Next Article in Journal
Instructional Mediation for Equitable Computational Thinking in STEAM Learning Across Diverse School Contexts
Previous Article in Journal
Adaptive Architectures for Gamified Learning in Software Engineering: A Systematic Review
Previous Article in Special Issue
Adoption of AI in Higher Education: Engineering Faculty Perceptions of Preparation for Industry 4.0
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

An Integrated Information Security Governance Model for Hyperconnected IoT Ecosystems; Unified Resilient Security Governance Model (URSGM)

by
Hamed Taherdoost
1,2,3,4,*,
Chin-Shiuh Shieh
4 and
Shashi Kant Gupta
4
1
Department of Arts, Communications and Social Sciences, School of Arts, Science, and Technology, University Canada West, Vancouver, BC V6B 1V9, Canada
2
GUS Institute, Global University Systems, London EC1N 2LX, UK
3
College of Technology and Engineering, Westcliff University, Irvine, CA 92614, USA
4
Department of Electronic Engineering, National Kaohsiung University of Science and Technology, Kaohsiung 807, Taiwan
*
Author to whom correspondence should be addressed.
Computers 2026, 15(4), 236; https://doi.org/10.3390/computers15040236
Submission received: 10 February 2026 / Revised: 6 April 2026 / Accepted: 7 April 2026 / Published: 10 April 2026

Abstract

Hyperconnected IoT ecosystems have become crucial for organizational operations; yet, existing governance structures remain fragmented, are technology-centric, and not well-equipped to manage the risks, compliance pressures, and resilience needs of IoT. This paper presents an integrated, theory-based information security governance model that is tailored for IoT-driven organizations. A conceptual synthesis is performed through integrating five theoretical anchors: governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive capacity theory. These theoretical lenses are used to derive essential governance constructs and to develop a modular architecture tailored to IoT security needs. The model’s validity is grounded in theoretical integration rather than empirical testing, consistent with the nature of conceptual research. The integrated model provides six interdependent governance dimensions: strategic governance, operational governance, technical oversight, compliance alignment, risk governance, and resilience/adaptation, anchored by an ecosystem coordination layer. It provides structured decision rights, continuous risk monitoring, regulatory legitimacy, and native adaptive capabilities toward dynamic cyber-physical threats. This research addresses a known gap in the literature on IoT governance by providing an integrated, theoretically validated governance model that systematically connects the rationale and operational mechanisms of governance for resilient, future-proof IoT adoption. The model is further operationalized through a five-level maturity structure, enabling organizations to assess and progressively enhance governance capabilities.

1. Introduction

The Internet of Things (IoT) is a complex ecosystem of devices connected by wired or wireless networks with the ultimate goal of providing services to humans and machines. IoT has witnessed remarkable development over the last decade [1]. IoT, powered by smart sensors, powerful embedded microelectronics, high-speed connectivity, and internet protocols, is poised to disrupt today’s value chains [2]. Traditional governance frameworks are often ill-equipped to address the unique characteristics of hyperconnected IoT environments. The large number and diversity of IoT devices create barriers to the adoption of uniform standards and regulations. Emerging governance approaches must manage complex data flows while protecting fundamental rights such as privacy, data protection, and informational self-determination. IoT ecosystems generate large volumes of personal and behavioral data through connected devices, raising significant ethical and regulatory concerns [3,4]. The interconnectedness of IoT devices creates vulnerability to cyberattacks, as illustrated by the Dyn cyberattack [5]. Many current governance systems are organized into sector-specific silos, hindering the development of holistic ecosystem-based management approaches [6]. In regions such as the Caribbean, the proximity of states and the presence of many SIDS intensify governance challenges over shared resources [7].
Consequently, there is an urgent need for resilient, theory-based governance models to manage the complexities of the hyperconnected IoT ecosystem. Adaptive governance provides links among individuals, organizations, agencies, and institutions across multiple levels of organization [8]. It is a learning, flexible approach to adapting to varying conditions [8,9]. Considering IoT ecosystems as SES provides a holistic perspective on how technological, human, and environmental aspects are interrelated within them [9]. As in the case of environment management, effective governance will result only from collaboration among various stakeholders, including governments, businesses, researchers, and citizens [8]. They note that “Bridging organizations” may have a crucial role in promoting collaboration to resolve emerging conflicts [8]. Governance models should take into account power imbalances and an equal representative channel for each stakeholder in decision-making [9,10]. Decentralized models of Internet governance and distributed trust schemes promote resilience and security [11].
Although the adoption of IoT is rapidly expanding across sectors, the existing governance and security literature remains fragmented and poorly tailored to the unique characteristics of IoT ecosystems. A review of prior work reveals several interrelated gaps. In reviews of IoT security literature, risk management is seldom comprehensively addressed; prior research focus on discrete technical issues such as secure protocols or device-level security, while few have set out to provide a holistic, organizational-level governance model integrating risk assessment and resilience planning as core elements [12]. Existing security or data-governance proposals, such as those on data lifecycle management, tend to cover only narrow elements, such as data governance in a particular domain, like digital IS ecosystems, rather than the more general organizational governance necessary in heterogeneous, multi-stakeholder IoT settings [13].
While prior studies have identified best practices and guideline-based frameworks, few provide progressive maturity levels that enable organizations to systematically assess and evolve their governance capabilities. Existing approaches often lack a structured pathway from ad hoc to optimized governance. IoT governance research has rarely mentioned how compliance requirements (data privacy, regulatory mandates), risk governance, and resilience/adaptation capabilities should be woven together in an overall organizational governance framework [14]. This paper addresses these deficiencies by proposing a theoretically grounded and unified organizational governance model specifically designed for IoT-driven ecosystems. This model responds to the growing complexity of IoT environments by integrating governance dimensions that are often examined in isolation within existing literature.
First, this study introduces a comprehensive governance model that incorporates strategic governance, operational oversight, compliance alignment, risk governance, resilience and adaptation, and stakeholder coordination. By bringing these elements together, the model captures a holistic view of IoT governance that is rarely addressed in an integrated manner. Second, this paper presents a maturity framework that enables organizations to assess and progressively enhance their IoT governance capabilities. This framework supports a structured transition from reactive governance practices toward more advanced, ecosystem-optimized governance approaches. Third, the proposed model embeds an integrated risk assessment and resilience planning approach. Through continuous monitoring and adaptive mechanisms, it addresses the dynamic and evolving nature of IoT-specific risks and environmental changes. Fourth, the framework is intentionally managerial in orientation rather than purely technical. This design ensures that the model is accessible and actionable for organizational decision-makers, risk managers, and governance boards. Finally, this study bridges key research gaps by combining governance theories, including organizational, socio-technical, and risk governance perspectives, with the unique characteristics of IoT systems. In doing so, it contributes to academic discourse while offering a practical roadmap for organizations seeking to deploy IoT technologies at scale. Unlike prior models that focus primarily on technical controls or isolated governance mechanisms, URSGM uniquely integrates governance decision rights, compliance alignment, risk governance, resilience feedback loops, and ecosystem coordination within a single unified architecture. This enables organizations to operationalize governance holistically across strategic, operational, and adaptive dimension something not explicitly achieved in existing IoT governance models.

2. Methodology

This study follows a conceptual synthesis research design to develop a theoretically grounded governance model for IoT-driven organizations. Conceptual research aims to integrate and extend existing theoretical knowledge to develop new frameworks capable of explaining complex phenomena without necessarily relying on empirical data collection [15]. Such approaches are widely used in emerging research domains where theoretical integration across multiple disciplines is required to address complex socio-technical challenges [16].
The research process consisted of three stages. First, a targeted literature review was conducted to identify theoretical foundations relevant to IoT security governance. Searches were performed in major academic databases, including Scopus and Web of Science, complemented by backward and forward citation tracking to ensure comprehensive coverage of relevant theoretical and governance literature. The objective of this stage was to identify theories capable of explaining governance structures, risk management practices, institutional pressures, and resilience mechanisms within complex digital ecosystems.
Second, governance constructs were extracted and categorized according to their functional roles within organizational governance systems. Prior research shows that governance mechanisms in digital ecosystems typically span strategic oversight, operational processes, risk governance, compliance alignment, and resilience mechanisms [3]. Third, these constructs were synthesized into a layered governance architecture using a theory-driven integration logic. Governance theory provides the structural foundation of decision rights and accountability mechanisms; socio-technical systems theory highlights the interaction between technological infrastructures and organizational actors; risk governance theory structures the identification and management of systemic risks; institutional theory explains regulatory and normative pressures shaping governance practices; and resilience theory introduces adaptive capacity and feedback mechanisms necessary for managing complex and evolving cyber-physical threats [17]. Integrating these theoretical perspectives enabled the development of the Unified Resilient Security Governance Model (URSGM).

3. Organizational Governance

Governance is about the structures, processes, and practices that direct an organization toward achieving its goals and objectives through risk management and accountability. Organizational resilience enables organizations to absorb or recover from disruptions caused by adverse events. Whiteman et al. [18] argue that businesses, particularly in high-latitude regions, must expand their understanding of resilience beyond traditional economic metrics to include ecological resilience as a vital component of sustainable corporate governance. This perspective emphasizes the importance of considering an organization’s environmental impact and the resilience of the ecosystems in which business is conducted. Governance narratives shape organizational behavior and stakeholder engagement, as Morrell’s analysis of governance in the NHS shows. In examining the roles of key actors, such as Foundation Trusts and NHS staff, Morrell [17] emphasizes that narrative is integral to governance itself, shaping perceptions of freedom, clinical governance, and patient choice.
Resilience, then, is emerging as a primary goal of governance models. Lockwood et al. [19] emphasize the need for adaptive governance mechanisms to respond to environmental changes affecting marine biodiversity. These results imply that learning, stakeholder engagement, and decision-making processes all contribute positively to the resilience of social-ecological systems and should be important components of effective governance. This is particularly crucial for an adaptive approach within organizations operating IoT ecosystems, due to the rapid advancement of technologies and environmental changes that demand flexible governance. Alves et al. [20], on the other hand, have underlined the role of governance mechanisms in software ecosystems in maintaining ecosystem health and fostering collaboration between organizations. Their systematic literature review indicates that governance mechanisms may influence decision rights, control, and organizational performance. The importance of this insight lies in the fact that organizations using IoT technologies must manage complex interdependencies among heterogeneous actors, and governance structures must enable collaborative innovation.
There has been an increasing application of polycentric governance models to tackle complex socio-ecological challenges. According to Cvitanovic et al. [21], polycentric systems with multiple governing bodies operating at different levels enhance the resilience of fisheries management. This model encourages greater stakeholder participation and local-level policy freedom, both vital for effective governance in dynamic environments. As more organizations embrace IoT technologies, principles of polycentric governance could lay the foundation for governance structures that are responsive at the local level and foster resilience.

4. Characteristics of IoT Ecosystems

As IoT technology adoption rapidly grows, it is important to understand the basic characteristics of these ecosystems to support resilience and governance effectiveness. A key characteristic of IoT ecosystems is their heterarchical structure, which enables decentralized decision-making and collaboration among multiple stakeholders. According to Leminen et al. [22], this heterarchical nature nurtures various business models, such as value chain efficiency and industry collaboration. Such features of business models promote innovation and adaptability within that very ecosystem. In this research, four archetypal IoT business models were identified, which demonstrate how organizations can create value through the use of IoT technologies in a collaborative environment. Governance within IoT ecosystems is crucial for providing assurance of data sharing and collaboration among stakeholders. For instance, De Prieelle et al. [23] identify ecosystem data governance as an increasingly relevant challenge, particularly in data-sensitive industries such as horticulture. They concluded that, although various factors affect the adoption of data-sharing platforms, ecosystem data governance is one of the most decisive variables that platform providers should consider to attract data owners.
Another critical characteristic of IoT ecosystems that has recently received attention is resilience. This denotes an ecosystem’s ability to resist disturbances, absorb shocks, and ultimately recover from disruption. Whaiduzzaman et al. [24] propose a resilient fog-IoT framework that ensures efficient resource management and system reliability, particularly in the event of failures in a master fog node. In this respect, the framework therefore demonstrates how architectural considerations can ensure IoT ecosystems resilience by facilitating fault-tolerant microservice execution. Advanced technologies, such as blockchain and AI, integrated into the IoT ecosystem, are changing the dynamics. El-Masri and Hussain [25] explain how blockchain can ensure the security of IoT ecosystems by addressing various threats through its built-in features, such as decentralization and transparency. This integration not only ensures security but, above all, builds trust among the relevant stakeholders, which is a pivotal factor for an effective IoT ecosystem. Beyond security, AI’s role in enhancing resilience and efficiency in IoT ecosystems cannot be ignored. Ahmad et al. [26] examine the role of AI-driven automation in optimizing energy usage and operational resilience in smart buildings. This study highlights the role of AI in enabling real-time monitoring and data-driven decision-making, which are critical to maintaining the sustainability and efficiency of IoT ecosystems.
Security governance is highly relevant in the context of IoT due to the unique challenges brought in by these systems. In general, IoT ecosystems are complex and involve a wide range of devices, networks, and applications [27]. The inherent complexity and resource limitation of most IoT devices make traditional security mechanisms ineffective [28]. Most importantly, the large volume of data generated by IoT devices also poses significant challenges for privacy, security, and data ownership. Therefore, it is essential to ensure that IoT systems and the data they process are subject to effective security governance to maintain confidentiality, integrity, and availability [29]. Given the challenges mentioned above, several researchers and practitioners have proposed various frameworks and approaches to IoT security governance (Table 1).

5. Resilience Theory and Adaptive Governance

In SES, resilience is the system’s ability to absorb disturbances and maintain its core functions and structures. According to Folke et al. [36], human activities that reduce biodiversity and alter disturbance regimes can reduce ecosystem resilience and cause regime shifts that affect the delivery of essential services. This calls for governance models that explicitly focus on building resilience to enable ecosystems to adapt to changing conditions. Adaptive governance involves a ‘no one-size-fits-all’, participatory, bottom-up process of managing resources, based on learning and collaboration between different levels of actors. Multi-level governance arrangements might facilitate adaptive management by linking local community initiatives to higher levels of government [37]. In this way, integration stimulates knowledge exchange and enhances the ability to respond to environmental transformations. Djalante et al. [38] outline the features of adaptive governance, noting that polycentric institutions, collaboration, and self-organization can enhance resilience against natural hazards.
Legal dimensions for adaptive governance are necessary for building resilience. According to Clarvis et al. [39], conventional legal frameworks often cannot capture the complexity of climate change and its effects on ecosystems; rather, they require mechanisms that incorporate principles of adaptive governance into laws, with an emphasis on flexibility and iterativity in policy design. This agrees with Hayes et al. [40], who noted that governance of transport infrastructure should embrace principles of socio-ecological resilience to manage vulnerabilities effectively. In integrating resilience within governance models, cities present special challenges. Friend et al. [41] discuss how planning and implementation of climate adaptation in urban areas often remain disconnected, especially for cities in developing countries. They assert that effective governance should be underpinned by key principles such as transparency and accountability if climate resilience is to be provided any meaningful chance of mainstreaming into urban planning processes. Tiernan et al. [42] also identify the socialization of responsibility for resilience as an overarching theme in the governance of disasters, which relies upon the integration of multiple actors through collaborative approaches.

6. Conceptual Foundations

Building a robust, coherent governance model requires more than ad hoc or practice-driven constructs: it demands a rigorous theoretical foundation that can anchor and justify the structural, organizational, and adaptive aspects of IoT governance. Thus, this section draws on well-established scholarly theories, including governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive-capacity theory. By doing so, the section establishes the ontological and epistemological bedrock for the unified governance model, ensuring that each governance dimension is conceptually grounded, theoretically justified, and capable of addressing the complexity and dynamic risks characteristic of IoT-driven organizations [43]. Table 2 synthesizes the primary theoretical foundations relevant to IoT governance.

6.1. Governance Theory

Organizational governance theory, especially as applied to IT governance, offers the foundational rationale for structuring a security governance model in IoT-driven organizations. Over decades of research, IT governance has evolved from narrow, control-oriented frameworks to more holistic, strategic frameworks that aim to align IT (and now digital/IoT) resources with organizational value creation, risk management, and long-term sustainability [50].
Concretely, modern governance theory emphasizes decision rights, accountability, oversight mechanisms, and alignment between organizational strategy and technological capabilities. In an IoT context, these aspects become paramount: as IoT devices proliferate, connect multiple stakeholders, and blur boundaries between IT, operations, and, at times, physical infrastructure, traditional governance mechanisms may no longer suffice. Thus, grounding the IoT security governance model in governance theory ensures that the notion of “governance” encompasses not only technical controls but also organizational structure, accountability, oversight, and strategic alignment of IoT within the enterprise. Recent scholarship argues that governance must adapt to complexity, dynamism, and convergence of technologies. For example, the notion of “cybernetic governance” suggests that governance theory itself must evolve to respond to the convergence of multiple technological systems, increased unpredictability, and overlapping governance regimes (e.g., across regulatory, technical, and organizational domains) [51].

6.2. Resilience and Adaptive Capacity Theory

Resilience theory provides a critical complement to governance: while governance secures structure, roles, and accountability, resilience ensures the organization can absorb, adapt, and recover in the face of disruptions, which, in IoT-driven environments, are frequent and manifold (cyberattacks, device failures, interoperability crises, supply-chain issues, etc.). The concept of resilience in organizational and cyber contexts has been increasingly studied, highlighting that resilience is not just about recovering after a disruption but also about anticipating changes, adapting, and evolving [17].
From a systems perspective, resilience can be framed as the capacity of socio-technical systems to respond to environmental changes via feedback loops, adaptation, and reorganization [52]. In the context of IoT governance, embedding adaptive capacity means that the governance model not only defines static policies or controls, but also fosters mechanisms for continuous monitoring, learning, feedback, and evolution. This dynamic orientation helps organizations handle the unpredictability, heterogeneity, and rapid change typical of IoT ecosystems.
Recent empirical research underscores the role of IT capabilities (infrastructure, human, business-spanning) and social capital in enabling organizational resilience, especially in volatile and uncertain contexts such as those shaped by IoT and digital transformation [53]. By anchoring the governance model in resilience and adaptive capacity theory, the framework can provide organizations with a structured approach to not only ensure governance compliance but also build long-term survivability and agility as IoT landscapes evolve.

6.3. Socio-Technical Systems Theory

This theory warns against purely technical approaches, emphasizing that technical solutions alone are insufficient without organizational, cultural, and process-level support. Indeed, empirical work in cybersecurity confirms that many security failures are rooted not in technical flaws, but in human behavior, organizational culture, weak processes, or misaligned incentives [54]. Thus, a governance model for IoT needs to integrate socio-technical thinking, balancing technical oversight with human, process, and organizational elements. In practical terms, embedding STS theory means the governance model will consider roles, responsibilities, training, change management processes, organizational security culture, stakeholder coordination, and accountability, not only device-level controls. This is especially important in IoT systems where device ownership, usage contexts, and stakeholders may be heterogeneous, distributed, and even external to the core organization (e.g., third-party providers, partners, customers).

6.4. Risk Governance Theory

While governance theory defines structures and decision-rights, and resilience theory addresses adaptability, risk governance theory provides the framework for understanding, assessing, managing, and mitigating risks, especially relevant in IoT environments where new risk vectors, dynamic threats, and complex interdependencies abound. Risk governance extends traditional risk management by incorporating strategic oversight, stakeholder involvement, accountability, and feedback. In particular, risk governance theory emphasizes the need for continuous risk monitoring, context-aware risk assessment, and dynamic adaptation of risk controls. This aligns with cyber-resilience demands, where static risk assessments or one-off audits are inadequate. Indeed, contemporary cybersecurity research increasingly calls for integrating risk governance within organizational governance structures, rather than treating risk as a peripheral or purely technical concern [55].
Applying risk governance theory to IoT governance means the model will not only define periodic risk assessments but embed risk governance across strategic, operational, and organizational layers, linking risk identification, evaluation, mitigation, compliance, and resilience. It will also support continuous monitoring and feedback loops, helping organizations adapt their risk posture as IoT ecosystems evolve, new threats emerge, or regulatory landscapes shift.

6.5. Institutional/Compliance Theory

Institutions, meaning formal and informal norms, rules, regulations, organizational norms, and external compliance regimes, play a crucial role in shaping organizational behavior, governance structures, and security practices. Institutional theory provides a lens to understand how external pressures (regulations, industry norms, standards, social expectations) and internal organizational pressures (norms, culture, legitimacy concerns) influence the adoption of governance practices.
In the cybersecurity and IoT domain, institutional pressures such as regulatory mandates (data protection laws, IoT security standards), industry compliance requirements, and stakeholder expectations for accountability and transparency can strongly shape how organizations design their governance models. Recent research argues that institutions exert coercive (regulation), mimetic (industry best practice), and normative (professional norms) pressures that shape cybersecurity governance adoption [56].
Because IoT systems often cross organizational, sectoral, and jurisdictional boundaries, institutional theory helps conceptualize how governance models must align with external regulatory regimes, compliance requirements, and demands for institutional legitimacy. In effect, institutional theory ensures that the governance model is not only internally consistent but also externally legitimate and sustainable in the broader institutional environment.

6.6. Integrative Logic for a Unified IoT Security Governance Model

Bringing together governance theory, resilience theory, socio-technical systems theory, risk governance, and institutional/compliance theory offers a powerful integrative logic that recognizes IoT-driven organizations as complex, socio-technical, adaptive systems operating in dynamic, regulated environments. This integrative foundation supports a robust, flexible, context-aware, and legitimate unified security governance model.
The logic proceeds as follows: governance theory defines the structural backbone (decision rights, oversight, accountability); socio-technical systems theory ensures that technical and human/organizational dimensions are jointly optimized; risk governance theory embeds continuous risk awareness, assessment, and mitigation; resilience theory injects adaptive capacity, learning, and system-level robustness; institutional theory aligns internal governance with external norms, regulations, and legitimacy requirements.
Using this integrative anchor enables the model to address the unique challenges of IoT ecosystems: device and stakeholder heterogeneity, rapid change, regulatory complexity, and evolving threat landscapes. It also ensures that the model is not overly technocratic or narrow, but embraces organizational structure, human factors, compliance, and adaptability. In doing so, the model becomes a living governance model: capable of guiding organizations through IoT adoption, growth, crisis, and evolution, while ensuring security, compliance, and resilience. Figure 1 illustrates how five core theories, each contributing distinct conceptual rationales that collectively inform and structure the proposed unified IoT security governance model.

7. Unified Resilient Security Governance Model (URSGM) for IoT-Driven Organizations

As organizations increasingly adopt IoT ecosystems, the complexity and interconnectedness of devices, data flows, and stakeholders demand a governance model that goes beyond traditional IT or cybersecurity frameworks. The unified model proposed here seeks to integrate strategic oversight, operational execution, risk governance, compliance alignment, resilience planning, and stakeholder coordination, treating IoT security not as a purely technical challenge but as an organizational, socio-technical, and governance challenge. This integrated perspective is supported by recent shifts in governance theory: some scholars argue for a “governance convergence” to address the complexity arising from technological convergence and overlapping regulatory regimes [51].
The unified model is conceived as a high-level governance architecture tailored to IoT ecosystems: it defines governance layers, delineates responsibilities and decision rights, embeds risk management and resilience mechanisms, ensures alignment with compliance and regulatory requirements, and provides for adaptation and stakeholder integration across internal and external domains (e.g., suppliers, service providers, regulatory bodies). In doing so, the model aims to bridge the gap between technical IoT security controls and organizational governance, offering executives and governance boards a structured, theory-informed roadmap for comprehensively managing IoT risks and resilience (Figure 2).

7.1. Core Dimensions of the Model

At the heart of the unified governance model are several core dimensions, each representing a governance “layer” that reflects both organizational and contextual needs. The Strategic Governance Layer establishes the long-term vision, policies, and governance structure for IoT adoption. It involves top management and board-level oversight, decision rights, resource allocation, and alignment with organizational objectives. This layer ensures that IoT adoption and security are not treated as afterthoughts but as strategic assets requiring governance commitment. This strategic orientation aligns with the call in recent literature to elevate cybersecurity to a board-level strategic concern, where boards perform sensemaking, threat scanning, and oversight across the pre-incident, incident, and post-incident phases [57].
The Operational Governance Layer translates strategic policies into operational practices. This includes defining roles and responsibilities (e.g., who manages IoT devices, who handles incident response, who liaises with suppliers), establishing processes and procedures (such as procurement guidelines, configuration management, patching schedules), and designing communication and reporting channels. Operational governance ensures that IoT security is embedded in everyday workflows rather than being siloed. Such embedding is critical: when governance remains abstract, operational teams may default to ad-hoc or contradictory practices. A dynamically adaptive governance model emphasizes the need for continuous review, updating, and alignment of procedures to business goals [58].
The Technical Oversight (managerial) dimension does not aim to re-implement device-level controls, but to oversee and coordinate technical security measures at a high level, ensuring that technical decisions (e.g., network segmentation, device onboarding, authentication, update policy) adhere to governance requirements, risk assessments, and compliance mandates. This oversight dimension recognizes the heterogeneity of IoT environments and treats technical security measures as part of a broader governance architecture rather than isolated technical silos. Such multilayered governance is particularly relevant in cloud-integrated or hybrid IoT deployments, where network-integrated governance frameworks have been proposed to manage distributed, heterogeneous IoT + cloud infrastructures [59].
The Compliance Alignment dimension ensures that the organization’s IoT governance aligns with external regulatory, standardization, and legal requirements. As organizations deploy IoT systems across jurisdictions and domains, regulatory pressures and compliance obligations become non-negligible. The governance framework, therefore, includes mechanisms to track regulatory change, embed compliance requirements into procurement, lifecycle management, and supplier contracts, and ensure compliance is not an afterthought but a core governance dimension. Recent work on compliance-driven cybersecurity governance underlines that embedding compliance within governance structures enhances operational resilience and policy enforcement across the enterprise [60].
IoT security governance is increasingly shaped by international cybersecurity standards and regulatory frameworks. Widely recognized standards such as ISO/IEC 27001 for information security management, ETSI EN 303 645 for consumer IoT security, and ISA/IEC 62443 for industrial control systems provide structured guidance for implementing governance controls across device lifecycle management, risk assessment, vulnerability management, and incident response. Aligning governance models with these standards enhances regulatory compliance, strengthens operational resilience, and supports institutional legitimacy in IoT deployments [61,62,63,64].
The Risk Governance dimension brings structured, continuous risk management into the governance model. Rather than treating risk assessment as a periodic or one-time activity, this dimension embeds risk identification, evaluation, mitigation, and monitoring as ongoing governance functions, covering threats to device integrity, data confidentiality, service availability, supply-chain risks, and cascading risks arising from interconnected systems. The inclusion of risk governance reflects broader movements in cybersecurity governance that view cyber risk as part of enterprise-wide risk and resilience management [65].
The Resilience & Adaptation dimension captures the organization’s capacity to anticipate, absorb, respond to, and recover from disruptions, whether caused by cyber incidents, device failures, supply-chain issues, or regulatory changes. Embedding resilience into governance ensures the organization is protected not only against known risks but also prepared for uncertainty and evolving threats. This dynamic/adaptive orientation resonates with recent proposals for adaptive cybersecurity governance frameworks, which emphasize feedback loops, continuous evaluation, and resilience planning as integral to organizational security governance [58].
Finally, the Stakeholder/Ecosystem Coordination dimension acknowledges that IoT ecosystems often span multiple internal units, supply-chain partners, third-party service providers, external regulators, and users. The governance model, therefore, includes structures and processes for stakeholder coordination and communication, supplier governance, shared responsibility agreements, and collaborative risk management. Through this dimension, the model recognizes IoT as not just an internal organizational deployment, but part of a broader ecosystem, requiring governance across organizational boundaries, supply-chain transparency, and accountability mechanisms spanning all stakeholders.

7.2. Governance Maturity Levels

To support progressive adoption of IoT governance practices, the URSGM incorporates a governance maturity perspective. Maturity models are widely used in cybersecurity and IT governance to evaluate organizational capabilities and guide incremental improvement of governance practices [66]. Such models enable organizations to assess their current governance posture and identify structured pathways toward more integrated and resilient governance mechanisms.
Within IoT ecosystems, governance maturity evolves from fragmented and reactive security practices toward integrated governance structures capable of managing risk, compliance, and ecosystem coordination. Early stages of maturity typically focus on basic security controls and reactive incident response. As governance capabilities develop, organizations increasingly integrate risk governance, compliance monitoring, and strategic oversight into formal governance structures. At the highest maturity levels, governance incorporates adaptive feedback loops and ecosystem-wide coordination mechanisms that support continuous learning and resilience against emerging cyber-physical threats [3]. Table 3 presents summery of governance maturity levels in IoT security governance.

7.3. Interactions and Information Flows

The layers and dimensions described above are not isolated silos; rather, the unified governance model envisions dynamic information flows and interactions across them. Strategic governance provides direction and policy that feed into operational governance and technical oversight. In turn, the operational and technical layers report upward on risk assessments, compliance status, incident reports, and supply-chain alerts, enabling strategic decision-makers to review, adapt, and reallocate resources. The risk governance and resilience layers operate continually, feeding data from monitoring, audits, incident response, and stakeholder feedback back into operational and strategic governance, thereby enabling continuous learning and adaptation.
Stakeholder coordination creates lateral flows among internal units, external partners, suppliers, and regulators. Compliance alignment ensures that regulatory changes or compliance audit findings flow into strategic and operational layers, prompting policy updates, process changes, or technical adjustments. In IoT environments with their distributed architecture, heterogeneous device population, and frequent external dependencies, such integrated flows are crucial. Indeed, practitioners designing governance for cloud-integrated IoT systems propose unified orchestration layers that enforce security policies across devices and cloud infrastructure, and that support real-time risk assessment and compliance monitoring [59]. Thus, the model draws on a cyber-resilience governance logic: continuous risk and compliance feedback, adaptive governance, and ecosystem-wide coordination, ensuring that IoT governance remains effective, current, and responsive to change.

7.4. Explanation of Constructs and Managerial Implications

The constructs of the unified governance model carry concrete managerial implications. The Strategic Governance dimension ensures that IoT security becomes part of the organization’s strategic agenda rather than merely an IT afterthought. For senior executives and boards, this means establishing clear governance structures (e.g., a dedicated IoT security governance committee), integrating IoT security into enterprise risk management (ERM), and allocating resources and accountability across the organization.
Operational Governance implies defining and formalizing roles, responsibilities, and workflows for IoT operations, including procurement, deployment, maintenance, incident response, and supplier management. From a managerial standpoint, this requires cross-functional collaboration (IT, operations, procurement, legal, compliance), clear documentation, and regular review, which support consistency, reduce silos, and ensure that IoT security is embedded in organizational processes.
Technical Oversight (managerial) means that technical decisions and security implementations are not left to ad hoc technical teams but are reviewed and governed within the broader governance framework, ensuring alignment with risk appetite, compliance obligations, and organizational strategy. Managers must provide oversight, ensure accountability, and maintain visibility on IoT-related technical activities.
Compliance Alignment means managers must treat regulatory and standards compliance proactively. This involves tracking relevant legislation and industry standards, embedding compliance into procurement and supplier contracts, conducting periodic compliance assessments, and possibly appointing compliance officers or committees. For IoT deployments, often cross-jurisdictional and multi-stakeholder, compliance alignment is not optional but essential to avoid regulatory, legal, and reputational risks.
Risk Governance places risk management at the heart of governance. Managerial implications include establishing continuous risk assessment programs, integrating IoT risk into enterprise-wide risk registers, developing risk mitigation strategies (technical, process, supplier), and embedding risk reporting and escalation paths. This enables informed decision-making under uncertainty and ensures resources are allocated to the most critical vulnerabilities.
Resilience & adaptation requires that management views IoT security not only in terms of prevention but also in terms of organizational capacity to absorb, adapt, and recover. This may involve business continuity planning, incident response planning, supplier contingency, redundancy strategies, and periodic resilience testing. Managers must foster a culture of resilience, support training, and champion continuous improvement.
Stakeholder/ecosystem Coordination emphasizes external relationships: supplier governance, supplier risk assessments, transparency of security posture, shared responsibility agreements, and communication with regulatory bodies or users. Managerial commitment to coordination ensures that IoT governance extends beyond internal boundaries, that supply-chain or third-party risks are managed, and that the organization remains accountable and trustworthy across its ecosystem.

8. Discussion

The unified framework proposed in this paper advances theory by filling a notable lacuna: the absence of a coherent, holistic governance model tailored to IoT’s socio-technical complexity. Prior reviews of IoT governance frameworks underscore this gap. For example, a comprehensive review of governance literature concludes that “ninety percent of the offerings currently in existence to address IoT-related risk are repackaged general-purpose IT security technologies”, which are inadequate given IoT’s heterogeneity and specialized risk profile. By rooting our model in multiple theoretical traditions, governance theory, socio-technical systems, risk governance, institutional compliance, and resilience/adaptive capacity, we provide a multi-dimensional, theory-anchored architecture that systematically maps why governance constructs exist (theoretical rationale) to what organizational functions they serve (governance mechanisms). This bridging of theory to mechanism responds directly to calls for more conceptually rigorous IoT governance frameworks rather than ad-hoc, technical-only designs.
By embedding a maturity model and feedback/adaptation loops (via resilience and risk governance theories), the framework contributes to dynamic governance theory. Instead of prescribing static controls, it conceptualizes governance as an emergent, evolving process, capable of adapting to changing threat landscapes, regulatory shifts, and evolving IoT ecosystems configurations. This aligns with resilience theory’s emphasis on adaptive capacity and learning, as exemplified in research on IoT resilience mechanisms [46]. The theoretical integration supports cross-disciplinary coherence, bridging organizational governance, cybersecurity, risk management, and compliance theory; thus, offering a comprehensive theoretical scaffold for future empirical research.
For practitioners and decision-makers, the proposed governance model offers a structured roadmap for embedding IoT security governance at the management and board levels. The Strategic Governance dimension transforms IoT from a technical project to a strategic asset, making it visible at the executive and board level, a shift echoed in corporate-governance research emphasizing decision-rights, accountability, and firm performance linkage [67]. Operational Governance and Technical Oversight provide concrete guidance on how to translate strategic policy into day-to-day practices, reducing the risk of ad hoc, inconsistent security measures. Risk Governance and Compliance Alignment enable organizations to systematically assess, prioritize, and respond to IoT-specific risks, addressing a known deficiency in existing IoT security literature, which rarely includes risk-management frameworks [12]. The Resilience & Adaptation component encourages a managerial focus on long-term continuity, incident response, and recovery planning, which are critical for IoT deployments, especially in sectors with high availability requirements (e.g., healthcare, critical infrastructure). The Stakeholder/Ecosystem Coordination layer supports holistic responsibility across supply chains, vendors, and third-party partners, often neglected in purely technical models but essential for real-world IoT ecosystems.
The modular architecture of the URSGM framework also enhances its applicability for small and medium-sized enterprises (SMEs), which often operate under resource constraints. Rather than requiring full-scale implementation, the framework allows incremental adoption, where organizations can initially focus on strategic governance and basic risk governance before progressively integrating compliance alignment, resilience mechanisms, and ecosystem coordination. This scalability ensures that the model remains practical and implementable across organizations of varying sizes and maturity levels [3].
To illustrate the practical applicability of the URSGM framework, consider a manufacturing organization deploying IoT-enabled sensors across its production lines. At the strategic level, governance structures define decision rights and align IoT initiatives with organizational objectives. At the operational level, policies govern device lifecycle management, maintenance, and incident response. Risk governance mechanisms continuously monitor vulnerabilities and assess cyber risks associated with interconnected devices. Compliance alignment ensures adherence to relevant standards and regulatory requirements. Finally, resilience mechanisms enable the organization to respond to disruptions and recover from cyber incidents through adaptive processes and feedback loops. This example demonstrates how the different governance dimensions operate cohesively in a real-world setting.
The framework is applicable across multiple contexts, making it practically useful in diverse IoT-driven organizational settings. For a large enterprise deploying IoT at scale (e.g., manufacturing, logistics, smart buildings), the model can guide the design of the governance architecture, from board-level commitment and procurement policies for IoT devices to supplier security requirements and continuous risk monitoring and resilience planning. In a critical-infrastructure context (e.g., energy, utilities, healthcare), the risk governance + resilience components help manage dynamic threat landscapes, supply-chain dependencies, and compliance with strict regulatory regimes. For small-to-medium enterprises (SMEs) or decentralized deployments (e.g., smart retail, distributed devices), the maturity model can help assess current governance posture and provide a roadmap to progressively improve, from reactive security to integrated governance and resilience. Finally, organizations undergoing digital transformation can use the model as a blueprint to integrate IoT governance with existing enterprise governance and risk management frameworks, reducing fragmentation and enhancing consistency.
Compared to existing IoT governance or cybersecurity frameworks, the proposed model offers significantly greater breadth and theoretical grounding. Many existing frameworks focus heavily on device-level security, encryption, network controls, or technical risk mitigation, with limited attention to organizational governance, compliance alignment, or adaptive resilience [12]. Others propose risk management frameworks for IoT, yet often remain technical and lack integration with organizational governance [68]. By contrast, this model brings together high-level governance, operational execution, risk & compliance, resilience, and stakeholder coordination, offering a unified governance architecture rather than a fragmented collection of technical controls or siloed risk assessments.
Because IoT ecosystems are inherently dynamic, like devices, standards, threat landscapes, and regulations constantly evolve, a static governance framework would quickly become obsolete. By embedding adaptive cycles, feedback loops (through resilience and risk governance), and stakeholder coordination, the framework equips organizations with a living governance framework that evolves. It anticipates emerging risks (e.g., new attack vectors, supply-chain vulnerabilities, regulatory changes) and embeds mechanisms for learning, adaptation, and re-alignment.
By being theory-anchored across multiple domains, the framework offers a sound conceptual basis for future empirical validation: researchers can operationalize constructs (e.g., governance maturity, risk posture, resilience capacity) and test them in real-world settings, providing robustness and generalizability. As the IoT ecosystems evolves (e.g., with edge computing, 5G/6G, integrated AI, decentralized architectures), the modular nature of the framework allows insertion or adaptation of new modules, for example, a “Privacy & Data Governance” module, or “AI-Governance” sub-layer, while preserving the overall structure.
The model can support standardization efforts, compliance regimes, and cross-industry alignment of governance. As regulatory and institutional pressures globally increase for IoT security (e.g., through data protection laws, IoT-specific standards, supply-chain legislation), the institutional/compliance dimension ensures that organizations are not only technically secure but also legally and socially legitimate. Thus, the framework offers both robustness and flexibility to navigate future uncertainties in technology, regulation, and business landscapes. Table 4 summarizes the framework’s contributions.

9. Conclusions and Future Directions

This paper developed an integrated, theoretically grounded security governance model for IoT-driven organizations. By integrating five theoretical anchors-governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive capacity theory- the model delivers a modular yet coherent architecture mapping theoretical rationale to concrete governance dimensions. The model synthesizes strategic governance, operational governance, technical oversight, compliance alignment, risk governance, resilience/adaptation, and ecosystem coordination into a unified framework. By embedding feedback loops and a maturity-based perspective, the framework conceptualizes IoT governance as a dynamic, evolving, and adaptive process rather than a static set of controls. This conceptual contribution addresses a recognized gap in the existing IoT governance literature by offering a structurally sound, theoretically justified governance model specifically designed for the socio-technical complexity, regulatory demands, and risk dynamics at play in IoT ecosystems.
The proposed framework provides a practical roadmap for the design, implementation, and maturation of governance mechanisms that are aligned with organizational objectives, regulatory obligations, and risk appetite for organizations deploying or intending to deploy IoT solutions. Executives and governance boards can use the strategic governance layer to ensure alignment of IoT initiatives with business goals and risk-management priorities. Operational units get clarity on roles, responsibilities, and procedures regarding device management, procurement, incident response, and supplier oversight. The layers of risk governance and resilience ensure ongoing risk assessment, incident preparedness, and adaptability to emerging threats. Compliance alignment and ecosystem coordination support regulatory readiness and shared responsibility across vendors, partners, and other stakeholders. Overall, the model helps organizations move beyond ad hoc or fragmented security practices toward structured, systemic, and sustainable governance of IoT ecosystems.
The model, as a conceptual/theoretical contribution, is plagued by inherent limitations, including a lack of empirical validation. In the absence of field testing, case studies, or any quantitative assessment, the practical effectiveness, performance, and scalability of the framework remain at best hypothetical. The generality required to reach into general IoT ecosystems may reduce specificity-in other words, the model may be subject to substantial tailoring when used in highly specialized domains: critical infrastructure, healthcare, industrial control systems. It also does not account for all organizational constraints, such as budget, culture, and legacy systems. External dynamics such as rapid technological changes or the emergence of new architectures-e.g., edge computing and decentralized systems of the IoT, or unexpected regulatory shifts, might challenge or override assumptions embodied in the model.
The research recommended advancing this conceptual model toward empirical and domain-specific maturity through several complementary trajectories. First, validating the framework’s applicability, assessing operational feasibility, and evaluating its performance in addressing real IoT security challenges require case studies and pilot implementations across various organizational settings. Complementarily, quantitative survey-based research might operationalize the framework’s constructs into measurable indicators of governance maturity, resilience capability, and risk posture, enabling comparative assessment across industries. Refinement in tailoring the model to sector-specific requirements, such as healthcare, energy, or industrial IoT, where regulatory pressures and the criticality and risk tolerance of devices may vary substantially, is also called for. Longitudinal investigations can reveal how governance mechanisms evolve in response to technological change, security incidents, and regulatory adaptation. Research should also examine how the model integrates emerging technologies such as edge computing, AI-driven IoT autonomy, and decentralized architectures, and explore potential extensions of the model through new modules, such as privacy or AI governance. Collaboration with standards bodies and policymakers could translate the framework into guidance for industry benchmarks and cross-jurisdictional governance alignment, enabling wider adoption and advancing the standardization of resilient IoT governance practices.

Author Contributions

Conceptualization, H.T.; methodology, H.T., C.-S.S.; validation, H.T.; Writing—first draft and original draft, H.T., visualization, H.T.; supervision, C.-S.S. & S.K.G.; editing and final draft, H.T., C.-S.S., S.K.G. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

Data sharing is not applicable.

Conflicts of Interest

The authors declare no conflict of interest.

References

  1. Paolone, G.; Iachetti, D.; Paesani, R.; Pilotti, F.; Marinelli, M.; Di Felice, P. A holistic overview of the internet of things ecosystem. IoT 2022, 3, 398–434. [Google Scholar] [CrossRef] [Scilit]
  2. Jesse, N. Internet of Things and Big Data: The disruption of the value chain and the rise of new software ecosystems. AI Soc. 2018, 33, 229–239. [Google Scholar] [CrossRef] [Scilit]
  3. Lee, I. Internet of Things (IoT) Cybersecurity: Literature Review and IoT Cyber Risk Management. Future Internet 2020, 12, 157. [Google Scholar] [CrossRef] [Scilit]
  4. European Union Agency for Cybersecurity (ENISA). Guidelines for Securing the Internet of Things; European Union Agency for Cybersecurity: Brussels, Belgium, 2020. [Google Scholar]
  5. Berman, F.; Cerf, V.G. Social and Ethical Behavior in the Internet of Things; ACM: New York, NY, USA, 2017; pp. 6–7. [Google Scholar]
  6. Taljaard, S.; Slinger, J.H.; Morant, P.D.; Theron, A.K.; Van Niekerk, L.; van der Merwe, J. Implementing integrated coastal management in a sector-based governance system. Ocean Coast. Manag. 2012, 67, 39–53. [Google Scholar] [CrossRef] [Scilit]
  7. Fanning, L.; Mahon, R.; McConney, P. Focusing on living marine resource governance: The Caribbean large marine ecosystem and adjacent areas project. Coast. Manag. 2009, 37, 219–234. [Google Scholar] [CrossRef] [Scilit]
  8. Folke, C.; Hahn, T.; Olsson, P.; Norberg, J. Adaptive governance of social-ecological systems. Annu. Rev. Environ. Resour. 2005, 30, 441–473. [Google Scholar] [CrossRef] [Scilit]
  9. Matthew, G. Situating Adaptive Environmental Governance Non-governmental Actors in the Protection of Nanjing’s Qinhuai River; University of Ottawa (Canada): Ottawa, ON, Canada, 2013. [Google Scholar]
  10. Gruchmann, T. Theorizing the impact of network characteristics on multitier sustainable supply chain governance: A power perspective. Int. J. Logist. Manag. 2022, 33, 170–192. [Google Scholar] [CrossRef] [Scilit]
  11. Psaras, I. Decentralised edge-computing and IoT through distributed trust. In Proceedings of 16th Annual International Conference on Mobile Systems, Applications, and Services; Association for Computing Machinery: New York, NY, USA, 2018. [Google Scholar]
  12. Sebestyen, H.; Popescu, D.E.; Zmaranda, R.D. A literature review on security in the Internet of Things: Identifying and analysing critical categories. Computers 2025, 14, 61. [Google Scholar] [CrossRef] [Scilit]
  13. Dasgupta, A.; Gill, A.; Hussain, F. A conceptual framework for data governance in IoT-enabled digital IS ecosystems. In Proceedings of 8th International Conference on Data Science, Technology and Applications; SCITEPRESS–Science and Technology Publications: Setúbal, Portugal, 2019. [Google Scholar]
  14. Ogunniye, G.; Hana, A.; Watson, J. PETRAS: A socio-technical framework for Internet of Things research and development. Front. Internet Things 2024, 3, 1336564. [Google Scholar] [CrossRef] [Scilit]
  15. Jaakkola, E. Designing conceptual articles: Four approaches. AMS RevEW 2020, 10, 18–26. [Google Scholar] [CrossRef] [Scilit]
  16. Gilson, L.L.; Goldberg, C.B. So, what is a conceptual paper? Group Organ. Manag. 2015, 40, 127–130. [Google Scholar] [CrossRef] [Scilit]
  17. Araujo, M.S.d.; Machado, B.A.S.; Passos, F.U. Resilience in the Context of Cyber Security: A Review of the Fundamental Concepts and Relevance. Appl. Sci. 2024, 14, 2116. [Google Scholar] [CrossRef] [Scilit]
  18. Whiteman, G.; Forbes, B.C.; Niemelä, J.; Chapin, F.S. Bringing feedback and resilience of high-latitude ecosystems into the corporate boardroom. AMBIO J. Hum. Environ. 2004, 33, 371–376. [Google Scholar] [CrossRef]
  19. Lockwood, M.; Davidson, J.; Hockings, M.; Haward, M.; Kriwoken, L. Marine biodiversity conservation governance and management: Regime requirements for global environmental change. Ocean Coast. Manag. 2012, 69, 160–172. [Google Scholar] [CrossRef] [Scilit]
  20. Alves, C.; Oliveira, J.; Jansen, S. Understanding governance mechanisms and health in software ecosystems: A systematic literature review. In International Conference on Enterprise Information Systems; Springer: Berlin/Heidelberg, Germany, 2018. [Google Scholar]
  21. Cvitanovic, C.; Hobday, A.; McDonald, J.; Van Putten, E.; Nash, K. Governing fisheries through the critical decade: The role and utility of polycentric systems. Rev. Fish Biol. Fish. 2018, 28, 1–18. [Google Scholar] [CrossRef] [Scilit]
  22. Leminen, S.; Rajahonka, M.; Westerlund, M.; Wendelin, R. The future of the Internet of Things: Toward heterarchical ecosystems and service business models. J. Bus. Ind. Mark. 2018, 33, 749–767. [Google Scholar] [CrossRef] [Scilit]
  23. De Prieëlle, F.; De Reuver, M.; Rezaei, J. The role of ecosystem data governance in adoption of data platforms by Internet-of-Things data providers: Case of Dutch horticulture industry. IEEE Trans. Eng. Manag. 2020, 69, 940–950. [Google Scholar] [CrossRef] [Scilit]
  24. Whaiduzzaman, M.; Barros, A.; Shovon, A.R.; Hossain, M.R.; Fidge, C. A resilient fog-IoT framework for seamless microservice execution. In 2021 IEEE International Conference on Services Computing (SCC); IEEE: Piscataway, NJ, USA, 2021. [Google Scholar]
  25. El-Masri, M.; Hussain, E.M.A. Blockchain as a mean to secure Internet of Things ecosystems–a systematic literature review. J. Enterp. Inf. Manag. 2021, 34, 1371–1405. [Google Scholar] [CrossRef] [Scilit]
  26. Ahmad, A.; Alshurideh, M. Digitization and IoT-Driven Transformation of Smart Buildings. Int. J. Manag. Mark. Intell. 2025, 2, 26–38. [Google Scholar] [CrossRef] [Scilit]
  27. Mazon-Olivo, B.; Pan, A. Internet of things: State-of-the-art, computing paradigms and reference architectures. IEEE Lat. Am. Trans. 2021, 20, 49–63. [Google Scholar] [CrossRef] [Scilit]
  28. Ali, M.; Raza, A.; Akram, M.A.; Arif, H.; Ali, A. Enhancing IOT Security: A review of Machine Learning-Driven Approaches to Cyber Threat Detection: Enhancing IOT Security: A review of Machine Learning-Driven Approaches to Cyber Threat Detection. J. Inform. Interact. Technol. 2025, 2, 316–324. [Google Scholar] [CrossRef] [Scilit]
  29. Khan, N.-e.; Rudman, R.J. IoT medical device risks: Data security, privacy, confidentiality and compliance with HIPAA and COBIT 2019. S. Afr. J. Bus. Manag. 2025, 56, 4796. [Google Scholar] [CrossRef] [Scilit]
  30. Ullah, F.; Qayyum, S.; Thaheem, M.J.; Al-Turjman, F.; Sepasgozar, S.M. Risk management in sustainable smart cities governance: A TOE framework. Technol. Forecast. Soc. Change 2021, 167, 120743. [Google Scholar] [CrossRef] [Scilit]
  31. Radanliev, P.; De Roure, D.; Cannady, S.; Mantilla Montalvo, R.; Nicolescu, R.; Huth, M. Analysing IoT cyber risk for estimating IoT cyber insurance. In Living in the Internet of Things: Cybersecurity of the IoT-2018. IET Conference Proceedings; The Institution of Engineering and Technology: London, UK, 2018. [Google Scholar]
  32. Rahman, S.; Perumath, N. Implementing Zero Trust Management in IoT Environment-Challenges and Solutions: Scoping Review. Master’s Thesis, Stockholm University, Stockholm, Sweden, 2025. [Google Scholar]
  33. Freter, R. Department of Defense (DOD) Zero Trust Reference Architecture; Version 2.0; Defense Information Systems Agency (DISA): Fort Meade, MD, USA, 2022. [Google Scholar]
  34. Khayer, B.; Mirzaei, S.; Alavizadeh, H.; Salehi Shahraki, A. Blockchain for Secure IoT: A Review of Identity Management, Access Control, and Trust Mechanisms. IoT 2025, 6, 65. [Google Scholar] [CrossRef] [Scilit]
  35. Rahayu, E.R.; Aprillia, A.; Ikhsan, R.Z.; Adiwijaya, A.; Kumara, A. Cybersecurity in the Age of IoT and Developing Frameworks for Securing Smart Devices and Networks. J. Comput. Sci. Technol. Appl. 2025, 2, 46–54. [Google Scholar] [CrossRef] [Scilit]
  36. Folke, C.; Carpenter, S.; Walker, B.; Scheffer, M.; Elmqvist, T.; Gunderson, L.; Holling, C.S. Regime shifts, resilience, and biodiversity in ecosystem management. Annu. Rev. Ecol. Evol. Syst. 2004, 35, 557–581. [Google Scholar] [CrossRef] [Scilit]
  37. Armitage, D. Governance and the commons in a multi-level world. Int. J. Commons 2008, 2, 7–32. [Google Scholar] [CrossRef]
  38. Djalante, R.; Holley, C.; Thomalla, F. Adaptive governance and managing resilience to natural hazards. Int. J. Disaster Risk Sci. 2011, 2, 1–14. [Google Scholar] [CrossRef] [Scilit]
  39. Clarvis, M.H.; Allan, A.; Hannah, D.M. Water, resilience and the law: From general concepts and governance design principles to actionable mechanisms. Environ. Sci. Policy 2014, 43, 98–110. [Google Scholar] [CrossRef] [Scilit]
  40. Hayes, S.; Desha, C.; Burke, M.; Gibbs, M.; Chester, M. Leveraging socio-ecological resilience theory to build climate resilience in transport infrastructure. Transp. Rev. 2019, 39, 677–699. [Google Scholar] [CrossRef] [Scilit]
  41. Friend, R.; Jarvie, J.; Reed, S.O.; Sutarto, R.; Thinphanga, P.; Toan, V.C. Mainstreaming urban climate resilience into policy and planning; reflections from Asia. Urban Clim. 2014, 7, 6–19. [Google Scholar] [CrossRef] [Scilit]
  42. Tiernan, A.; Drennan, L.; Nalau, J.; Onyango, E.; Morrissey, L.; Mackey, B. A review of themes in disaster resilience literature and international practice since 2012. Policy Des. Pract. 2019, 2, 53–74. [Google Scholar] [CrossRef] [Scilit]
  43. van der Waldt, G. Constructing theoretical frameworks in social science research. J. Transdiscipl. Res. S. Afr. 2024, 20, 1–12. [Google Scholar] [CrossRef] [Scilit]
  44. Pöhler, L.D.; Diepold, K.; Wallach, W. A practical multilevel governance framework for autonomous and intelligent systems. arXiv 2024, arXiv:2404.13719. [Google Scholar] [CrossRef] [Scilit]
  45. Liu, H.; Renn, O. Polycrisis and Systemic Risk: Assessment, Governance, and Communication. Int. J. Disaster Risk Sci. 2025, 16, 526–549. [Google Scholar] [CrossRef] [Scilit]
  46. Berger, C.; Eichhammer, P.; Reiser, H.P.; Domaschka, J.; Hauck, F.J.; Habiger, G. A survey on resilience in the iot: Taxonomy, classification, and discussion of resilience mechanisms. ACM Comput. Surv. (CSUR) 2021, 54, 1–39. [Google Scholar] [CrossRef] [Scilit]
  47. Devos, J.; Van de Ginste, K. Towards a theoretical foundation of IT governance: The COBIT 5 case. In Proceedings of ECIME; Academic Publishing Limited: Cambridge, MA, USA, 2015. [Google Scholar]
  48. Wu, A.; Khanna, S.; Keidar, S.; Berman, P.; Brubacher, L.J. How have researchers defined institutions, politics, organizations and governance in research related to epidemic and pandemic response? A scoping review to map current concepts. Health Policy Plan. 2023, 38, 377–393. [Google Scholar] [CrossRef] [Scilit]
  49. Yin, L.; Chakraborti, M.; Yan, Y.; Schweik, C.; Frey, S.; Filkov, V. Open source software sustainability: Combining institutional analysis and socio-technical networks. Proc. ACM Hum.-Comput. Interact. 2022, 6, 1–23. [Google Scholar] [CrossRef] [Scilit]
  50. Vaya-Arboledas, Á.; Ferrer-Oliva, M.; Medina-Merodio, J.A. Evolution and Perspectives in IT Governance: A Systematic Literature Review. Computers 2025, 14, 520. [Google Scholar] [CrossRef] [Scilit]
  51. Zwitter, A. Cybernetic governance: Implications of technology convergence on governance convergence. Ethics Inf. Technol. 2024, 26, 24. [Google Scholar] [CrossRef] [Scilit]
  52. Mayar, K.; Carmichael, D.G.; Shen, X. Resilience and systems—A review. Sustainability 2022, 14, 8327. [Google Scholar] [CrossRef] [Scilit]
  53. Li, M.; Cheng, S.; Lu, M. Impact of information technology capabilities on organizational resilience: The mediating role of social capital. Humanit. Soc. Sci. Commun. 2024, 11, 1–11. [Google Scholar] [CrossRef] [Scilit]
  54. Malatji, M.; Marnewick, A.; von Solms, S. Validation of a socio-technical management process for optimising cybersecurity practices. Comput. Secur. 2020, 95, 101846. [Google Scholar] [CrossRef] [Scilit]
  55. Marquez-Tejon, J.; Jimenez-Partearroyo, M.; Benito-Osorio, D. Integrated security management model: A proposal applied to organisational resilience. Secur. J. 2023, 37, 375–398. [Google Scholar] [CrossRef] [Scilit]
  56. Singh, K.; Chatterjee, S.; Mariani, M.; Wamba, S.F. Cybersecurity resilience and innovation ecosystems for sustainable business excellence: Examining the dramatic changes in the macroeconomic business environment. Technovation 2025, 143, 103219. [Google Scholar] [CrossRef] [Scilit]
  57. Harel, Y.; Carmeli, A. A strategic cybersecurity oversight framework: A board’s imperative. J. Cybersecur. 2025, 11, tyaf021. [Google Scholar] [CrossRef] [Scilit]
  58. Melaku, H.M. A dynamic and adaptive cybersecurity governance framework. J. Cybersecur. Priv. 2023, 3, 327–350. [Google Scholar] [CrossRef] [Scilit]
  59. Poddar, S.; Sachan, R.C.; Ouaissa, M.; Ouaissa, M. Network security governance framework for cloud-integrated IoT systems. In Information Security Governance using Artificial Intelligence of Things in Smart Environments; CRC Press: Boca Raton, FL, USA, 2025; pp. 129–145. [Google Scholar]
  60. Mehmood, K.T.; Ashraf, Z.; Iqbal, R.; Rafique, A.A.; Gul, H.; Ali, M. Cyber security Governance as a Pillar of Enterprise Risk Management: Designing a Compliance-Driven Framework for Operational Resilience, Policy Enforcement, and Regulatory Alignment. Annu. Methodol. Arch. Res. Rev. 2025, 3, 59–77. [Google Scholar] [CrossRef] [Scilit]
  61. National Institute of Standards and Technology (NIST). Framework for Improving Critical Infrastructure Cybersecurity; Version 1.1; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2018.
  62. ETSI EN 303 645 V3.1.3—CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements. European Telecommunications Standards Institute: Sophia Antipolis, France, 2024.
  63. ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. ISO/IEC: Geneva, Switzerland, 2022.
  64. IEC 62443; Industrial Communication Networks—Network and System Security. International Electrotechnical Commission: Geneva, Switzerland, 2024.
  65. Oh, K.B.; Hoang, G.; Sturdy, J.; Guo, S.S. Cybersecurity and Governance. In Cybersecurity Governance: An Enterprise Risk Management Strategy for Cyber Risk Control; Springer: Berlin/Heidelberg, Germany, 2025; pp. 19–63. [Google Scholar]
  66. Büyüközkan, G.; Güler, M. Cybersecurity maturity model: Systematic literature review and a proposed model. Technol. Forecast. Soc. Change 2025, 213, 123996. [Google Scholar] [CrossRef] [Scilit]
  67. Tuấn, N.V. Mainstream theories of corporate governance and the corporate governance–firm performance relationship. VNUHCM J. Econ. Law Manag. 2021, 5, 1638–1647. [Google Scholar] [CrossRef] [Scilit]
  68. Kandasamy, K.; Srinivas, S.; Achuthan, K.; Rangan, V.P. IoT cyber risk: A holistic analysis of cyber risk assessment frameworks, risk vectors, and risk ranking process. EURASIP J. Inf. Secur. 2020, 2020, 8. [Google Scholar] [CrossRef] [Scilit]
  69. Speckman, T.H.; Gerber, M.; Pottas, D. Internet of things governance frameworks: A literature review. Issues Soc. Enviromental Account. 2023, 1, 64–80. [Google Scholar]
  70. Burch, G.F.; Burch, J.; Mcgarry, M. Cybersecurity Risk Management Governance: An Agency Theory Perspective. ISACA J. 2024. Available online: https://www.isaca.org/resources/isaca-journal/issues/2024/volume-5/cybersecurity-risk-management-governance (accessed on 6 April 2026).
Figure 1. Theoretical foundations feeding into the unified IoT security governance model.
Figure 1. Theoretical foundations feeding into the unified IoT security governance model.
Computers 15 00236 g001
Figure 2. Resilient Security Governance Model (URSGM) for IoT-Driven Organizations.
Figure 2. Resilient Security Governance Model (URSGM) for IoT-Driven Organizations.
Computers 15 00236 g002
Table 1. Summary of approaches and technologies for enhancing IoT security and resilience.
Table 1. Summary of approaches and technologies for enhancing IoT security and resilience.
Technology/ApproachPurposeComponentsReferences
Risk Management FrameworksImprove risk visibility, systematic governance, and impact assessment of cyber risks in smart cities and Industry 4.0.TOE layers (Technology–Organization–Environment), risk identification, risk evaluation, IoT cyber-risk modeling.[30,31]
Zero Trust ArchitectureStrengthen access control and reduce unauthorized access in IoT ecosystems.Continuous authentication, micro-segmentation, least-privilege access, and identity verification.[32,33]
Blockchain TechnologyEnhance trust, integrity, and transparency in IoT data and transactions.Distributed ledger, smart contracts, hashing, consensus (e.g., PoW, PoS).[34]
Machine Learning & Artificial IntelligenceReal-time threat detection, reduce false positives, and adapt to new or evolving attacks.Deep learning models, anomaly detection, intrusion detection systems, and pattern recognition.[28]
Multi-Layered Cybersecurity FrameworksProvide comprehensive protection across IoT devices, networks, and data layers.Device authentication, data encryption, continuous monitoring, and privacy-enhancing technologies.[35]
Table 2. Theoretical foundations and their relevance to IoT governance.
Table 2. Theoretical foundations and their relevance to IoT governance.
TheoryCore ConceptsGovernance Implications for IoTReferences
Governance TheoryStructures, rules, stakeholders, authority, accountability, and institutional mechanismsThe necessity of clear governance frameworks for IoT, defining who governs, how decisions are made, and how they are enforced[44]
Resilience & Adaptive Capacity TheoryResilience: absorb disturbances; Adaptive capacity: learn, adapt, recover IoT governance must embed flexibility, feedback loops, and adaptability to evolving threats or failures[45,46]
Socio-Technical Systems Theory (STS)Interdependent social (people, norms, organizations) and technical (infrastructure, devices, processes) subsystemsGovernance must address both technical aspects (security, architecture) and social/institutional aspects (user behavior, norms)[47]
Risk Governance TheoryProcesses for risk identification, assessment, management, communication, monitoring, and stakeholder involvementProvides a structured process to identify, assess, mitigate, and monitor IoT risks (security, privacy, systemic)[48]
Institutional/Compliance TheoryInstitutions = norms, rules, routines; pressures for legitimacy, conformity, coercionExplains adoption of IoT governance practices under regulatory, normative, or peer pressure; alignment with institutional incentives.[49]
Table 3. Governance maturity levels in IoT security governance.
Table 3. Governance maturity levels in IoT security governance.
LevelGovernance Characteristics
Level 1—Ad-hocReactive security practices and decentralized decision-making
Level 2—InitialBasic governance policies exist but implementation is inconsistent
Level 3—StructuredDefined governance roles, policies, and oversight mechanisms
Level 4—IntegratedRisk governance and compliance integrated across operations
Level 5—OptimizedContinuous monitoring, adaptive governance, ecosystem coordination
Table 4. Contributions of the Resilient Security Governance Model (URSGM) for IoT-Driven Organizations.
Table 4. Contributions of the Resilient Security Governance Model (URSGM) for IoT-Driven Organizations.
DomainContributionDescription of Academic RationaleValue for IoT-Driven Organizations
TheoreticalTheory-based integration of fragmented governance perspectivesIntegrates multiple theoretical anchors, governance theory, socio-technical systems theory, risk governance theory, institutional/compliance theory, and resilience/adaptive capacity theory into a unified governance logic tailored for IoT-driven environments. This addresses the fragmentation and technology-centric limitations reported in prior IoT governance research [69].Provides a coherent conceptual foundation for security governance in IoT-enabled organizations where existing approaches remain siloed or incomplete.
Resilience-centered security governance framingConceptualizes resilience and adaptive capacity as core governance capabilities (not only operational outcomes), enabling governance structures to adapt to evolving cyber-physical threats and contextual disruptions [17].Strengthens organizational readiness and long-term robustness in dynamic, uncertain IoT threat landscapes.
Ecosystem-level coordination and shared accountabilityIntroduces an ecosystem coordination layer to account for multi-stakeholder dependency and distributed responsibilities in IoT ecosystems [70], extending governance logic beyond organizational boundaries.Enables cross-boundary governance and shared accountability for IoT security across vendors, partners, platforms, and distributed infrastructures.
ManagerialStructured governance dimensions with clarified decision rightsOperationalizes IoT security governance through six interdependent dimensions (strategic governance, operational governance, technical oversight, compliance alignment, risk governance, resilience/adaptation) supported by explicit decision rights and responsibilities [57].Supports leadership teams in assigning accountability, aligning governance functions, and reducing ambiguity in IoT security decision-making.
Modular architecture supporting scalable implementationPresents a modular governance structure that can be tailored based on maturity, risk exposure, and resource constraints, enabling practical adoption in diverse organizational contexts [66].Enhances feasibility across SMEs and large enterprises without imposing a rigid one-size-fits-all structure.
Alignment of governance with legitimacy and compliance pressuresEmbeds compliance alignment and institutional legitimacy as formal governance dimensions, supporting transparency, audit preparedness, and stakeholder trust [69].Strengthens regulatory readiness and improves organizational credibility in IoT adoption and security governance practices.
PracticalContinuous risk monitoring and governance feedback loopsEmphasizes continuous risk monitoring, evaluation, and adaptive feedback loops as integral governance mechanisms, improving responsiveness to emergent vulnerabilities and shifting threats [69].Supports real-time governance optimization and timely detection of governance gaps in IoT operations.
Bridging technical security controls with governance mechanismsExplicitly connects technical oversight and security controls to governance-level structures (policies, accountability, compliance), addressing the common gap between technical security and organizational governance [69].Enables consistent implementation and enforceable IoT cybersecurity decision-making aligned with institutional objectives.
Foundation for benchmarking and future empirical validationEstablishes a conceptual foundation for future empirical testing, governance benchmarking, maturity assessments, and KPI development in IoT security governance research [3].Enables measurable governance improvements over time and supports evidence-based refinement across research and practice.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Taherdoost, H.; Shieh, C.-S.; Gupta, S.K. An Integrated Information Security Governance Model for Hyperconnected IoT Ecosystems; Unified Resilient Security Governance Model (URSGM). Computers 2026, 15, 236. https://doi.org/10.3390/computers15040236

AMA Style

Taherdoost H, Shieh C-S, Gupta SK. An Integrated Information Security Governance Model for Hyperconnected IoT Ecosystems; Unified Resilient Security Governance Model (URSGM). Computers. 2026; 15(4):236. https://doi.org/10.3390/computers15040236

Chicago/Turabian Style

Taherdoost, Hamed, Chin-Shiuh Shieh, and Shashi Kant Gupta. 2026. "An Integrated Information Security Governance Model for Hyperconnected IoT Ecosystems; Unified Resilient Security Governance Model (URSGM)" Computers 15, no. 4: 236. https://doi.org/10.3390/computers15040236

APA Style

Taherdoost, H., Shieh, C.-S., & Gupta, S. K. (2026). An Integrated Information Security Governance Model for Hyperconnected IoT Ecosystems; Unified Resilient Security Governance Model (URSGM). Computers, 15(4), 236. https://doi.org/10.3390/computers15040236

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop