•  
  •  
 
MIS Quarterly Executive

Abstract

Cybersecurity governance is increasingly regulated, yet best practice remains fragmented across executive leadership. This article, which draws on our 31 interviews with financial sector leaders, identifies pressing challenges around cybersecurity governance—specifically those connected to tensions around (1) accountability vs. authority, (2) strategic alignment vs. operational execution and (3) clarity vs. ambiguity. To strengthen organizational resilience, we propose a framework for cybersecurity responsibility, ownership and accountability (CROA) and then offer seven recommendations, as well as a self-assessment tool for executives.

Share

COinS