Skip to Content
SystemsSystems
  • Article
  • Open Access

9 March 2026

36 Pages

Communication and Information Systems User Support as a Governance Mechanism in a High-Security Public Organization

1
Ministry of Defence, Slovenian Armed Forces, SI-1000 Ljubljana, Slovenia
2
Faculty of Logistics, University of Maribor, SI-3000 Celje, Slovenia

Abstract

Reliable internal communication and information systems (CISs) constitute a foundational yet often under-examined layer of contemporary digital government and organizational resilience. While existing research has predominantly focused on citizen-facing services and external platforms, comparatively limited attention has been devoted to how internal CIS user support structures function as governance mechanisms that sustain institutional continuity, authority, and operational control. This article reconceptualises CIS user support as a governance mechanism and empirically examines its implementation within a high-security public-sector organization, the Slovenian Armed Forces. The study integrates perspectives from information systems governance and IT service management with an in-depth case study based on legal and organizational framework analysis, structured user interviews (n = 24), and longitudinal operational data on CIS incidents and service performance (2022–2024). The findings demonstrate that a multi-tier CIS user support architecture, informed by IT service management principles and integrated with cybersecurity and cryptographic control functions, contributes to institutional reliability, process accountability, and operational resilience. Building on these results, the article develops a five-dimensional governance model of CIS user support encompassing organizational authority, process formalization, security integration, communication legitimacy, and data-driven oversight. By conceptualizing CIS user support as an embedded governance structure rather than merely an operational IT function, the study extends information systems governance and digital government scholarship and provides analytically transferable insights for high-security public organizations operating under conditions of elevated risk and institutional constraint.

1. Introduction

Communication and information systems (CISs) constitute a foundational layer of contemporary digital government by enabling reliable communication, coordination, and the execution of core public-sector functions. Beyond their technical role, internal digital infrastructures shape institutional continuity, accountability, and state capacity in the information age. However, despite their centrality to everyday government operations, such infrastructures remain largely underexamined in mainstream digital government research, which has predominantly focused on citizen-facing services, online platforms, and front-office transformation. In security-sensitive public organizations, where operational reliability and information protection are integral to institutional legitimacy, the governance of CIS—and the organization of user support in particular—acquires heightened strategic significance.
In such contexts, CISs do not function merely as operational tools but as core governance infrastructures that sustain decision-making, command and control, and the delivery of legally mandated public functions. Their increasing complexity, deep integration with critical infrastructure, and continuous exposure to technological change and cyber threats place heightened demands on the organization and governance of support structures. Particularly in military environments, where information systems underpin operational readiness and the timely execution of command decisions, ensuring the uninterrupted functioning of CIS is of strategic importance. System disruptions in such settings may directly impair decision-making speed, coordination, and the state’s ability to respond effectively to security challenges.
Research in the field of information technology service management (ITSM) emphasizes the role of standardized processes in improving transparency, reducing errors, and enhancing service quality [1,2,3]. Frameworks such as the Information Technology Infrastructure Library (ITIL), Control Objectives for Information and Related Technologies (COBIT), and related models provide widely adopted methodological foundations for organizing support services and managing incidents across both private and public-sector organizations. Within public administrations, these frameworks are increasingly associated not only with efficiency gains but also with enhanced accountability, traceability, and the reliability of government information flows. However, military organizations operate under distinctive conditions shaped by national security policy, hierarchical command structures, classified information handling, and requirements for continuous operational readiness. These constraints limit the direct transferability of civilian IT service management practices and necessitate their adaptation to governance arrangements that integrate operational control, security enforcement, and formal authority structures.
While digital government scholarship has extensively examined citizen-facing services, online platforms, and front-office transformation, the governance of internal digital infrastructures that sustain everyday state operations remains comparatively underexplored. This gap is particularly evident in security-sensitive public organizations, where continuity of operations, institutional accountability, and organizational resilience are critical and where internal information systems constitute essential components of state capacity rather than auxiliary technical assets.
Systematic analyses of the effectiveness of CIS user support within military organizations—particularly with respect to cyber and cryptographic incident handling—remain limited in the existing literature. Although numerous studies address the application of ITIL, COBIT, and related IT service management frameworks in civilian and public-sector contexts, their empirical evaluation in military environments is comparatively scarce. In particular, research has paid limited attention to how established IT service management practices operate under conditions of strict security requirements, formal authority structures, and mission-critical operational demands. Moreover, the integration of cyber defence and cryptographic support into ITSM processes is typically addressed only indirectly, despite its central relevance for high-security public organizations. Empirical studies focusing on smaller armed forces, characterized by constrained resources and geographically dispersed infrastructures, are especially rare, further limiting the analytical generalization of existing findings. In addition, the literature tends to underestimate the role of digitalization, automation, and data-driven governance mechanisms in shaping contemporary user support models within military settings.
The Slovenian Armed Forces (SAF) constitute an analytically relevant case of a small-state yet technologically demanding public-sector organization, in which limited resources, geographically dispersed infrastructure, and persistent cyber threats generate continuous operational pressure. Under such conditions, the effectiveness of CIS user support cannot be understood solely as a technical matter but must be examined as a governance issue, as it directly influences the reliability, continuity, and security of state information systems. Within this context, the present study analyses the organization, responsiveness, and performance of CIS user support structures in the SAF, examining their alignment with established IT service management practices while situating them within broader digital government and public-sector governance processes.
Despite extensive research on IT service management and information systems governance, a conceptual gap persists regarding how governance is enacted through internal user support structures. ITSM scholarship predominantly conceptualizes support in terms of process efficiency and service quality, while governance research focuses on strategic alignment, oversight, and control mechanisms at higher organizational levels. What remains under-theorized is how authority allocation, escalation control, and security enforcement are operationalized through routine support workflows at the operational core of digital infrastructures. In this respect, user support has rarely been conceptualized as a governance mechanism in its own right.
Building on this identified theoretical gap, this study reconceptualises CIS user support as a governance mechanism and empirically examines how authority allocation, control structures, security enforcement, and organizational resilience are enacted through structured support processes in a high-security public organization. Rather than treating user support as a technical or service-oriented function, the paper positions it as an institutional mechanism through which governance is operationalized at the core of digital infrastructures. In doing so, the study extends information systems governance and digital government scholarship toward the operational layer of high-security public organizations and contributes to systems-oriented thinking by highlighting multi-level interactions, escalation dynamics, and adaptive incident management structures.
The research focuses on examining the organization of CIS user support within the SAF as a governance-oriented support system and on assessing the extent to which this support aligns with established IT service management best practices while enabling the effective handling of operational, cyber, and cryptographic incidents. The purpose of the study is to analyse the structure and functioning of the existing support system, identify its strengths and limitations, and explore opportunities for further development in terms of resilience, accountability, and operational continuity. Accordingly, the study addresses the following research questions:
  • How is governance of the CIS layer operationalized through user support structures within the SAF?
  • To what extent do existing support processes follow IT service management best practices, such as ITIL and COBIT?
  • How effective is the support in handling operational, cyber, and cryptographic incidents?
  • How do CIS users assess the quality, responsiveness, and communication of the support structures?
  • Which improvements could enhance the reliability and resilience of the CIS support system in a military context?
The research objectives are oriented toward a comprehensive and empirically grounded assessment of CIS user support within the SAF. The study examines the organizational and legal frameworks governing CIS operations, followed by an analysis of how existing support processes align with established methodological frameworks such as ITIL and COBIT. Particular attention is devoted to user experiences captured through structured interviews, as well as to a longitudinal statistical assessment of system performance based on the handling of operational, cyber, and cryptographic incidents. On the basis of these findings, the study identifies key governance and organizational challenges and formulates recommendations aimed at strengthening the effectiveness, resilience, and coherence of CIS support structures.
By integrating theoretical perspectives on information systems governance with an empirical analysis of CIS user support within the SAF, this study contributes to digital government and public-sector governance literature by demonstrating how standardized IT service management principles can be adapted and reinterpreted within high-security public organizations. The findings show how process standardization, organizational design, and the integration of cybersecurity and cryptographic support function not merely as technical solutions but as governance mechanisms that enhance institutional resilience, accountability, and the operational continuity of government information systems in dynamic and security-sensitive environments. In doing so, the article frames CIS user support as a systemic governance component embedded within complex digital infrastructures, highlighting interdependencies, feedback dynamics, and adaptive coordination mechanisms that contribute to institutional resilience. Taken together, the study conceptualizes CIS user support as a socio-technical governance subsystem embedded within a broader organizational system, characterized by structured escalation pathways, feedback loops, and adaptive resilience mechanisms.
This contribution is not limited to describing a military case of IT service management implementation. Rather, the study advances information systems governance scholarship by empirically demonstrating how governance is enacted through routine support workflows at the operational core of digital infrastructures. By integrating longitudinal incident data, structured interviews, and formal organizational analysis, the article shows how authority allocation, escalation control, security enforcement, and data-driven oversight are institutionalized within everyday CIS user support processes. In this way, the proposed five-dimensional model provides a transferable analytical framework for examining governance mechanisms embedded in internal digital infrastructures of high-security public organizations.

2. Methodology

This study adopts an information systems governance case study design that combines qualitative and quantitative methods in order to examine CIS user support not merely as an operational service function, but as a governance mechanism through which authority, control, security, and organizational resilience are enacted in practice. A case study approach is particularly suitable for investigating complex socio-technical arrangements embedded in specific institutional contexts, where governance processes unfold through routine operational practices rather than formal policy statements alone.
The methodological framework integrates four complementary components: (1) a structured literature review, (2) analysis of legal and organizational foundations, (3) structured user interviews, and (4) quantitative analysis of operational incident data. This multi-method design enables systematic data triangulation and supports both empirical validation and theory-informed interpretation.
The literature review was conducted to establish the theoretical foundations of the study and to situate CIS user support within broader debates on information systems governance, IT service management, digital government, and cybersecurity. Sources included peer-reviewed scientific articles, professional publications, and methodological guidelines in the fields of IT service management, process governance, cybersecurity, and military information systems.
The review was structured into five thematic areas corresponding to the analytical dimensions of governance developed later in the study. This structure enabled a systematic comparison between civilian IT service management practices and the specific institutional and security requirements characteristic of military organizations. The literature review informed both the empirical data collection and the analytical interpretation of findings, ensuring conceptual consistency across the study.
The analysis of legal and organizational foundations focused on formal governance arrangements shaping CIS operations within the SAF. This component was based on a review of national legislation, governmental regulations, internal SAF directives, and organizational documents defining responsibilities, authority structures, and procedures related to CIS management and user support.
This analysis provided insight into how governance is formally articulated within the organization, including escalation rights, security obligations, and accountability mechanisms. It also served as a reference point for assessing the alignment between formal governance frameworks and their operational implementation through user support practices.
Qualitative data were collected through structured interviews with 24 participants from different organizational levels of the SAF who are directly involved in the use, management, or support of CIS. Participants included end users, personnel from the Service Centre (SC), and representatives of local and technical support units.
Participants were selected using purposive sampling based on their formal role within the CIS support structure. Inclusion criteria required active involvement in incident handling, supervisory responsibilities, or direct end-user interaction with CISs. The sampling strategy ensured representation across hierarchical levels (SC, LSU, and end users) in order to capture variation in governance experience and operational perspective. Participation was voluntary, and all respondents provided informed consent. Interview data were anonymized to ensure confidentiality.
The interviews focused not only on perceived service quality and responsiveness but also on governance-relevant aspects of user support, such as clarity of escalation procedures, transparency of decision-making, perceived authority of support structures, and the handling of security-sensitive incidents. In this way, the interviews captured how governance arrangements are experienced and interpreted by users in everyday operational contexts.
Interviews were conducted using a structured interview guide organized into thematic blocks corresponding to the five analytical governance dimensions developed in the study. Each interview lasted between approximately 30 and 60 min. Interviews were documented through structured written notes, and key statements were subsequently systematized for analytical purposes. The structured format ensured comparability across respondents while allowing contextual elaboration where necessary.
Interview data were analysed thematically, with responses coded into categories corresponding to the analytical dimensions of the study (SC-related issues, local support units, and cross-cutting governance themes). The qualitative findings were systematically compared with insights from the literature review and the analysis of organizational documents to enhance interpretive validity. In the empirical sections below, selected anonymized quotations (Interview 1–24) are included to illustrate representative patterns identified in the qualitative analysis. The coding process followed a two-stage analytical approach. First, a deductive coding framework was developed based on the five governance dimensions identified in the literature review. Second, inductive refinement enabled the identification of emergent sub-themes within each category. Coding was conducted iteratively through repeated comparison of transcripts to ensure internal consistency and analytical coherence.
The quantitative component of the study comprised a statistical analysis of CIS incident data covering the period from 2022 to 2024. The dataset included operational, cyber, and cryptographic incidents recorded across different support levels, including the SC, Local Support Units (LSUs), Technical Support Units (TSUs), the Military Computer Emergency Response Team (MilCERT), and the Cryptographic Sub-Registry (CSR).
For analytical clarity, three categories of incidents were distinguished. Operational incidents refer to technical failures, service disruptions, configuration problems, and user-related system malfunctions affecting routine CIS functionality. Cyber incidents denote events involving malicious activity, unauthorized access attempts, malware detection, or other security-relevant digital threats handled primarily by MilCERT. Cryptographic incidents encompass issues related to key management, cryptographic device malfunction, certificate handling, and secure communication infrastructure managed by the CSR. These distinctions ensure conceptual consistency across the quantitative and qualitative analyses.
The analysis examined the number and types of incidents, resolution success rates, temporal trends, and the distribution of incidents across support levels. These indicators were interpreted not merely as performance metrics but as proxies for governance effectiveness, reflecting how consistently escalation, control, and resolution mechanisms function across the organization. Longitudinal analysis enabled the identification of patterns relevant to organizational learning, preventive measures, and adaptive governance.
Quantitative data were analysed using descriptive statistical techniques, including frequency distributions, proportional analysis, and longitudinal trend comparison across the three-year period. Resolution rates were calculated as the proportion of formally closed incidents relative to the total number of recorded incidents. Escalation distribution was measured by the percentage of incidents resolved at each support tier. Statistical processing was performed using structured administrative datasets extracted from the CIS incident management system.
Governance effectiveness was operationalized through three measurable indicators: (1) incident resolution rate, reflecting procedural control consistency; (2) escalation distribution across support tiers, indicating authority allocation and decision thresholds; and (3) longitudinal trends in cyber and cryptographic incidents, reflecting adaptive governance capacity and preventive learning mechanisms. In this sense, incident data provide empirical evidence of how governance principles are operationalized in practice, revealing not only service performance but also the stability, responsiveness, and adaptive capacity of the CIS support framework.
The SAF represents an analytically relevant case of a small-state, high-security public organization characterized by constrained resources, geographically dispersed infrastructure, and persistent cyber threats. Under such conditions, governance mechanisms embedded in user support structures are amplified and become particularly visible, as failures cannot be easily absorbed or externalized.
The study does not pursue cross-national comparison, as comparable empirical data from other military and high-security public organizations are typically non-public and embedded in heterogeneous governance arrangements, limiting meaningful comparability. Instead, the case study follows an analytical generalization logic, aiming to derive transferable insights into governance mechanisms rather than statistically representative conclusions. The small-state context thus functions as an analytical amplifier that reveals structural features of CIS user support governance that may remain less visible in larger or more resource-rich public administrations.
The integration of qualitative and quantitative methods enabled systematic data triangulation, thereby increasing the reliability and robustness of the findings. Potential bias in interview data was mitigated through cross-validation with organizational documents and operational incident statistics. While the single-case design limits statistical generalization, the study provides theory-informed insights into the governance of CIS user support that are relevant for a broader range of high-security public-sector organizations.

3. Results

This section presents the findings of the study examining user support for the CIS within the SAF. The analysis integrates a review of the literature on IT service management best practices, an examination of the organization of support structures, results from user interviews, and statistical data on operational, cyber, and cryptographic incidents for the years 2022, 2023, and 2024. The presented results provide a comprehensive insight into the functioning of the existing support system and its readiness to respond effectively to the challenges of the contemporary digital and security environment.

3.1. Literature Review

The literature review is structured to comprehensively address the domain of CIS user support and the adoption of IT service management best practices in both civilian and military environments. The analysed sources are organized into five thematic areas. The first area examines frameworks and methodologies for IT service management, with a particular focus on ITIL and COBIT as standardized frameworks for process optimization and service quality assurance. The second area focuses on process optimization and user support, addressing Help Desk and Service Desk concepts as well as incident, change, and problem management. The third area covers organizational factors and human capital, including leadership roles, organizational culture, and the importance of training and informal support structures. The fourth area addresses analytics, digital transformation, and innovation, emphasizing data analytics, digital user support, and the integration of IT and operational technologies. The fifth area examines the military context and cybersecurity, analysing the specific characteristics of military environments, the role of military values in IT service management, and best practices in cyber training.
The first thematic area focuses on frameworks and methodologies for IT service management, which form the foundation for organizing and optimizing support processes. Among the most widely adopted methodologies are the ITIL, which represents a collection of best practices for effective IT service organization, and COBIT, which emphasizes holistic governance and control of information technology. Research confirms that the COBIT structure enables a systematic representation of processes and can serve as a complementary framework to existing quality practices by strengthening transparency, roles, and responsibilities within organizations [4]. The ITIL framework has been the subject of numerous studies examining its effectiveness and alignment with contemporary concepts such as service-dominant logic (S-D logic), in which users act as co-creators of value. Cronholm et al. [5] note that, despite its service-oriented focus, ITIL frequently employs terminology characteristic of product-dominant logic, which limits its full alignment with S-D logic principles. To improve ITIL effectiveness, they propose adjustments in language and conceptual framing that would emphasize value co-creation between organizations and users. A central issue in successful ITIL implementation relates to organizational readiness, leadership support, and the cultural changes introduced by process standardization. Mohammed [6] identifies critical success factors for ITIL adoption in public organizations, highlighting top management support, interdepartmental collaboration, clearly defined objectives, and continuous training. Similarly, Marrone et al. [1] report in an international study that organizations most often focus on operational processes such as incident and change management when adopting ITIL, as these processes enable rapid results and measurable improvements in service quality. ITIL implementation also exerts a notable influence on organizational culture. Berntsen [7] finds that ITIL adoption leads to increased process formalization and a stronger service-oriented mindset among employees; however, implementation success depends on sustained leadership support, practice-oriented training, and employee involvement in decision-making and tool selection. Talla and Valverde [8], in their case study, confirm that the introduction of ITIL processes—such as Service Desk, Incident Management, and Change Management—significantly enhances the efficiency of support services and improves the user experience. From a military perspective, ITIL gains additional value as a tool for standardizing and integrating IT services within complex systems. Weaver [9] emphasizes that the application of ITIL within the U.S. Air Force Air Operations Centre (AOC) enables a transition from managing individual components to managing services, thereby supporting organizational strategic objectives. Similarly, Salcedo [10] highlights that the adoption of ITIL in military educational institutions improves service quality, standardizes processes, and fosters a culture of continuous improvement, which is particularly important for the effective operation of telematics services.
The second thematic area of the literature review focuses on process optimization and user support, highlighting the Help Desk and Service Desk concepts as foundational components of effective service management. TG [11] analyses the reorganization of technical support in higher education institutions, where increasing demands for IT services confront organizations with resource constraints. The study demonstrates that decentralization and process rationalization can lead to improved responsiveness and higher levels of user satisfaction. A similar approach is described by Bulchand-Gidumal and Melian-Gonzalez [12], who developed an internal market model in a Spanish university setting, enabling flexibility, knowledge retention, and improved user satisfaction without relying on external service providers. The quality of technical documentation and user guidelines is often underestimated, despite its direct impact on the effectiveness of user support. Blackwell [13] finds that clearly and accurately documented instructions reduce error rates, improve usability, and consequently lower support costs. User support can be effective only if processes such as incident management, problem management, and change management are properly implemented and integrated into daily operations. Talla and Valverde [8], in a case study of a healthcare network, show that ITIL processes—including Incident Management, Problem Management, and Change Management—enable measurable improvements in service quality and enhance the responsiveness of the Service Desk function. The importance of process optimization in user support is also evident in military environments. Woo et al. [2] analyse the effects of ITSM implementation in the military electronic services of the Republic of Korea, finding that the consolidation of services into a unified Service Desk system increases transparency, operational efficiency, and user satisfaction. Overall, research findings indicate that standardized processes, supported by tools for monitoring key performance indicators, play an essential role in ensuring the reliable operation of support structures.
The third thematic area of the literature review focuses on organizational factors and human capital, both of which significantly influence the effectiveness of IT service management and support structures. Lin et al. [14] find that the success of business process reengineering (BPR) projects depends on a combination of factors, including leadership support, organizational culture, project team quality, the use of information technology, and effective change management. They emphasize that success emerges from the coordinated interaction of these elements, a conclusion that is equally applicable to the adoption of ITIL or similar frameworks within support services. Bapna et al. [15] extend this perspective through an analysis of investments in human capital, highlighting the importance of combining technical training with soft skills development, as this combination significantly improves employee performance and reduces competency gaps. Organizational culture plays a particularly important role in the adoption of new processes and tools for IT service support. Berntsen [7] observes that the process formalization and service orientation introduced by ITIL influence work practices and require active employee involvement in decision-making; otherwise, resistance or low levels of change adoption may occur. Similarly, Sykes [16] emphasizes the importance of informal support structures, such as advice networks among colleagues, which often prove more effective than formal training programs during the implementation of new information systems. Such networks contribute to faster problem resolution, reduced stress, and higher levels of job satisfaction. Understanding and managing human capital, therefore, represent a foundation for the sustainable improvement of support services. Training approaches that incorporate practical examples, a combination of technical and communication skills, and active employee participation in process design have a substantial impact on the effectiveness of IT services and their ability to respond to complex user requirements [15,16].
The fourth thematic area of the literature review focuses on analytics, digital transformation, and innovation, which represent central drivers of the development of support services in IT environments. Polzin [17] emphasizes that the application of data analytics in IT service management enables deeper insights into incident patterns and user behaviour, thereby supporting proactive problem resolution and process optimization. The use of analytical tools and methods, such as predictive models, allows organizations to extend traditional reactive approaches with advanced prevention strategies, thus increasing service reliability. Digital transformation introduces new opportunities to improve user experience and the efficiency of support processes. Bhagwatwar et al. [18] examine digitally supported user assistance, showing that the integration of modern tools—such as self-service portals and mobile applications—enhances user autonomy and accelerates access to services. This reduces the workload of Service Desk units and enables the reallocation of resources toward strategic activities, including the development of new functionalities and the management of innovation. An important component of contemporary IT environments is the integration of information technology and operational technology (IT and OT), as defined by Industry 4.0 concepts. Shilenge and Telukdarie [19] emphasize that successful integration of these domains depends on appropriate security management approaches, protocol standardization, and the use of advanced monitoring and data analytics tools. This convergence supports the development of intelligent and adaptive systems capable of timely risk identification and effective support for organizational core processes. Together, digital transformation and analytics create the foundation for innovation that enhances the effectiveness of user support and enables more informed strategic decision-making. Organizations that actively adopt new digital solutions can improve their processes, reduce operational costs, and increase operational reliability [17,18,19].
The fifth thematic area of the literature review addresses the military context and cybersecurity, where IT service user support intersects with the specific requirements of the defence environment. Woo et al. [2] analyse the implementation of IT service management in the military electronic services of the Republic of Korea and find that process standardization and the transition to a centralized Service Desk system enable higher levels of transparency, reliability, and user satisfaction. This is particularly important in military systems, where support functions must operate continuously and under conditions that often demand a high degree of resilience to disruptions. Massey [20] emphasizes that effective IT service management in military environments is closely linked to military values such as discipline, accountability, and hierarchical decision-making structures. These values facilitate the execution of support processes, as both users and administrators are expected to adhere strictly to established procedures and security protocols. Similarly, Guttieri [21] notes that military IT infrastructures must provide comparable levels of responsiveness and security in both peacetime and crisis conditions. Cybersecurity holds a distinct and critical role in military systems, as any disruption or compromise of IT services may be associated with operational risks and security threats. Bogdański [3] highlights that user training in recognizing cyber threats and applying security protocols is as important as the technical protection of infrastructure. Jones [22] adds that military organizations adopting ITIL and other standards must focus on adapting processes to specific operational requirements, including strict access control and rapid response to security incidents. The military context therefore requires a close integration of traditional IT service management concepts with advanced approaches to information security, where process standardization, user competence, and the continuous enhancement of protective measures together form a comprehensive framework for supporting and safeguarding communication and information systems [2,3,20].
The literature review indicates that effective user support is the outcome of a comprehensive approach that integrates process standardization, service optimization, organizational adaptability, the use of digital tools, and robust information security practices. Established IT service management frameworks, including structured process models and quality guidelines, support improved resource management, enhanced transparency, and continuous service improvement. Support structures such as Help Desk and Service Desk functions emerge as central elements for rapid incident resolution, improved user communication, and the monitoring of user satisfaction and operational performance. The effectiveness of these systems depends on organizational culture, adequate leadership support, and the competencies of personnel, who are required to possess both technical expertise and soft skills. Digital transformation, through the introduction of self-service solutions, mobile platforms, and data analytics, further enhances responsiveness and enables proactive problem resolution. In military environments, these practices are augmented by requirements for uninterrupted operation, resilience to cyber threats, and strict information protection, highlighting the need for close integration between support processes and security protocols.
While the reviewed literature provides valuable insights into process standardization, service optimization, organizational factors, digital transformation, and security integration, it largely treats these dimensions as parallel analytical domains. Existing frameworks such as ITIL and COBIT emphasize procedural control and performance optimization but rarely conceptualize user support as an institutionalized governance layer through which authority, escalation, and security enforcement are enacted in practice. Similarly, digital government research highlights accountability and institutional capacity yet pays limited attention to the operational mechanisms that stabilize internal digital infrastructures. As a result, the interdependencies between organizational structure, process formalization, security integration, communication practices, and data analytics remain insufficiently theorized as components of a unified governance subsystem. This gap motivates the development of the five-dimensional CIS User Support Governance Model proposed in this study.

3.2. Organization of CIS Support in the SAF

The organizational foundation of the SAF CIS is defined by Article 102 of the Defence Act, which mandates the establishment of a unified and autonomous information and telecommunications system for the needs of the defence sector, including the SAF. The system is intended to support administrative and professional tasks and to provide communication and information support for command, control, and operational activities of military structures. The Ministry of Defence (MOD) determines the organizational levels of the system and the responsibilities of duty services, thereby ensuring continuous operation, effective responsiveness to user requirements, and comprehensive protection of the communication infrastructure [23].
The organization and protection of CIS SAF are further regulated by the Regulation on the Protection of the Communication and Information System of the MOD. This regulation defines technical and organizational measures to ensure the confidentiality, integrity, and availability of data, as well as the security mechanisms applied throughout the entire system life cycle. It specifies the responsibilities of security authorities, including the authority for cryptographic protection of classified information, the authority responsible for system security accreditation, and local and senior information security officers, who ensure the implementation of prescribed procedures and measures at all organizational levels. The regulation also covers rules governing the use, deployment, and upgrading of hardware, software, and communication equipment, network interconnections, data transmission, and protection against computer viruses and other threats. Particular emphasis is placed on risk management, the preparation of security accreditations for individual subsystems, and the enforcement of access control over data and services. In addition, it defines procedures for the handling of security events and incidents and provides for periodic and ad hoc user training, thereby ensuring the secure and reliable use of CIS within the defence sector [24].
CIS SAF represents a functional component of the broader CIS of the MOD and is designed to support command and control (C2) as well as to provide communication and information support for operational processes within the SAF. The CIS SAF structure comprises a wide range of components, including communication transmission and cryptographic equipment, active network and security devices, telephone exchanges, servers, data centres, terminal hardware, application software, databases, and identification and authorization procedures. The operation and organization of the system are further specified in Directive 16-01 on the Operation and Protection of CIS SAF, which defines the fundamental processes, responsibilities, and rules for system maintenance and use. The system is based on best-practice principles and guidelines of the ITIL, which support the efficient organization and delivery of services [25].
User support for the CIS SAF is organized as a multi-tier structure (see Figure 1) and is designed to ensure uninterrupted system operation and the rapid handling of incidents and user requests. A central role in user support is performed by the SC, which operates as a single point of contact for all users and system administrators. Its responsibilities include incident logging, categorization, and prioritization; initial diagnostics and resolution of issues that can be addressed remotely; and informing users about the status of incident resolution and service requests. In addition, SC analyses aggregated incident data and prepares reports for expert and supervisory bodies.
Figure 1. Multi-tier structure of CIS user support in the Slovenian Armed Forces.
At the local level, LSUs operate as the first level of user support. Their primary responsibility is to maintain and ensure uninterrupted system operation at individual locations, as well as to handle standard service requests, such as granting access to basic services and installing software. LSUs also perform first-level incident resolution and basic infrastructure monitoring.
More complex technical challenges are addressed by TSUs, which function as the second level of support. These units resolve more complex incidents, perform maintenance of communication and information infrastructure, and ensure the technical implementation of new subsystems and services. TSU closely cooperates with external service providers and expert groups within the MOD Information and Communications Service (ICS), which together represent the third level of support.
Continuous system oversight is provided by the CIS Network and Systems Monitoring Centre (NSMC), which monitors key operational parameters, proactively detects irregularities, and notifies management authorities. In addition, NSMC prepares regular system status reports and proposes improvement measures.
The operation of CIS user support is based on clearly defined processes, including event management, incident management, request fulfilment, access management, and problem management. Incident management is focused on the rapid restoration of normal system operation, while problem management supports the identification of root causes of recurring issues and the implementation of permanent solutions. All processes are documented and traceable, ensuring operational efficiency and transparency.
A further important element of effective CIS SAF operation is the systematic training of users and management authorities. Prior to being granted access to the CIS, users must be familiarized with the fundamental rules governing system use and protection [25].
The governance and custodianship bodies of CIS SAF are defined in Directive No. 16-02, which specifies the structure, roles, and responsibilities of entities responsible for the operation and maintenance of the CIS. The governance framework includes the CIS SAF system owner, CIS subsystem owners, technical and functional owners of information solutions, information asset owners, and multiple levels of administrators. These bodies cooperate in planning, supervision, and development of individual subsystems, incident handling, and ensuring compliance with information security regulations. Their activities are closely coordinated with those of the NSMC, LSU, and TSU, together forming an integrated mechanism for the effective management of CIS SAF [26].

3.3. Interview Analysis

The results of the structured interviews with SAF CIS users indicate a high level of satisfaction with the operation of the SC, while simultaneously revealing several systemic challenges, particularly in relation to LSU and coordination among different actors within the support chain. Users are well acquainted with the SC contact number (77 5656) and use it regularly; most respondents reported having contacted the SC at least once during the previous six months. Establishing contact is described as straightforward and reliable, and the responsiveness of operators is assessed as very high. Interview responses consistently emphasize that the SC resolves issues rapidly, often within a few minutes in the case of standard incidents such as forgotten passwords or login problems, and within the same working day for more complex cases. Users perceive the SC staff as highly professional and approachable, and they report being well informed about subsequent steps in the support process, such as the escalation or transfer of incidents to LSU. This perception is reflected in interview statements such as: “The SC resolves standard incidents within minutes and more complex cases within the same working day. Communication is professional, and users are regularly informed about escalation steps” (Interviewee 7).
Despite these positive aspects, several limitations were identified. A notable issue concerns the limited accessibility of the SC contact number from certain external networks, particularly during remote work or when performing tasks within military mission operations. Users also report that the automated response system does not provide information on queue length or expected waiting times, which makes it difficult to assess responsiveness during periods of high demand. As one respondent noted: “During remote work or mission deployment, the SC contact number is not always accessible, and the automated system provides no indication of waiting times” (Interviewee 12). A particularly pronounced challenge relates to the Information System for Document Handling (ISDH) application, as the SC is unable to resolve issues associated with this system. Users are therefore forced to rely on informal assistance from individuals within the SAF or the MOD, indicating a lack of systematic support for one of the organization’s core process tools.
Assessments of LSU reveal more heterogeneous results. At certain locations, users report rapid response times, effective problem resolution, and clear communication. However, interviews more frequently highlight challenges related to understaffing of LSU, which negatively affects responsiveness and incident resolution times. Users indicate that handling times may extend to several days, often as a consequence of limited staff availability or competing operational duties. Several interviewees explicitly pointed to structural limitations at the local level. For example, one respondent stated that “response times at the LSU level can extend to several days, primarily due to limited staffing and competing operational duties” (Interviewee 4). Overall, user experiences suggest that the quality of local support is strongly dependent on individual motivation, personal competencies, and work organization, indicating a high degree of variability across locations. This variability is captured in the following observation: “The quality of local support strongly depends on individual competencies and motivation, resulting in significant variability across locations” (Interviewee 15). Users frequently express a need for improved accessibility of local support units, particularly through officially defined communication channels, which are often replaced in practice by informal phone calls to personal mobile numbers.
When comparing the SC and LSU, the majority of interviewees report that they primarily contact the SC. This preference is attributed to its more structured approach, faster resolution times, and comprehensive handling of incidents. LSU is perceived as a necessary complement, particularly for hardware-related issues or problems involving physical infrastructure; however, users consistently agree that LSUs face a higher workload and exhibit considerably less predictable availability. Regarding cooperation between the SC and LSU, users generally express neutral to positive perceptions. Nevertheless, some respondents with insight into internal processes point out that coordination between the two levels is not fully optimized. A particularly notable finding is the lack of systematically ensured coordination between the MOD ICS and CIS support within the SAF, which results in limited transparency regarding system changes and their impact on user-facing services.
The interview analysis highlights several recurring improvement proposals that emerge across different units and therefore represent relevant strategic directions. Users frequently emphasize the need for greater transparency of support processes, particularly through the introduction of visibility into incident status and estimated resolution timelines. A commonly proposed improvement is the implementation of a web-based portal or self-service system that would allow users to monitor requests, review their history, and track priorities, which aligns with contemporary ITIL practices and the digital transformation of support services. Several interviewees also suggest the introduction of a “chatbot” to reduce the workload of first-line support, especially in handling recurring issues and frequently asked questions. In addition, users propose the deployment of an automated interactive voice response (IVR) system that would enable call routing based on service type, thereby reducing operator workload and improving response times.
A key shared finding across the interviews is the need for staffing reinforcement and greater professionalization of LSU. Users point out that the current staffing structure does not enable timely incident resolution and hinders consistent process execution across different military installations. Proposed improvements include the introduction of rotation systems, additional training programs, motivational measures, and clearer delineation of responsibilities among organizational units. A particularly prominent proposal is the introduction of a CIS point-of-contact role at the unit level. Such a role would ensure the proper preparation of service requests and greater process alignment, thereby reducing the burden on the SC and improving the overall quality of incident handling.
Overall, the interviews indicate that the SAF CIS support system operates effectively, particularly at the SC level, while exhibiting notable challenges at the level of LSU, inter-organizational coordination, and process digitalization. Users express satisfaction with the core functionality of the system, but simultaneously identify several improvement opportunities that could enhance responsiveness, transparency, and overall system robustness. The interview analysis therefore confirms that the current support model largely adheres to ITIL principles, yet requires further organizational and technological enhancement, especially in the areas of staffing policy, process integration, and the deployment of digital support tools.

3.4. Quantitative Overview of Support Performance

The review of statistical data for the period 2022–2024 enables a comprehensive assessment of the effectiveness of the multi-tier SAF CIS support system. The data cover the handling of all operational, cyber, and cryptographic incidents, the distribution of resolution activities across different support levels, and the overall success of case closure. The analysis confirms a high degree of stability of the support system and reveals several relevant trends that are important for understanding its future development.
Across all three years, between 5619 and 6139 incidents were recorded annually (see Table 1), with a 100% resolution rate achieved in each year. This stable workload reflects a consistently high operational demand on the support structures and simultaneously confirms the maturity and effectiveness of the established incident management processes. Minor year-to-year fluctuations can be attributed to the expansion of digital infrastructure, the broadening of CIS services, and gradual changes in the operational requirements of the SAF, while the overall system workload remains comparable over time.
Table 1. Overview of incidents by year.
From a governance perspective, the longitudinal stability reflected in Table 1 indicates institutionalized procedural control and predictable escalation patterns across support levels. The combination of a stable incident volume and consistently full resolution suggests that authority allocation, decision thresholds, and workflow standardization are functioning reliably over time. Rather than merely reporting performance data, the table provides quantitative evidence of process maturity and operational resilience within the CIS support framework.
The SC assumed a central role in the incident resolution process throughout the analysed period (see Table 2). In 2022, it independently resolved approximately two-thirds of all reported incidents, representing a strong core of first-level support. In 2023, this share decreased slightly due to increased workload related to administrative tasks and system updates; however, in 2024 it increased markedly again, reaching nearly four-fifths of all resolved incidents. This trend indicates a gradual improvement in operator competencies, greater standardization of support processes, and more effective use of incident management tools, in line with ITIL and COBIT guidelines.
Table 2. Overview of resolved incidents by support level and year.
LSU, representing the second level of incident resolution, handled between 15% and 24% of all cases during the 2022–2024 period. Their share shows a declining trend over time, which confirms the improved effectiveness of the SC and the increasing maturity of first-level support processes. LSU remains essential primarily for tasks requiring physical intervention, hardware-related troubleshooting, or on-site configuration of network components. However, the stable yet decreasing proportion of cases addressed by local support suggests a need for staffing reinforcement and the establishment of more uniform standards across different military installations, a point also emphasized by interview respondents.
SAF TSU represents the smallest but highly specialized component of the support system. During the 2022–2024 period, its share of incident resolution ranged between 4% and 6%, which is characteristic of support units responsible for handling more complex failures, system upgrades, and integrations of core systems. An even smaller proportion of incidents—between 1% and 4% in individual years—was escalated to the ICS, primarily for the most complex interventions that exceed the competencies of the SAF.
From a governance perspective, the distribution presented in Table 2 demonstrates a clearly institutionalized escalation architecture in which authority and technical intervention rights are progressively allocated across support levels. The predominance of SC-level resolution indicates procedural maturity and effective first-line control, while the limited but stable role of higher-level units reflects functional specialization rather than systemic overload. The table therefore provides quantitative evidence of structured authority allocation and stable governance design within the CIS support hierarchy.
A more comprehensive perspective is provided by MilCERT data, which reveal a gradual decline in the number of cyber incidents over the observed period (see Table 3). In 2022, a total of 106 incidents were recorded, decreasing to 73 in 2023 and further to 47 in 2024. This long-term downward trend can be associated with improvements in preventive security mechanisms, higher levels of user awareness and training, and the introduction of systematic cyber risk management procedures. Nevertheless, some incidents remain security-relevant, which underscores the need for continued capacity building within MilCERT and for stronger integration of its activities into IT service management processes.
Table 3. Overview of MilCERT incidents.
From a governance perspective, the declining trend presented in Table 3 reflects adaptive capacity within the CIS support framework. The reduction in incident frequency suggests that preventive measures, security governance integration, and awareness mechanisms are not merely formally established but operationally effective. Rather than serving as descriptive statistics alone, the MilCERT data provide quantitative evidence of institutional learning and strengthening cyber resilience over time.
A similar level of stability is also observed in cryptographic incidents recorded in the CSR of the SAF. Between 2022 and 2024 (see Table 4), between 12 and 24 incidents were recorded annually, with the increase observed in 2023 being associated with cyclical key rotation procedures and security equipment updates. The majority of incidents were technical in nature and were successfully resolved within prescribed timeframes, confirming the effective organization of cryptographic governance and the appropriate allocation of responsibilities among supporting authorities.
Table 4. Overview of cryptographic incidents.
From a governance perspective, the relatively low and stable number of cryptographic incidents indicates a high degree of procedural control and regulatory compliance within the CSR framework. The limited fluctuation across years suggests that cryptographic governance mechanisms are embedded in routine operational practices rather than reactive responses to failure. Table 4 therefore illustrates the stability and institutionalization of security governance at the most sensitive layer of the CIS support system.
The overall analysis for the 2022–2024 period confirms that the CIS support system of the SAF is stable, reliable, and largely aligned with IT service management best practices. The high proportion of incidents resolved at the first support level reflects the maturity of the SC and the appropriate design of support processes, while the identified challenges primarily relate to staffing reinforcement of local support units, improved process coordination, and further digitalization of support services. The statistical findings therefore complement the qualitative insights derived from the interviews, together providing a comprehensive perspective on the performance of CIS support structures within the SAF.

4. Discussion

This section discusses the central findings of the study on CIS user support within the SAF and compares them with best practices and theoretical foundations identified in the literature review. The discussion is structured around several thematic areas, including the comparison of the CIS organizational arrangement with standardized approaches such as ITIL and COBIT, an evaluation of the multi-tier support model (SC, LSU, TSU), interpretation of user feedback obtained through interviews, and statistical analysis of operational, cyber, and cryptographic incidents. Particular attention is also given to the role of MilCERT and the CSR in handling security incidents, as well as to the relationship between these processes and digital transformation and innovation within support structures. Based on the findings, key challenges and improvement proposals are identified that may contribute to greater effectiveness and resilience of the support system.
The research findings indicate that CIS user support within the SAF aligns in many respects with best practices defined by established IT service management frameworks such as ITIL and COBIT. The literature emphasizes the importance of standardized processes for effective incident resolution, workflow optimization, and enhancement of user experience, which is also reflected in the practical operation of SC, LSU, and TSU. As in civilian environments, the main success factors include responsiveness, process transparency, and coordinated operation across all support levels. A distinctive feature of the military environment, however, lies in the additional security requirements and the integration of cyber and cryptographic support, which significantly expand the scope and complexity of support activities. In comparison with the literature, which highlights the central role of ITIL processes in incident and change management, the SAF case confirms that a multi-tier organizational model with clearly defined responsibilities is effective and consistent with international guidelines, while being complemented by domain-specific security protocols and defence standards.
The organizational structure of CIS support within the SAF, based on a multi-tier model comprising the SC, LSU, and TSU, proves effective in ensuring uninterrupted system operation and rapid response to user requests. This structure is consistent with the literature, which highlights the importance of clearly defined roles and responsibilities within support services, as well as the value of a centralized point of contact for incident reporting. The role of SC as a single point of contact corresponds directly to the ITIL Service Desk concept, while LSU and TSU complement the system by providing local expertise and addressing more complex technical issues. The results confirm that users perceive SC as highly responsive and professional, while LSU is regarded as an indispensable component for resolving issues requiring on-site intervention. In comparison with recommendations from the literature that emphasize proactive communication and digital support channels, the findings suggest room for improvement primarily in the adoption of modern digital tools, such as self-service portals and automated incident tracking systems.
The analysis of interviews with CIS users and support stakeholders reveals numerous parallels with findings in the literature regarding the importance of responsiveness, transparent communication, and continuous staff training. Users within the SAF assess the SC as highly responsive and professional, which aligns with research emphasizing that an effective Service Desk constitutes a foundation of user satisfaction and the reduction in operational disruptions. The interviews confirm that SC provides significant added value primarily through clear communication on request status and the resolution of issues at first contact, corresponding to ITIL recommendations on so-called first call resolution. LSUs are recognized as essential for addressing issues that require physical presence; however, users highlight shortcomings in response times, particularly during periods of increased workload. Such findings are consistent with the literature, which indicates that support quality is closely linked to adequate staffing levels, process organization, and the availability of appropriate incident resolution tools. In several interviews, users proposed the establishment of a web-based portal offering self-help guidance and incident status tracking, further confirming the importance of digitalizing support processes—an aspect widely recognized in research as essential for enhancing service efficiency and transparency.
The statistical analysis of operational, cyber, and cryptographic incident handling within the SAF confirms a high level of effectiveness of the support structures, in line with the literature emphasizing the importance of continuous monitoring of performance indicators to ensure high-quality IT services. Data for the 2022–2024 period show that all reported incidents were successfully resolved, demonstrating the stability and reliability of the established processes. During this period, the SC independently handled the largest share of incidents (between 65% and 79% annually), reinforcing the role of a centralized point of contact as one of the core ITIL concepts. The analysis of cyber incidents reveals a pronounced downward trend, declining from 106 incidents in 2022 to 47 in 2024. These patterns are consistent with global trends identified in information security research. In this context, the role of MilCERT is particularly notable, as it complements existing support levels through advanced detection procedures, forensic analysis, and preventive measures. Reports on cryptographic support indicate a stable volume of cryptographic incidents (between 12 and 24 annually), most of which are associated with cyclical key rotation procedures and technical adjustments. Together, these findings confirm that the integration of cyber and cryptographic processes into a unified support framework adheres to the principles of secure and reliable IT service management in demanding environments.
Cybersecurity and cryptographic security within the SAF are inseparably linked to CIS user support, as effective incident management requires coordinated action among the SC, LSU, and TSU in close cooperation with MilCERT and the CSR. The literature emphasizes that integrating cyber defence into IT support structures is essential for timely threat detection and response, a conclusion further supported by MilCERT data for the 2022–2024 period. During this time, the number of cyber incidents gradually declined (from 106 to 47 annually), with malware infections, phishing attempts, and unauthorized access attempts being the most prevalent categories, reflecting global cyber threat trends. Within this framework, MilCERT not only provides operational response capabilities but also conducts proactive activities, including forensic analysis, updates to security policies, and user awareness initiatives addressing cyber risks. Similarly, cryptographic support provided by CSR—through regular key rotations, equipment upgrades, and oversight of cryptographic procedures—makes a substantial contribution to securing communication channels and strengthening the resilience of CIS in the military environment.
Reports on cryptographic support confirm that the CSR is not limited to the replacement and maintenance of cryptographic keys and devices, but functions as a central security component in the protection of communication channels. The information security literature emphasizes that cryptography constitutes a fundamental mechanism for ensuring data confidentiality and integrity, which in the SAF is operationalized through regular updates, technical controls, and support for military activities and exercises. The findings of this study indicate that integrating cyber and cryptographic procedures into a unified support framework is consistent with best practices in security incident management and contributes to increased resilience of CIS against contemporary security threats.
The analysis of the results demonstrates that the CIS user support system of the SAF achieves a high level of responsiveness and operational effectiveness, while also revealing areas with potential for further improvement. User interviews highlight the need to introduce additional digital support channels, such as self-service portals and automated incident status tracking systems. The findings also point to the importance of strengthened coordination between the SC and LSU in the prioritization of requests, which could reduce resolution times for more complex issues. The statistical analysis confirms a high success rate in handling operational, cyber, and cryptographic incidents; however, more proactive trend monitoring and increased preventive activities could further enhance system resilience. In the context of cyber and cryptographic security, the importance of continuous staff training and the regular updating of security policies is emphasized to ensure timely threat detection and impact mitigation. The proposed improvements, supported by the literature, include a higher degree of digitalization, the integration of data analytics for incident prediction, and strengthened interdepartmental collaboration, all of which may contribute to improved performance and sustainability of the support system in the future.
This study contributes to systems-oriented governance theory by demonstrating that governance is not exclusively exercised through hierarchical decision structures, but recursively enacted through operational support processes that stabilize digital infrastructures under conditions of complexity and risk. In this sense, CIS user support functions as a dynamic governance subsystem, where authority allocation, escalation mechanisms, security controls, and feedback analytics interact to produce institutional resilience. Governance thus emerges not only from formal structures but from the patterned coordination of socio-technical processes embedded within everyday operational routines. On this basis, the following section presents the CIS User Support Governance Model as a structured representation of these systemic governance dynamics.

4.1. CIS User Support Governance Model

Based on the analysis of organizational documents, statistical data, and user interviews, a CIS User Support Governance Model for the SAF is proposed, representing an integrated system-level, process-oriented, and security-focused framework (see Figure 2). The model is grounded in the specific requirements of the military environment while simultaneously drawing on IT service management principles articulated in ITIL and COBIT, as well as contemporary ITSM concepts. User support within the SAF is distinctly multi-tiered; accordingly, the model is based on a clear delineation of functions, responsibilities, and processes across individual support levels, while also incorporating the security requirements that are inherent to military information systems.
Figure 2. CIS user support model of the SAF.
The CIS user support model of the SAF comprises the following dimensions:
  • Organizational dimension, which defines the distribution of support levels (SC, LSU, TSU, and ICS), their responsibilities, mutual relationships, and escalation paths that enable effective handling of incidents and service requests.
  • Process dimension, which includes formalized procedures for incident management, service request management, cyber threat handling, cryptographic processes, and other activities that ensure consistent, traceable, and standardized execution of support functions.
  • Security dimension, which integrates organizational, technical, and cryptographic security mechanisms embedded across all support levels, ensuring that CIS operations within the SAF comply with national security requirements and internal security standards characteristic of the military environment.
  • Communication and user dimension, which addresses user experience, communication channels, responsiveness of support structures, and the perceived quality of support. This dimension incorporates the digitalization of support services, automated feedback mechanisms, and transparency of incident status information.
  • Data and analytics dimension, which enables the collection, analysis, and interpretation of data on incidents, trends, and workload distribution. This supports the transition from reactive to proactive management of information services and provides a foundation for strategic capability development planning.
Taken together, these five dimensions are theoretically embedded in established information systems governance and IT service management frameworks. The organizational and data dimensions reflect COBIT’s emphasis on role clarity, accountability, monitoring, and strategic oversight. The process dimension aligns with ITIL’s structured approach to incident and service request management, emphasizing formalization and traceability. The security dimension extends ITSM principles by integrating cybersecurity and cryptographic controls into governance structures characteristic of high-security public organizations. Finally, the communication and user dimension corresponds to governance principles of transparency, responsiveness, and communicative accountability emphasized in public-sector governance literature. Through this theoretical anchoring, the model connects operational support practices with established governance and control frameworks.
While ITIL and COBIT provide structured process guidance and governance control frameworks, the proposed five-dimensional model extends these perspectives by integrating authority allocation, embedded security enforcement, communicative legitimacy, and data-driven oversight into a unified governance construct. Rather than treating service management, security, and governance as partially overlapping domains, the model conceptualizes CIS user support as the operational site where these dimensions converge and are enacted simultaneously. In this sense, the model does not replace established ITSM frameworks but reframes them within a systemic governance perspective tailored to high-security public organizations. This integrative approach highlights how institutional resilience emerges from the coordinated interaction of organizational hierarchy, procedural formalization, security integration, user interface dynamics, and analytics-based feedback mechanisms.
The selection of these five dimensions is based on a combined theoretical and empirical rationale. Conceptually, the dimensions reflect core elements of governance identified in information systems governance and public-sector governance literature, including authority allocation, process formalization, security integration, communicative accountability, and data-driven oversight. Empirically, the dimensions emerged as analytically distinct yet interrelated categories during the qualitative and quantitative analysis of CIS support structures within the SAF. Together, they capture how governance of the CIS layer is enacted across organizational, procedural, security, communicative, and analytical domains. The five-dimensional structure therefore represents a theoretically informed and empirically grounded governance framework rather than an ad hoc classification.
The organizational dimension constitutes the foundation of the model, within which the SC is defined as the primary and central point of contact for all CIS users. Its role encompasses the intake, categorization, logging, and initial resolution of incidents. Empirical data indicate that SC handles between 65% and 79% of all incidents annually, confirming its central position within the support structure. LSUs at individual military installations represent the second level of the system and are responsible for tasks requiring direct physical intervention, equipment configuration, or on-site problem resolution. Despite a generally high level of perceived expertise, the analysis reveals substantial variability in their responsiveness, which underscores the importance of further standardization and staffing reinforcement at this level. Several interviewees explicitly pointed to structural limitations at the local level. For example, one respondent stated that “response times at the LSU level can extend to several days, primarily due to limited staffing and competing operational duties” (Interview 4, LSU level). This variability is captured in the following observation: “The quality of local support strongly depends on individual competencies and motivation, resulting in significant variability across locations” (Interview 15, field unit). TSU, positioned at the third expert level, is responsible for addressing the most complex cases and ensuring overall system stability, while the ICS serves as the final escalation point for systemic or infrastructural issues that exceed the competencies of the SAF.
The model is process-oriented and grounded in formalized procedures for incident management, service request management, problem management, cyber threat handling, and cryptographic processes. The process dimension of the model is informed by and broadly consistent with ITIL guidance for incident management while also incorporating security procedures defined in internal SAF regulations. The analysis for the 2022–2024 period shows that all incidents during this timeframe were resolved with a 100% success rate, reflecting the high effectiveness of the existing processes. From a governance perspective, the consistently high resolution rate indicates a mature and stable process structure in which authority allocation, escalation pathways, and procedural controls function reliably across support levels. Rather than representing a mere operational metric, this performance reflects institutionalized governance mechanisms that strengthen organizational resilience and reduce systemic vulnerability to disruption. A distinct role within the model is assigned to MilCERT and CSR, which operate as specialized functional support elements responsible for handling cyber and cryptographic incidents. Multi-year data indicate a declining trend in cyber incidents, confirming the effectiveness of preventive security mechanisms and user awareness activities. This trend also reflects adaptive governance capacity, as preventive measures and security integration appear to translate into measurable reductions in incident frequency over time. Similarly, the volume of cryptographic incidents remains stable and is primarily associated with routine key rotation procedures and maintenance activities.
The security dimension of the model is grounded in the fact that CIS in a military environment represents not merely an operational infrastructure but a core component of defence operations, where data confidentiality, integrity, and availability constitute critical elements of national security. Accordingly, the model incorporates organizational, technical, and cryptographic security as integral components of user support. Security mechanisms are not treated as a separate subsystem but as a horizontal function permeating all support levels—from initial incident handling at the SC to complex interventions performed by technical support units or the Ministry of Defence Information and Communications Service. Through this approach, the model embeds security standards within operational support processes, reflecting the heightened importance of security–process coherence in military environments.
An important component of the model is the communication and user dimension, which focuses on user perceptions and the quality of user experience. Interviews with users confirm that the SC is perceived as highly responsive, professional, and reliable, whereas satisfaction with LSU is strongly influenced by staffing levels and the actual availability of personnel at individual units. This perception is reflected in interview statements such as: “The SC resolves standard incidents within minutes and more complex cases within the same working day. Communication is professional and users are regularly informed about escalation steps” (Interview 7, SC level). Nevertheless, some limitations were identified in specific operational contexts. As one respondent noted, “During remote work or mission deployment, the SC contact number is not always accessible, and the automated system provides no indication of waiting times” (Interview 12, operational unit). Accordingly, the model places particular emphasis on improving information flow, establishing standardized communication protocols, and digitalizing support services. This includes capabilities for incident status tracking, automated feedback mechanisms, and centralized request management. Such an arrangement complements the process dimension of the model and makes a significant contribution to the development of a positive user experience, which is of substantial importance for system operation in the military environment.
The data and analytics dimension of the model enhances its operational value. By analysing incident patterns, root causes, and temporal trends, the model enables a transition from reactive to proactive management of information services. The integration of data from the SC, local support units, technical support, MilCERT, and CSR facilitates the identification of recurring issues, priority setting, and optimization of available resources. Such an analytical foundation supports strategic planning for the development of information capabilities and contributes to the long-term strengthening of the resilience of the SAF information environment.
The CIS user support model of the SAF can therefore be defined as an integrated, multi-tier, and security-oriented architecture that combines organizational structures, formalized processes, security mechanisms, user experience considerations, data analytics, and coordination structures. It represents a conceptual framework grounded in empirical evidence while extending beyond the existing arrangement through proposals for digitalization, process integration, and increased staffing capacity, particularly at the level of local support units. The model provides a clear structure for further improvement and serves as a foundation for the standardization of support services, enhanced operational reliability, and strengthened resilience of the communication and information system of the SAF.
To provide a structured overview of the theoretical and empirical foundations of the CIS User Support Governance Model, Table 5 summarizes the linkage between each dimension, its theoretical anchoring in established governance and IT service management frameworks, the key empirical findings derived from the SAF case study, and its broader governance implications. This overview demonstrates that the five-dimensional structure is not merely descriptive but conceptually grounded and empirically substantiated. By explicitly connecting theory, empirical evidence, and governance functions, the table clarifies how CIS user support operates as an institutional mechanism of governance in a high-security public organization.
Table 5. Theoretical and empirical anchoring of the CIS user support governance model.
While the model presented above is empirically grounded in the organizational and operational realities of the SAF, its analytical relevance extends beyond the specific institutional context. In the following section, the model is interpreted as a governance construct, highlighting its theoretical implications for information systems governance and digital government research.

4.2. Reconceptualising CIS User Support as a Governance Construct

The CIS user support model presented in the previous section was developed on the basis of empirical evidence from a high-security public organization. This section makes explicit the governance contribution that emerges from these empirical findings. Although grounded in a specific institutional setting, the model has broader analytical relevance. This section reconceptualises CIS user support as a governance construct, shifting the analytical focus from service provision toward the mechanisms through which authority, control, security, and organizational resilience are enacted in digital environments. This reconceptualization is derived directly from the empirical findings presented above, including incident statistics, interview data, and organizational analysis.
The findings of this study converge around a central analytical argument: CIS user support operates as a governance mechanism through which authority allocation, procedural control, security enforcement, and organizational learning are institutionalized in everyday digital operations. Rather than representing isolated operational practices, the empirical results demonstrate a structured governance logic embedded across organizational, process, security, communicative, and analytical dimensions.
To avoid terminological ambiguity, it is useful to distinguish three related but analytically distinct notions used throughout this section. The term support structure refers to the formal organizational arrangement of roles and levels (SC, LSU, TSU, and ICS) and their defined responsibilities. The term governance mechanism denotes the functional enactment of authority, escalation, procedural control, and security enforcement through routine support workflows. Finally, the term governance subsystem captures the integrated socio-technical configuration in which organizational arrangements, formalized processes, embedded security controls, communication practices, and incident analytics interact to reproduce governance effects over time. While closely related, these concepts operate at different analytical levels and are used accordingly in the discussion that follows.
Although the proposed model is informed by established IT service management frameworks such as ITIL and COBIT, it does not represent a direct replication of these structures. The military context of the SAF introduces governance constraints and operational imperatives that diverge from standard civilian ITSM configurations. Hierarchical command authority, classified information handling, the integration of cyber defence and cryptographic control functions, and the requirement for continuous operational readiness necessitate adaptations that extend beyond conventional ITSM implementations. The model therefore reflects a context-specific reinterpretation of ITSM principles, shaped by national security considerations and institutional command structures.
In much of the information systems and digital government literature, user support is implicitly treated as an auxiliary or operational layer whose primary purpose is to ensure technical continuity and user assistance. Such a framing positions support activities as subordinate to “core” governance concerns, such as policy formulation, system architecture, or cybersecurity strategy. This perspective underestimates the extent to which user support functions actively shape how digital infrastructures are governed in practice. The empirical findings of this study indicate that user support constitutes a central mechanism through which organizations manage system failures, enforce rules, and translate formal governance principles into everyday operational reality.
From this perspective, CIS user support should be understood not merely as a technical service but as an institutional arrangement that structures how organizations respond to uncertainty, disruption, and risk. Support processes determine who is authorised to intervene in digital systems, how incidents are interpreted and prioritised, and which failures are treated as routine operational issues versus security-relevant events. In doing so, user support performs a governance function by operationalising control over digital infrastructures and by mediating the relationship between users and formal authority structures.

4.2.1. From Operational Support to Governance Mechanism

Reframing user support as a governance mechanism requires moving beyond a functional understanding of support activities and recognising their role in shaping organisational power relations and decision-making processes. Incidents, service requests, and security events are not neutral technical occurrences; they are socially and institutionally constructed through support procedures that define categories, escalation paths, and acceptable responses. Through these procedures, organisations determine which disruptions require immediate intervention, which can be deferred, and which trigger higher-level authority involvement.
The empirical results demonstrate that the centralisation of incident intake and categorisation creates a structured decision environment in which system disturbances become governable phenomena. This is empirically illustrated by the fact that between 65% and 79% of all incidents were resolved at the SC level during 2022–2024 (see Table 2), confirming the centralization of intake and first-level governance control. By transforming failures into logged, classified, and traceable events, user support enables organisations to exercise control over uncertainty. This transformation represents a core governance function: it converts potentially destabilising events into manageable objects of organisational action.
Furthermore, user support structures allocate authority over digital systems in ways that are often invisible but institutionally consequential. Multi-tier support arrangements define who has the right to modify configurations, restore services, or escalate incidents to security authorities. These decision rights are not merely technical competencies; they reflect governance choices about responsibility, accountability, and risk tolerance. In this sense, user support operates as a practical instantiation of governance, embedding abstract principles of control and oversight into routine operational workflows.
While overall perceptions of CIS user support were predominantly positive, notable differences emerged across organizational levels. Personnel at the SC emphasized procedural consistency and rapid incident intake, whereas end users placed greater importance on responsiveness and communication clarity. At the LSU level, perceptions were more heterogeneous and often linked to local staffing constraints and operational workload. These divergences indicate that governance effectiveness is experienced differently depending on positional context within the support hierarchy. These differentiated perceptions are consistent with the interview data (Interviews 4, 12, 15), indicating that governance effectiveness is experienced unevenly across support levels.

4.2.2. Governance Logic of the Multi-Dimensional Support Model

Interpreted as a governance construct, the five dimensions of the CIS user support model represent complementary mechanisms through which organisational control over digital infrastructures is exercised.
The organisational dimension captures the allocation of authority and responsibility across support levels. Rather than serving solely as a coordination structure, the support hierarchy institutionalises escalation rights and decision thresholds. It determines when incidents remain local, when they require specialised intervention, and when they become matters of strategic or security concern. This distribution of authority directly affects organisational responsiveness and shapes how risks are absorbed or amplified within the system.
The process dimension embodies governance through formalised control mechanisms. Standardised procedures for incident and request handling translate organisational norms into repeatable practices, ensuring consistency, traceability, and accountability. The 100% incident resolution rate across three consecutive years (see Table 1) further indicates the procedural stability and maturity of these governance mechanisms. In this context, “resolution” denotes full technical remediation in accordance with established procedures; incidents were not administratively closed without corrective action, nor carried over unresolved into subsequent reporting periods. The reported resolution rate therefore reflects the organization’s capacity to technically address and complete all recorded incidents within the observed timeframe. By embedding decision rules into processes, organisations reduce discretionary variation and render system management auditable. From a governance perspective, processes thus function as instruments that stabilise expectations and align individual actions with institutional objectives.
The security dimension represents the enforcement of security policy through everyday operational practices. Cybersecurity and cryptographic controls are not confined to strategic planning or technical architecture; they are continuously enacted through support interactions, access decisions, and incident responses. Integrating security into user support ensures that security governance is not episodic but persistent, operating across routine and exceptional situations alike. This interpretation is supported by the longitudinal decline in MilCERT incidents (see Table 3), suggesting adaptive capacity within embedded security-support coordination. This horizontal integration is particularly significant in high-security environments, where the boundary between operational incidents and security threats is inherently fluid.
The communication and user dimension constitutes the interface between governance structures and system users. Through responsiveness, transparency, and clarity of communication, support mechanisms shape user perceptions of legitimacy and authority. Effective communication fosters compliance with procedures and security requirements, while deficiencies in support interactions can undermine trust and encourage informal workarounds. In this sense, user support performs a legitimising function by making governance visible and intelligible to users in their daily interactions with digital systems.
Finally, the data and analytics dimension enables governance through measurement and learning. By quantifying incidents, response times, and escalation patterns, organisations create visibility into system behaviour and support performance. This visibility supports anticipatory governance by enabling trend analysis, capacity planning, and proactive risk mitigation. Data thus become a governance resource, allowing organisations to adapt support structures in response to evolving operational and security conditions.
Taken together, the empirical findings support three core propositions. First, the multi-tier structure institutionalizes authority and escalation control, transforming technical support into a governance architecture. Second, standardized processes and consistently high-resolution rates reflect procedural maturity and stable control mechanisms. Third, longitudinal cyber and cryptographic data demonstrate adaptive capacity and resilience embedded within support structures. These elements collectively substantiate the conceptualization of CIS user support as a governance construct rather than a purely operational service function.
These dimensions collectively demonstrate that CIS user support operates as an embedded governance mechanism rather than a peripheral technical service. Governance is enacted at the operational core of digital infrastructures through coordinated authority allocation, procedural control, security enforcement, communicative legitimacy, and analytical oversight.
The governance interpretation developed in this section synthesizes the empirical evidence and demonstrates that the reconceptualization emerges from observed operational patterns rather than abstract theorizing. The model therefore contributes theoretically by conceptualizing governance not as a hierarchically imposed control structure, but as an operationally enacted mechanism embedded within routine support workflows. Rather than locating governance exclusively at strategic or supervisory levels, the findings demonstrate how authority allocation, escalation dynamics, and security enforcement are continuously reproduced through everyday incident management practices. In this sense, governance emerges as a recursive and adaptive process within a socio-technical support subsystem, reinforcing institutional resilience through structured feedback and multi-level interaction.
From a systems-thinking perspective, the CIS user support model can be interpreted as a dynamic governance subsystem embedded within a broader digital infrastructure. The interaction between organizational hierarchy, procedural rules, security controls, and incident analytics generates feedback loops that continuously adjust escalation patterns, authority allocation, and preventive measures. These interdependencies illustrate how localized support actions influence system-wide stability, demonstrating that resilience is not a static property but an emergent outcome of structured adaptive coordination across multiple levels of the organization.
At the same time, the interpretation of these findings must account for contextual constraints specific to high-security military environments. The strong alignment observed between structured escalation procedures, full incident resolution, and embedded security coordination may depend on centralized authority, clearly defined hierarchical accountability, and institutional coherence. In more decentralized or resource-fragmented settings, similar governance architectures may yield different operational outcomes. The present case therefore illustrates how IT service management principles can be institutionally embedded under specific structural conditions rather than demonstrating their unconditional effectiveness across organizational contexts.

4.2.3. Theoretical Implications

The findings of this study contribute to IT service management scholarship by extending its analytical focus beyond operational efficiency toward governance enactment. While ITSM frameworks such as ITIL and COBIT traditionally emphasize process standardization and service performance, this study demonstrates that user support structures also institutionalize authority allocation, escalation control, and embedded security enforcement.
By conceptualizing user support as an interconnected governance subsystem characterized by feedback mechanisms and adaptive escalation structures, the study aligns with systems-oriented perspectives that emphasize relational interdependencies and emergent organizational stability.
For information systems governance research, the study provides empirical evidence that governance mechanisms are not confined to formal oversight bodies or strategic decision-making layers but are enacted through routine operational workflows. Incident categorization, escalation procedures, and distributed decision rights function as practical governance instruments within digital infrastructures.
Within digital government scholarship, the study redirects attention from citizen-facing platforms toward internal digital infrastructures that sustain institutional capacity. By conceptualizing CIS user support as a measurable governance layer, the article highlights how internal support systems shape organizational resilience, reliability, and operational continuity in high-security public organizations.

4.2.4. Practical Implications

The findings of this study offer concrete guidance for governance design in high-security public organizations. First, user support structures should be explicitly recognized as governance instruments rather than solely operational service units. Clear allocation of escalation rights, documented decision thresholds, and formalized coordination between technical, cyber, and cryptographic functions strengthen institutional control over digital infrastructures.
Second, the integration of security mechanisms within routine support workflows—rather than treating cybersecurity as a parallel structure—enhances coherence between operational continuity and security enforcement.
Third, systematic incident analytics should be embedded into governance processes to enable proactive risk identification, capacity planning, and resilience enhancement.
For small-state or resource-constrained environments in particular, a multi-tier support architecture with centralized intake and structured escalation provides an effective model for balancing operational efficiency with security requirements.

4.3. Challenges of Implementing ITIL in Military CIS Support

Although frameworks such as ITIL are widely adopted in civilian organizations, their direct implementation in military environments presents significant challenges. Civilian IT service management models are primarily designed for market-oriented organizations, where service availability, customer satisfaction, and cost efficiency are dominant priorities. In contrast, military CISs operate within a fundamentally different context, characterized by strict hierarchical command structures, heightened security requirements, classified information handling, and the need for continuous operational readiness under both peacetime and crisis conditions.
One of the main challenges in applying ITIL within a military setting lies in the mismatch between the flexible, customer-centric logic of civilian service management and the rule-based, authority-driven nature of military organizations. Standard ITIL concepts such as service ownership, change management, or user self-service must be carefully adapted to ensure compliance with military regulations, security policies, and command-and-control procedures. As a result, a literal transfer of ITIL processes is neither feasible nor desirable in defence environments.
The findings of this study demonstrate that the SAF has addressed this challenge by selectively integrating ITIL principles into an internally regulated and security-oriented support framework. Core ITIL concepts—such as a centralized Service Desk, structured incident management, and multi-level escalation—are preserved, while their implementation is modified to align with military operational requirements. User support processes are embedded within formal directives, clearly defined roles, and security controls, ensuring both procedural consistency and compliance with defence-specific standards.
This adaptive approach illustrates how a civilian IT service management framework can be translated into a military context without compromising operational security or command authority. Rather than treating ITIL as a prescriptive model, it is applied as a guiding reference that informs process design while allowing necessary deviations dictated by the military environment. The resulting support system represents a hybrid model that bridges civilian ITSM best practices and military operational realities, offering a practical pathway for other armed forces seeking to modernize CIS user support without undermining core defence principles.

4.4. Implications for Small-State Military Organizations

Although empirically grounded in a military setting, the CIS user support model developed in this study is not exclusively applicable to armed forces. The underlying governance principles—multi-tier coordination, formalized escalation mechanisms, integration of security incident handling, and data-informed process oversight—are transferable to a broader range of high-security public-sector organizations. These include law enforcement agencies, civil protection and emergency management services, operators of critical national infrastructure, and other public institutions responsible for ensuring the continuity of essential public services under conditions of heightened risk and limited resources.
In such contexts, user support functions play a comparable role in sustaining operational reliability, enforcing information security and accountability mechanisms, and mitigating the risk of institutional disruption. The SAF case thus illustrates how civilian IT service management frameworks can be translated into governance-oriented support models suitable for security-sensitive public organizations, offering a reference point for small states seeking to strengthen digital resilience and state capacity beyond the military domain.
From an analytical perspective, small-state military organizations represent environments in which governance mechanisms are exposed with particular clarity. Limited resources, reduced redundancy, and tight coupling between information systems and operational functions mean that support failures translate rapidly into institutional risk. Under such conditions, user support cannot remain a background technical service but becomes a central mechanism through which continuity, authority, and security are sustained. The small-state context therefore does not merely constrain governance arrangements but instead reveals their structural significance for understanding governance in digitally mediated public organizations.
From a digital government perspective, these findings suggest that internal user support structures constitute a critical yet frequently overlooked layer of governance in digitally mediated public organizations. Rather than functioning as auxiliary technical services, such structures shape how governments govern through information systems rather than merely deploy them. The analysis demonstrates that studying user support in small-state, high-security contexts makes these governance mechanisms particularly visible, thereby offering insights that are applicable beyond the military domain. In this sense, CIS user support emerges as a foundational component of state capacity and digital resilience, shaping how governments govern through information systems rather than merely deploy them.

4.5. Linking CIS User Support to Digital Government and Public-Sector Governance Literature

While the analytical framework of this study is grounded primarily in IT service management and cybersecurity literature, the findings can also be meaningfully interpreted through the lens of digital government and public-sector governance. Digital government scholarship emphasizes that the reliability, resilience, and responsiveness of internal information systems are not merely technical concerns, but fundamental components of state capacity and institutional performance in the digital era [36,37].
From a digital-era governance perspective, effective CIS user support represents an enabling infrastructure that allows public organizations to operate with speed, coordination, and continuity under conditions of complexity and uncertainty. Dunleavy et al. [36] argue that digital-era governance replaces fragmented, silo-based arrangements with integrated, process-oriented systems that prioritize user needs and operational coherence. The multi-tier CIS support model observed in the SAF aligns with this logic by centralizing incident intake through a single service desk while preserving specialized capabilities at local, technical, cyber, and cryptographic levels. Such an arrangement supports both efficiency and control, which are essential characteristics of public-sector organizations operating in security-sensitive environments.
Recent digital government research further highlights the importance of adaptive governance and institutional resilience in responding to rapidly evolving technological and security challenges [38]. Adaptive governance emphasizes the need to balance stability, accountability, and hierarchical control with decentralized problem-solving and rapid operational response. The CIS support structures within the SAF reflect this balancing act: while strategic oversight, security policies, and escalation paths remain centralized, operational incident handling is distributed across multiple support levels, enabling timely responses without undermining organizational accountability.
In addition, digital-state literature conceptualizes internal digital infrastructures as core elements of state capacity rather than as auxiliary technical systems [37]. From this perspective, CIS user support functions contribute directly to the ability of public institutions to deliver services, maintain continuity of operations, and manage risks. The empirical findings of this study—particularly the sustained 100% incident resolution rate and the declining trend in cyber incidents—suggest that robust internal support mechanisms can strengthen institutional resilience even in small-state contexts with limited resources.
Finally, public-sector digital transformation research emphasizes that governance challenges often arise not from technological limitations, but from coordination problems, institutional rigidity, and insufficient integration between technical and organizational domains [39]. The SAF case demonstrates that aligning IT service management processes with security governance, formal command structures, and user support practices can mitigate these challenges. In this sense, CIS user support should be understood as part of the broader digital government architecture that enables public organizations to adapt, learn, and maintain operational reliability under conditions of persistent cyber risk.
Taken together, these perspectives position CIS user support not only as an operational IT function but as a governance mechanism that underpins digital resilience, institutional adaptability, and state capacity in the digital era. This interpretation strengthens the relevance of the present study for digital government research and highlights the importance of internal support structures as foundational components of modern public-sector governance.

4.6. CIS User Support as a Component of Digital Government and Public-Sector Governance

CIS user support in a military environment should not be understood solely as a technical or operational function, but as an integral component of digital government and public-sector governance. In the context of the SAF, CISs constitute a critical element of state capacity, enabling command and control, decision-making, and the execution of legally mandated public functions across the defence sector. As such, the effectiveness of CIS user support directly influences the reliability of government information flows, institutional accountability, and the operational resilience of public institutions.
Unlike civilian service environments, where IT service management is primarily driven by market logic, user satisfaction, and cost efficiency, military CIS support operates within a dense framework of public policies, legal constraints, and security regulations. Support processes are shaped by national defence legislation, information security policies, classification regimes, and internal governance mechanisms that define roles, responsibilities, and escalation paths. Consequently, CIS user support represents a governance mechanism through which state information and security policies are operationalized and enforced in practice, ensuring that digital services remain available, secure, and compliant with public-sector mandates.
The findings of this study demonstrate that structured user support systems can function as instruments of public-sector coordination and control rather than merely technical service providers. The centralized Service Desk, multi-level escalation structure, and integration of cyber and cryptographic incident handling illustrate how operational support processes contribute to maintaining institutional coherence across geographically dispersed units. This aligns with digital government literature that emphasizes the role of information systems not only as service delivery platforms, but also as tools for managing complexity, risk, and inter-organizational dependencies within the public sector.
From a governance perspective, the SAF case highlights how digital support infrastructures can reconcile competing public-sector values. While transparency, user autonomy, and openness are often central to digital government initiatives, military environments necessarily prioritize security, hierarchy, and controlled information access. The CIS user support model demonstrates that accountability and reliability can still be achieved under such constraints through process formalization, traceability of incidents, and clearly defined decision authority. In this sense, the model extends digital government research by illustrating how governance mechanisms adapt in high-security public organizations where conventional notions of openness must be balanced against national security imperatives.
For policymakers and public-sector managers, these findings suggest that investments in governance-oriented process design may yield greater resilience than purely technological upgrades. The SAF experience indicates that clearly defined support structures, integrated security functions, and data-informed coordination mechanisms can enhance the robustness of government information infrastructures, particularly in small-state contexts with limited resources. As digital government initiatives increasingly intersect with national security, critical infrastructure protection, and cyber resilience, CIS user support should be recognized as a strategic governance capability rather than a background technical service.
From a public-sector governance perspective, CIS user support also carries a distinct public value dimension. Reliable and responsive support structures reduce the risk of institutional disruption by ensuring continuity of core information services under routine and crisis conditions. In this sense, CIS user support contributes directly to the reliability of state operations and the sustained delivery of public functions, even though it remains largely invisible to external actors and oversight bodies. By enabling traceability of incidents, accountability of responsibilities, and predictable recovery mechanisms, user support systems function as a form of “hidden infrastructure of public trust,” reinforcing confidence in the state’s capacity to operate securely, reliably, and effectively in the digital era. This perspective aligns with digital government research that emphasizes continuity, reliability, and institutional resilience as foundational elements of public value creation in high-security public organizations.

4.7. Responses to the Research Questions

This section presents synthesized responses to the research questions formulated in the study, drawing on the literature review, the analysis of the organizational structure of CIS support within the SAF, the conducted interviews, and the statistical examination of operational, cyber, and cryptographic incidents. The purpose of this section is to clarify how the existing support system operates in practice, the extent to which it aligns with IT service management best practices, and which improvements appear necessary to enhance its effectiveness and resilience.
The first research question examines how governance of the CIS layer is operationalized through user support structures within the SAF. The analysis shows that governance is enacted through a multi-tier support model comprising the SC as the central point for incident intake and categorization, LSU responsible for on-site interventions and direct user assistance, and TSU dedicated to resolving system-level and technologically complex issues. This structured allocation of roles and escalation paths institutionalizes decision authority, process accountability, and traceable incident management across organizational levels. The integration of MilCERT and the CSR further embeds cyber and cryptographic control functions within the support architecture, extending governance mechanisms into security-sensitive domains that are particularly critical in the military context.
The second research question examines the extent to which support processes follow IT service management best practices, such as ITIL, COBIT, and related methodological frameworks. The results indicate that the design of the support system is largely aligned with standardized service management guidelines. The SC structure closely corresponds to the ITIL Service Desk function; incident management processes are formalized and traceable; the role of technical support aligns with second- and third-level incident resolution concepts; and organizational documents clearly define the responsibilities of system and process owners. Despite this alignment, the analysis also identifies opportunities for further enhancement, particularly in the digitalization of user interfaces, automation of routine procedures, and the incorporation of more advanced trend-monitoring mechanisms. These improvements would further align the system with contemporary ITSM practices highlighted in the literature.
The third research question focuses on the effectiveness of support in handling operational, cyber, and cryptographic incidents. Statistical data demonstrate an exceptionally high level of effectiveness, with a 100% incident resolution rate recorded for the 2022–2024 period, while the SC independently resolves the largest proportion of all reported incidents. MilCERT data show a pronounced downward trend in the number of cyber incidents, indicating improvements in preventive measures, user behaviour, and the responsiveness of defensive structures. The cryptographic support system exhibits similar stability, with incidents typically being technical in nature and resolved within prescribed timeframes. Taken together, these findings indicate that the overall support mechanism is robust, responsive, and capable of addressing diverse incident types, reflecting a high level of process maturity.
The fourth research question explores user satisfaction and perceptions of the quality and responsiveness of support structures. Interview findings indicate very positive evaluations of the SC, which users describe as professional, responsive, and clear in communication. Assessments of LSU are more heterogeneous, with effectiveness strongly influenced by staffing levels, workload, and work organization at individual units. Users most frequently emphasize the need for improved availability of local support, more consistent communication, and digital access to request status information. For system-critical applications such as ISDH, there is a clear demand for the establishment of formalized support, as users currently rely on informal, personal assistance channels. Overall, user perceptions indicate high satisfaction at the first support level and considerable variability at the second, suggesting that while the system is effective, it is not yet optimally balanced across all segments.
The fifth research question addresses improvement measures that could enhance the resilience and reliability of the support system in a military environment. The analysis identifies several key development directions: process digitalization through the introduction of self-service and incident-tracking portals; automation of routine procedures; improved coordination among support levels; strengthening of staffing capacities within local support units; enhanced integration of processes between CIS SAF and the MOD ICS; and the establishment of clearer mechanisms for process alignment. In addition, the need for regular training, user awareness activities, and proactive monitoring of security trends is highlighted as a significant factor. Collectively, these measures would bring the support system closer to contemporary IT service management practices and strengthen its resilience against cyber, organizational, and technological challenges characteristic of the military environment.

4.8. Limitations of the Study

Despite its comprehensive approach, this study is subject to several limitations that affect the broader generalizability of its findings. The first limitation concerns the restricted interview sample, which is based exclusively on the experiences of users and support personnel within the SAF. Although the collected data are rich and multi-layered, the results do not necessarily reflect conditions in other organizational contexts or allied military structures, where CIS support processes may be organized differently.
The second limitation relates to the temporal scope of the study, which covers a three-year period from 2022 to 2024. While this timeframe provides a relevant insight into the functioning of the support system, a longer observation period could reveal additional annual or seasonal patterns in the volume and nature of incidents that are not captured within this analysis.
A third limitation is associated with the availability of data on cyber and cryptographic incidents. For security reasons, these data are partially anonymized or aggregated, which restricts the possibility of more detailed qualitative analyses of attack vectors, root causes, and behavioural patterns. In addition, the study does not directly assess the financial or operational impact of these incidents on the organization as a whole, which could further illuminate the effectiveness of the existing support structures.
The fourth limitation concerns the limited access to comparable data from other countries or international military environments, which complicates benchmarking against best practices in a broader context. Although the study references standards such as ITIL and COBIT, it primarily focuses on internal processes and places less emphasis on cross-organizational learning and external benchmarking.
Finally, the study does not include a detailed analysis of the impact of digital transformation, automation, and advanced analytical tools on improvements in user support, despite these factors being identified in the literature as significant trends. This limitation opens avenues for future research that could examine the integration of artificial intelligence, advanced cyber defence mechanisms, and the development of new service optimization models applicable to both military and civilian environments.
The findings should therefore be interpreted through analytical rather than statistical generalization. While the institutional configuration of the SAF is context-specific, the structural mechanisms identified in this study—such as multi-tier escalation logic, embedded security coordination, and feedback-based incident analytics—may be transferable to other complex digital infrastructures where similar governance characteristics exist. Transferability depends on the degree of alignment with hierarchical authority structures, centralized coordination, and resource capacity. The model is thus presented as structurally informative rather than institutionally prescriptive.

5. Conclusions

This study examined the governance and effectiveness of CIS user support within the SAF as a high-security, small-state public organization. The empirical findings demonstrate that the multi-tier CIS user support arrangement provides a high level of operational responsiveness and reliability. Incident data for the period 2022–2024 indicate consistent and effective resolution performance, supported by clearly defined responsibilities, structured escalation mechanisms, and coordinated interaction between the SC, LSU, and technical support structures. The integration of specialized cyber and cryptographic functions, including MilCERT and the Cryptographic Sub-Registry, further strengthens system resilience and contributes to the secure operation of the communication and information environment.
Qualitative findings from structured user interviews complement the quantitative results by highlighting the perceived legitimacy and effectiveness of the support structures. Users consistently emphasized responsiveness, professionalism, and clarity of communication as key strengths of the system, while also identifying areas requiring further development. These include deeper digitalization of support processes, improved cross-level coordination, expanded self-service capabilities, and strengthened staffing at the local level. While existing support processes are largely aligned with established IT service management frameworks such as ITIL and COBIT, the findings also point to opportunities for further optimization through greater use of automation, advanced analytics, and integrated incident management.
A central contribution of this study is the development and interpretation of a five-dimensional CIS user support governance model encompassing organizational authority, process control, security integration, user communication, and data analytics. Rather than serving solely as an operational improvement tool, the model provides an analytical framework for understanding how governance is enacted through everyday support practices in security-sensitive information environments. It illustrates how user support functions operate as a core layer of organizational information infrastructure, shaping reliability, accountability, and resilience across digital systems.
From a practical perspective, the findings offer an empirically grounded basis for the continued modernization of CIS user support within the defence sector. The identified measures—process digitalization, integration of data-driven management, enhanced communication mechanisms, and reinforcement of local support capacities—provide concrete guidance for strengthening operational continuity and long-term resilience. At the same time, the model is transferable to other high-security public-sector organizations facing similar constraints related to limited resources, elevated security requirements, and critical service dependencies.
Beyond its operational implications, this study contributes to digital government and public-sector governance research by demonstrating that internal CIS user support constitutes a critical, though often overlooked, component of state capacity. The findings show that effective user support enables continuity of public services, reinforces accountability in information processing, and reduces institutional vulnerability under both routine and crisis conditions. In high-security environments, user support functions as a form of hidden governance infrastructure, sustaining public trust by ensuring that digital systems remain reliable even when their operation is largely invisible to external stakeholders. In this sense, CIS user support contributes to public value creation by safeguarding the stability and reliability of government information services that underpin the functioning of an information polity.
Future research could extend this analysis by examining longer time horizons, comparing governance dynamics across support levels, or exploring cross-organizational patterns in allied or civilian high-security contexts. Particularly promising avenues include the study of artificial intelligence-enabled incident detection, automated response mechanisms, and advanced cyber defence capabilities as emerging components of governance-oriented user support. Such research would further clarify how governance-oriented user support mediates between internal digital infrastructures and state capacity by shaping resilience, adaptability, and operational continuity in increasingly complex and contested digital environments.
Taken together, these findings suggest that internal user support infrastructures deserve greater theoretical and empirical attention within digital government research. Although they remain largely invisible in public discourse, they constitute an operationally decisive layer of governance that underpins the continuity, reliability, and legitimacy of contemporary public-sector organizations.
By foregrounding internal user support as a governance mechanism, this study invites digital government research to look beyond visible platforms and citizen-facing services and to engage more systematically with the infrastructural foundations through which state capacity, resilience, and operational continuity are enacted in digitally mediated public organizations.

Funding

This research received no external funding.

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the author.

Conflicts of Interest

The author declares no conflicts of interest.

Abbreviations

C2Command and Control
CISCommunication and Information Systems
COBITControl Objectives for Information and Related Technologies
CSRCryptographic Sub-Registry
ICSInformation and Communications Service—SIK
ISDHInformation System for Document Handling
ITInformation Technology
ITILInformation Technology Infrastructure Library
ITSM IT Service Management
IVRInteractive Voice Response
LSULocal Support Units
MilCERTMilitary Computer Emergency Response Team
MODMinister of Defence
NSMCNetwork and Systems Monitoring Centre—NC
SAFSlovenian Armed Forces
SCService Centre
TSUTechnical Support Units

References

  1. Marrone, M.; Gacenga, F.; Cater-Steel, A.; Kolbe, L. IT service management: A cross-national study of ITIL adoption. Commun. Assoc. Inf. Syst. 2014, 34, 49. [Google Scholar] [CrossRef] [Scilit]
  2. Woo, H.; Jeong, S.J.; Huh, J.H. Improvement of ITSM IT service efficiency in military electronic service. J. Inf. Process. Syst. 2020, 16, 246–260. [Google Scholar] [CrossRef]
  3. Bogdański, A. Good practices in military cybersecurity training. Eduk. Anal. Transakcyjna 2024, 13, 455–469. [Google Scholar] [CrossRef] [Scilit]
  4. Žvanut, B.; Burnik, M.; Kolnik, T.Š.; Pucer, P. The applicability of COBIT processes representation structure for quality improvement in healthcare: A Delphi study. Int. J. Qual. Health Care 2020, 32, 577–584. [Google Scholar] [CrossRef] [Scilit]
  5. Cronholm, S.; Göbel, H.; Åkesson, M. ITIL compliance with service-dominant logic. E-Serv. J. 2020, 11, 74. [Google Scholar] [CrossRef] [Scilit]
  6. Mohammed, T.A. Critical success factors for information technology infrastructure library implementation in public service organizations: An exploratory study. Int. J. Adv. Inf. Technol. 2018, 8, 01–19. [Google Scholar] [CrossRef] [Scilit]
  7. Berntsen, K.R. The use of ITIL and its effect on organizational culture—Bringing the employee perspective to the scene. Ostfold Univ. Coll. 2017. Available online: https://api.semanticscholar.org/CorpusID:158060531 (accessed on 26 July 2025).
  8. Malleswara, T.; Raul, V. An Implementation of ITIL Guidelines for IT Support Process in a Service Organization. Int. J. Inf. Electron. Eng. 2013, 3, 334–340. [Google Scholar]
  9. Weaver, R.V., III. Leveraging ITIL to Govern AOC Information Technology. Ph.D. Thesis, Air Force Institute of Technology, Wright-Patterson AFB, OH, USA, 2005. [Google Scholar]
  10. Salcedo, R. Implementation of the ITIL Framework as an Information Technology Tool for Cadet Training in the Telematics Department of the Peruvian Air Force Officers School. Professional Thesis, Escuela de Oficiales de la Fuerza Aérea del Perú, Lima, Peru, 2021. [Google Scholar]
  11. TG. HELP DESK: Scaling Down to Keep Up. ASEE Prism. 2006, 15, 16. [Google Scholar]
  12. Bulchand-Gidumal, J.; Melian-Gonzalez, S. Redesign of the IS/ICT Help Desk at a Spanish Public University. High. Educ. 2010, 60, 205–216. [Google Scholar] [CrossRef] [Scilit]
  13. Blackwell, C.A. A Good Installation Guide Increases User Satisfaction and Reduces Support Costs. Tech. Commun. 1995, 42, 56–60. [Google Scholar]
  14. Lin, F.; Guan, L.; Fang, W. Critical Factors Affecting the Evaluation of Information Control Systems with the COBIT Framework: A Study of CPA Firms in Taiwan. Emerg. Mark. Financ. Trade 2010, 46, 42–55. [Google Scholar] [CrossRef] [Scilit]
  15. Bapna, R.; Langer, N.; Mehra, A.; Gopal, R.; Gupta, A. Human capital investments and employee performance: An analysis of IT services industry. Manag. Sci. 2013, 59, 641–658. [Google Scholar] [CrossRef] [Scilit]
  16. Sykes, T.A. Support Structures and Their Impacts on Employee Outcomes: A Longitudinal Field Study of an Enterprise System Implementation. MIS Q. 2015, 39, 473–496. [Google Scholar] [CrossRef] [Scilit]
  17. Polzin, F.R. Exploring the Data Analytics Strategies Information Technology Service Managers Need to Improve Knowledge Management Practices. Ph.D. Thesis, Colorado Technical University, Colorado Springs, CO, USA, 2019. [Google Scholar]
  18. Bhagwatwar, A.; Bala, H.; Ramesh, V. IT Service Management Employee Compensation: Determinants and Outcomes. E-Serv. J. 2014, 9, 1–18. [Google Scholar] [CrossRef] [Scilit]
  19. Shilenge, M.; Telukdarie, A. 4IR integration of information technology best practice framework in operational technology. J. Ind. Eng. Manag. 2021, 14, 457. [Google Scholar] [CrossRef] [Scilit]
  20. Massey, C. Military values in ITSM: Translating discipline, leadership, and determination into service excellence. In Itsmf UK—Armed Forces Community Practice; itSMF: London, UK, 2023. [Google Scholar]
  21. Guttieri, K.R. Governance, Innovation, and Information and Communications Technology for Civil-Military Interactions. Stab. Int. J. Secur. Dev. 2014, 3, 1–16. [Google Scholar] [CrossRef] [Scilit]
  22. Jones, L.S. Using Web 2.0 Technology to Support Humanitarian Assistance and Disaster Relief Operations: Applying the Lessons Learnt from the United States Military Response to the 2010 Haiti Earthquake to Improve the Utilisation of the New Zealand Defence Force’s Communications and Information Systems During Humanitarian Assistance and Disaster Relief Operations. Ph.D. Thesis, Massey University, Palmerston North, New Zealand, 2011. [Google Scholar]
  23. Defense Act. Official Gazette of the Republic of Slovenia, 1994. No. 139/20. Available online: https://pisrs.si/pregledPredpisa?id=ZAKO532 (accessed on 25 October 2025).
  24. MoD, R.S. Rules on the Protection of the Communication and Information System of the Ministry of Defence of the Republic of Slovenia; Ministry of Defence: Ljubljana, Slovenia, 2008.
  25. Directive No. 16-01. In On the Operation and Protection of the Slovenian Armed Forces’ Communications and Information System; Internal directive, non-public document; General Staff: Ljubljana, Slovenia, 2022.
  26. Directive No. 16-02. In On the Bodies Responsible for the Custody and Management of Communication and Information Systems in the Slovenian Armed Forces; Internal directive, non-public document; General Staff: Ljubljana, Slovenia, 2023.
  27. Slovenian Armed Forces. Overview of Incidents in the Year 2022; Internal report, non-public document; Report Slovenian Armed Forces: Ljubljana, Slovenia, 2022.
  28. Slovenian Armed Forces. Overview of Incidents in the Year 2023; Internal report, non-public document; Report Slovenian Armed Forces: Ljubljana, Slovenia, 2023.
  29. Slovenian Armed Forces. Overview of Incidents in the Year 2024; Internal report, non-public document; Report Slovenian Armed Forces: Ljubljana, Slovenia, 2024.
  30. Slovenian Armed Forces. Annual Report of the Cyber Defence Working Group for the Year 2022; Internal report, non-public document; Report General Staff: Ljubljana, Slovenia, 2022.
  31. Slovenian Armed Forces. Annual Report of the Cyber Defence Working Group for the Year 2023; Internal report, non-public document; Report General Staff: Ljubljana, Slovenia, 2023.
  32. Slovenian Armed Forces. Annual Report of the Cyber Defence Working Group for the Year 2024; Internal report, non-public document; Report General Staff: Ljubljana, Slovenia, 2024.
  33. Annual Report of the CSR for 2022; Internal report, non-public document; Report Force Command: Vrhnika, Slovenia, 2022.
  34. Annual Report of the CSR for 2023; Internal report, non-public document; Report Force Command: Vrhnika, Slovenia, 2023.
  35. Annual Report of the CSR for 2024; Internal report, non-public document; Report Force Command: Vrhnika, Slovenia, 2024.
  36. Dunleavy, P.; Margetts, H.; Bastow, S.; Tinkler, J. New public management is dead–long live digital-era governance. J. Public. Adm. Res. Theory 2006, 16, 467–494. [Google Scholar] [CrossRef] [Scilit]
  37. Margetts, H.; Dunleavy, P. The second wave of digital-era governance: A quasi-paradigm for government on the Web. Philos. Trans. A Math. Phys. Eng. Sci. 2013, 371, 20120382. [Google Scholar] [CrossRef] [Scilit]
  38. Janssen, M.; van der Voort, H. Adaptive governance: Towards a stable, accountable and responsive government. Gov. Inf. Q. 2016, 33, 1–5. [Google Scholar] [CrossRef] [Scilit]
  39. Janssen, M.; Charalabidis, Y.; Zuiderwijk, A. Benefits, adoption barriers and myths of open data and open government. Inf. Syst. Manag. 2012, 29, 258–268. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.