2. Literature Review
As already mentioned, societies have an increasing dependency on technology. While digitalization has clear benefits, it also creates novel risks that need to be understood and addressed. One example that shows the dependency and the need to address risks is critical infrastructure, i.e., functions and systems that are critical to society’s well-being. The significance of this sector is reflected in current European Union (EU) law. Directive (EU) 2022/2557 defines critical infrastructure as “an asset, a facility, equipment, a network or a system, or a part of an asset, a facility, equipment, a network or a system, which is necessary for the provision of an essential service” [
2], while Directive (EU) 2022/2555 (NIS2) establishes the corresponding cybersecurity risk-management and incident-reporting obligations for essential and important entities [
3]. The underlying concern is long-standing, not exclusive to the EU, and has already been articulated [
4]; what the contemporary framing makes explicit is that the object of protection is the continuity of an essential service rather than the asset itself. Similarly, in [
5] it is recognized that there have been several regulatory measures and legislation that aim to support the cybersecurity framework and directives of the European Union (EU). Additional policies, directives and legal requirements regarding cybersecurity for products and sectors that are not part of critical infrastructure have been proposed [
6]. Such policies and regulatory requirements are the product of acknowledging modern society’s reliance on technology and the need to address the risks that stem from that dependence, i.e., the fact that a cyberattack against a system that society depends upon can impact society itself.
Although the significance and the risk of this reliance are recognized and widely understood, various reports document an increase in attacks. As observed in [
7], each year not only does the number of attacks increase, but larger corporations are also targeted successfully [
5,
8,
9]. The increase in attacks is also highlighted in reports of relevant authorities. In [
10], it is clear that there has been an increase in complaints regarding cybercrime (cyber fraud and cyber threats) received between 2018 and 2022. Furthermore, it is reported that there has been an increase in the total amount of losses, reaching 10.2 billion USD for 2022 alone. The increase in the number of complaints and losses is also observed in the 2023 report [
8]. In the 2024 report [
9], the increase in losses and reports is also noted, and the total number of cyberthreat complaints received for 2024 is 263,455, of which more than 4800 are from critical infrastructures alone. It is important to note here that besides the losses a victim may incur, the cost of prevention is also increased [
11,
12]. This increase is expected to continue for two reasons. First, digitalization expands the attack surface. Second, cybercriminals adapt; they exploit new technologies both to create unprecedented threats and to strengthen existing ones. Large Language Models (LLMs) are the clearest current example, used to develop phishing campaigns or malware [
13,
14] and make sophisticated techniques accessible to low-skill actors [
15].
Several contributing factors can be identified in the literature reviewed above, of which those most relevant to the present argument are discussed below. The first contributing factor is the increase in digitalization. While there was demand for digitalization before the COVID-19 pandemic, during the pandemic there was a significant acceleration of the digitalization pace [
5,
16,
17]. Moreover, governments and public organizations have pursued digitalization initiatives of their own. One example is the electronic Identification, Authentication and Trust Services (eIDAS)—originally published by the European Commission [
18] and revised in [
18]—which aims to establish a common framework that member states of the EU can use to support digital transactions and cross-border identification. Undoubtedly, this interoperability between member states brings significant benefits for EU citizens but also introduces additional security risks that need to be addressed [
19]. The demand for digitalization and technological advancements introduces risks that need to be addressed.
The recent discussions around cyber resilience are an acknowledgment that prevention on its own is not enough and cannot address “unknown unknowns” [
20]. According to Geer [
21], faster and broader adoption of new technologies increased the interdependence between systems, and this interdependence can hide away complexity. Interdependence of technologies and abstracted-away complexity can lead to cascading failures. This diagnosis has sharpened rather than dated: Vargas and Tien [
22] demonstrate that the adoption of 5G across connected critical infrastructure introduces cyber-physical risks that propagate between systems that were previously independent, and recent survey evidence indicates that 65% of large organizations now identify third-party and supply chain vulnerabilities as their greatest cybersecurity challenge, up from 54% one year earlier, while only 33% comprehensively map their supply chain ecosystems [
12]. Similarly, domains such as Internet of Things (IoT), cloud, etc., can assist with digital transformation but challenge existing security practices [
23,
24,
25]. More recent reviews confirm that these challenges have persisted rather than being resolved as the technologies matured, both in IoT [
26] and in cloud adoption [
27]. Fundamentally, technological progress and interdependence between systems are outpacing our ability to understand and properly defend systems. At the same time, organizations tend to have unique needs and security requirements, requiring context-specific, adaptive security policy development [
28].
While digitalization and new technologies deliver substantial results and have undeniable benefits for society, they simultaneously increase the difficulty of efficiently securing those systems. The significance of those systems and the need to secure them is recognized both on a regulatory level and throughout academia. Yet there is evidence that cyberattacks are increasing in frequency, costs, and sophistication. Addressing this asymmetry requires an understanding of the gaps and challenges reported by those tasked with defending these systems.
Section 3 develops Evolutionary Governance Theory as the lens through which this asymmetry is analyzed, and derives from it the five propositions that the empirical study evaluates.
2.1. Theoretical Framings of the Governance Gap
The literature reviewed above establishes that a gap exists between the pace at which the technological environment evolves and the pace at which the arrangements meant to govern it adapt. It does not, however, settle what kind of problem that gap is, and several established traditions offer competing answers. Although this paper discusses EGT, it is worth discussing alternatives.
Resilience engineering is concerned with what a system should do when prevention fails, and it grew out of safety science [
29]. It treats a gap as a shortfall in adaptive capacity and is concerned with what allows a system to absorb disturbance, recover, and learn. Recent work extends this reasoning from technical components to institutional scale [
30]. Resilience engineering, implicitly, places governance outside the system, as the party that designs resilience into everything else. It does not, however, ask why the designer itself cannot keep up with the pace.
Another theoretical framing is socio-technical systems theory, in which the system is considered to be composed of technical and social arrangements. These arrangements must be optimized together [
31]. This is in line with the information security view that both the human and the technical must be jointly considered [
32]. Although the importance of the human aspect is recognized by this study as well, this study is concerned with understanding why a sub-system is drifting apart from the others.
The closest theory to the one utilized by this study is Institutional Theory. Information security arrangements spread through regulatory pressure, professional norms, etc., and formal policy can decouple from what is actually practiced [
33]. This pattern has been documented in the domain of information security [
34]. Institutional theory explains why ISG converges on common arrangements, but it does not explain why those arrangements keep falling behind what they govern.
EGT is adopted here because governance is treated as an evolving object. Specifically, it considers the co-evolution between systems and supplies relevant terminology that can be used to decompose the gap and address it.
Section 3 develops the framework and derives the five propositions from it.
2.2. Prior Survey-Based Research on Information Security Practitioners
Questionnaires have been used in research in the domain of information security in the past, e.g., for cybersecurity awareness reasons [
35], smart cities and cybersecurity challenges [
36]. Closer to the organizational focus of this study, mixed-methods work has assessed information security culture across international IT departments [
32]. Also, practitioners have been recently surveyed on the topics of cybersecurity risks, DevSecOps practice, and emerging security priorities [
37]. There is growing evidence that practitioner perception is treated as evidence, rather than as a proxy for technical measurement. Furthermore, studies of security professionals have also demonstrated the viability of recruiting this population through professional certification bodies and professional networks [
38]. Professional networks and certification bodies are the approaches used by this paper.
This study contributes two features to the body of work. First, it targets perceptions of governance adaptation. Second, the survey instrument propositions are derived based on Evolutionary Governance Theory. This survey is therefore not only a description of practitioner opinion but an evaluation of whether perceptions match the way EGT predicts.
3. Evolutionary Governance Theory
ISG has conventionally been used by organizations—through the specification of policies, structures, accountability mechanisms, etc.—to direct and oversee the protection of their information assets [
39,
40]. As information technology evolves, systems grow more interconnected, and threat actors adapt faster than institutions. This creates an imbalance where ISG is perceived as important but lags behind the environment it is meant to regulate. This study argues that EGT offers a theoretical lens capable of capturing any imbalance and assisting in understanding and developing the required processes to address it.
Throughout this paper, a distinction is drawn between security tools and governance processes. By tools we mean the technical capabilities deployed to observe and act on the environment: monitoring and detection platforms, vulnerability scanners, endpoint and network controls, asset inventories, and similar. By governance processes we mean the organizational routines through which those capabilities are directed, evaluated, and revised. Governance processes include who decides what is monitored and how detection scope is re-prioritized when the asset base or the threat landscape shifts, the criteria by which vulnerabilities are treated, how often those criteria are themselves revisited, the escalation authority during an incident, and whether post-incident findings are carried back into policy, how often and through which processes security policies are reviewed and updated, and similar processes. Most operational activities in information security have both layers. Threat monitoring, for example, depends on a detection platform, but it depends equally on a routine that decides what that platform should look for, reviews what it returned, and adjusts its scope when the organization or its environment changes. The tool supplies capacity; the process supplies direction and revision.
This layering is what makes the asymmetry within the co-evolving pair visible. The tool layer is renewed often, and largely by others: threat intelligence feeds, detection signatures, and vendor releases arrive without organizational deliberation. The process layer is renewed on institutional time, which is usually not as often as the tool layer. An adaptive deficit, in these terms, is not a shortage of capability but a shortage in the loop that keeps capability aligned to a moving target: the environment produces variety faster than the process layer can observe it, interpret it, and revise the arrangements that respond to it.
EGT, developed principally by van Assche, Beunen, and Duineveld [
41,
42], considers governance not as a fixed architecture but as the continuously evolving outcome of interactions among actors, institutions, knowledge, and their environments. EGT is an interdisciplinary framework. It draws on systems theory, institutional economics, autopoiesis, post-structuralist theory, and actor–network theory, among others. EGT holds that governance arrangements co-evolve with the domains they govern: each shapes and is shaped by the other, and neither can be understood in isolation. The framework therefore offers a way to trace how the various participants (actors, objects, subjects, etc.) co-evolve and governance is shaped. Central to the theory are dependencies. More specifically, path dependence means that prior governance choices constrain present options; inter-dependence means that actors and institutions transform one another through interaction; and goal dependence means that future goals feed back into present arrangements. Governance is therefore always contingent, always in transition, and never fully in control of its own evolution.
Applying EGT to information security, this perspective reframes familiar problems. ISG and the socio-technical environment it addresses form a co-evolving pair, albeit an asymmetric one. Technology, threat landscapes, and systems interconnection and interdependence evolve at an accelerating pace, whereas governance evolves at the pace of institutions, through committees, standards cycles, regulatory revision, etc. From an EGT standpoint, a “governance gap” is not an implementation failure to be engineered away but a structural property of co-evolution between a fast-moving environment and a governance system, where the regulating system (the governance system) cannot match the variety of the system it tries to regulate. This insight echoes Ashby’s law of requisite variety [
43]: a regulating system must match the variety of the system it regulates, and where it cannot, it must find alternative adaptive strategies. Essentially, a gap in ISG may not be solved simply by introducing new technology and tools, but it may require updating processes, introducing new ones, etc.
Based on the above, five propositions are derived from EGT. The first proposition (P1), regarding the environmental pressure, explores the fast-adapting pole of the co-evolving pair. Through EGT, we consider the environment not as a passive backdrop but as an active participant that can influence governance, continuously producing variety to which institutions must respond. As information technology evolves and systems become more interconnected, it is the environment that sets the adaptive demand governance must meet.
The second proposition (P2), regarding adaptive deficit, is this study’s central claim and follows EGT’s account of co-evolution. As governance co-evolves with technology but adapts more slowly, an adaptive deficit emerges in which governance cannot match the speed of change. This study considers that this asymmetry can lead to governance gaps: professionals may perceive governance as having benefited from technological change while still lacking the processes to detect and respond to environmental change. In this reading, the binding constraint lies in governance itself rather than in technical tooling.
The third proposition (P3), regarding adaptive differentiation, concerns how governance recognizes change. We argue that governance systems able to differentiate between internally emergent and externally emergent change may be better positioned to respond to environmental change, since a system that cannot locate the source of change cannot select an appropriate response.
The fourth proposition (P4), regarding resilience as adaptive response, addresses what follows when stable alignment with a fast-evolving environment cannot be achieved. We expect information security professionals to converge on cyber-resilience—institutions will seek to maintain adaptive capacity—as the necessary response, and we consider the ability to identify critical operational dependencies to be associated with this resilience orientation. We interpret this dependency–resilience link through the cyber-resilience literature rather than as evidence for EGT’s own construct of governance dependencies.
The fifth proposition (P5), regarding institutionalization, explores the distribution of these perceptions across the profession. If the dynamics described above have co-evolved into a shared professional understanding, we expect these perceptions to vary little across tenure or organization size. We advance this proposition as a theory-motivated interpretation of any observed homogeneity rather than as a discriminating test.
Together, the propositions trace a single theoretical arc: a fast-adapting environment (P1) outpaces a path-dependent governance system (P2), whose adaptive capacity turns on its ability to differentiate sources of change (P3), whose realistic response to permanent misalignment is resilience (P4), and whose resulting understandings have sedimented into shared professional knowledge (P5). By translating EGT from its origins in spatial planning and public administration into ISG, the study contributes both a theoretical reframing of the ISG gap and an empirical assessment of whether practitioners’ perceptions pattern in the way the theory predicts.
4. Research
The rise in information security incidents documented in
Section 2 has multiple contributing factors. Based on the literature review, these factors include the pace of technological adoption and the increasing interdependencies between systems [
21,
44], the requirement for more holistic approaches that take into consideration both the human and the technical aspects in the cyber domain [
45,
46,
47,
48,
49,
50], and other challenges. For this research, we hypothesize that some of the contributing factors to the increasing number of attacks are the following:
H1. The evolution of technology is increasing the overall complexity, which impacts the security of the systems.
H2. Challenges are not only technical; the human aspect is still perceived as an important factor when it comes to securing systems.
H3. The evolution of technology is outpacing the governance processes through which the organization detects and responds to change, both internally and in its environment.
H4. This hypothesis is split into two claims. a. There is a growing need for resilience. b. There is a gap in the tools and processes available to meet that need.
The four hypotheses do not map one-to-one onto the five propositions, because they are formulated at the level of contributing factors to rising incidents rather than at the level of governance mechanisms. H1 is derived from P1, H3 from P2, and H4a and H4b from P4. H2 does not correspond to a single proposition; because the human factor is a co-actor of governance, it supplies supporting evidence for both P2 and P3. P3 and P5 are not carried by a dedicated hypothesis but are addressed directly in the analysis: P3 through the governance-differentiation item and its relationship with environmental detection and response capacity (
Section 5.9, Table 5), and P5 through the pattern of demographic correlations across all substantive items (
Section 5.9, Tables 4 and 5). H3 is stated at the level of governance processes rather than formal organizational structure. The corresponding items (18, 19, 21) ask about the routines through which governance detects, differentiates and responds to change, in the sense defined in
Section 3, rather than about reporting lines, mandate or the placement of the security function. Structural change in that narrower sense is not measured by this instrument.
Table 1 sets out the full mapping between propositions, hypotheses, questionnaire items, and the analysis in which each is addressed.
To validate our hypotheses and assess the extent to which those factors pose a threat to information security, we developed a closed-ended questionnaire and asked information security professionals from diverse backgrounds to answer it. The questionnaire has two objectives: the first is to quantify the opinions of professionals regarding the original hypotheses, and the second is to explore the perception of professionals on the proposed application of evolutionary methodologies in the domain of information security. This questionnaire aims to gather real-world information regarding the challenges that professionals face and the extent to which they perceive the application of EGT in information security as useful. As discussed in
Section 2.2, questionnaires are well-established in the domain.
Research Methods
We used closed-ended questions because predetermined answers simplify the analysis and facilitate hypothesis testing [
51]. To achieve the goal of closed-ended questions, the questionnaire relies on a Likert scale (i.e., participants must indicate the extent to which they agree or disagree with specific statements). Additionally, a set of screening questions regarding the sample was also collected and used during the statistical analysis to explore whether there are potential correlations between the answers and the size of the company, the seniority of the respondents’ roles, etc. There were 24 questions in total, excluding the consent item. Before distribution, the questionnaire was piloted with two practitioners to ensure clarity, and their responses did not count toward the overall sample.
Our first pool of respondents was the GIAC Advisory Board mailing list. GIAC is a certification body that specializes in information security and maintains the Advisory Board mailing list. The Advisory Board mailing list consists of GIAC-certified professionals who achieved certification scores above 90% (more details available at
https://www.giac.org/frequently-asked-questions/?categories=advisory-board. The site was last accessed on 15 February 2026). It is important to note here that GIAC does not officially provide the exact number of members. Members come from various backgrounds (e.g., different industries, size of the organization, different aspects of information security, etc.), which offers diversity in the sample. We initially reached out to the GIAC Advisory Board in October 2024, and after about three weeks, there were N = 35 respondents. Given the initial response rate, we expanded recruitment via LinkedIn, asking information security professionals to share the questionnaire with their information security teams. The post reached approximately 200 people. We stopped collecting responses in March 2025, with a total of 65 respondents (N = 65).
For the collection of responses, Google Forms was used. For the analysis of the data, IBM SPSS Statistics 31 (SPSS) was used. Furthermore, Microsoft Excel was used for some initial visualization. Responses were collected anonymously, and the results were used only for the purposes of this research.
The analysis of the data was split into two parts. The first part was descriptive statistics, while the second explored potential correlations that could be made based on the responses to the questionnaire. Associations were examined using Spearman’s rank-order correlation (
rs), with two-tailed significance evaluated at α = 0.05 throughout. The correlations reported in
Section 5.9 are exploratory. They examine all pairwise associations among the substantive items and the screening variables rather than a pre-specified subset and are interpreted as hypothesis-generating rather than confirmatory. Coefficient magnitudes are described using fixed bands throughout:
rs smaller than 0.10 negligible, between 0.10 and 0.29 weak, between 0.30 and 0.49 moderate, between 0.50 and 0.69 strong, and greater than 0.70 very strong. Associations that do not reach significance are reported as such and are not interpreted directionally.
6. Discussion
This section discusses the findings of the analysis and their relation to the four research hypotheses (H1–H4) originally posed, situates the analysis within the broader information security literature, and addresses challenges and shortcomings that future work could take up. Throughout, the evidence is perceptual. The questionnaire records how information security professionals characterize their governance environment; it does not observe governance processes or their co-evolution with the systems they manage. Findings are therefore reported as consistent or inconsistent with an EGT-based reading, not as confirmation of the theory.
H1, that “The evolution of technology is increasing overall complexity, which impacts the security of systems” (P1), is strongly supported by respondents’ perceptions. All respondents (100%) agreed that information technology has evolved over the last ten years, and an overwhelming majority (72.3% strongly agree, 23.1% agree) confirmed that information systems have become more interconnected and interdependent. These findings are consistent with the observations of Geer [
21], who argued that faster and broader adoption of new technologies has increased systemic interdependence and introduced hidden complexity. More recent evidence shows that third-party and supply chain interdependence is now the leading cyber concern reported by large organizations, and documented incidents exhibit the cascading dynamics Geer anticipated [
12,
22].
At these levels of agreement, the perception is shared throughout the sample rather than confined to particular sectors or roles. A statistically significant but weak positive correlation links the view that technological progress has introduced new threats with the view that information security has the required tools to respond to them (
rs = +0.251). Awareness of new threats therefore coexists with confidence in available defenses. The weakness of the association matters, however: a substantial number of respondents recognize emerging threats without regarding current tools as adequate, and the reverse also holds. Finally, views on system interconnectedness and system complexity are themselves moderately correlated (
rs = +0.345), which is what the argument that interdependence drives complexity would predict [
21,
44]. This aligns with the literature on digital transformation and cybersecurity challenges [
25] that emphasizes that new domains such as IoT and cloud computing not only expand the attack surface but fundamentally alter the nature of the security problem.
For H2, “Challenges are not only technical; the human aspect is still perceived as an important factor” (P2)
, the analysis provides substantial support for the perceived importance of the human factor. A clear majority of respondents (75.4%) agreed that users are the weakest link in terms of security, and 72.3% acknowledged that information security is increasingly recognizing the importance of the human factor. This pattern matches a well-established body of literature identifying human behavior as a critical factor in information security [
45,
46,
49,
50]. This is a respondent perception, not an observation of user behavior, and the item does not identify what produces it. One interesting finding is the divided opinion on estimating organizational impact. Approximately one third of the respondents agreed that it has become easier to estimate the organizational impact of security decisions, one third took a neutral stance, and roughly 29% disagreed. The lack of consensus here may reflect the inherent difficulty of bridging the technical and human domains, which is also recognized in the literature [
46,
47]. A weak negative association between estimating organizational impact and total years of experience (
rs = −0.128) was observed but did not reach statistical significance; this direction is worth exploring with larger samples. In summary, the data confirm that the human factor is perceived as important and a growing challenge.
H3, “The evolution of technology is outpacing the governance processes through which the organization detects and responds to change, both internally and in its environment” (P2), is partially supported by the data. While the majority of respondents agreed that ISG has benefited from technological progress, a substantial proportion of respondents (41.5%) disagree that ISG has the required processes in place to detect and respond to changes in the environment of the organization. This tension may suggest that governance processes are, currently, outpaced by technological change. One notable finding is that none of the demographic variables showed a statistically significant correlation with the ISG views. All
p-values were well above 0.05, and the correlation coefficients were negligible. That this pattern holds across every demographic group in the sample suggests the challenges are recognized irrespective of setting, at least among the participants of this study. Although this finding is consistent with the arguments for adaptive, context-aware security policy development [
28], future research should establish that this is demonstrated in larger samples. Future research on H3 could benefit from mixed methods approaches that would allow respondents to describe specific transformations in their organizational context, which would allow a researcher to measure how organizational structures have been affected by technological progress.
Finally, H4 is evaluated as two separate claims (P4). H4a states that “There is a growing need for resilience”; H4b states that “There is a gap in the tools and processes available to meet that need”. The data strongly supports H4a. 95% of respondents agree that information security must ensure that specific processes remain functional despite any adverse events, and 97% agree that information security must plan to respond to threats that were not originally considered. Both figures track the growing cyber-resilience literature and its central claim that prevention alone cannot address “unknown unknowns” [
20]. The near unanimity among respondents indicates that resilience is not a niche concern within this group, though a sample recruited through a certification body is one in which broad acceptance of resilience is particularly likely.
At the same time, one statistically significant finding is the correlation between identifying critical services and their dependencies and ensuring functionality in adverse situations (rs = +0.351, p = 0.004), which is also the largest correlation observed in this study. This suggests that professionals who value the identification of critical dependencies are also those who prioritize continuity and resilience. The strength of this relationship, significant at the 1% level, is consistent with the theoretical link between asset identification and resilience planning: effective resilience requires a clear understanding of what needs to be protected and how components depend on one another. However, the evidence for a gap in tools and processes is more mixed than H4 anticipated. Only 15.4% of respondents disagreed that information security has the required tools to respond to challenges. The tooling landscape therefore is perceived as reasonably adequate.
This apparent tension with H4 can be reconciled by interpreting the gap as processual and organizational rather than technical: tools may exist without being effectively integrated, deployed, or adapted to a rapidly evolving threat landscape, a reading reinforced by the 41.5% who disagreed that ISG has the processes to detect and respond to environmental changes. Sample composition may also play a role, as the predominance of seasoned professionals working in large organizations (46% in firms with 5000+ employees) may reflect environments with mature, well-resourced security programs that are not representative of the broader profession. Either way, the core finding is clear: resilience is broadly perceived as essential, but the gap lies less in the absence of tools and more in the organizational and processual capacity to deploy them effectively.
While the questionnaire did not ask respondents to endorse EGT explicitly, several items tap directly into P1–P5. EGT emphasizes that governance systems co-evolve with the systems they govern, that adaptive governance must differentiate between internally and externally emergent change, and that the interplay between structure and environment shapes the capacity for response. The association between the views that ISG can differentiate between internally and externally emergent changes and that ISG has the required processes to detect and respond to environmental change (
rs = +0.293,
p = 0.018) is the most direct evidence bearing on P3. Given the number of exploratory tests reported in
Section 5.9 and the size of the sample, we advance it as suggestive rather than established. It indicates that these two capacities, which EGT treats as linked dimensions of adaptive governance, are also perceived as linked by practitioners.
At the same time, the finding that 41.5% of respondents disagree that ISG has the processes in place to detect and respond to environmental change, juxtaposed with the 76.9% who agree that ISG has benefited from technological progress, is consistent with the adaptive deficit anticipated by P2, which EGT predicts when governance cannot keep pace with the systems it manages. Combined with the near-unanimous agreement on the need for resilience, continuity, and planning for unanticipated threats, the challenges practitioners identify fall within the range of phenomena EGT is designed to describe. This correspondence is in part by construction, since the questionnaire items were derived from the propositions; it therefore indicates coherence between the instrument and the theory rather than an independent test of it. What the study does establish is that EGT can be operationalized in this domain: its propositions translate into measurable items, and practitioners’ perceptions pattern in the way those propositions anticipate. For a theory carried from spatial planning and public administration into ISG, that is the necessary first result, and it identifies the specific relationships that subsequent work—designs able to observe governance processes directly—can test.
P5 is addressed by a recurring finding across the correlation analyses: the absence of statistically significant relationships between demographic variables and the substantive views on information security. Neither years of experience, tenure, nor organization size showed significant correlations with the ISG items, the complexity items, or the resilience items, and while the sample size (N = 65) limits the statistical power to detect small effects, the consistency of this null finding across multiple tests is noteworthy. One interpretation is that the challenges identified (increasing complexity, the human factor, governance gaps, and the need for resilience) are perceived similarly because they are systemic, with information security professionals facing a fundamentally similar set of pressures regardless of the context they operate in, consistent with the systemic nature of the challenges described in the literature [
21,
25,
44].
Another explanation relates to sample homogeneity: the recruitment strategy, primarily through the GIAC Advisory Board and supplemented by LinkedIn outreach, may have produced a sample that, while diverse in industry and organization size, is relatively homogeneous in professional training and awareness, making demographic differences less likely to produce variation in responses. This should be addressed in future research by targeting more diverse populations (different career stages, different regulatory environments, different industries) and by expanding the sample size.
Overall, the data make the case for security strategies that explicitly account for complexity, inter-dependence, and the human factor. The strong consensus on resilience combined with the perceived gap in governance processes indicates that organizations should invest not only in tools but in the organizational capacity that takes into consideration a rapidly changing environment. Two of the significant correlations merit further investigation: threat awareness with tool confidence, and dependency identification with resilience orientation. Both point to conceptual relationships that larger samples, longitudinal designs, and multivariate methods could test directly. More broadly, a framework connecting technological evolution, complexity, and governance adaptability would benefit from deeper engagement with EGT as a lens for understanding how governance structures co-evolve with the systems they are designed to manage.
This study has several limitations. The sample size of 65 respondents, while sufficient for exploratory analysis, limits the statistical power of the correlation tests and restricts the use of more sophisticated multivariate methods. With N = 65, the study has approximately 80% power to detect a correlation of
rs ≈ 0.34 at α = 0.05, which is larger than any association observed here. The correlation analysis is therefore underpowered for the effect sizes of interest.
Section 5.9 further reports a large number of pairwise tests without correction for multiple comparisons, and at α = 0.05 a small number of nominally significant results would be expected by chance alone. We therefore treat the correlations throughout as exploratory and hypothesis-generating rather than as established findings. The same limitation applies in reverse to the absence of demographic associations reported throughout. At this sample size, failure to detect a relationship is weak evidence that no relationship exists. The demographic breakdowns in
Section 5 are likewise descriptive only. Several subgroups—notably the gender categories and the majority of the eighteen industry categories—contain fewer than five respondents, and the percentages reported for them are given for completeness rather than as estimates of population proportions.
The reliance on the GIAC Advisory Board as the primary recruitment channel introduces a potential selection bias toward highly qualified, experienced professionals who may not be representative of the broader information security workforce. Furthermore, GIAC does not provide the total number of people on its mailing list, making it hard to reason about the response rate. Additionally, the questionnaire relied on Likert-scale items that capture perceptions but not behaviors or outcomes. Respondents’ views on the adequacy of tools or governance processes may therefore not correspond to the actual state of affairs in their organizations. It is important to note here that many items, including “Users are the weakest link in terms of security”, are worded as assertions. Agreement with such an item records endorsement of a framing rather than an observation, and the instrument does not distinguish between the mechanisms that might produce that endorsement. Finally, the cross-sectional design captures a single point in time and cannot establish causal relationships between the variables examined. Although the findings are interpreted and evaluated through EGT, this study does not establish that EGT explains the findings better than competing accounts.
Despite these limitations, the study provides a valuable empirical contribution by quantifying professional perceptions across a diverse set of information security challenges. Additionally, it identifies a deficiency in governance processes and highlights a need for dependency mapping. The practical implication follows from where respondents locate the constraint: in governance capability rather than in tooling. Stronger governance processes would also improve the value extracted from the tools already deployed. For example, dependency mapping can be used both to understand technical dependencies (e.g., supply chain risks, cloud vendor dependencies, etc.) and to understand the governance processes and available options (e.g., understanding constraints from previous decisions, compliance requirements, etc.). Similarly, resilience and adaptability metrics could be used to provide real-time board-level insights. The consistency of findings across demographic groups, and the alignment of results with established theoretical arguments, supports the validity of the conclusions drawn while also highlighting clear directions for future research.