COMPARATIVE ANALYSIS OF CYBERSECURITY GOVERNANCE MODELS ACROSS INDUSTRIES
Karyn Ekpo
University of West Georgia – Richards College of Business, Georgia, USA
Abstract
Cybersecurity is an essential governance issue in industries in the United States, yet governance models lack homogeneity and maturity. This paper provides an integrative comparative analysis of cybersecurity governance in five domains, namely financial services, healthcare, energy and operational technology (OT), local government, and higher education. Based on global frameworks (ISO/IEC 27001, NIST Cybersecurity Framework, COBIT 2019), sectoral maturity models, and empirical reviews in recent literature, the research analyzes how boards, executives, and risk functions organize their responsibilities, coordinate their frameworks, and react to regulatory pressure. The convergence around a limited number of multi-framework stacks and governance-risk-compliance logics is demonstrated by the analysis, but the analysis also identifies divergences based on regulatory intensity, resource constraints, organizational culture, and variations in risk profiles (data-centric and safety-critical environments). The public and education sectors, especially, which are under-resourced, find it hard to bring the formal responsibilities to actual practice. The article suggests a three-tier integrative reference model of cybersecurity governance that is aligned to the framework and sensitive sector and points out new requirements to govern AI-enabled security capabilities in addition to traditional controls.
Keywords: Cybersecurity Governance, NIST Cybersecurity Framework, ISO/IEC 27001, Critical Infrastructure.
Journal Name :
VIEW PDF
EPRA International Journal of Research & Development (IJRD)
VIEW PDF
Published on : 2026-04-01
| Vol | : | 11 |
| Issue | : | 3 |
| Month | : | March |
| Year | : | 2026 |