Previous Article in Journal
Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security

by
Emmanouil Mavrofidis
1,*,
Aikaterini Tsatsaroni
2 and
Achilles D. Kameas
1
1
School of Science and Technology, Hellenic Open University, Aristotelous 18, 26335 Patras, Greece
2
Faculty of Business and Economics, UniDistance Suisse, Schinerstrasse 18, 3900 Brig, Switzerland
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(5), 165; https://doi.org/10.3390/jcp6050165 (registering DOI)
Submission received: 29 July 2026 / Revised: 3 September 2026 / Accepted: 15 September 2026 / Published: 17 September 2026
(This article belongs to the Section Security Engineering & Applications)

Abstract

Despite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilience through Evolutionary Governance Theory (EGT) and explore whether information security governance (ISG) co-evolves with the same velocity as the systems it manages. A closed-ended, five-point Likert questionnaire was developed, which was completed by 65 information security professionals recruited through the Global Information Assurance Certification (GIAC) Advisory Board and LinkedIn between October 2024 and March 2025. Responses were analyzed using descriptive statistics and Spearman correlations. Respondents were near-unanimous that technological evolution has increased complexity and interdependence, and that resilience is essential. 41.5% of respondents consider that governance lacks the processes to detect and respond to environmental changes, identifying a gap in governance capacity. Within this sample, no item was significantly associated with tenure, experience, or organization size, though the analysis is underpowered for small effects. This study applies EGT in the domain of information security, and reports practitioner evidence consistent with an interpretation of the ISG gap as an adaptive deficit of co-evolving systems rather than as an implementation failure.
Keywords: information security governance; cyber resilience; evolutionary governance theory; security professionals; survey research information security governance; cyber resilience; evolutionary governance theory; security professionals; survey research

Share and Cite

MDPI and ACS Style

Mavrofidis, E.; Tsatsaroni, A.; Kameas, A.D. The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. J. Cybersecur. Priv. 2026, 6, 165. https://doi.org/10.3390/jcp6050165

AMA Style

Mavrofidis E, Tsatsaroni A, Kameas AD. The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. Journal of Cybersecurity and Privacy. 2026; 6(5):165. https://doi.org/10.3390/jcp6050165

Chicago/Turabian Style

Mavrofidis, Emmanouil, Aikaterini Tsatsaroni, and Achilles D. Kameas. 2026. "The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security" Journal of Cybersecurity and Privacy 6, no. 5: 165. https://doi.org/10.3390/jcp6050165

APA Style

Mavrofidis, E., Tsatsaroni, A., & Kameas, A. D. (2026). The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. Journal of Cybersecurity and Privacy, 6(5), 165. https://doi.org/10.3390/jcp6050165

Article Metrics

Back to TopTop