International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722491

1722491 Vol 3 · Issue 4 Download Paper

Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks

Bisola Akeju Ayokunle Olamide Ijagbemi Shalom Alugwe

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity Risk Management

DOI: https://doi.org/10.64388/IREV3I4-1722491

Abstract

This review examines how contemporary organizations can identify, assess, govern, mitigate, and recover from cybersecurity risks generated by expanding digital interdependence. Its purpose is to integrate the technical, managerial, regulatory, and resilience dimensions of cyber risk management within a coherent organizational perspective. A structured narrative review approach was adopted, drawing upon peer-reviewed scholarship, governance concepts, risk-assessment methodologies, and resilience frameworks relevant to enterprises, public institutions, critical infrastructure, and smaller organizations. The analysis shows that organizational exposure is increasingly shaped by advanced persistent threats, malware, ransomware, social engineering, insider activity, cloud computing, Internet of Things deployments, mobile platforms, third-party supply chains, and artificial intelligence-enabled attacks. It further reveals that effective protection depends upon accurate asset identification, scenario-based risk assessment, control effectiveness evaluation, prioritization, and continuous reassessment. Governance emerged as a determinant of cybersecurity maturity because boards, executives, security leaders, business owners, employees, and external providers require defined responsibilities, reporting, and enforceable accountability. The review also establishes that preventive safeguards alone are insufficient; resilient organizations must maintain detection, incident response, business continuity, recovery, adaptation, and institutional learning capabilities. Implementation barriers include legacy systems, fragmented ownership, inadequate budgets, skills shortages, inconsistent awareness, regulatory complexity, weak supplier assurance, and limited empirical datasets, especially in developing economies. The study concludes that cybersecurity should be managed as an enterprise-wide strategic risk. It recommends stronger board oversight, risk-aligned investment, role-specific workforce development, supplier governance, tested recovery arrangements, measurable resilience frameworks, regulatory harmonization, and improved cross-sector threat-intelligence collaboration. Future research should prioritize longitudinal, comparative, and sector-specific evidence capable of identifying practices that produce durable reductions in cyber exposure.

Keywords

cybersecurity governance; cyber risk assessment; organizational resilience; threat management; regulatory compliance; incident response.

References

[1] Adebayo, O.S. and Abdul Aziz, N. (2019) ‘Improved malware detection model with Apriori association rule and particle swarm optimization’, Security and Communication Networks, 2019, pp. 1–13. Available at: https://doi.org/10.1155/2019/2850932.

[2] Adelola, T., Dawson, R. and Batmaz, F. (2015) ‘The urgent need for an enforced awareness programme to create internet security awareness in Nigeria’, in Proceedings of the 17th International Conference on Information Integration and Web-Based Applications & Services. New York: ACM, pp. 1–7. Available at: https://doi.org/10.1145/2837185.2837237.

[3] Ahmad, A., Hadgkiss, J. and Ruighaver, A.B. (2012) ‘Incident response teams: Challenges in supporting the organisational security function’, Computers & Security, 31(5), pp. 643–652. Available at: https://doi.org/10.1016/j.cose.2012.04.001.

[4] Ahmad, A., Maynard, S.B. and Shanks, G. (2015) ‘A case analysis of information systems and security incident responses’, International Journal of Information Management, 35(6), pp. 717–723. Available at: https://doi.org/10.1016/j.ijinfomgt.2015.08.001.

[5] Akinrolabu, O., Nurse, J.R.C., Martin, A. and New, S. (2019) ‘Cyber risk assessment in cloud provider environments: Current models and future needs’, Computers & Security, 87, article 101600. Available at: https://doi.org/10.1016/j.cose.2019.101600.

[6] Akinwumi, D.A., Iwasokun, G.B., Alese, B.K. and Oluwadare, S.A. (2017) ‘A review of game theory approach to cyber security risk management’, Nigerian Journal of Technology, 36(4), pp. 1271–1285. Available at: 10.4314/njt.v36i4.38.

[7] AlHogail, A. (2015) ‘Design and validation of information security culture framework’, Computers in Human Behavior, 49, pp. 567–575. Available at: 10.1016/j.chb.2015.03.054.

[8] Al-Rimy, B.A.S., Maarof, M.A. and Shaid, S.Z.M. (2018) ‘Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions’, Computers & Security, 74, pp. 144–166. Available at: https://doi.org/10.1016/j.cose.2018.01.001.

[9] Alshamrani, A., Myneni, S., Chowdhary, A. and Huang, D. (2019) ‘A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities’, IEEE Communications Surveys & Tutorials, 21(2), pp. 1851–1877. Available at: https://doi.org/10.1109/COMST.2019.2891891.

[10] Anderson, R. and Moore, T. (2006) ‘The economics of information security’, Science, 314(5799), pp. 610–613. Available at: 10.1126/science.1130992.

[11] Asllani, A., Lari, A. and Lari, N. (2018) ‘Strengthening information technology security through the failure modes and effects analysis approach’, International Journal of Quality Innovation, 4, article 5. Available at: https://doi.org/10.1186/s40887-018-0025-1.

[12] Aven, T. (2016) ‘Risk assessment and risk management: Review of recent advances on their foundation’, European Journal of Operational Research, 253(1), pp. 1–13. Available at: https://doi.org/10.1016/j.ejor.2015.12.023.

[13] Awan, M.S.K., Burnap, P. and Rana, O.F. (2016) ‘Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk’, Computers & Security, 57, pp. 31–46. Available at: https://doi.org/10.1016/j.cose.2015.11.003.

[14] Biener, C., Eling, M. and Wirfs, J.H. (2015) ‘Insurability of cyber risk: An empirical analysis’, The Geneva Papers on Risk and Insurance—Issues and Practice, 40(1), pp. 131–158. Available at: 10.1057/gpp.2014.19.

[15] Biggio, B. and Roli, F. (2018) ‘Wild patterns: Ten years after the rise of adversarial machine learning’, Pattern Recognition, 84, pp. 317–331. Available at: https://doi.org/10.1016/j.patcog.2018.07.023.

[16] Boyson, S. (2014) ‘Cyber supply chain risk management: Revolutionizing the strategic control of critical IT systems’, Technovation, 34(7), pp. 342–353. Available at: 10.1016/j.technovation.2014.02.001.

[17] Brundage, M., Avin, S., Clark, J., Toner, H., Eckersley, P., Garfinkel, B. et al. (2018) The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation. Cambridge: University of Cambridge. Available at: https://doi.org/10.17863/CAM.22520.

[18] Bryce, C. (2019) ‘Security governance as a service on the cloud’, Journal of Cloud Computing, 8, article 23. Available at: https://doi.org/10.1186/s13677-019-0148-5.

[19] Bulgurcu, B., Cavusoglu, H. and Benbasat, I. (2010) ‘Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness’, MIS Quarterly, 34(3), pp. 523–548. Available at: https://doi.org/10.2307/25750690.

[20] Chen, S., Xue, M., Fan, L., Hao, S., Xu, L., Zhu, H. and Li, B. (2018) ‘Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach’, Computers & Security, 73, pp. 326–344. Available at: https://doi.org/10.1016/j.cose.2017.11.007.

[21] Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H. and Stoddart, K. (2016) ‘A review of cyber security risk assessment methods for SCADA systems’, Computers & Security, 56, pp. 1–27. Available at: https://doi.org/10.1016/j.cose.2015.09.009.

[22] Cram, W.A., Proudfoot, J.G. and D’Arcy, J. (2017) ‘Organizational information security policies: A review and research framework’, European Journal of Information Systems, 26(6), pp. 605–641. Available at: 10.1057/s41303-017-0059-9.

[23] Da Veiga, A. and Eloff, J.H.P. (2007) ‘An information security governance framework’, Information Systems Management, 24(4), pp. 361–372. Available at: https://doi.org/10.1080/10580530701586136.

[24] Da Veiga, A. and Martins, N. (2015) ‘Improving the information security culture through monitoring and implementation actions illustrated through a case study’, Computers & Security, 49, pp. 162–176. Available at: https://doi.org/10.1016/j.cose.2014.12.006.

[25] Dinh, H.T., Lee, C., Niyato, D. and Wang, P. (2013) ‘A survey of mobile cloud computing: Architecture, applications, and approaches’, Wireless Communications and Mobile Computing, 13(18), pp. 1587–1611. Available at: 10.1002/wcm.1203.

[26] Dupont, B. (2019) ‘The cyber-resilience of financial institutions: Significance and applicability’, Journal of Cybersecurity, 5(1), article tyz013. Available at: https://doi.org/10.1093/cybsec/tyz013.

[27] Eling, M. and Schnell, W. (2016) ‘What do we know about cyber risk and cyber risk insurance?’, The Journal of Risk Finance, 17(5), pp. 474–491. Available at: 10.1108/JRF-09-2016-0122.

[28] Fernandes, D.A.B., Soares, L.F.B., Gomes, J.V., Freire, M.M. and Inácio, P.R.M. (2014) ‘Security issues in cloud environments: A survey’, International Journal of Information Security, 13(2), pp. 113–170. Available at: 10.1007/s10207-013-0208-7.

[29] Gordon, L.A., Loeb, M.P. and Sohail, T. (2010) ‘Market value of voluntary disclosures concerning information security’, MIS Quarterly, 34(3), pp. 567–594. Available at: https://doi.org/10.2307/25750692.

[30] Gordon, L.A., Loeb, M.P., Lucyshyn, W. and Zhou, L. (2015) ‘Increasing cybersecurity investments in private sector firms’, Journal of Cybersecurity, 1(1), pp. 3–17. Available at: https://doi.org/10.1093/cybsec/tyv011.

[31] Greitzer, F.L. and Frincke, D.A. (2010) ‘Combining traditional cyber security audit data with psychosocial data: Towards predictive modeling for insider threat mitigation’, in Probst, C.W., Hunker, J., Gollmann, D. and Bishop, M. (eds.) Insider Threats in Cyber Security. New York: Springer, pp. 85–113. Available at: https://doi.org/10.1007/978-1-4419-7133-3_5.

[32] Hashizume, K., Rosado, D.G., Fernández-Medina, E. and Fernandez, E.B. (2013) ‘An analysis of security issues for cloud computing’, Journal of Internet Services and Applications, 4(1), article 5. Available at: 10.1186/1869-0238-4-5.

[33] Heartfield, R. and Loukas, G. (2015) ‘A taxonomy of attacks and a survey of defence mechanisms for semantic social engineering attacks’, ACM Computing Surveys, 48(3), article 37, pp. 1–39. Available at: https://doi.org/10.1145/2835375.

[34] Heidt, M., Gerlach, J.P. and Buxmann, P. (2019) ‘Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments’, Information Systems Frontiers, 21(6), pp. 1285–1305. Available at: https://doi.org/10.1007/s10796-019-09959-1.

[35] Herath, T. and Rao, H.R. (2009) ‘Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness’, Decision Support Systems, 47(2), pp. 154–165. Available at: https://doi.org/10.1016/j.dss.2009.02.005.

[36] Higgs, J.L., Pinsker, R.E., Smith, T.J. and Young, G.R. (2016) ‘The relationship between board-level technology committees and reported security breaches’, Journal of Information Systems, 30(3), pp. 79–98. Available at: https://doi.org/10.2308/isys-51402.

[37] Humayed, A., Lin, J., Li, F. and Luo, B. (2017) ‘Cyber-physical systems security—A survey’, IEEE Internet of Things Journal, 4(6), pp. 1802–1831. Available at: 10.1109/JIOT.2017.2703172.

[38] Humphreys, E. (2008) ‘Information security management standards: Compliance, governance and risk management’, Information Security Technical Report, 13(4), pp. 247–255. Available at: https://doi.org/10.1016/j.istr.2008.10.010.

[39] Ifinedo, P. (2012) ‘Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory’, Computers & Security, 31(1), pp. 83–95. Available at: https://doi.org/10.1016/j.cose.2011.10.007.

[40] Iorliam, A. (2019) Cybersecurity in Nigeria: A Case Study of Surveillance and Prevention of Digital Crime. Cham: Springer. Available at: https://doi.org/10.1007/978-3-030-15210-9.

[41] Jansen van Vuuren, J.C. and Leenen, L. (2018) ‘Cybersecurity capability and capacity building for South Africa’, in Kreps, D., Ess, C., Leenen, L. and Kimppa, K. (eds.) This Changes Everything—ICT and Climate Change: What Can We Do? Cham: Springer, pp. 123–135. Available at: https://doi.org/10.1007/978-3-319-99605-9_9.

[42] Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L. and Kirda, E. (2015) ‘Cutting the Gordian knot: A look under the hood of ransomware attacks’, in Almgren, M., Gulisano, V. and Maggi, F. (eds.) Detection of Intrusions and Malware, and Vulnerability Assessment. Cham: Springer, pp. 3–24. Available at: https://doi.org/10.1007/978-3-319-20550-2_1.Kshetri, N. (2019) ‘Cybercrime and cybersecurity in Africa’, Journal of Global Information Technology Management, 22(2), pp. 77–81. Available at: https://doi.org/10.1080/1097198X.2019.1603527.

[43] Linkov, I., Eisenberg, D.A., Plourde, K., Seager, T.P., Allen, J. and Kott, A. (2013) ‘Resilience metrics for cyber systems’, Environment Systems and Decisions, 33(4), pp. 471–476. Available at: https://doi.org/10.1007/s10669-013-9485-y.

[44] Mabunda, S. (2017) ‘Cyber extortion, ransomware and the South African Cybercrimes and Cybersecurity Bill’, Statute Law Review, 40(2), pp. 143–154. Available at: https://doi.org/10.1093/slr/hmx028.

[45] Mbanaso, U.M., Abrahams, L. and Apene, O.Z. (2019) ‘Conceptual design of a Cybersecurity Resilience Maturity Measurement (CRMM) framework’, The African Journal of Information and Communication, 23, pp. 1–26. Available at: https://doi.org/10.23962/10539/27535.

[46] Mohammed, K.H., Mohammed, Y.D. and Solanke, A.A. (2019) ‘Cybercrime and digital forensics: Bridging the gap in legislation, investigation and prosecution of cybercrime in Nigeria’, International Journal of Cybersecurity Intelligence & Cybercrime, 2(1), pp. 56–63. Available at: https://doi.org/10.52306/02010519ZJRK2912.Mollah, M.B., Azad, M.A.K. and Vasilakos, A.V. (2017) ‘Security and privacy challenges in mobile cloud computing: Survey and way ahead’, Journal of Network and Computer Applications, 84, pp. 38–54. Available at: 10.1016/j.jnca.2017.02.001.

[47] Nicho, M. (2018) ‘A process model for implementing information systems security governance’, Information & Computer Security, 26(1), pp. 10–38. Available at: https://doi.org/10.1108/ICS-07-2016-0061.

[48] Nurse, J.R.C., Buckley, O., Legg, P.A., Goldsmith, M., Creese, S., Wright, G.R.T. and Whitty, M. (2014) ‘Understanding insider threat: A framework for characterising attacks’, in 2014 IEEE Security and Privacy Workshops. Piscataway, NJ: IEEE, pp. 214–228. Available at: https://doi.org/10.1109/SPW.2014.38.

[49] Oladipupo, O. (2019) ‘Determinants of information security awareness among employees of capital market registrars in Lagos, Nigeria: An empirical study’, Asian Journal of Computer Science and Technology, 8(1), pp. 48–52. Available at: https://doi.org/10.51983/ajcst-2019.8.1.2119.

[50] Orji, U.J. (2018) ‘The African Union Convention on Cybersecurity: A regional response towards cyber stability?’, Masaryk University Journal of Law and Technology, 12(2), pp. 91–130. Available at: https://doi.org/10.5817/MUJLT2018-2-1.

[51] Parsons, K., McCormac, A., Butavicius, M., Pattinson, M. and Jerram, C. (2014) ‘Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q)’, Computers & Security, 42, pp. 165–176. Available at: https://doi.org/10.1016/j.cose.2013.12.003.

[52] Posthumus, S. and von Solms, R. (2004) ‘A framework for the governance of information security’, Computers & Security, 23(8), pp. 638–646. Available at: https://doi.org/10.1016/j.cose.2004.10.006.

[53] Ring, M., Wunderlich, S., Scheuring, D., Landes, D. and Hotho, A. (2019) ‘A survey of network-based intrusion detection data sets’, Computers & Security, 86, pp. 147–167. Available at: https://doi.org/10.1016/j.cose.2019.06.005.

[54] Roman, R., Zhou, J. and Lopez, J. (2013) ‘On the features and challenges of security and privacy in distributed Internet of Things’, Computer Networks, 57(10), pp. 2266–2279. Available at: 10.1016/j.comnet.2012.12.018.

[55] Samaila, M.G., Neto, M., Fernandes, D.A.B., Freire, M.M. and Inácio, P.R.M. (2018) ‘Challenges of securing Internet of Things devices: A survey’, Security and Privacy, 1(2), article e20. Available at: 10.1002/spy2.20.

[56] Scaife, N., Carter, H., Traynor, P. and Butler, K.R.B. (2016) ‘CryptoLock (and Drop It): Stopping ransomware attacks on user data’, in 2016 IEEE 36th International Conference on Distributed Computing Systems. Piscataway, NJ: IEEE, pp. 303–312. Available at: https://doi.org/10.1109/ICDCS.2016.46.

[57] Shameli-Sendi, A., Aghababaei-Barzegar, R. and Cheriet, M. (2016) ‘Taxonomy of information security risk assessment (ISRA)’, Computers & Security, 57, pp. 14–30. Available at: https://doi.org/10.1016/j.cose.2015.11.001.

[58] Sicari, S., Rizzardi, A., Grieco, L.A. and Coen-Porisini, A. (2015) ‘Security, privacy and trust in Internet of Things: The road ahead’, Computer Networks, 76, pp. 146–164. Available at: 10.1016/j.comnet.2014.11.008.

[59] Siponen, M. and Willison, R. (2009) ‘Information security management standards: Problems and solutions’, Information & Management, 46(5), pp. 267–270. Available at: https://doi.org/10.1016/j.im.2008.12.007.

[60] Siponen, M., Mahmood, M.A. and Pahnila, S. (2014) ‘Employees’ adherence to information security policies: An exploratory field study’, Information & Management, 51(2), pp. 217–224. Available at: https://doi.org/10.1016/j.im.2013.08.006.

[61] Soomro, Z.A., Shah, M.H. and Ahmed, J. (2016) ‘Information security management needs more holistic approach: A literature review’, International Journal of Information Management, 36(2), pp. 215–225. Available at: 10.1016/j.ijinfomgt.2015.11.009.

[62] Sunday, E.A. and Omoegun, G.O. (2018) ‘Integrating solar power solutions in small-scale manufacturing industries in Nigeria’, International Journal of Scientific Research in Science, Engineering and Technology, 4(8), pp. 832–853.

[63] Sunday, E.A. and Omoegun, G.O. (2019) ‘Optimizing electrical load distribution for hybrid solar installations in developing economies’, International Journal of Scientific Research in Mechanical and Materials Engineering, 3(6), pp. 27–47.

[64] Sunday, E.A., Omoegun, G.O., Essien, M.A. and Oluokun, O.A. (2019) ‘Thermodynamic efficiency and control strategies in residential air conditioning systems’, International Journal of Scientific Research in Civil Engineering, 3(3), pp. 52–76.

[65] Taddeo, M., McCutcheon, T. and Floridi, L. (2019) ‘Trusting artificial intelligence in cybersecurity is a double-edged sword’, Nature Machine Intelligence, 1(12), pp. 557–560. Available at: https://doi.org/10.1038/s42256-019-0109-1.

[66] Tatt, D.Y.B., Ganesan, Y. and Fernando, Y. (2019) ‘The effects of cyber supply chain risk management in financial industry’, European Proceedings of Social and Behavioural Sciences, 65, pp. 512–521. Available at: 10.15405/epsbs.2019.08.51.

[67] Tounsi, W. and Rais, H. (2018) ‘A survey on technical threat intelligence in the age of sophisticated cyber attacks’, Computers & Security, 72, pp. 212–233. Available at: https://doi.org/10.1016/j.cose.2017.09.001.

[68] Turel, O. and Bart, C. (2014) ‘Board-level IT governance and organizational performance’, European Journal of Information Systems, 23(2), pp. 223–239. Available at: https://doi.org/10.1057/ejis.2012.61.

[69] Ussath, M., Jaeger, D., Cheng, F. and Meinel, C. (2016) ‘Advanced persistent threats: Behind the scenes’, in 2016 Annual Conference on Information Science and Systems. Piscataway, NJ: IEEE, pp. 181–186. Available at: https://doi.org/10.1109/CISS.2016.7460498.

[70] Van Niekerk, B. (2017) ‘An analysis of cyber-incidents in South Africa’, The African Journal of Information and Communication, 20, pp. 113–132. Available at: https://doi.org/10.23962/10539/23573.

[71] Vishwanath, A., Herath, T., Chen, R., Wang, J. and Rao, H.R. (2011) ‘Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model’, Decision Support Systems, 51(3), pp. 576–586. Available at: https://doi.org/10.1016/j.dss.2011.03.002.

[72] von Solms, R. and van Niekerk, J. (2013) ‘From information security to cyber security’, Computers & Security, 38, pp. 97–102. Available at: 10.1016/j.cose.2013.04.004.

[73] von Solms, R. and Willett, M. (2017) ‘Cloud computing assurance: A review of literature guidance’, Information & Computer Security, 25(1), pp. 26–46. Available at: 10.1108/ICS-09-2015-0037.

[74] Wang, Z. (2018) ‘Deep learning-based intrusion detection with adversaries’, IEEE Access, 6, pp. 38367–38384. Available at: https://doi.org/10.1109/ACCESS.2018.2854599.

[75] Wangen, G., Hallstensen, C. and Snekkenes, E. (2018) ‘A framework for estimating information security risk assessment method completeness’, International Journal of Information Security, 17(6), pp. 681–699. Available at: https://doi.org/10.1007/s10207-017-0382-0.

[76] Windelberg, M. (2016) ‘Objectives for managing cyber supply chain risk’, International Journal of Critical Infrastructure Protection, 12, pp. 4–11. Available at: 10.1016/j.ijcip.2015.11.003.

[77] Woods, D.D. (2015) ‘Four concepts for resilience and the implications for the future of resilience engineering’, Reliability Engineering & System Safety, 141, pp. 5–9. Available at: https://doi.org/10.1016/j.ress.2015.03.018.

[78] Yan, J., Qi, Y. and Rao, Q. (2018) ‘Detecting malware with an ensemble method based on deep neural network’, Security and Communication Networks, 2018, pp. 1–16. Available at: https://doi.org/10.1155/2018/7247095.

How to cite this paper

Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals Volume 3 Issue 4 2019 Page 673-694 https://doi.org/10.64388/IREV3I4-1722491
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals, vol. 3, no. 4, Oct. 2019, doi: https://doi.org/10.64388/IREV3I4-1722491
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe (2019). Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks. Iconic Research And Engineering Journals, 3(4). doi: https://doi.org/10.64388/IREV3I4-1722491
Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe "Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks" Iconic Research And Engineering Journals, vol. 3, no. 4, Oct. 2019. Crossref, https://doi.org/10.64388/IREV3I4-1722491
@article{1722491,
      author = {Bisola Akeju, Ayokunle Olamide Ijagbemi, Shalom Alugwe},
      title = {Cybersecurity Risk Management in Modern Organizations: Threats, Governance, and Resilience Frameworks},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {3},
      number = {4},
      pages = {673-694},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722491.pdf},
      abstract = {This review examines how contemporary organizations can identify, assess, govern, mitigate, and recover from cybersecurity risks generated by expanding digital interdependence. Its purpose is to integrate the technical, managerial, regulatory, and resilience dimensions of cyber risk management within a coherent organizational perspective. A structured narrative review approach was adopted, drawing upon peer-reviewed scholarship, governance concepts, risk-assessment methodologies, and resilience frameworks relevant to enterprises, public institutions, critical infrastructure, and smaller organizations. The analysis shows that organizational exposure is increasingly shaped by advanced persistent threats, malware, ransomware, social engineering, insider activity, cloud computing, Internet of Things deployments, mobile platforms, third-party supply chains, and artificial intelligence-enabled attacks. It further reveals that effective protection depends upon accurate asset identification, scenario-based risk assessment, control effectiveness evaluation, prioritization, and continuous reassessment. Governance emerged as a determinant of cybersecurity maturity because boards, executives, security leaders, business owners, employees, and external providers require defined responsibilities, reporting, and enforceable accountability. The review also establishes that preventive safeguards alone are insufficient; resilient organizations must maintain detection, incident response, business continuity, recovery, adaptation, and institutional learning capabilities. Implementation barriers include legacy systems, fragmented ownership, inadequate budgets, skills shortages, inconsistent awareness, regulatory complexity, weak supplier assurance, and limited empirical datasets, especially in developing economies. The study concludes that cybersecurity should be managed as an enterprise-wide strategic risk. It recommends stronger board oversight, risk-aligned investment, role-specific workforce development, supplier governance, tested recovery arrangements, measurable resilience frameworks, regulatory harmonization, and improved cross-sector threat-intelligence collaboration. Future research should prioritize longitudinal, comparative, and sector-specific evidence capable of identifying practices that produce durable reductions in cyber exposure.},
      keywords = {cybersecurity governance; cyber risk assessment; organizational resilience; threat management; regulatory compliance; incident response.},
      month = {October},
      doi = {https://doi.org/10.64388/IREV3I4-1722491}
  }