Previous Article in Journal
Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security

by
Emmanouil Mavrofidis
1,*,
Aikaterini Tsatsaroni
2 and
Achilles D. Kameas
1
1
School of Science and Technology, Hellenic Open University, Aristotelous 18, 26335 Patras, Greece
2
Faculty of Business and Economics, UniDistance Suisse, Schinerstrasse 18, 3900 Brig, Switzerland
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(5), 165; https://doi.org/10.3390/jcp6050165 (registering DOI)
Submission received: 29 July 2026 / Revised: 3 September 2026 / Accepted: 15 September 2026 / Published: 17 September 2026
(This article belongs to the Section Security Engineering & Applications)

Abstract

Despite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilience through Evolutionary Governance Theory (EGT) and explore whether information security governance (ISG) co-evolves with the same velocity as the systems it manages. A closed-ended, five-point Likert questionnaire was developed, which was completed by 65 information security professionals recruited through the Global Information Assurance Certification (GIAC) Advisory Board and LinkedIn between October 2024 and March 2025. Responses were analyzed using descriptive statistics and Spearman correlations. Respondents were near-unanimous that technological evolution has increased complexity and interdependence, and that resilience is essential. 41.5% of respondents consider that governance lacks the processes to detect and respond to environmental changes, identifying a gap in governance capacity. Within this sample, no item was significantly associated with tenure, experience, or organization size, though the analysis is underpowered for small effects. This study applies EGT in the domain of information security, and reports practitioner evidence consistent with an interpretation of the ISG gap as an adaptive deficit of co-evolving systems rather than as an implementation failure.

1. Introduction

The widespread integration of technology into modern life has brought both opportunities and significant risks. As society grows more dependent on information systems for daily operations and essential services, these systems must be robust enough to withstand evolving cyber threats. There is a worrying rise in cybercrime and attacks, a trend that is expected to continue due to the increasing adoption of artificial intelligence and other emerging technologies [1]. Understanding the factors behind this surge is a precondition for developing defenses that address current conditions rather than past ones. This paper explores whether governance can co-evolve quickly enough with the environment it is tasked with defending; i.e., this paper considers whether a governance-adaptation problem exists. This research uses EGT to formally frame the problem and organize a study on how information security professionals perceive the challenges they face. Furthermore, this paper presents the results of quantitative research conducted on information security professionals regarding their beliefs on technology, its evolution, and the challenges they perceive in securing systems. The goal of the research is to provide insights on the challenges faced by those tasked with defending those systems and provide a better understanding of the identified issues.
First, to the best of our knowledge, this paper provides one of the first operationalizations of EGT in the information security domain, deriving specific governance propositions and evaluating them against survey evidence, which is the main contribution. Second, the survey documents a governance gap: although surveyed professionals (N = 65) report no significant shortage of tooling, deficiencies in the governance processes are reported, indicating a constraint on organizational adaptation. Third, based on the survey results, the reported perceptions of the survey participants are uniform across tenure and organization size, suggesting a converged understanding of the challenges. This conclusion is drawn from a single perceptual instrument and a sample of 65 that is underpowered for small effects; we therefore offer it as a direction for further work rather than as an established result.
The remainder of the paper is organized as follows: Section 2 presents the current body of work and situates the current study; Section 3 introduces the theoretical framework and states the propositions regarding ISG; Section 4 presents the methods, the questionnaire, and samples; Section 5 presents descriptive and correlational results; finally, Section 6 and Section 7 interpret the findings and implications for governance and suggest future directions.

2. Literature Review

As already mentioned, societies have an increasing dependency on technology. While digitalization has clear benefits, it also creates novel risks that need to be understood and addressed. One example that shows the dependency and the need to address risks is critical infrastructure, i.e., functions and systems that are critical to society’s well-being. The significance of this sector is reflected in current European Union (EU) law. Directive (EU) 2022/2557 defines critical infrastructure as “an asset, a facility, equipment, a network or a system, or a part of an asset, a facility, equipment, a network or a system, which is necessary for the provision of an essential service” [2], while Directive (EU) 2022/2555 (NIS2) establishes the corresponding cybersecurity risk-management and incident-reporting obligations for essential and important entities [3]. The underlying concern is long-standing, not exclusive to the EU, and has already been articulated [4]; what the contemporary framing makes explicit is that the object of protection is the continuity of an essential service rather than the asset itself. Similarly, in [5] it is recognized that there have been several regulatory measures and legislation that aim to support the cybersecurity framework and directives of the European Union (EU). Additional policies, directives and legal requirements regarding cybersecurity for products and sectors that are not part of critical infrastructure have been proposed [6]. Such policies and regulatory requirements are the product of acknowledging modern society’s reliance on technology and the need to address the risks that stem from that dependence, i.e., the fact that a cyberattack against a system that society depends upon can impact society itself.
Although the significance and the risk of this reliance are recognized and widely understood, various reports document an increase in attacks. As observed in [7], each year not only does the number of attacks increase, but larger corporations are also targeted successfully [5,8,9]. The increase in attacks is also highlighted in reports of relevant authorities. In [10], it is clear that there has been an increase in complaints regarding cybercrime (cyber fraud and cyber threats) received between 2018 and 2022. Furthermore, it is reported that there has been an increase in the total amount of losses, reaching 10.2 billion USD for 2022 alone. The increase in the number of complaints and losses is also observed in the 2023 report [8]. In the 2024 report [9], the increase in losses and reports is also noted, and the total number of cyberthreat complaints received for 2024 is 263,455, of which more than 4800 are from critical infrastructures alone. It is important to note here that besides the losses a victim may incur, the cost of prevention is also increased [11,12]. This increase is expected to continue for two reasons. First, digitalization expands the attack surface. Second, cybercriminals adapt; they exploit new technologies both to create unprecedented threats and to strengthen existing ones. Large Language Models (LLMs) are the clearest current example, used to develop phishing campaigns or malware [13,14] and make sophisticated techniques accessible to low-skill actors [15].
Several contributing factors can be identified in the literature reviewed above, of which those most relevant to the present argument are discussed below. The first contributing factor is the increase in digitalization. While there was demand for digitalization before the COVID-19 pandemic, during the pandemic there was a significant acceleration of the digitalization pace [5,16,17]. Moreover, governments and public organizations have pursued digitalization initiatives of their own. One example is the electronic Identification, Authentication and Trust Services (eIDAS)—originally published by the European Commission [18] and revised in [18]—which aims to establish a common framework that member states of the EU can use to support digital transactions and cross-border identification. Undoubtedly, this interoperability between member states brings significant benefits for EU citizens but also introduces additional security risks that need to be addressed [19]. The demand for digitalization and technological advancements introduces risks that need to be addressed.
The recent discussions around cyber resilience are an acknowledgment that prevention on its own is not enough and cannot address “unknown unknowns” [20]. According to Geer [21], faster and broader adoption of new technologies increased the interdependence between systems, and this interdependence can hide away complexity. Interdependence of technologies and abstracted-away complexity can lead to cascading failures. This diagnosis has sharpened rather than dated: Vargas and Tien [22] demonstrate that the adoption of 5G across connected critical infrastructure introduces cyber-physical risks that propagate between systems that were previously independent, and recent survey evidence indicates that 65% of large organizations now identify third-party and supply chain vulnerabilities as their greatest cybersecurity challenge, up from 54% one year earlier, while only 33% comprehensively map their supply chain ecosystems [12]. Similarly, domains such as Internet of Things (IoT), cloud, etc., can assist with digital transformation but challenge existing security practices [23,24,25]. More recent reviews confirm that these challenges have persisted rather than being resolved as the technologies matured, both in IoT [26] and in cloud adoption [27]. Fundamentally, technological progress and interdependence between systems are outpacing our ability to understand and properly defend systems. At the same time, organizations tend to have unique needs and security requirements, requiring context-specific, adaptive security policy development [28].
While digitalization and new technologies deliver substantial results and have undeniable benefits for society, they simultaneously increase the difficulty of efficiently securing those systems. The significance of those systems and the need to secure them is recognized both on a regulatory level and throughout academia. Yet there is evidence that cyberattacks are increasing in frequency, costs, and sophistication. Addressing this asymmetry requires an understanding of the gaps and challenges reported by those tasked with defending these systems. Section 3 develops Evolutionary Governance Theory as the lens through which this asymmetry is analyzed, and derives from it the five propositions that the empirical study evaluates.

2.1. Theoretical Framings of the Governance Gap

The literature reviewed above establishes that a gap exists between the pace at which the technological environment evolves and the pace at which the arrangements meant to govern it adapt. It does not, however, settle what kind of problem that gap is, and several established traditions offer competing answers. Although this paper discusses EGT, it is worth discussing alternatives.
Resilience engineering is concerned with what a system should do when prevention fails, and it grew out of safety science [29]. It treats a gap as a shortfall in adaptive capacity and is concerned with what allows a system to absorb disturbance, recover, and learn. Recent work extends this reasoning from technical components to institutional scale [30]. Resilience engineering, implicitly, places governance outside the system, as the party that designs resilience into everything else. It does not, however, ask why the designer itself cannot keep up with the pace.
Another theoretical framing is socio-technical systems theory, in which the system is considered to be composed of technical and social arrangements. These arrangements must be optimized together [31]. This is in line with the information security view that both the human and the technical must be jointly considered [32]. Although the importance of the human aspect is recognized by this study as well, this study is concerned with understanding why a sub-system is drifting apart from the others.
The closest theory to the one utilized by this study is Institutional Theory. Information security arrangements spread through regulatory pressure, professional norms, etc., and formal policy can decouple from what is actually practiced [33]. This pattern has been documented in the domain of information security [34]. Institutional theory explains why ISG converges on common arrangements, but it does not explain why those arrangements keep falling behind what they govern.
EGT is adopted here because governance is treated as an evolving object. Specifically, it considers the co-evolution between systems and supplies relevant terminology that can be used to decompose the gap and address it. Section 3 develops the framework and derives the five propositions from it.

2.2. Prior Survey-Based Research on Information Security Practitioners

Questionnaires have been used in research in the domain of information security in the past, e.g., for cybersecurity awareness reasons [35], smart cities and cybersecurity challenges [36]. Closer to the organizational focus of this study, mixed-methods work has assessed information security culture across international IT departments [32]. Also, practitioners have been recently surveyed on the topics of cybersecurity risks, DevSecOps practice, and emerging security priorities [37]. There is growing evidence that practitioner perception is treated as evidence, rather than as a proxy for technical measurement. Furthermore, studies of security professionals have also demonstrated the viability of recruiting this population through professional certification bodies and professional networks [38]. Professional networks and certification bodies are the approaches used by this paper.
This study contributes two features to the body of work. First, it targets perceptions of governance adaptation. Second, the survey instrument propositions are derived based on Evolutionary Governance Theory. This survey is therefore not only a description of practitioner opinion but an evaluation of whether perceptions match the way EGT predicts.

3. Evolutionary Governance Theory

ISG has conventionally been used by organizations—through the specification of policies, structures, accountability mechanisms, etc.—to direct and oversee the protection of their information assets [39,40]. As information technology evolves, systems grow more interconnected, and threat actors adapt faster than institutions. This creates an imbalance where ISG is perceived as important but lags behind the environment it is meant to regulate. This study argues that EGT offers a theoretical lens capable of capturing any imbalance and assisting in understanding and developing the required processes to address it.
Throughout this paper, a distinction is drawn between security tools and governance processes. By tools we mean the technical capabilities deployed to observe and act on the environment: monitoring and detection platforms, vulnerability scanners, endpoint and network controls, asset inventories, and similar. By governance processes we mean the organizational routines through which those capabilities are directed, evaluated, and revised. Governance processes include who decides what is monitored and how detection scope is re-prioritized when the asset base or the threat landscape shifts, the criteria by which vulnerabilities are treated, how often those criteria are themselves revisited, the escalation authority during an incident, and whether post-incident findings are carried back into policy, how often and through which processes security policies are reviewed and updated, and similar processes. Most operational activities in information security have both layers. Threat monitoring, for example, depends on a detection platform, but it depends equally on a routine that decides what that platform should look for, reviews what it returned, and adjusts its scope when the organization or its environment changes. The tool supplies capacity; the process supplies direction and revision.
This layering is what makes the asymmetry within the co-evolving pair visible. The tool layer is renewed often, and largely by others: threat intelligence feeds, detection signatures, and vendor releases arrive without organizational deliberation. The process layer is renewed on institutional time, which is usually not as often as the tool layer. An adaptive deficit, in these terms, is not a shortage of capability but a shortage in the loop that keeps capability aligned to a moving target: the environment produces variety faster than the process layer can observe it, interpret it, and revise the arrangements that respond to it.
EGT, developed principally by van Assche, Beunen, and Duineveld [41,42], considers governance not as a fixed architecture but as the continuously evolving outcome of interactions among actors, institutions, knowledge, and their environments. EGT is an interdisciplinary framework. It draws on systems theory, institutional economics, autopoiesis, post-structuralist theory, and actor–network theory, among others. EGT holds that governance arrangements co-evolve with the domains they govern: each shapes and is shaped by the other, and neither can be understood in isolation. The framework therefore offers a way to trace how the various participants (actors, objects, subjects, etc.) co-evolve and governance is shaped. Central to the theory are dependencies. More specifically, path dependence means that prior governance choices constrain present options; inter-dependence means that actors and institutions transform one another through interaction; and goal dependence means that future goals feed back into present arrangements. Governance is therefore always contingent, always in transition, and never fully in control of its own evolution.
Applying EGT to information security, this perspective reframes familiar problems. ISG and the socio-technical environment it addresses form a co-evolving pair, albeit an asymmetric one. Technology, threat landscapes, and systems interconnection and interdependence evolve at an accelerating pace, whereas governance evolves at the pace of institutions, through committees, standards cycles, regulatory revision, etc. From an EGT standpoint, a “governance gap” is not an implementation failure to be engineered away but a structural property of co-evolution between a fast-moving environment and a governance system, where the regulating system (the governance system) cannot match the variety of the system it tries to regulate. This insight echoes Ashby’s law of requisite variety [43]: a regulating system must match the variety of the system it regulates, and where it cannot, it must find alternative adaptive strategies. Essentially, a gap in ISG may not be solved simply by introducing new technology and tools, but it may require updating processes, introducing new ones, etc.
Based on the above, five propositions are derived from EGT. The first proposition (P1), regarding the environmental pressure, explores the fast-adapting pole of the co-evolving pair. Through EGT, we consider the environment not as a passive backdrop but as an active participant that can influence governance, continuously producing variety to which institutions must respond. As information technology evolves and systems become more interconnected, it is the environment that sets the adaptive demand governance must meet.
The second proposition (P2), regarding adaptive deficit, is this study’s central claim and follows EGT’s account of co-evolution. As governance co-evolves with technology but adapts more slowly, an adaptive deficit emerges in which governance cannot match the speed of change. This study considers that this asymmetry can lead to governance gaps: professionals may perceive governance as having benefited from technological change while still lacking the processes to detect and respond to environmental change. In this reading, the binding constraint lies in governance itself rather than in technical tooling.
The third proposition (P3), regarding adaptive differentiation, concerns how governance recognizes change. We argue that governance systems able to differentiate between internally emergent and externally emergent change may be better positioned to respond to environmental change, since a system that cannot locate the source of change cannot select an appropriate response.
The fourth proposition (P4), regarding resilience as adaptive response, addresses what follows when stable alignment with a fast-evolving environment cannot be achieved. We expect information security professionals to converge on cyber-resilience—institutions will seek to maintain adaptive capacity—as the necessary response, and we consider the ability to identify critical operational dependencies to be associated with this resilience orientation. We interpret this dependency–resilience link through the cyber-resilience literature rather than as evidence for EGT’s own construct of governance dependencies.
The fifth proposition (P5), regarding institutionalization, explores the distribution of these perceptions across the profession. If the dynamics described above have co-evolved into a shared professional understanding, we expect these perceptions to vary little across tenure or organization size. We advance this proposition as a theory-motivated interpretation of any observed homogeneity rather than as a discriminating test.
Together, the propositions trace a single theoretical arc: a fast-adapting environment (P1) outpaces a path-dependent governance system (P2), whose adaptive capacity turns on its ability to differentiate sources of change (P3), whose realistic response to permanent misalignment is resilience (P4), and whose resulting understandings have sedimented into shared professional knowledge (P5). By translating EGT from its origins in spatial planning and public administration into ISG, the study contributes both a theoretical reframing of the ISG gap and an empirical assessment of whether practitioners’ perceptions pattern in the way the theory predicts.

4. Research

The rise in information security incidents documented in Section 2 has multiple contributing factors. Based on the literature review, these factors include the pace of technological adoption and the increasing interdependencies between systems [21,44], the requirement for more holistic approaches that take into consideration both the human and the technical aspects in the cyber domain [45,46,47,48,49,50], and other challenges. For this research, we hypothesize that some of the contributing factors to the increasing number of attacks are the following:
H1. 
The evolution of technology is increasing the overall complexity, which impacts the security of the systems.
H2. 
Challenges are not only technical; the human aspect is still perceived as an important factor when it comes to securing systems.
H3. 
The evolution of technology is outpacing the governance processes through which the organization detects and responds to change, both internally and in its environment.
H4. 
This hypothesis is split into two claims. a. There is a growing need for resilience. b. There is a gap in the tools and processes available to meet that need.
The four hypotheses do not map one-to-one onto the five propositions, because they are formulated at the level of contributing factors to rising incidents rather than at the level of governance mechanisms. H1 is derived from P1, H3 from P2, and H4a and H4b from P4. H2 does not correspond to a single proposition; because the human factor is a co-actor of governance, it supplies supporting evidence for both P2 and P3. P3 and P5 are not carried by a dedicated hypothesis but are addressed directly in the analysis: P3 through the governance-differentiation item and its relationship with environmental detection and response capacity (Section 5.9, Table 5), and P5 through the pattern of demographic correlations across all substantive items (Section 5.9, Tables 4 and 5). H3 is stated at the level of governance processes rather than formal organizational structure. The corresponding items (18, 19, 21) ask about the routines through which governance detects, differentiates and responds to change, in the sense defined in Section 3, rather than about reporting lines, mandate or the placement of the security function. Structural change in that narrower sense is not measured by this instrument. Table 1 sets out the full mapping between propositions, hypotheses, questionnaire items, and the analysis in which each is addressed.
To validate our hypotheses and assess the extent to which those factors pose a threat to information security, we developed a closed-ended questionnaire and asked information security professionals from diverse backgrounds to answer it. The questionnaire has two objectives: the first is to quantify the opinions of professionals regarding the original hypotheses, and the second is to explore the perception of professionals on the proposed application of evolutionary methodologies in the domain of information security. This questionnaire aims to gather real-world information regarding the challenges that professionals face and the extent to which they perceive the application of EGT in information security as useful. As discussed in Section 2.2, questionnaires are well-established in the domain.

Research Methods

We used closed-ended questions because predetermined answers simplify the analysis and facilitate hypothesis testing [51]. To achieve the goal of closed-ended questions, the questionnaire relies on a Likert scale (i.e., participants must indicate the extent to which they agree or disagree with specific statements). Additionally, a set of screening questions regarding the sample was also collected and used during the statistical analysis to explore whether there are potential correlations between the answers and the size of the company, the seniority of the respondents’ roles, etc. There were 24 questions in total, excluding the consent item. Before distribution, the questionnaire was piloted with two practitioners to ensure clarity, and their responses did not count toward the overall sample.
Our first pool of respondents was the GIAC Advisory Board mailing list. GIAC is a certification body that specializes in information security and maintains the Advisory Board mailing list. The Advisory Board mailing list consists of GIAC-certified professionals who achieved certification scores above 90% (more details available at https://www.giac.org/frequently-asked-questions/?categories=advisory-board. The site was last accessed on 15 February 2026). It is important to note here that GIAC does not officially provide the exact number of members. Members come from various backgrounds (e.g., different industries, size of the organization, different aspects of information security, etc.), which offers diversity in the sample. We initially reached out to the GIAC Advisory Board in October 2024, and after about three weeks, there were N = 35 respondents. Given the initial response rate, we expanded recruitment via LinkedIn, asking information security professionals to share the questionnaire with their information security teams. The post reached approximately 200 people. We stopped collecting responses in March 2025, with a total of 65 respondents (N = 65).
For the collection of responses, Google Forms was used. For the analysis of the data, IBM SPSS Statistics 31 (SPSS) was used. Furthermore, Microsoft Excel was used for some initial visualization. Responses were collected anonymously, and the results were used only for the purposes of this research.
The analysis of the data was split into two parts. The first part was descriptive statistics, while the second explored potential correlations that could be made based on the responses to the questionnaire. Associations were examined using Spearman’s rank-order correlation (rs), with two-tailed significance evaluated at α = 0.05 throughout. The correlations reported in Section 5.9 are exploratory. They examine all pairwise associations among the substantive items and the screening variables rather than a pre-specified subset and are interpreted as hypothesis-generating rather than confirmatory. Coefficient magnitudes are described using fixed bands throughout: rs smaller than 0.10 negligible, between 0.10 and 0.29 weak, between 0.30 and 0.49 moderate, between 0.50 and 0.69 strong, and greater than 0.70 very strong. Associations that do not reach significance are reported as such and are not interpreted directionally.

5. Analysis

All demographic figures report percentages of the full sample (N = 65) and give the raw number of respondents behind each category (n) in the category label. Several categories contain fewer than five respondents, and percentages for those categories are reported for completeness rather than as stable estimates.

5.1. Gender and Age

As shown in Figure 1, our sample consists of 83.1% men and 9.2% women, while 7.7% of the respondents selected another gender identification or chose not to answer.
Regarding the age of the respondents, in our sample the intermediate age categories predominate, with the 35–44 age group leading (36.9%), followed by the 25–34 (33.8%) and 45–54 (18.5%) categories. This is shown in Figure 2.

5.2. Work Experience and Tenure in Current Role

Regarding work experience, more than half of our sample (56.9%) has been working for over 10 years, indicating that most respondents are seasoned professionals with substantial career backgrounds. The 6–10 years category accounts for 18.5% of the sample. Only 6.2% of respondents reported having 2 years of work experience or less, suggesting that the sample is predominantly composed of individuals with considerable professional maturity. The full percentages are reported in Figure 3. This distribution may reflect a greater willingness among more experienced professionals to participate in the survey, or it may be indicative of the characteristics of the target population.
Regarding the experience in their current role, we observe that 52.4% of respondents have been working in their current role for 1–4 years, 18.5% for less than one year, and 12.3% for more than 10 years. Figure 4 contains the full breakdown.

5.3. Type of Industry and Current Position

As shown in Figure 5, although most of our sample has over 10 years of total work experience, only 12% have held their current position for the same length of time. This discrepancy may suggest a tendency among respondents to change roles every few years, reflecting a pattern of professional mobility within the workforce.
Of the respondents, 38.5% hold an engineering position and 20% serve as middle managers, while only 4.6% occupy roles such as researcher, temporary employee, or student. Full analysis is shown in Figure 6. Additionally, we observe that respondents are primarily employed in the Software (20%), Other Information Industry (13.8%), and Finance and Insurance (12.3%) sectors, whereas the least represented industries include Construction (1.5%), Primary/Secondary Education (1.5%), and Publishing (1.5%). The full analysis is shown in Figure 7.
Figure 8 shows the relationship between gender and job position. We observe that in our survey, women are not represented across all job positions, with most of them holding middle manager roles in our sample. Moreover, only 9% of our sample, that is, approximately 1 in 10 respondents, are women. This may highlight the unequal representation across genders both within the cybersecurity sector and in higher-level positions.

5.4. Number of Employees

As shown in Figure 9, 46.2% of the respondents are employed in an organization that employs 5000 or more employees, whereas 7.7% are employed in an organization that employs 49 or fewer employees.

5.5. Information Security and Resilience

We investigated the respondents’ views on information security and resilience (Figure 10). The overwhelming majority of respondents strongly agree and agree with the statements “Information security must ensure that specific processes, services, etc., remain functional even in adverse situations” (95%) and “Information Security must plan ahead to respond to threats that were not originally considered (e.g., during a risk assessment phase)” (97%).

5.6. Information Security and the Human Aspect

The majority of the respondents consider the human factor to be particularly important. 75.4% agreed with the statement “Users are the weakest link in terms of security”, and 72.3% agreed that “Information security is increasingly recognizing the importance of the human factor”. At the same time, respondents appear divided regarding organizational impact, as one third of respondents agree with the view that “it has become easier for information security to estimate the organizational impact of security decisions”, while one third takes a neutral stance on the same statement and one third disagrees. Full results are shown in Figure 11.

5.7. Information Security and Organizational Change

76.9% of respondents believe that “In the last ten years, ISG has benefited from technological progress”. In contrast, 41.5% disagree with the view that “information security governance has the required processes in place to detect and respond to change in the environment (i.e., other organizations, private citizens, etc.) of the organization”. At the same time, only 21.5% disagree with the view that “Information security governance can differentiate between internally emergent and externally emergent changes”. The full results are available in Figure 12.

5.8. Evolution of Technology and Complexity

As shown in Figure 13, all respondents agreed or strongly agreed with the view that “Information technology has evolved over the last ten years”. At the same time, 72.3% strongly agree, and 23.1% agree with the view that “Information systems have become more interconnected and interdependent in the last ten years”. Regarding the view that “Information security has the required tools to respond to challenges”, only 15.4% disagree.

5.9. Exploratory Analysis and Correlations

As shown in Table 2, a Spearman non-parametric correlation analysis was applied to examine whether a statistically significant relationship exists between the view that “Information security has the required tools to respond to challenges” and the view that “Technological progress has introduced new threats for information security”. The results show that rs = +0.251, indicating a positive but weak correlation. Given the number of tests reported in this section, it is treated as exploratory. Participants who agreed more strongly that technological progress has introduced new threats also tended to agree that information security possesses the required tools to respond to them, though the association is weak.
A second Spearman correlation test (shown in Table 3) was performed to examine the relationship between “Information security has processes in place to identify critical services and their dependencies” and “Information security must ensure that specific processes, services, etc., remain functional even in adverse situations”. The test revealed a moderate positive correlation (rs = +0.351, p = 0.004).
Given our original hypotheses, we decided to proceed with the above correlations because they offer the clearest insight into the pattern of responses. Furthermore, the sample had a diverse set of participants, and these correlations would allow us to see whether specific views are shared across different organizations, etc. It can be observed that there is a positive correlation between the views that “Information systems have become more inter-connected and inter-dependent in the last ten years” and “The complexity of information systems has increased over the last ten years”. We find that the correlation is positive and moderate (rs = +0.345). Two further correlations in Table 4 reach nominal significance at the 5% level: complexity and tooling adequacy (rs = +0.258, p = 0.038), and tooling adequacy and ease of estimating organizational impact (rs = +0.246, p = 0.048). Given the number of tests reported in this section, both are treated as exploratory. Industry is reported descriptively. The three largest sectors—Software (n = 13), Other Information Industry (n = 9), and Finance and Insurance (n = 8)—together account for 46.2% of the sample, and the remaining fifteen categories contain five respondents or fewer. Response distributions on the substantive items within these three sectors did not differ visibly from the sample as a whole. With subgroups of this size, no comparison between sectors is warranted, and none is attempted.
The full associations are reported in Appendix B, Table A1. None of the associations between the substantive views and the demographic variables reached significance at the 5% level. The largest in magnitude were between organization size and the view that estimating organizational impact has become easier (rs = +0.204, p = 0.104), organization size and perceived interconnectedness (rs = +0.186, p = 0.137); all remaining coefficients were negligible. We therefore do not interpret the direction of any of these associations. The full set is reported in Table 4.
Table 5 shows that none of the demographic variables examined (years of professional experience, tenure in current role, organization size) showed a statistically significant correlation with either of the two ISG views at the 5% significance level. All corresponding p-values were well above 0.05, and the correlation coefficients were negligible, |rs| = 0.023 and |rs| = 0.187, so no substantive relationship can be inferred between respondents’ professional or organizational characteristics and their perceptions of ISG.
Nevertheless, we observe a positive, weak correlation between the view “Information security governance can differentiate between internally emergent and externally emergent changes” and the view “Information security governance has the required processes in place to detect and respond to change in the environment (i.e., other organizations, private citizens, etc.) of the organization” (rs = +0.293). This association suggests that respondents who perceived ISG as capable of distinguishing between internal and external changes also tended to view it as having adequate detection and response processes, and vice versa. This is not unexpected, as both items reflect confidence in the overall capability of ISG.
The full results are reported in Appendix B, Table A2. The largest in magnitude is between years of professional experience and the view that ISG has the required processes to detect and respond to environmental change (rs = −0.187, p = 0.135); we do not interpret the direction of these associations.

6. Discussion

This section discusses the findings of the analysis and their relation to the four research hypotheses (H1–H4) originally posed, situates the analysis within the broader information security literature, and addresses challenges and shortcomings that future work could take up. Throughout, the evidence is perceptual. The questionnaire records how information security professionals characterize their governance environment; it does not observe governance processes or their co-evolution with the systems they manage. Findings are therefore reported as consistent or inconsistent with an EGT-based reading, not as confirmation of the theory.
H1, that “The evolution of technology is increasing overall complexity, which impacts the security of systems” (P1), is strongly supported by respondents’ perceptions. All respondents (100%) agreed that information technology has evolved over the last ten years, and an overwhelming majority (72.3% strongly agree, 23.1% agree) confirmed that information systems have become more interconnected and interdependent. These findings are consistent with the observations of Geer [21], who argued that faster and broader adoption of new technologies has increased systemic interdependence and introduced hidden complexity. More recent evidence shows that third-party and supply chain interdependence is now the leading cyber concern reported by large organizations, and documented incidents exhibit the cascading dynamics Geer anticipated [12,22].
At these levels of agreement, the perception is shared throughout the sample rather than confined to particular sectors or roles. A statistically significant but weak positive correlation links the view that technological progress has introduced new threats with the view that information security has the required tools to respond to them (rs = +0.251). Awareness of new threats therefore coexists with confidence in available defenses. The weakness of the association matters, however: a substantial number of respondents recognize emerging threats without regarding current tools as adequate, and the reverse also holds. Finally, views on system interconnectedness and system complexity are themselves moderately correlated (rs = +0.345), which is what the argument that interdependence drives complexity would predict [21,44]. This aligns with the literature on digital transformation and cybersecurity challenges [25] that emphasizes that new domains such as IoT and cloud computing not only expand the attack surface but fundamentally alter the nature of the security problem.
For H2, “Challenges are not only technical; the human aspect is still perceived as an important factor” (P2), the analysis provides substantial support for the perceived importance of the human factor. A clear majority of respondents (75.4%) agreed that users are the weakest link in terms of security, and 72.3% acknowledged that information security is increasingly recognizing the importance of the human factor. This pattern matches a well-established body of literature identifying human behavior as a critical factor in information security [45,46,49,50]. This is a respondent perception, not an observation of user behavior, and the item does not identify what produces it. One interesting finding is the divided opinion on estimating organizational impact. Approximately one third of the respondents agreed that it has become easier to estimate the organizational impact of security decisions, one third took a neutral stance, and roughly 29% disagreed. The lack of consensus here may reflect the inherent difficulty of bridging the technical and human domains, which is also recognized in the literature [46,47]. A weak negative association between estimating organizational impact and total years of experience (rs = −0.128) was observed but did not reach statistical significance; this direction is worth exploring with larger samples. In summary, the data confirm that the human factor is perceived as important and a growing challenge.
H3, “The evolution of technology is outpacing the governance processes through which the organization detects and responds to change, both internally and in its environment” (P2), is partially supported by the data. While the majority of respondents agreed that ISG has benefited from technological progress, a substantial proportion of respondents (41.5%) disagree that ISG has the required processes in place to detect and respond to changes in the environment of the organization. This tension may suggest that governance processes are, currently, outpaced by technological change. One notable finding is that none of the demographic variables showed a statistically significant correlation with the ISG views. All p-values were well above 0.05, and the correlation coefficients were negligible. That this pattern holds across every demographic group in the sample suggests the challenges are recognized irrespective of setting, at least among the participants of this study. Although this finding is consistent with the arguments for adaptive, context-aware security policy development [28], future research should establish that this is demonstrated in larger samples. Future research on H3 could benefit from mixed methods approaches that would allow respondents to describe specific transformations in their organizational context, which would allow a researcher to measure how organizational structures have been affected by technological progress.
Finally, H4 is evaluated as two separate claims (P4). H4a states that “There is a growing need for resilience”; H4b states that “There is a gap in the tools and processes available to meet that need”. The data strongly supports H4a. 95% of respondents agree that information security must ensure that specific processes remain functional despite any adverse events, and 97% agree that information security must plan to respond to threats that were not originally considered. Both figures track the growing cyber-resilience literature and its central claim that prevention alone cannot address “unknown unknowns” [20]. The near unanimity among respondents indicates that resilience is not a niche concern within this group, though a sample recruited through a certification body is one in which broad acceptance of resilience is particularly likely.
At the same time, one statistically significant finding is the correlation between identifying critical services and their dependencies and ensuring functionality in adverse situations (rs = +0.351, p = 0.004), which is also the largest correlation observed in this study. This suggests that professionals who value the identification of critical dependencies are also those who prioritize continuity and resilience. The strength of this relationship, significant at the 1% level, is consistent with the theoretical link between asset identification and resilience planning: effective resilience requires a clear understanding of what needs to be protected and how components depend on one another. However, the evidence for a gap in tools and processes is more mixed than H4 anticipated. Only 15.4% of respondents disagreed that information security has the required tools to respond to challenges. The tooling landscape therefore is perceived as reasonably adequate.
This apparent tension with H4 can be reconciled by interpreting the gap as processual and organizational rather than technical: tools may exist without being effectively integrated, deployed, or adapted to a rapidly evolving threat landscape, a reading reinforced by the 41.5% who disagreed that ISG has the processes to detect and respond to environmental changes. Sample composition may also play a role, as the predominance of seasoned professionals working in large organizations (46% in firms with 5000+ employees) may reflect environments with mature, well-resourced security programs that are not representative of the broader profession. Either way, the core finding is clear: resilience is broadly perceived as essential, but the gap lies less in the absence of tools and more in the organizational and processual capacity to deploy them effectively.
While the questionnaire did not ask respondents to endorse EGT explicitly, several items tap directly into P1–P5. EGT emphasizes that governance systems co-evolve with the systems they govern, that adaptive governance must differentiate between internally and externally emergent change, and that the interplay between structure and environment shapes the capacity for response. The association between the views that ISG can differentiate between internally and externally emergent changes and that ISG has the required processes to detect and respond to environmental change (rs = +0.293, p = 0.018) is the most direct evidence bearing on P3. Given the number of exploratory tests reported in Section 5.9 and the size of the sample, we advance it as suggestive rather than established. It indicates that these two capacities, which EGT treats as linked dimensions of adaptive governance, are also perceived as linked by practitioners.
At the same time, the finding that 41.5% of respondents disagree that ISG has the processes in place to detect and respond to environmental change, juxtaposed with the 76.9% who agree that ISG has benefited from technological progress, is consistent with the adaptive deficit anticipated by P2, which EGT predicts when governance cannot keep pace with the systems it manages. Combined with the near-unanimous agreement on the need for resilience, continuity, and planning for unanticipated threats, the challenges practitioners identify fall within the range of phenomena EGT is designed to describe. This correspondence is in part by construction, since the questionnaire items were derived from the propositions; it therefore indicates coherence between the instrument and the theory rather than an independent test of it. What the study does establish is that EGT can be operationalized in this domain: its propositions translate into measurable items, and practitioners’ perceptions pattern in the way those propositions anticipate. For a theory carried from spatial planning and public administration into ISG, that is the necessary first result, and it identifies the specific relationships that subsequent work—designs able to observe governance processes directly—can test.
P5 is addressed by a recurring finding across the correlation analyses: the absence of statistically significant relationships between demographic variables and the substantive views on information security. Neither years of experience, tenure, nor organization size showed significant correlations with the ISG items, the complexity items, or the resilience items, and while the sample size (N = 65) limits the statistical power to detect small effects, the consistency of this null finding across multiple tests is noteworthy. One interpretation is that the challenges identified (increasing complexity, the human factor, governance gaps, and the need for resilience) are perceived similarly because they are systemic, with information security professionals facing a fundamentally similar set of pressures regardless of the context they operate in, consistent with the systemic nature of the challenges described in the literature [21,25,44].
Another explanation relates to sample homogeneity: the recruitment strategy, primarily through the GIAC Advisory Board and supplemented by LinkedIn outreach, may have produced a sample that, while diverse in industry and organization size, is relatively homogeneous in professional training and awareness, making demographic differences less likely to produce variation in responses. This should be addressed in future research by targeting more diverse populations (different career stages, different regulatory environments, different industries) and by expanding the sample size.
Overall, the data make the case for security strategies that explicitly account for complexity, inter-dependence, and the human factor. The strong consensus on resilience combined with the perceived gap in governance processes indicates that organizations should invest not only in tools but in the organizational capacity that takes into consideration a rapidly changing environment. Two of the significant correlations merit further investigation: threat awareness with tool confidence, and dependency identification with resilience orientation. Both point to conceptual relationships that larger samples, longitudinal designs, and multivariate methods could test directly. More broadly, a framework connecting technological evolution, complexity, and governance adaptability would benefit from deeper engagement with EGT as a lens for understanding how governance structures co-evolve with the systems they are designed to manage.
This study has several limitations. The sample size of 65 respondents, while sufficient for exploratory analysis, limits the statistical power of the correlation tests and restricts the use of more sophisticated multivariate methods. With N = 65, the study has approximately 80% power to detect a correlation of rs ≈ 0.34 at α = 0.05, which is larger than any association observed here. The correlation analysis is therefore underpowered for the effect sizes of interest. Section 5.9 further reports a large number of pairwise tests without correction for multiple comparisons, and at α = 0.05 a small number of nominally significant results would be expected by chance alone. We therefore treat the correlations throughout as exploratory and hypothesis-generating rather than as established findings. The same limitation applies in reverse to the absence of demographic associations reported throughout. At this sample size, failure to detect a relationship is weak evidence that no relationship exists. The demographic breakdowns in Section 5 are likewise descriptive only. Several subgroups—notably the gender categories and the majority of the eighteen industry categories—contain fewer than five respondents, and the percentages reported for them are given for completeness rather than as estimates of population proportions.
The reliance on the GIAC Advisory Board as the primary recruitment channel introduces a potential selection bias toward highly qualified, experienced professionals who may not be representative of the broader information security workforce. Furthermore, GIAC does not provide the total number of people on its mailing list, making it hard to reason about the response rate. Additionally, the questionnaire relied on Likert-scale items that capture perceptions but not behaviors or outcomes. Respondents’ views on the adequacy of tools or governance processes may therefore not correspond to the actual state of affairs in their organizations. It is important to note here that many items, including “Users are the weakest link in terms of security”, are worded as assertions. Agreement with such an item records endorsement of a framing rather than an observation, and the instrument does not distinguish between the mechanisms that might produce that endorsement. Finally, the cross-sectional design captures a single point in time and cannot establish causal relationships between the variables examined. Although the findings are interpreted and evaluated through EGT, this study does not establish that EGT explains the findings better than competing accounts.
Despite these limitations, the study provides a valuable empirical contribution by quantifying professional perceptions across a diverse set of information security challenges. Additionally, it identifies a deficiency in governance processes and highlights a need for dependency mapping. The practical implication follows from where respondents locate the constraint: in governance capability rather than in tooling. Stronger governance processes would also improve the value extracted from the tools already deployed. For example, dependency mapping can be used both to understand technical dependencies (e.g., supply chain risks, cloud vendor dependencies, etc.) and to understand the governance processes and available options (e.g., understanding constraints from previous decisions, compliance requirements, etc.). Similarly, resilience and adaptability metrics could be used to provide real-time board-level insights. The consistency of findings across demographic groups, and the alignment of results with established theoretical arguments, supports the validity of the conclusions drawn while also highlighting clear directions for future research.

7. Conclusions

This study investigated the perceptions of information security professionals regarding the challenges posed by technological evolution, complexity, the human factor, organizational governance, and the need for resilience. Based on a quantitative analysis of 65 questionnaire responses from GIAC-certified professionals and broader industry participants recruited through LinkedIn, four hypotheses (H1–H4) were examined, and, through them, the five propositions (P1–P5) were derived. Section 6 evaluates each hypothesis and proposition in detail. What carries beyond the individual verdicts is the shape of the pattern: near-unanimous agreement that the environment is evolving and that resilience is necessary, coexisting with a substantial minority reporting that governance lacks the processes to track that evolution, and no demographic variable predicting either view.
The study contributes to the information security literature by quantifying professional perceptions on a set of challenges that are often discussed theoretically but less frequently examined through empirical survey work. Its limitations, set out in Section 6, point directly to the work that should follow. More specifically, as part of our future work, we aim to develop a governance framework built using EGT as the main kernel theory, implement it in various organizations, and assess its effectiveness ex-post.
The absence of significant relationships between demographic variables and the substantive views (P5) suggests that these challenges are shared across the sample, and this study reads that uniformity through EGT. Organizations in a field can converge because regulators, professional norms, and similar pressures push them towards the same arrangements [33,34]. Future work should explore perceptions through institutional theory and compare with EGT both within the same domain and cross-domain. For example, a study could explore perceptions after a regulatory change or a similar event across the same domain or compare perceptions between practitioners working in the United States and the EU where regulatory requirements are different. Similarly, cross-domain research between information security, which is relatively established as a domain, and a new domain can be conducted.
Finally, and most important, these findings point to a governance-adaptation gap: governance struggling to keep pace with a fast-evolving environment. What makes this more than a local observation is that nothing in the pattern is specific to information security. The deficit our respondents report is a rate differential: the governed system changing faster than the arrangements meant to steer it. Any domain exhibiting that differential should exhibit the same signature. Artificial intelligence governance is the clearest current instance, with capability advancing considerably faster than the institutions, oversight mechanisms, and norms meant to steer it [52]. Read through EGT, the parallel is structural rather than merely rhetorical: in both domains governance must co-evolve with the object it governs, and in both it must distinguish change emerging inside the organization from change emerging in its environment. AI governance can be used as a domain to conduct cross-domain research as mentioned previously. For ISG specifically, the surveyed practitioners report that the constraint lies in the organizational capacity to adapt. Although the data support only tentative recommendations, the principal one is investing in adaptive governance capacity, rather than technical controls alone. In this regard, examining other fast-moving technology domains may be a promising direction for future work.

Author Contributions

Conceptualization, E.M. and A.D.K.; Methodology, E.M. and A.D.K.; Investigation, E.M.; Formal analysis, A.T.; Writing—original draft, E.M. and A.T.; Writing—review and editing, A.D.K. and A.T.; Supervision, A.D.K. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

The study was approved by the Ethics Committee of Hellenic Open University (protocol code 66/11-04-2024, approved on the 16 July 2024).

Informed Consent Statement

Informed consent was obtained from all subjects involved in the study.

Data Availability Statement

The anonymized dataset is available from the corresponding author upon reasonable request.

Conflicts of Interest

The authors declare no conflicts of interest.

Appendix A

The questionnaire was administered online via Google Forms between October 2024 and March 2025. All responses were collected anonymously and used solely for the purposes of this research. The questionnaire consisted of a consent item, seven demographic and screening questions, and seventeen substantive Likert-scale items grouped thematically. Substantive items were measured on a five-point Likert scale with the options: Strongly disagree, Disagree, Neither agree nor disagree, Agree, and Strongly agree. The full set of items is reproduced below in the order in which they appeared to respondents.

Appendix A.1. Consent

  • I consent to participate.
Response: I consent to participate (required to proceed).

Appendix A.2. Demographic and Screening Questions

2.
What age group do you belong to?
Response options: 18–24; 25–34; 35–44; 45–54; 55–64; 65 or older.
3.
What gender do you identify as?
Response options: Female; Male; Transgender female; Transgender male; Non-binary; Prefer not to answer; Other.
4.
How long have you worked at your current role?
Response options: Less than one year; 1–2 years; 3–4 years; 5–6 years; 6–10 years; More than 10 years; Don’t know/Not sure.
5.
How many years of work experience do you have in total?
Response options: Less than a year; 1–2 years; 3–4 years; 5–6 years; 6–10 years; More than 10 years.
6.
Which of the following categories best describes the industry you primarily work in (regardless of your actual position)?
Response options: Computer and Electronics Manufacturing; Construction; Finance and Insurance; Government and Public Administration; Health Care and Social Assistance; Hotel and Food Services; Information Services and Data Processing; Legal Services; Other Information Industry; Other Manufacturing; Primary/Secondary (K–12) Education; Publishing; Retail; Scientific or Technical Services; Software; Telecommunications; Transportation and Warehousing; Utilities.
7.
How many employees work, in total, for your organization or firm?
Response options: 1–49; 50–999; 1000–4999; 5000 or more.
8.
Which of the following best describes your current position?
Response options: Analyst; Consultant; Engineer; Junior Management; Middle Management; Upper Management; Researcher; Student; Temporary Employee; Other.

Appendix A.3. Substantive Items (Five-Point Likert Scale)

All items in this section were measured on a five-point Likert scale. Response options for every item were: Strongly disagree, Disagree, Neither agree nor disagree, Agree, Strongly agree.

Appendix A.3.1. Evolution of Technology and Complexity

9.
Information technology has evolved over the last ten years.
10.
Information systems have become more inter-connected and inter-dependent in the last ten years.
11.
The complexity of information systems has increased over the last ten years.
12.
Technological progress has introduced new threats for information security.

Appendix A.3.2. Information Security Tools and Capacity

13.
Information security has the required tools to respond to challenges.
14.
Information security has the required tools to manage the complexity of information systems.

Appendix A.3.3. The Human Factor and Organizational Impact

15.
Information security is, increasingly, recognizing the importance of the human factor.
16.
It has become easier for information security to estimate the organizational impact of security decisions.
17.
Users are the weakest link in terms of security.

Appendix A.3.4. Information Security Governance and Organizational Change

18.
Information security governance has the required processes in place to detect and respond to organizational change internally.
19.
Information security governance has the required processes in place to detect and respond to change in the environment (i.e., other organizations, private citizens, etc.) of the organization.
20.
Information security governance can differentiate between internally emergent and externally emergent changes.
21.
In the last ten years, information security governance has benefited from technological progress.

Appendix A.3.5. Resilience and Continuity

22.
Information security must plan ahead to respond to threats that were not originally considered (e.g., during a risk assessment phase).
23.
Information security must ensure that specific processes, services, etc., remain functional even in adverse situations.
24.
Information security is well positioned to ensure that critical services remain functional even in adverse situations.
25.
Information security has processes in place to identify critical services and their dependencies.

Appendix B

Table A1. Spearman correlations among technology, complexity and tooling views and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated. Full labels available in Appendix A.
Table A1. Spearman correlations among technology, complexity and tooling views and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated. Full labels available in Appendix A.
12345678
Current Role Tenure (1).rs1.0000.146−0.094−0.1130.109−0.009−0.141−0.044
p.0.2450.4550.3720.3870.9440.2640.731
Total Work Experience (2).rs0.1461.000−0.0770.058−0.0020.033−0.158−0.128
p0.245.0.5400.6450.9860.7960.2090.310
Primary industry (3).rs−0.094−0.0771.0000.084−0.0380.1410.0230.023
p0.4550.540.0.5060.7630.2630.8550.856
Organization Size (4).rs−0.1130.0580.0841.0000.186−0.0800.0690.204
p0.3720.6450.506.0.1370.5280.5830.104
Increased interconnectivity & interdependence in information systems (5).rs0.109−0.002−0.0380.1861.0000.345 **0.1980.047
p0.3870.9860.7630.137.0.0050.1140.708
Information systems grew more complex (6).rs−0.0090.0330.141−0.0800.345 **1.0000.258 *−0.005
p0.9440.7960.2630.5280.005.0.0380.967
Security tools meet current response needs (7).rs−0.141−0.1580.0230.0690.1980.258 *1.0000.246 *
p0.2640.2090.8550.5830.1140.038.0.048
Easier to estimate IS decisions’ organizational impact (8).rs−0.044−0.1280.0230.2040.047−0.0050.246 *1.000
p0.7310.3100.8560.1040.7080.9670.048.
* Correlation is significant at the 0.05 level (2-tailed). ** Correlation is significant at the 0.01 level (2-tailed).
Table A2. Spearman correlations among ISG and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated. Full labels available in Appendix A.
Table A2. Spearman correlations among ISG and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated. Full labels available in Appendix A.
123456
ISG differentiation between internal and external change. (1)rs1.0000.293 *0.1260.0230.087−0.157
p.0.0180.3160.8580.4890.211
ISG can detect and respond to changes in the environment (2)rs0.293 *1.000−0.084−0.1870.088−0.054
p0.018.0.5080.1350.4860.672
Current Role Tenure (3).rs0.126−0.0841.0000.146−0.094−0.113
p0.3160.508.0.2450.4550.372
Total Work Experience (4).rs0.023−0.1870.1461.000−0.0770.058
p0.8580.1350.245.0.5400.645
Primary industry (5).rs0.0870.088−0.094−0.0771.0000.084
p0.4890.4860.4550.540.0.506
Organization Size (6).rs−0.157−0.054−0.1130.0580.0841.000
p0.2110.6720.3720.6450.506.
* Correlation is significant at the 0.05 level (2-tailed).

References

  1. Treleaven, P.; Barnett, J.; Brown, D.; Bud, A.; Fenoglio, E.; Kerrigan, C.; Koshiyama, A.; Sfeir-Tait, S.; Schoernig, M. The Future of Cybercrime: AI and Emerging Technologies Are Creating a Cybercrime Tsunami. SSRN J. 2023. [Google Scholar] [CrossRef] [Scilit]
  2. European Union. Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC. Off. J. Eur. Union 2022, OJ L 333, 164–198. Available online: https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng (accessed on 14 September 2026).
  3. European Union. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on Measures for a High Common Level of Cybersecurity across the Union. Off. J. Eur. Union 2022, OJ L 333, 80–152. Available online: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng (accessed on 14 September 2026).
  4. President’s commission on critical infrastructure protection (PCCIP). Critical Foundations: Protecting America’s Infrastructures; PCCIP: Washington, DC, USA, 1997; Available online: https://nsarchive.gwu.edu/document/21584-document-02-president-s-commission-critical (accessed on 14 September 2026).
  5. European Union Agency for Cybersecurity (ENISA). 2024 Report on the State of Cybersecurity in the Union; Office of the European Union: Luxembourg, 2024; Available online: https://www.enisa.europa.eu/publications/2024-report-on-the-state-of-the-cybersecurity-in-the-union (accessed on 14 September 2026).
  6. European Union. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). Off. J. Eur. Union 2024. Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847 (accessed on 14 September 2026).
  7. Bendovschi, A. Cyber-Attacks–Trends, Patterns and Security Countermeasures. Procedia Econ. Financ. 2015, 28, 24–31. [Google Scholar] [CrossRef] [Scilit]
  8. IC3 FBI. Internet Crime Report 2023; Federal Bureau of Investigations: Washington, DC, USA, 2024. Available online: https://www.ic3.gov/annualreport/reports/2024_ic3report.pdf (accessed on 14 September 2026).
  9. IC3 FBI. Internet Crime Report 2024; Federal Bureau of Investigations: Washington, DC, USA, 2025. Available online: https://www.ic3.gov/annualreport/reports/2023_ic3report.pdf (accessed on 14 September 2026).
  10. IC3 FBI. Internet Crime Report 2022; Federal Bureau of Investigations: Washington, DC, USA, 2023. Available online: https://www.ic3.gov/AnnualReport/Reports/2022_ic3report.Pdf (accessed on 14 September 2026).
  11. Sharif, M.; Mohammed, M. A Literature Review of Financial Losses Statistics for Cyber Security and Future Trend. World J. Adv. Res. Rev. 2022, 15, 138–156. [Google Scholar] [CrossRef] [Scilit]
  12. World Economic Forum. Cybersecurity Outlook 2026; World Economic Forum: Geneva, Switzerland, 2026. [Google Scholar]
  13. Gupta, M.; Akiri, C.; Aryal, K.; Parker, E.; Praharaj, L. From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy. IEEE Access 2023, 11, 80218–80245. [Google Scholar] [CrossRef] [Scilit]
  14. Cetin, O.; Birinci, B.; Uysal, C.; Arief, B. Exploring the Cybercrime Potential of LLMs: A Focus on Phishing and Malware Generation. In Cybersecurity; Praca, I., Bernardi, S., Inacio, P.R.M., Eds.; Communications in Computer and Information Science; Springer Nature: Cham, Switzerland, 2025; Volume 2500, pp. 98–115. ISBN 978-3-031-94854-1. [Google Scholar]
  15. European Union Agency for Law Enforcement Cooperation. Internet Organised Crime Threat Assessment (IOCTA); Publications Office of the European Union: Luxembourg, 2024.
  16. Gulyas, O.; Kiss, G. Impact of Cyber-Attacks on the Financial Institutions. Procedia Comput. Sci. 2023, 219, 84–90. [Google Scholar] [CrossRef] [Scilit]
  17. Mostaghel, R.; Oghazi, P.; Parida, V.; Sohrabpour, V. Digitalization Driven Retail Business Model Innovation: Evaluation of Past and Avenues for Future Research Trends. J. Bus. Res. 2022, 146, 134–145. [Google Scholar] [CrossRef] [Scilit]
  18. European Union. Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. Off. J. Eur. Union 2024. Available online: https://eur-lex.europa.eu/eli/reg/2024/1183/oj (accessed on 14 September 2026).
  19. Sharif, A.; Ranzi, M.; Carbone, R.; Sciarretta, G.; Marino, F.A.; Ranise, S. The eIDAS Regulation: A Survey of Technological Trends for European Electronic Identity Schemes. Appl. Sci. 2022, 12, 12679. [Google Scholar] [CrossRef] [Scilit]
  20. Tzavara, V.; Vassiliadis, S. Tracing the Evolution of Cyber Resilience: A Historical and Conceptual Review. Int. J. Inf. Secur. 2024, 23, 1695–1719. [Google Scholar] [CrossRef] [Scilit]
  21. Geer, D.E. A Rubicon; Aegis Series Paper No. 1801; Hoover Institution, Stanford University: Stanford, CA, USA, 2018; 20p, Available online: https://s3.documentcloud.org/documents/4366740/Geer-Webready-Updated.pdf (accessed on 14 September 2026).
  22. Vargas, P.; Tien, I. Impacts of 5G on Cyber-Physical Risks for Interdependent Connected Smart Critical Infrastructure Systems. Int. J. Crit. Infrastruct. Prot. 2023, 42, 100617. [Google Scholar] [CrossRef] [Scilit]
  23. Arafat, M. Information Security Management System Challenges within a Cloud Computing Environment. In Proceedings of the 2nd International Conference on Future Networks and Distributed Systems, Amman, Jordan, 26 June 2018; pp. 1–6. [Google Scholar]
  24. Nurse, J.R.C.; Creese, S.; De Roure, D. Security Risk Assessment in Internet of Things Systems. IT Prof. 2017, 19, 20–26. [Google Scholar] [CrossRef] [Scilit]
  25. Saeed, S.; Altamimi, S.A.; Alkayyal, N.A.; Alshehri, E.; Alabbad, D.A. Digital Transformation and Cybersecurity Challenges for Businesses Resilience: Issues and Recommendations. Sensors 2023, 23, 6666. [Google Scholar] [CrossRef] [Scilit]
  26. Dritsas, E.; Trigka, M. A Survey on Cybersecurity in IoT. Future Internet 2025, 17, 30. [Google Scholar] [CrossRef] [Scilit]
  27. Ukeje, N.; Gutierrez, J.; Petrova, K. Information Security and Privacy Challenges of Cloud Computing for Government Adoption: A Systematic Review. Int. J. Inf. Secur. 2024, 23, 1459–1475. [Google Scholar] [CrossRef] [Scilit]
  28. Paananen, H.; Lapke, M.; Siponen, M. State of the Art in Information Security Policy Development. Comput. Secur. 2020, 88, 101608. [Google Scholar] [CrossRef] [Scilit]
  29. Woods, D.D. Resilience Engineering: Concepts and Precepts, 1st ed.; Hollnagel, E., Woods, D.D., Leveson, N., Eds.; CRC Press: Boca Raton, FL, USA, 2017; ISBN 978-1-315-60568-5. [Google Scholar]
  30. Hilger, R.P. From Cybersecurity to Cyber Resilience: A Systemic and Scalable Approach for Improving Resilience and Adaptive Capacity. J. Cybersecur. 2026, 12, 1–10. [Google Scholar] [CrossRef] [Scilit]
  31. Trist, E.L.; Bamforth, K.W. Some Social and Psychological Consequences of the Longwall Method of Coal-Getting: An Examination of the Psychological Situation and Defences of a Work Group in Relation to the Social Structure and Technological Content of the Work System. Hum. Relat. 1951, 4, 3–38. [Google Scholar] [CrossRef] [Scilit]
  32. Zanke, A.; Weber, T.; Dornheim, P.; Engel, M. Assessing Information Security Culture: A Mixed-Methods Approach to Navigating Challenges in International Corporate IT Departments. Comput. Secur. 2024, 144, 103938. [Google Scholar] [CrossRef] [Scilit]
  33. DiMaggio, P.J.; Powell, W.W. The Iron Cage Revisited: Institutional Isomorphism and Collective Rationality in Organizational Fields. Am. Sociol. Rev. 1983, 48, 147. [Google Scholar] [CrossRef] [Scilit]
  34. Hsu, C.; Lee, J.-N.; Straub, D.W. Institutional Influences on Information Systems Security Innovations. Inf. Syst. Res. 2012, 23, 918–939. [Google Scholar] [CrossRef] [Scilit]
  35. Takacs, J.; Pogatsnik, M. A Comprehensive Study on Cybersecurity Awareness: Adaptation and Validation of a Questionnaire in Hungarian Higher Technical Education. Acta Polytech. Hung. 2024, 21, 533–552. [Google Scholar] [CrossRef] [Scilit]
  36. Riyaz Belgaum, M.; Alansari, Z.; Jain, R.; Alshaer, J. A Framework for Evaluation of Cyber Security Challenges in Smart Cities. In Proceedings of the Smart Cities Symposium 2018, Zallaq, Bahrain, 22–23 April 2018; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
  37. Canedo, E.D.; Sposito, S.L.; Peotta, L.; Nunes, R.R.; Ladeira, M. Cybersecurity Risks, DevSecOps Challenges, and Emerging Security Priorities: An Empirical Study across Brazilian Organizations. Comput. Secur. 2026, 170, 105026. [Google Scholar] [CrossRef] [Scilit]
  38. Katcher, S.; Wang, L.; Yang, C.; Messdaghi, C.; Mazurek, M.L.; Chetty, M.; Fulton, K.R.; Votipka, D. A Survey of Cybersecurity Professionals’ Perceptions and Experiences of Safety and Belonging in the Community. In Proceedings of the Twentieth Symposium on Usable Privacy and Security, Philadelphia, PA, USA, 11–13 August 2024; pp. 1–20. [Google Scholar]
  39. Von Solms, B. Information Security—The Fourth Wave. Comput. Secur. 2006, 25, 165–168. [Google Scholar] [CrossRef] [Scilit]
  40. Vaya-Arboledas, A.; Ferrer-Oliva, M.; Medina-Merodio, J.A. Evolution and Perspectives in IT Governance: A Systematic Literature Review. Computers 2025, 14, 520. [Google Scholar] [CrossRef] [Scilit]
  41. Beunen, R.; Van Assche, K.; Duineveld, M. (Eds.) Evolutionary Governance Theory: Theory and Applications; Springer International Publishing: Cham, Switzerland, 2015; ISBN 978-3-319-12273-1. [Google Scholar]
  42. Van Assche, K.; Beunen, R.; Duineveld, M. Evolutionary Governance Theory: An Introduction; Springer Briefs in Economics; Springer International Publishing: Cham, Switzerland, 2014; ISBN 978-3-319-00983-4. [Google Scholar]
  43. Ashby, W.R. An Introduction to Cybernetics; Chapman & Hall: London, UK, 1956. [Google Scholar]
  44. Lewis, T.G. Critical Infrastructure Protection in Homeland Security: Defending a Networked Nation; John Wiley & Sons, Inc.: Hoboken, NJ, USA, 2006; ISBN 978-0-471-78954-3. [Google Scholar]
  45. Cram, W.A.; Proudfoot, J.G.; D’Arcy, J. Organizational Information Security Policies: A Review and Research Framework. Eur. J. Inf. Syst. 2017, 26, 605–641. [Google Scholar] [CrossRef] [Scilit]
  46. Malatji, M.; Marnewick, A.; von Solms, S. Validation of a Socio-Technical Management Process for Optimising Cybersecurity Practices. Comput. Secur. 2020, 95, 101846. [Google Scholar] [CrossRef] [Scilit]
  47. Nabben, K. Blockchain Security as “People Security”: Applying Sociotechnical Security to Blockchain Technology. Front. Comput. Sci. 2021, 2, 599406. [Google Scholar] [CrossRef] [Scilit]
  48. Peersman, C.; Williams, E.; Edwards, M.; Rashid, A. Understanding Motivations and Characteristics of Financially-Motivated Cybercriminals. arXiv 2022, arXiv:2203.08642. [Google Scholar]
  49. Soomro, Z.A.; Shah, M.H.; Ahmed, J. Information Security Management Needs More Holistic Approach: A Literature Review. Int. J. Inf. Manag. 2016, 36, 215–225. [Google Scholar] [CrossRef] [Scilit]
  50. Whitman, M.E.; Mattord, H.J. The Enemy Is Still at the Gates: Threats to Information Security Revisited. In Proceedings of the 2010 Information Security Curriculum Development Conference on–InfoSecCD ’10, Kennesaw, GE, USA, 1–3 October 2010; p. 95. [Google Scholar]
  51. Stockemer, D. Quantitative Methods for the Social Sciences: A Practical Introduction with Examples in SPSS and Stata; Springer: Berlin/Heidelberg, Germany; New York, NY, USA, 2018; ISBN 978-3-319-99117-7. [Google Scholar]
  52. Currie, W.L.; Leimeister, J.M.; Schlagwein, D.; Willcocks, L. Rethinking Technology Regulation in the Age of AI Risks. J. Inf. Technol. 2025, 40, 236–245. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Gender. Source: authors’ own survey data (N = 65).
Figure 1. Gender. Source: authors’ own survey data (N = 65).
Jcp 06 00165 g001
Figure 2. Age. Source: authors’ own survey data (N = 65).
Figure 2. Age. Source: authors’ own survey data (N = 65).
Jcp 06 00165 g002
Figure 3. Years of work experience. Source: authors’ own survey data (N = 65).
Figure 3. Years of work experience. Source: authors’ own survey data (N = 65).
Jcp 06 00165 g003
Figure 4. Years in current role. Source: authors’ own survey data (N = 65). Category labels give the number of respondents (n). “Don’t know/Not sure” responses (n = 2) are included, so the categories sum to 100%.
Figure 4. Years in current role. Source: authors’ own survey data (N = 65). Category labels give the number of respondents (n). “Don’t know/Not sure” responses (n = 2) are included, so the categories sum to 100%.
Jcp 06 00165 g004
Figure 5. Tenure in current role compared with total work experience. Two series plotted on the same category axis; bars show the percentage of respondents, and category labels give the number behind each bar (n). Source: authors’ own survey data (N = 65).
Figure 5. Tenure in current role compared with total work experience. Two series plotted on the same category axis; bars show the percentage of respondents, and category labels give the number behind each bar (n). Source: authors’ own survey data (N = 65).
Jcp 06 00165 g005
Figure 6. Current position. Source: authors’ own survey data (N = 65). Categories are ordered by frequency and labeled with the number of respondents (n); four of the ten categories contain one or two respondents.
Figure 6. Current position. Source: authors’ own survey data (N = 65). Categories are ordered by frequency and labeled with the number of respondents (n); four of the ten categories contain one or two respondents.
Jcp 06 00165 g006
Figure 7. Type of Industry. Source: authors’ own survey data (N = 65). Categories are ordered by frequency and labeled with the number of respondents (n). Ten of the eighteen categories contain two or fewer respondents.
Figure 7. Type of Industry. Source: authors’ own survey data (N = 65). Categories are ordered by frequency and labeled with the number of respondents (n). Ten of the eighteen categories contain two or fewer respondents.
Jcp 06 00165 g007
Figure 8. Current position by gender, raw counts. Source: authors’ own survey data (N = 65). Cells are counts rather than percentages of the sample.
Figure 8. Current position by gender, raw counts. Source: authors’ own survey data (N = 65). Cells are counts rather than percentages of the sample.
Jcp 06 00165 g008
Figure 9. Number of employees in the organization. Source: authors’ own survey data (N = 65). Category labels give the number of respondents (n).
Figure 9. Number of employees in the organization. Source: authors’ own survey data (N = 65). Category labels give the number of respondents (n).
Jcp 06 00165 g009
Figure 10. Information security and resilience. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Figure 10. Information security and resilience. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Jcp 06 00165 g010
Figure 11. Information security and the human aspect. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Figure 11. Information security and the human aspect. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Jcp 06 00165 g011
Figure 12. Information security and organizational change. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Figure 12. Information security and organizational change. Source: authors’ own survey data (N = 65). Item labels are abbreviated; full labels are available in Appendix A.
Jcp 06 00165 g012
Figure 13. Evolution of technology and complexity. Source: authors’ own survey data (N = 65).
Figure 13. Evolution of technology and complexity. Source: authors’ own survey data (N = 65).
Jcp 06 00165 g013
Table 1. Relationship between propositions, hypotheses and questionnaire items.
Table 1. Relationship between propositions, hypotheses and questionnaire items.
PropositionHypothesisQuestionnaire Items
P1H19, 10, 11, 12
P2H3, with supporting evidence from H218, 19, 21 (H3); 15, 16, 17 (H2)
P3No dedicated hypothesis; addressed directly at the item level 19, 20
P4H413, 14; 22, 23, 24, 25
P5No dedicated hypothesis, addressed through demographic correlationsAll substantive items
Table 2. Correlation between information security tooling and technology. Source: authors’ own survey data (N = 65).
Table 2. Correlation between information security tooling and technology. Source: authors’ own survey data (N = 65).
12
Information security has the required tools to respond to challenges (1).rs1.0000.251 *
p.0.044
Technological progress has introduced new threats to information security (2).rs0.251 *1.000
p0.044.
* Correlation is significant at the 0.05 level (2-tailed).
Table 3. Correlation between processes and resilience. Source: authors’ own survey data (N = 65).
Table 3. Correlation between processes and resilience. Source: authors’ own survey data (N = 65).
12
Information security has processes in place to identify critical services and their dependencies (1).rs1.0000.351 **
p.0.004
Information security must ensure that specific processes, services, etc., remain functional even in adverse situations (2).rs0.351 **1.000
p0.004.
** Correlation is significant at the 0.01 level (2-tailed).
Table 4. Selected Spearman’s rho correlations among technology, complexity and tooling views and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated; full labels available in Appendix A.
Table 4. Selected Spearman’s rho correlations among technology, complexity and tooling views and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated; full labels available in Appendix A.
1234
Increased interconnectivity & interdependence in information systems. (1)rs1.0000.345 **0.1980.047
p.0.0050.1140.708
Information systems grew more complex. (2)rs0.345 **1.0000.258 *−0.005
p0.005.0.0380.967
Security tools meet current response needs. (3)rs0.1980.258 *1.0000.246 *
p0.1140.038.0.048
Easier to estimate IS decisions’ organizational impact. (4)rs0.047−0.0050.246 *1.000
p0.7080.9670.048.
** Correlation is significant at the 0.01 level (2-tailed). * Correlation is significant at the 0.05 level (2-tailed).
Table 5. Selected Spearman’s rho correlations among views on ISG and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated; full labels available in Appendix A.
Table 5. Selected Spearman’s rho correlations among views on ISG and respondent demographics. Source: authors’ own survey data (N = 65). Labels abbreviated; full labels available in Appendix A.
12
ISG differentiation between internal and external change. (1)rs1.0000.293 *
p.0.018
ISG can detect and respond to changes in the environment (2)rs0.293 *1.000
p0.018.
* Correlation is significant at the 0.05 level (2-tailed).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Mavrofidis, E.; Tsatsaroni, A.; Kameas, A.D. The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. J. Cybersecur. Priv. 2026, 6, 165. https://doi.org/10.3390/jcp6050165

AMA Style

Mavrofidis E, Tsatsaroni A, Kameas AD. The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. Journal of Cybersecurity and Privacy. 2026; 6(5):165. https://doi.org/10.3390/jcp6050165

Chicago/Turabian Style

Mavrofidis, Emmanouil, Aikaterini Tsatsaroni, and Achilles D. Kameas. 2026. "The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security" Journal of Cybersecurity and Privacy 6, no. 5: 165. https://doi.org/10.3390/jcp6050165

APA Style

Mavrofidis, E., Tsatsaroni, A., & Kameas, A. D. (2026). The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security. Journal of Cybersecurity and Privacy, 6(5), 165. https://doi.org/10.3390/jcp6050165

Article Metrics

Back to TopTop