Integrating NIST CSF 2.0 governance function with agency theory for enhanced accountability

Purpose Recurring cybersecurity breaches are increasingly attributable to governance failures rooted in human behavior, incentive misalignment, information asymmetry and moral hazard, rather than to technical deficiencies. This paper aims to examine why existing governance frameworks fail to enforce behavioral compliance and proposes a conceptual architecture to address this gap. Design/methodology/approach This study follows the Design Science Research paradigm, structured around Hevner’s three-cycle view and the six-activity methodology of Peffers et al. Ex ante evaluation combines scenario-based walkthroughs of governance failure modes and comparative feature analysis against existing methods, following the Framework for Evaluation in Design Science. Findings This paper proposes the Integrated Behavioral Governance Architecture (IBGA), which reinterprets GV.RR (Roles, Responsibilities and Authorities) through incentive-compatible contracting and augments GV.OV (Oversight) with behavioral monitoring. Analytical evaluation indicates that IBGA is designed to mitigate moral hazard and policy–practice decoupling by rendering agent effort observable and truthful disclosure individually rational, subject to future empirical validation. Research limitations/implications As a conceptual artifact, IBGA has not been empirically instantiated; effectiveness claims are analytically derived and require field validation. Practical implications IBGA provides CISOs with a phased, GRC-integrable behavioral assurance layer supplementing RACI matrices and NIST CSF 2.0 without displacing them and directly addresses recent board-level disclosure obligations under the SEC 2023 cyber rules and DORA. Originality/value This paper contributes a narrow but targeted synthesis: integrating specific agency theory mechanisms into two specific NIST CSF 2.0 Govern categories (GV.RR and GV.OV), bridging organizational economics and cybersecurity governance.

Authors

Institutions

Publication Details

Journal
Information and Computer Security
Published
2026-09-29
DOI
https://doi.org/10.1108/ics-04-2026-0198
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Integrating NIST CSF 2.0 governance function with agency theory for enhanced accountability

Sibgha Tahir, Muhammad Hasnain, Hilmand Khan, Muhammad Ozair et al.
Information and Computer Security
Information and Cyber Security
article

Integrating NIST CSF 2.0 governance function with agency theory for enhanced accountability

Sibgha Tahir, Muhammad Hasnain, Hilmand Khan, Muhammad Ozair, Muhammad Umar Akhlaq
article en

Abstract

Purpose Recurring cybersecurity breaches are increasingly attributable to governance failures rooted in human behavior, incentive misalignment, information asymmetry and moral hazard, rather than to technical deficiencies. This paper aims to examine why existing governance frameworks fail to enforce behavioral compliance and proposes a conceptual architecture to address this gap. Design/methodology/approach This study follows the Design Science Research paradigm, structured around Hevner’s three-cycle view and the six-activity methodology of Peffers et al. Ex ante evaluation combines scenario-based walkthroughs of governance failure modes and comparative feature analysis against existing methods, following the Framework for Evaluation in Design Science. Findings This paper proposes the Integrated Behavioral Governance Architecture (IBGA), which reinterprets GV.RR (Roles, Responsibilities and Authorities) through incentive-compatible contracting and augments GV.OV (Oversight) with behavioral monitoring. Analytical evaluation indicates that IBGA is designed to mitigate moral hazard and policy–practice decoupling by rendering agent effort observable and truthful disclosure individually rational, subject to future empirical validation. Research limitations/implications As a conceptual artifact, IBGA has not been empirically instantiated; effectiveness claims are analytically derived and require field validation. Practical implications IBGA provides CISOs with a phased, GRC-integrable behavioral assurance layer supplementing RACI matrices and NIST CSF 2.0 without displacing them and directly addresses recent board-level disclosure obligations under the SEC 2023 cyber rules and DORA. Originality/value This paper contributes a narrow but targeted synthesis: integrating specific agency theory mechanisms into two specific NIST CSF 2.0 Govern categories (GV.RR and GV.OV), bridging organizational economics and cybersecurity governance.

Information and Computer Security
University of Strathclyde (GB), Air University (PK)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.