Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Asian journal of current res...· 0 citations
Risk-based IT auditing and cybersecurity assurance have become central mechanisms for protecting regulated organizations amid evolving digital threats. This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure. Drawing from a broad body of literature, it examines how regulatory frameworks shape risk identification and control deployment while highlighting assurance practices that contribute to measurable improvements in threat mitigation and compliance. The analysis reveals consistent emphasis on integrated governance approaches alongside persistent implementation tensions, such as mismatches between risk-based ideals and practical application. Key insights underscore the role of adaptive controls, outcome-focused assurance, and sector-specific adaptations in enhancing overall cybersecurity posture. The review also identifies areas where current practices fall short, offering grounded directions for advancing both theory and practice in regulated environments.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations