1. Introduction
The Internet of Things (IoT) is a complex ecosystem of devices connected by wired or wireless networks with the ultimate goal of providing services to humans and machines. IoT has witnessed remarkable development over the last decade [
1]. IoT, powered by smart sensors, powerful embedded microelectronics, high-speed connectivity, and internet protocols, is poised to disrupt today’s value chains [
2]. Traditional governance frameworks are often ill-equipped to address the unique characteristics of hyperconnected IoT environments. The large number and diversity of IoT devices create barriers to the adoption of uniform standards and regulations. Emerging governance approaches must manage complex data flows while protecting fundamental rights such as privacy, data protection, and informational self-determination. IoT ecosystems generate large volumes of personal and behavioral data through connected devices, raising significant ethical and regulatory concerns [
3,
4]. The interconnectedness of IoT devices creates vulnerability to cyberattacks, as illustrated by the Dyn cyberattack [
5]. Many current governance systems are organized into sector-specific silos, hindering the development of holistic ecosystem-based management approaches [
6]. In regions such as the Caribbean, the proximity of states and the presence of many SIDS intensify governance challenges over shared resources [
7].
Consequently, there is an urgent need for resilient, theory-based governance models to manage the complexities of the hyperconnected IoT ecosystem. Adaptive governance provides links among individuals, organizations, agencies, and institutions across multiple levels of organization [
8]. It is a learning, flexible approach to adapting to varying conditions [
8,
9]. Considering IoT ecosystems as SES provides a holistic perspective on how technological, human, and environmental aspects are interrelated within them [
9]. As in the case of environment management, effective governance will result only from collaboration among various stakeholders, including governments, businesses, researchers, and citizens [
8]. They note that “Bridging organizations” may have a crucial role in promoting collaboration to resolve emerging conflicts [
8]. Governance models should take into account power imbalances and an equal representative channel for each stakeholder in decision-making [
9,
10]. Decentralized models of Internet governance and distributed trust schemes promote resilience and security [
11].
Although the adoption of IoT is rapidly expanding across sectors, the existing governance and security literature remains fragmented and poorly tailored to the unique characteristics of IoT ecosystems. A review of prior work reveals several interrelated gaps. In reviews of IoT security literature, risk management is seldom comprehensively addressed; prior research focus on discrete technical issues such as secure protocols or device-level security, while few have set out to provide a holistic, organizational-level governance model integrating risk assessment and resilience planning as core elements [
12]. Existing security or data-governance proposals, such as those on data lifecycle management, tend to cover only narrow elements, such as data governance in a particular domain, like digital IS ecosystems, rather than the more general organizational governance necessary in heterogeneous, multi-stakeholder IoT settings [
13].
While prior studies have identified best practices and guideline-based frameworks, few provide progressive maturity levels that enable organizations to systematically assess and evolve their governance capabilities. Existing approaches often lack a structured pathway from ad hoc to optimized governance. IoT governance research has rarely mentioned how compliance requirements (data privacy, regulatory mandates), risk governance, and resilience/adaptation capabilities should be woven together in an overall organizational governance framework [
14]. This paper addresses these deficiencies by proposing a theoretically grounded and unified organizational governance model specifically designed for IoT-driven ecosystems. This model responds to the growing complexity of IoT environments by integrating governance dimensions that are often examined in isolation within existing literature.
First, this study introduces a comprehensive governance model that incorporates strategic governance, operational oversight, compliance alignment, risk governance, resilience and adaptation, and stakeholder coordination. By bringing these elements together, the model captures a holistic view of IoT governance that is rarely addressed in an integrated manner. Second, this paper presents a maturity framework that enables organizations to assess and progressively enhance their IoT governance capabilities. This framework supports a structured transition from reactive governance practices toward more advanced, ecosystem-optimized governance approaches. Third, the proposed model embeds an integrated risk assessment and resilience planning approach. Through continuous monitoring and adaptive mechanisms, it addresses the dynamic and evolving nature of IoT-specific risks and environmental changes. Fourth, the framework is intentionally managerial in orientation rather than purely technical. This design ensures that the model is accessible and actionable for organizational decision-makers, risk managers, and governance boards. Finally, this study bridges key research gaps by combining governance theories, including organizational, socio-technical, and risk governance perspectives, with the unique characteristics of IoT systems. In doing so, it contributes to academic discourse while offering a practical roadmap for organizations seeking to deploy IoT technologies at scale. Unlike prior models that focus primarily on technical controls or isolated governance mechanisms, URSGM uniquely integrates governance decision rights, compliance alignment, risk governance, resilience feedback loops, and ecosystem coordination within a single unified architecture. This enables organizations to operationalize governance holistically across strategic, operational, and adaptive dimension something not explicitly achieved in existing IoT governance models.
3. Organizational Governance
Governance is about the structures, processes, and practices that direct an organization toward achieving its goals and objectives through risk management and accountability. Organizational resilience enables organizations to absorb or recover from disruptions caused by adverse events. Whiteman et al. [
18] argue that businesses, particularly in high-latitude regions, must expand their understanding of resilience beyond traditional economic metrics to include ecological resilience as a vital component of sustainable corporate governance. This perspective emphasizes the importance of considering an organization’s environmental impact and the resilience of the ecosystems in which business is conducted. Governance narratives shape organizational behavior and stakeholder engagement, as Morrell’s analysis of governance in the NHS shows. In examining the roles of key actors, such as Foundation Trusts and NHS staff, Morrell [
17] emphasizes that narrative is integral to governance itself, shaping perceptions of freedom, clinical governance, and patient choice.
Resilience, then, is emerging as a primary goal of governance models. Lockwood et al. [
19] emphasize the need for adaptive governance mechanisms to respond to environmental changes affecting marine biodiversity. These results imply that learning, stakeholder engagement, and decision-making processes all contribute positively to the resilience of social-ecological systems and should be important components of effective governance. This is particularly crucial for an adaptive approach within organizations operating IoT ecosystems, due to the rapid advancement of technologies and environmental changes that demand flexible governance. Alves et al. [
20], on the other hand, have underlined the role of governance mechanisms in software ecosystems in maintaining ecosystem health and fostering collaboration between organizations. Their systematic literature review indicates that governance mechanisms may influence decision rights, control, and organizational performance. The importance of this insight lies in the fact that organizations using IoT technologies must manage complex interdependencies among heterogeneous actors, and governance structures must enable collaborative innovation.
There has been an increasing application of polycentric governance models to tackle complex socio-ecological challenges. According to Cvitanovic et al. [
21], polycentric systems with multiple governing bodies operating at different levels enhance the resilience of fisheries management. This model encourages greater stakeholder participation and local-level policy freedom, both vital for effective governance in dynamic environments. As more organizations embrace IoT technologies, principles of polycentric governance could lay the foundation for governance structures that are responsive at the local level and foster resilience.
4. Characteristics of IoT Ecosystems
As IoT technology adoption rapidly grows, it is important to understand the basic characteristics of these ecosystems to support resilience and governance effectiveness. A key characteristic of IoT ecosystems is their heterarchical structure, which enables decentralized decision-making and collaboration among multiple stakeholders. According to Leminen et al. [
22], this heterarchical nature nurtures various business models, such as value chain efficiency and industry collaboration. Such features of business models promote innovation and adaptability within that very ecosystem. In this research, four archetypal IoT business models were identified, which demonstrate how organizations can create value through the use of IoT technologies in a collaborative environment. Governance within IoT ecosystems is crucial for providing assurance of data sharing and collaboration among stakeholders. For instance, De Prieelle et al. [
23] identify ecosystem data governance as an increasingly relevant challenge, particularly in data-sensitive industries such as horticulture. They concluded that, although various factors affect the adoption of data-sharing platforms, ecosystem data governance is one of the most decisive variables that platform providers should consider to attract data owners.
Another critical characteristic of IoT ecosystems that has recently received attention is resilience. This denotes an ecosystem’s ability to resist disturbances, absorb shocks, and ultimately recover from disruption. Whaiduzzaman et al. [
24] propose a resilient fog-IoT framework that ensures efficient resource management and system reliability, particularly in the event of failures in a master fog node. In this respect, the framework therefore demonstrates how architectural considerations can ensure IoT ecosystems resilience by facilitating fault-tolerant microservice execution. Advanced technologies, such as blockchain and AI, integrated into the IoT ecosystem, are changing the dynamics. El-Masri and Hussain [
25] explain how blockchain can ensure the security of IoT ecosystems by addressing various threats through its built-in features, such as decentralization and transparency. This integration not only ensures security but, above all, builds trust among the relevant stakeholders, which is a pivotal factor for an effective IoT ecosystem. Beyond security, AI’s role in enhancing resilience and efficiency in IoT ecosystems cannot be ignored. Ahmad et al. [
26] examine the role of AI-driven automation in optimizing energy usage and operational resilience in smart buildings. This study highlights the role of AI in enabling real-time monitoring and data-driven decision-making, which are critical to maintaining the sustainability and efficiency of IoT ecosystems.
Security governance is highly relevant in the context of IoT due to the unique challenges brought in by these systems. In general, IoT ecosystems are complex and involve a wide range of devices, networks, and applications [
27]. The inherent complexity and resource limitation of most IoT devices make traditional security mechanisms ineffective [
28]. Most importantly, the large volume of data generated by IoT devices also poses significant challenges for privacy, security, and data ownership. Therefore, it is essential to ensure that IoT systems and the data they process are subject to effective security governance to maintain confidentiality, integrity, and availability [
29]. Given the challenges mentioned above, several researchers and practitioners have proposed various frameworks and approaches to IoT security governance (
Table 1).
6. Conceptual Foundations
Building a robust, coherent governance model requires more than ad hoc or practice-driven constructs: it demands a rigorous theoretical foundation that can anchor and justify the structural, organizational, and adaptive aspects of IoT governance. Thus, this section draws on well-established scholarly theories, including governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive-capacity theory. By doing so, the section establishes the ontological and epistemological bedrock for the unified governance model, ensuring that each governance dimension is conceptually grounded, theoretically justified, and capable of addressing the complexity and dynamic risks characteristic of IoT-driven organizations [
43].
Table 2 synthesizes the primary theoretical foundations relevant to IoT governance.
6.1. Governance Theory
Organizational governance theory, especially as applied to IT governance, offers the foundational rationale for structuring a security governance model in IoT-driven organizations. Over decades of research, IT governance has evolved from narrow, control-oriented frameworks to more holistic, strategic frameworks that aim to align IT (and now digital/IoT) resources with organizational value creation, risk management, and long-term sustainability [
50].
Concretely, modern governance theory emphasizes decision rights, accountability, oversight mechanisms, and alignment between organizational strategy and technological capabilities. In an IoT context, these aspects become paramount: as IoT devices proliferate, connect multiple stakeholders, and blur boundaries between IT, operations, and, at times, physical infrastructure, traditional governance mechanisms may no longer suffice. Thus, grounding the IoT security governance model in governance theory ensures that the notion of “governance” encompasses not only technical controls but also organizational structure, accountability, oversight, and strategic alignment of IoT within the enterprise. Recent scholarship argues that governance must adapt to complexity, dynamism, and convergence of technologies. For example, the notion of “cybernetic governance” suggests that governance theory itself must evolve to respond to the convergence of multiple technological systems, increased unpredictability, and overlapping governance regimes (e.g., across regulatory, technical, and organizational domains) [
51].
6.2. Resilience and Adaptive Capacity Theory
Resilience theory provides a critical complement to governance: while governance secures structure, roles, and accountability, resilience ensures the organization can absorb, adapt, and recover in the face of disruptions, which, in IoT-driven environments, are frequent and manifold (cyberattacks, device failures, interoperability crises, supply-chain issues, etc.). The concept of resilience in organizational and cyber contexts has been increasingly studied, highlighting that resilience is not just about recovering after a disruption but also about anticipating changes, adapting, and evolving [
17].
From a systems perspective, resilience can be framed as the capacity of socio-technical systems to respond to environmental changes via feedback loops, adaptation, and reorganization [
52]. In the context of IoT governance, embedding adaptive capacity means that the governance model not only defines static policies or controls, but also fosters mechanisms for continuous monitoring, learning, feedback, and evolution. This dynamic orientation helps organizations handle the unpredictability, heterogeneity, and rapid change typical of IoT ecosystems.
Recent empirical research underscores the role of IT capabilities (infrastructure, human, business-spanning) and social capital in enabling organizational resilience, especially in volatile and uncertain contexts such as those shaped by IoT and digital transformation [
53]. By anchoring the governance model in resilience and adaptive capacity theory, the framework can provide organizations with a structured approach to not only ensure governance compliance but also build long-term survivability and agility as IoT landscapes evolve.
6.3. Socio-Technical Systems Theory
This theory warns against purely technical approaches, emphasizing that technical solutions alone are insufficient without organizational, cultural, and process-level support. Indeed, empirical work in cybersecurity confirms that many security failures are rooted not in technical flaws, but in human behavior, organizational culture, weak processes, or misaligned incentives [
54]. Thus, a governance model for IoT needs to integrate socio-technical thinking, balancing technical oversight with human, process, and organizational elements. In practical terms, embedding STS theory means the governance model will consider roles, responsibilities, training, change management processes, organizational security culture, stakeholder coordination, and accountability, not only device-level controls. This is especially important in IoT systems where device ownership, usage contexts, and stakeholders may be heterogeneous, distributed, and even external to the core organization (e.g., third-party providers, partners, customers).
6.4. Risk Governance Theory
While governance theory defines structures and decision-rights, and resilience theory addresses adaptability, risk governance theory provides the framework for understanding, assessing, managing, and mitigating risks, especially relevant in IoT environments where new risk vectors, dynamic threats, and complex interdependencies abound. Risk governance extends traditional risk management by incorporating strategic oversight, stakeholder involvement, accountability, and feedback. In particular, risk governance theory emphasizes the need for continuous risk monitoring, context-aware risk assessment, and dynamic adaptation of risk controls. This aligns with cyber-resilience demands, where static risk assessments or one-off audits are inadequate. Indeed, contemporary cybersecurity research increasingly calls for integrating risk governance within organizational governance structures, rather than treating risk as a peripheral or purely technical concern [
55].
Applying risk governance theory to IoT governance means the model will not only define periodic risk assessments but embed risk governance across strategic, operational, and organizational layers, linking risk identification, evaluation, mitigation, compliance, and resilience. It will also support continuous monitoring and feedback loops, helping organizations adapt their risk posture as IoT ecosystems evolve, new threats emerge, or regulatory landscapes shift.
6.5. Institutional/Compliance Theory
Institutions, meaning formal and informal norms, rules, regulations, organizational norms, and external compliance regimes, play a crucial role in shaping organizational behavior, governance structures, and security practices. Institutional theory provides a lens to understand how external pressures (regulations, industry norms, standards, social expectations) and internal organizational pressures (norms, culture, legitimacy concerns) influence the adoption of governance practices.
In the cybersecurity and IoT domain, institutional pressures such as regulatory mandates (data protection laws, IoT security standards), industry compliance requirements, and stakeholder expectations for accountability and transparency can strongly shape how organizations design their governance models. Recent research argues that institutions exert coercive (regulation), mimetic (industry best practice), and normative (professional norms) pressures that shape cybersecurity governance adoption [
56].
Because IoT systems often cross organizational, sectoral, and jurisdictional boundaries, institutional theory helps conceptualize how governance models must align with external regulatory regimes, compliance requirements, and demands for institutional legitimacy. In effect, institutional theory ensures that the governance model is not only internally consistent but also externally legitimate and sustainable in the broader institutional environment.
6.6. Integrative Logic for a Unified IoT Security Governance Model
Bringing together governance theory, resilience theory, socio-technical systems theory, risk governance, and institutional/compliance theory offers a powerful integrative logic that recognizes IoT-driven organizations as complex, socio-technical, adaptive systems operating in dynamic, regulated environments. This integrative foundation supports a robust, flexible, context-aware, and legitimate unified security governance model.
The logic proceeds as follows: governance theory defines the structural backbone (decision rights, oversight, accountability); socio-technical systems theory ensures that technical and human/organizational dimensions are jointly optimized; risk governance theory embeds continuous risk awareness, assessment, and mitigation; resilience theory injects adaptive capacity, learning, and system-level robustness; institutional theory aligns internal governance with external norms, regulations, and legitimacy requirements.
Using this integrative anchor enables the model to address the unique challenges of IoT ecosystems: device and stakeholder heterogeneity, rapid change, regulatory complexity, and evolving threat landscapes. It also ensures that the model is not overly technocratic or narrow, but embraces organizational structure, human factors, compliance, and adaptability. In doing so, the model becomes a living governance model: capable of guiding organizations through IoT adoption, growth, crisis, and evolution, while ensuring security, compliance, and resilience.
Figure 1 illustrates how five core theories, each contributing distinct conceptual rationales that collectively inform and structure the proposed unified IoT security governance model.
7. Unified Resilient Security Governance Model (URSGM) for IoT-Driven Organizations
As organizations increasingly adopt IoT ecosystems, the complexity and interconnectedness of devices, data flows, and stakeholders demand a governance model that goes beyond traditional IT or cybersecurity frameworks. The unified model proposed here seeks to integrate strategic oversight, operational execution, risk governance, compliance alignment, resilience planning, and stakeholder coordination, treating IoT security not as a purely technical challenge but as an organizational, socio-technical, and governance challenge. This integrated perspective is supported by recent shifts in governance theory: some scholars argue for a “governance convergence” to address the complexity arising from technological convergence and overlapping regulatory regimes [
51].
The unified model is conceived as a high-level governance architecture tailored to IoT ecosystems: it defines governance layers, delineates responsibilities and decision rights, embeds risk management and resilience mechanisms, ensures alignment with compliance and regulatory requirements, and provides for adaptation and stakeholder integration across internal and external domains (e.g., suppliers, service providers, regulatory bodies). In doing so, the model aims to bridge the gap between technical IoT security controls and organizational governance, offering executives and governance boards a structured, theory-informed roadmap for comprehensively managing IoT risks and resilience (
Figure 2).
7.1. Core Dimensions of the Model
At the heart of the unified governance model are several core dimensions, each representing a governance “layer” that reflects both organizational and contextual needs. The Strategic Governance Layer establishes the long-term vision, policies, and governance structure for IoT adoption. It involves top management and board-level oversight, decision rights, resource allocation, and alignment with organizational objectives. This layer ensures that IoT adoption and security are not treated as afterthoughts but as strategic assets requiring governance commitment. This strategic orientation aligns with the call in recent literature to elevate cybersecurity to a board-level strategic concern, where boards perform sensemaking, threat scanning, and oversight across the pre-incident, incident, and post-incident phases [
57].
The Operational Governance Layer translates strategic policies into operational practices. This includes defining roles and responsibilities (e.g., who manages IoT devices, who handles incident response, who liaises with suppliers), establishing processes and procedures (such as procurement guidelines, configuration management, patching schedules), and designing communication and reporting channels. Operational governance ensures that IoT security is embedded in everyday workflows rather than being siloed. Such embedding is critical: when governance remains abstract, operational teams may default to ad-hoc or contradictory practices. A dynamically adaptive governance model emphasizes the need for continuous review, updating, and alignment of procedures to business goals [
58].
The Technical Oversight (managerial) dimension does not aim to re-implement device-level controls, but to oversee and coordinate technical security measures at a high level, ensuring that technical decisions (e.g., network segmentation, device onboarding, authentication, update policy) adhere to governance requirements, risk assessments, and compliance mandates. This oversight dimension recognizes the heterogeneity of IoT environments and treats technical security measures as part of a broader governance architecture rather than isolated technical silos. Such multilayered governance is particularly relevant in cloud-integrated or hybrid IoT deployments, where network-integrated governance frameworks have been proposed to manage distributed, heterogeneous IoT + cloud infrastructures [
59].
The Compliance Alignment dimension ensures that the organization’s IoT governance aligns with external regulatory, standardization, and legal requirements. As organizations deploy IoT systems across jurisdictions and domains, regulatory pressures and compliance obligations become non-negligible. The governance framework, therefore, includes mechanisms to track regulatory change, embed compliance requirements into procurement, lifecycle management, and supplier contracts, and ensure compliance is not an afterthought but a core governance dimension. Recent work on compliance-driven cybersecurity governance underlines that embedding compliance within governance structures enhances operational resilience and policy enforcement across the enterprise [
60].
IoT security governance is increasingly shaped by international cybersecurity standards and regulatory frameworks. Widely recognized standards such as ISO/IEC 27001 for information security management, ETSI EN 303 645 for consumer IoT security, and ISA/IEC 62443 for industrial control systems provide structured guidance for implementing governance controls across device lifecycle management, risk assessment, vulnerability management, and incident response. Aligning governance models with these standards enhances regulatory compliance, strengthens operational resilience, and supports institutional legitimacy in IoT deployments [
61,
62,
63,
64].
The Risk Governance dimension brings structured, continuous risk management into the governance model. Rather than treating risk assessment as a periodic or one-time activity, this dimension embeds risk identification, evaluation, mitigation, and monitoring as ongoing governance functions, covering threats to device integrity, data confidentiality, service availability, supply-chain risks, and cascading risks arising from interconnected systems. The inclusion of risk governance reflects broader movements in cybersecurity governance that view cyber risk as part of enterprise-wide risk and resilience management [
65].
The Resilience & Adaptation dimension captures the organization’s capacity to anticipate, absorb, respond to, and recover from disruptions, whether caused by cyber incidents, device failures, supply-chain issues, or regulatory changes. Embedding resilience into governance ensures the organization is protected not only against known risks but also prepared for uncertainty and evolving threats. This dynamic/adaptive orientation resonates with recent proposals for adaptive cybersecurity governance frameworks, which emphasize feedback loops, continuous evaluation, and resilience planning as integral to organizational security governance [
58].
Finally, the Stakeholder/Ecosystem Coordination dimension acknowledges that IoT ecosystems often span multiple internal units, supply-chain partners, third-party service providers, external regulators, and users. The governance model, therefore, includes structures and processes for stakeholder coordination and communication, supplier governance, shared responsibility agreements, and collaborative risk management. Through this dimension, the model recognizes IoT as not just an internal organizational deployment, but part of a broader ecosystem, requiring governance across organizational boundaries, supply-chain transparency, and accountability mechanisms spanning all stakeholders.
7.2. Governance Maturity Levels
To support progressive adoption of IoT governance practices, the URSGM incorporates a governance maturity perspective. Maturity models are widely used in cybersecurity and IT governance to evaluate organizational capabilities and guide incremental improvement of governance practices [
66]. Such models enable organizations to assess their current governance posture and identify structured pathways toward more integrated and resilient governance mechanisms.
Within IoT ecosystems, governance maturity evolves from fragmented and reactive security practices toward integrated governance structures capable of managing risk, compliance, and ecosystem coordination. Early stages of maturity typically focus on basic security controls and reactive incident response. As governance capabilities develop, organizations increasingly integrate risk governance, compliance monitoring, and strategic oversight into formal governance structures. At the highest maturity levels, governance incorporates adaptive feedback loops and ecosystem-wide coordination mechanisms that support continuous learning and resilience against emerging cyber-physical threats [
3].
Table 3 presents summery of governance maturity levels in IoT security governance.
7.3. Interactions and Information Flows
The layers and dimensions described above are not isolated silos; rather, the unified governance model envisions dynamic information flows and interactions across them. Strategic governance provides direction and policy that feed into operational governance and technical oversight. In turn, the operational and technical layers report upward on risk assessments, compliance status, incident reports, and supply-chain alerts, enabling strategic decision-makers to review, adapt, and reallocate resources. The risk governance and resilience layers operate continually, feeding data from monitoring, audits, incident response, and stakeholder feedback back into operational and strategic governance, thereby enabling continuous learning and adaptation.
Stakeholder coordination creates lateral flows among internal units, external partners, suppliers, and regulators. Compliance alignment ensures that regulatory changes or compliance audit findings flow into strategic and operational layers, prompting policy updates, process changes, or technical adjustments. In IoT environments with their distributed architecture, heterogeneous device population, and frequent external dependencies, such integrated flows are crucial. Indeed, practitioners designing governance for cloud-integrated IoT systems propose unified orchestration layers that enforce security policies across devices and cloud infrastructure, and that support real-time risk assessment and compliance monitoring [
59]. Thus, the model draws on a cyber-resilience governance logic: continuous risk and compliance feedback, adaptive governance, and ecosystem-wide coordination, ensuring that IoT governance remains effective, current, and responsive to change.
7.4. Explanation of Constructs and Managerial Implications
The constructs of the unified governance model carry concrete managerial implications. The Strategic Governance dimension ensures that IoT security becomes part of the organization’s strategic agenda rather than merely an IT afterthought. For senior executives and boards, this means establishing clear governance structures (e.g., a dedicated IoT security governance committee), integrating IoT security into enterprise risk management (ERM), and allocating resources and accountability across the organization.
Operational Governance implies defining and formalizing roles, responsibilities, and workflows for IoT operations, including procurement, deployment, maintenance, incident response, and supplier management. From a managerial standpoint, this requires cross-functional collaboration (IT, operations, procurement, legal, compliance), clear documentation, and regular review, which support consistency, reduce silos, and ensure that IoT security is embedded in organizational processes.
Technical Oversight (managerial) means that technical decisions and security implementations are not left to ad hoc technical teams but are reviewed and governed within the broader governance framework, ensuring alignment with risk appetite, compliance obligations, and organizational strategy. Managers must provide oversight, ensure accountability, and maintain visibility on IoT-related technical activities.
Compliance Alignment means managers must treat regulatory and standards compliance proactively. This involves tracking relevant legislation and industry standards, embedding compliance into procurement and supplier contracts, conducting periodic compliance assessments, and possibly appointing compliance officers or committees. For IoT deployments, often cross-jurisdictional and multi-stakeholder, compliance alignment is not optional but essential to avoid regulatory, legal, and reputational risks.
Risk Governance places risk management at the heart of governance. Managerial implications include establishing continuous risk assessment programs, integrating IoT risk into enterprise-wide risk registers, developing risk mitigation strategies (technical, process, supplier), and embedding risk reporting and escalation paths. This enables informed decision-making under uncertainty and ensures resources are allocated to the most critical vulnerabilities.
Resilience & adaptation requires that management views IoT security not only in terms of prevention but also in terms of organizational capacity to absorb, adapt, and recover. This may involve business continuity planning, incident response planning, supplier contingency, redundancy strategies, and periodic resilience testing. Managers must foster a culture of resilience, support training, and champion continuous improvement.
Stakeholder/ecosystem Coordination emphasizes external relationships: supplier governance, supplier risk assessments, transparency of security posture, shared responsibility agreements, and communication with regulatory bodies or users. Managerial commitment to coordination ensures that IoT governance extends beyond internal boundaries, that supply-chain or third-party risks are managed, and that the organization remains accountable and trustworthy across its ecosystem.
8. Discussion
The unified framework proposed in this paper advances theory by filling a notable lacuna: the absence of a coherent, holistic governance model tailored to IoT’s socio-technical complexity. Prior reviews of IoT governance frameworks underscore this gap. For example, a comprehensive review of governance literature concludes that “ninety percent of the offerings currently in existence to address IoT-related risk are repackaged general-purpose IT security technologies”, which are inadequate given IoT’s heterogeneity and specialized risk profile. By rooting our model in multiple theoretical traditions, governance theory, socio-technical systems, risk governance, institutional compliance, and resilience/adaptive capacity, we provide a multi-dimensional, theory-anchored architecture that systematically maps why governance constructs exist (theoretical rationale) to what organizational functions they serve (governance mechanisms). This bridging of theory to mechanism responds directly to calls for more conceptually rigorous IoT governance frameworks rather than ad-hoc, technical-only designs.
By embedding a maturity model and feedback/adaptation loops (via resilience and risk governance theories), the framework contributes to dynamic governance theory. Instead of prescribing static controls, it conceptualizes governance as an emergent, evolving process, capable of adapting to changing threat landscapes, regulatory shifts, and evolving IoT ecosystems configurations. This aligns with resilience theory’s emphasis on adaptive capacity and learning, as exemplified in research on IoT resilience mechanisms [
46]. The theoretical integration supports cross-disciplinary coherence, bridging organizational governance, cybersecurity, risk management, and compliance theory; thus, offering a comprehensive theoretical scaffold for future empirical research.
For practitioners and decision-makers, the proposed governance model offers a structured roadmap for embedding IoT security governance at the management and board levels. The Strategic Governance dimension transforms IoT from a technical project to a strategic asset, making it visible at the executive and board level, a shift echoed in corporate-governance research emphasizing decision-rights, accountability, and firm performance linkage [
67]. Operational Governance and Technical Oversight provide concrete guidance on how to translate strategic policy into day-to-day practices, reducing the risk of ad hoc, inconsistent security measures. Risk Governance and Compliance Alignment enable organizations to systematically assess, prioritize, and respond to IoT-specific risks, addressing a known deficiency in existing IoT security literature, which rarely includes risk-management frameworks [
12]. The Resilience & Adaptation component encourages a managerial focus on long-term continuity, incident response, and recovery planning, which are critical for IoT deployments, especially in sectors with high availability requirements (e.g., healthcare, critical infrastructure). The Stakeholder/Ecosystem Coordination layer supports holistic responsibility across supply chains, vendors, and third-party partners, often neglected in purely technical models but essential for real-world IoT ecosystems.
The modular architecture of the URSGM framework also enhances its applicability for small and medium-sized enterprises (SMEs), which often operate under resource constraints. Rather than requiring full-scale implementation, the framework allows incremental adoption, where organizations can initially focus on strategic governance and basic risk governance before progressively integrating compliance alignment, resilience mechanisms, and ecosystem coordination. This scalability ensures that the model remains practical and implementable across organizations of varying sizes and maturity levels [
3].
To illustrate the practical applicability of the URSGM framework, consider a manufacturing organization deploying IoT-enabled sensors across its production lines. At the strategic level, governance structures define decision rights and align IoT initiatives with organizational objectives. At the operational level, policies govern device lifecycle management, maintenance, and incident response. Risk governance mechanisms continuously monitor vulnerabilities and assess cyber risks associated with interconnected devices. Compliance alignment ensures adherence to relevant standards and regulatory requirements. Finally, resilience mechanisms enable the organization to respond to disruptions and recover from cyber incidents through adaptive processes and feedback loops. This example demonstrates how the different governance dimensions operate cohesively in a real-world setting.
The framework is applicable across multiple contexts, making it practically useful in diverse IoT-driven organizational settings. For a large enterprise deploying IoT at scale (e.g., manufacturing, logistics, smart buildings), the model can guide the design of the governance architecture, from board-level commitment and procurement policies for IoT devices to supplier security requirements and continuous risk monitoring and resilience planning. In a critical-infrastructure context (e.g., energy, utilities, healthcare), the risk governance + resilience components help manage dynamic threat landscapes, supply-chain dependencies, and compliance with strict regulatory regimes. For small-to-medium enterprises (SMEs) or decentralized deployments (e.g., smart retail, distributed devices), the maturity model can help assess current governance posture and provide a roadmap to progressively improve, from reactive security to integrated governance and resilience. Finally, organizations undergoing digital transformation can use the model as a blueprint to integrate IoT governance with existing enterprise governance and risk management frameworks, reducing fragmentation and enhancing consistency.
Compared to existing IoT governance or cybersecurity frameworks, the proposed model offers significantly greater breadth and theoretical grounding. Many existing frameworks focus heavily on device-level security, encryption, network controls, or technical risk mitigation, with limited attention to organizational governance, compliance alignment, or adaptive resilience [
12]. Others propose risk management frameworks for IoT, yet often remain technical and lack integration with organizational governance [
68]. By contrast, this model brings together high-level governance, operational execution, risk & compliance, resilience, and stakeholder coordination, offering a unified governance architecture rather than a fragmented collection of technical controls or siloed risk assessments.
Because IoT ecosystems are inherently dynamic, like devices, standards, threat landscapes, and regulations constantly evolve, a static governance framework would quickly become obsolete. By embedding adaptive cycles, feedback loops (through resilience and risk governance), and stakeholder coordination, the framework equips organizations with a living governance framework that evolves. It anticipates emerging risks (e.g., new attack vectors, supply-chain vulnerabilities, regulatory changes) and embeds mechanisms for learning, adaptation, and re-alignment.
By being theory-anchored across multiple domains, the framework offers a sound conceptual basis for future empirical validation: researchers can operationalize constructs (e.g., governance maturity, risk posture, resilience capacity) and test them in real-world settings, providing robustness and generalizability. As the IoT ecosystems evolves (e.g., with edge computing, 5G/6G, integrated AI, decentralized architectures), the modular nature of the framework allows insertion or adaptation of new modules, for example, a “Privacy & Data Governance” module, or “AI-Governance” sub-layer, while preserving the overall structure.
The model can support standardization efforts, compliance regimes, and cross-industry alignment of governance. As regulatory and institutional pressures globally increase for IoT security (e.g., through data protection laws, IoT-specific standards, supply-chain legislation), the institutional/compliance dimension ensures that organizations are not only technically secure but also legally and socially legitimate. Thus, the framework offers both robustness and flexibility to navigate future uncertainties in technology, regulation, and business landscapes.
Table 4 summarizes the framework’s contributions.
9. Conclusions and Future Directions
This paper developed an integrated, theoretically grounded security governance model for IoT-driven organizations. By integrating five theoretical anchors-governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive capacity theory- the model delivers a modular yet coherent architecture mapping theoretical rationale to concrete governance dimensions. The model synthesizes strategic governance, operational governance, technical oversight, compliance alignment, risk governance, resilience/adaptation, and ecosystem coordination into a unified framework. By embedding feedback loops and a maturity-based perspective, the framework conceptualizes IoT governance as a dynamic, evolving, and adaptive process rather than a static set of controls. This conceptual contribution addresses a recognized gap in the existing IoT governance literature by offering a structurally sound, theoretically justified governance model specifically designed for the socio-technical complexity, regulatory demands, and risk dynamics at play in IoT ecosystems.
The proposed framework provides a practical roadmap for the design, implementation, and maturation of governance mechanisms that are aligned with organizational objectives, regulatory obligations, and risk appetite for organizations deploying or intending to deploy IoT solutions. Executives and governance boards can use the strategic governance layer to ensure alignment of IoT initiatives with business goals and risk-management priorities. Operational units get clarity on roles, responsibilities, and procedures regarding device management, procurement, incident response, and supplier oversight. The layers of risk governance and resilience ensure ongoing risk assessment, incident preparedness, and adaptability to emerging threats. Compliance alignment and ecosystem coordination support regulatory readiness and shared responsibility across vendors, partners, and other stakeholders. Overall, the model helps organizations move beyond ad hoc or fragmented security practices toward structured, systemic, and sustainable governance of IoT ecosystems.
The model, as a conceptual/theoretical contribution, is plagued by inherent limitations, including a lack of empirical validation. In the absence of field testing, case studies, or any quantitative assessment, the practical effectiveness, performance, and scalability of the framework remain at best hypothetical. The generality required to reach into general IoT ecosystems may reduce specificity-in other words, the model may be subject to substantial tailoring when used in highly specialized domains: critical infrastructure, healthcare, industrial control systems. It also does not account for all organizational constraints, such as budget, culture, and legacy systems. External dynamics such as rapid technological changes or the emergence of new architectures-e.g., edge computing and decentralized systems of the IoT, or unexpected regulatory shifts, might challenge or override assumptions embodied in the model.
The research recommended advancing this conceptual model toward empirical and domain-specific maturity through several complementary trajectories. First, validating the framework’s applicability, assessing operational feasibility, and evaluating its performance in addressing real IoT security challenges require case studies and pilot implementations across various organizational settings. Complementarily, quantitative survey-based research might operationalize the framework’s constructs into measurable indicators of governance maturity, resilience capability, and risk posture, enabling comparative assessment across industries. Refinement in tailoring the model to sector-specific requirements, such as healthcare, energy, or industrial IoT, where regulatory pressures and the criticality and risk tolerance of devices may vary substantially, is also called for. Longitudinal investigations can reveal how governance mechanisms evolve in response to technological change, security incidents, and regulatory adaptation. Research should also examine how the model integrates emerging technologies such as edge computing, AI-driven IoT autonomy, and decentralized architectures, and explore potential extensions of the model through new modules, such as privacy or AI governance. Collaboration with standards bodies and policymakers could translate the framework into guidance for industry benchmarks and cross-jurisdictional governance alignment, enabling wider adoption and advancing the standardization of resilient IoT governance practices.