral exposure shape the extent and content of reporting. Disclosure can reduce information asymmetry, strengthen reputation, support firm value, moderate breach contagion, and inform audit risk assessment. However, longer or more readable reporting does not necessarily indicate stronger preparedness and may reveal heightened cyber exposure, increase stock-price crash risk, or generate adversarial costs. Boilerplate language, delayed incident reporting, strategic news timing, and possible manipulation of incident discovery dates further weaken credibility. The review contributes a Cyber Transparency Security Trust framework in which governance capacity and cyber exposure shape disclosure attributes, stakeholders assess both usefulness and security sensitivity, and resulting responses affect market value, audit fees, reputation, trust, and future cyber risk. The review is limited by its curated rather than exhaustive corpus and its focus on predominantly listed firms in developed economies. Future research should prioritize disclosure quality, preventive versus mitigative content, independent assurance, materiality judgments, emerging economies, artificial-intelligence-based analysis, and causal evidence on subsequent cyberattacks.
Keywords: Cybersecurity Disclosure, Cyber Risk, Corporate Governance, Stakeholder Trust, Information Asymmetry.
A. Saputra, Suherni Dwi Listiani, Ridwansyah· Proceeding of International...· 0 citations
This study aims to empirically advance understanding of how cybersecurity and data governance oversight influence board-level sustainable corporate governance outcomes in the context of digitalization.
Drawing on agency theory, stakeholder theory, and resource dependence theory, the study develops an integrative conceptual framework directly linking board cybersecurity oversight to environmental, social, and governance (ESG) performance, with digital risk governance quality as a process-based mediating mechanism, and regulatory pressure (REG) as a moderating institutional condition. The hypotheses are tested using large-sample longitudinal panel data for firms observed over the period 2018–2023. Fixed-effects regression models with robust standard errors and mediation analysis are employed.
The results show that board cybersecurity and data governance oversight are consistently positively associated with ESG performance. Digital risk governance quality partially empirically mediates this relationship, indicating that board oversight enhances sustainable governance outcomes both directly and indirectly through improved digital organizational risk governance processes. Robustness analyses using governance and social ESG pillars confirm the empirical stability of the findings.
The study provides new empirical evidence that cybersecurity and data governance constitute strategic board responsibilities with significant sustainability implications in the digital era. It highlights digital risk governance as a key previously underexplored governance mechanism linking board-level cybersecurity oversight to ESG performance. The study further contributes by demonstrating the mediating role of digital risk governance quality and the moderating role of REG, thereby clarifying how and under what conditions board cybersecurity oversight influences sustainable corporate governance outcomes.
Syed Amjad Hussain· Corporate Governance : The i...· 0 citations
The global business landscape is currently undergoing a fundamental transformation driven by the massive integration of digital technologies across organizational value chains. However, this accelerated digitalization brings a paradoxical consequence: while it enhances operational efficiency, it simultaneously expands the "attack surface" for increasingly sophisticated cyber threats. Cyber threats are no longer merely technical disruptions to IT infrastructure; they have evolved into existential risks capable of paralyzing entire business strategies. Consequently, organizations are compelled to shift their risk management paradigm from a reactive-operational approach toward Strategic Risk Management (SRM) that is proactive and integrated with the company's long-term objectives. In a highly competitive market, digital resilience is now viewed as a new source of Competitive Advantage, fostering higher levels of digital trust among stakeholders, particularly customers and investors. Despite the widely recognized urgency of cybersecurity, a critical research problem persists: many organizations remain trapped in "siloed" governance models that focus strictly on technical compliance. The effectiveness of information asset protection depends heavily on the extent to which Information Security Governance (ISG) is internalized within leadership structures and organizational culture. Without a mature governance framework, cyber vulnerabilities can lead to significant financial losses, brand reputation damage, and the loss of intellectual property. This issue is further compounded by a distinct research gap in current literature; prior studies have predominantly focused on technical aspects, such as encryption or intrusion detection, without empirically linking them to an organization's dynamic capability to respond to strategic threats. Therefore, this article aims to bridge this gap by analyzing the influence of information security governance on competitive advantage within a strategic risk management framework to build competitive cyber resilience.
JEL Codes:
Keywords: Strategic Risk Management, Information Security Governance, Competitive Advantage, Cyber Threats, Digital Trust
Bondan Haryono, Galih Wahid Hasyim, Edwin Julianus Sebayang et al.· Global Conference on Busines...· 0 citations
Corporate boards are increasingly expected to provide transparent oversight of cybersecurity risk; however, formal governance structures do not necessarily translate into substantive accountability. Building on institutional and legitimacy perspectives (Suchman, 1995; Marquis & Qian, 2014), this study examines the quality of cybersecurity governance disclosure (CGD) and the extent to which disclosures reflect symbolic compliance rather than substantive accountability. Using a hand-collected balanced panel of 70 Saudi Exchange-listed firms (350 firm-year observations) covering 2020–2024, the study develops a CGD index based on 20 disclosure items and introduces a boilerplate ratio to distinguish generic disclosure from firm-specific, verifiable reporting. The findings reveal a mean CGD index of 19.59 and a mean boilerplate ratio of 0.785, indicating that CGD remains heavily dominated by symbolic compliance. The COVID-19 shock significantly increased boilerplate disclosure, highlighting the fragility of voluntary governance reporting under systemic stress. In contrast, board size, Big 4 auditor engagement, and firm size show limited explanatory power for disclosure substantiveness. The study contributes to board governance literature by introducing a portable measure of disclosure quality and providing evidence that governance structures may create an appearance of accountability without necessarily generating substantive transparency.
O. M. Alghasham· Corporate Board: role, dutie...· 1 citation
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.