International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722491

1722491 Vol 3 · Issue 4 Download Paper

Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks

Bisola Akeju Ayokunle Olamide Ijagbemi Shalom Alugwe

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity Risk Management

Abstract

This review examines how contemporary organizations can identify, assess, govern, mitigate, and recover from cybersecurity risks generated by expanding digital interdependence. Its purpose is to integrate the technical, managerial, regulatory, and resilience dimensions of cyber risk management within a coherent organizational perspective. A structured narrative review approach was adopted, drawing upon peer-reviewed scholarship, governance concepts, risk-assessment methodologies, and resilience frameworks relevant to enterprises, public institutions, critical infrastructure, and smaller organizations. The analysis shows that organizational exposure is increasingly shaped by advanced persistent threats, malware, ransomware, social engineering, insider activity, cloud computing, Internet of Things deployments, mobile platforms, third-party supply chains, and artificial intelligence-enabled attacks. It further reveals that effective protection depends upon accurate asset identification, scenario-based risk assessment, control effectiveness evaluation, prioritization, and continuous reassessment. Governance emerged as a determinant of cybersecurity maturity because boards, executives, security leaders, business owners, employees, and external providers require defined responsibilities, reporting, and enforceable accountability. The review also establishes that preventive safeguards alone are insufficient; resilient organizations must maintain detection, incident response, business continuity, recovery, adaptation, and institutional learning capabilities. Implementation barriers include legacy systems, fragmented ownership, inadequate budgets, skills shortages, inconsistent awareness, regulatory complexity, weak supplier assurance, and limited empirical datasets, especially in developing economies. The study concludes that cybersecurity should be managed as an enterprise-wide strategic risk. It recommends stronger board oversight, risk-aligned investment, role-specific workforce development, supplier governance, tested recovery arrangements, measurable resilience frameworks, regulatory harmonization, and improved cross-sector threat-intelligence collaboration. Future research should prioritize longitudinal, comparative, and sector-specific evidence capable of identifying practices that produce durable reductions in cyber exposure.

Keywords

cybersecurity governance; cyber risk assessment; organizational resilience; threat management; regulatory compliance; incident response.

How to cite this paper

Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals Volume 3 Issue 4 2019 Page 673-694
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals, vol. 3, no. 4, Oct. 2019
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe (2019). Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks. Iconic Research And Engineering Journals, 3(4).
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals, vol. 3, no. 4, Oct. 2019.
@article{1722491,
      author = {Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe},
      title = {Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {3},
      number = {4},
      pages = {673-694},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722491.pdf},
      abstract = {This review examines how contemporary organizations can identify, assess, govern, mitigate, and recover from cybersecurity risks generated by expanding digital interdependence. Its purpose is to integrate the technical, managerial, regulatory, and resilience dimensions of cyber risk management within a coherent organizational perspective. A structured narrative review approach was adopted, drawing upon peer-reviewed scholarship, governance concepts, risk-assessment methodologies, and resilience frameworks relevant to enterprises, public institutions, critical infrastructure, and smaller organizations. The analysis shows that organizational exposure is increasingly shaped by advanced persistent threats, malware, ransomware, social engineering, insider activity, cloud computing, Internet of Things deployments, mobile platforms, third-party supply chains, and artificial intelligence-enabled attacks. It further reveals that effective protection depends upon accurate asset identification, scenario-based risk assessment, control effectiveness evaluation, prioritization, and continuous reassessment. Governance emerged as a determinant of cybersecurity maturity because boards, executives, security leaders, business owners, employees, and external providers require defined responsibilities, reporting, and enforceable accountability. The review also establishes that preventive safeguards alone are insufficient; resilient organizations must maintain detection, incident response, business continuity, recovery, adaptation, and institutional learning capabilities. Implementation barriers include legacy systems, fragmented ownership, inadequate budgets, skills shortages, inconsistent awareness, regulatory complexity, weak supplier assurance, and limited empirical datasets, especially in developing economies. The study concludes that cybersecurity should be managed as an enterprise-wide strategic risk. It recommends stronger board oversight, risk-aligned investment, role-specific workforce development, supplier governance, tested recovery arrangements, measurable resilience frameworks, regulatory harmonization, and improved cross-sector threat-intelligence collaboration. Future research should prioritize longitudinal, comparative, and sector-specific evidence capable of identifying practices that produce durable reductions in cyber exposure.},
      keywords = {cybersecurity governance; cyber risk assessment; organizational resilience; threat management; regulatory compliance; incident response.},
      month = {October},
  }