Home > Journals > AIS Journals > MISQE > Vol. 25 (2026) > Iss. 3
Abstract
Cyber risk is now a board-level governance challenge, as increasingly sophisticated threats undermine organizations’ ability to balance resilience and business performance. Drawing on more than 1,800 simulation exercises and executive interviews, we find that decision quality declines sharply as threat complexity increases. We identify four managerial heuristics for strengthening cyber resilience: faster adaptation, iterative learning, business-wide responsibility for managing cyber risk and proactively building capabilities. These findings suggest that effective cyber risk governance depends less on technology than on maintaining decision quality under uncertainty.
Recommended Citation
Zeijlemaker, Sander; Proudfoot, Jeffrey G.; Pal, Ranjan; and Siegel, Michael
(2026)
"Insights from Simulation Exercises on Strengthening Cyber Risk Governance,"
MIS Quarterly Executive: Vol. 25:
Iss.
3, Article 7.
Available at:
https://aisel.aisnet.org/misqe/vol25/iss3/7