From Risk Reporting to Resilience: A Narrative Integrative Review of Cybersecurity Governance Practices in Organizations

William Asare Yirenkyi *

Temple University, Fox School of Business, Philadelphia, PA, United States.

Apaflo Godson Teye

University of Energy and Natural Resources, Sunyani, Ghana.

Matilda Konotey

Temple University, Fox School of Business, Philadelphia, PA, United States.

Yeboah Mary Magdalene

University of Ghana, Accra, Ghana.

*Author to whom correspondence should be addressed.


Abstract

Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.

Keywords: Cybersecurity governance, organizational resilience, enterprise risk management, board oversight, cyber risk disclosure


How to Cite

Yirenkyi, William Asare, Apaflo Godson Teye, Matilda Konotey, and Yeboah Mary Magdalene. 2026. “From Risk Reporting to Resilience: A Narrative Integrative Review of Cybersecurity Governance Practices in Organizations”. Asian Journal of Current Research 11 (3):233-48. https://doi.org/10.56557/ajocr/2026/v11i310877.

Downloads

Download data is not yet available.