
Purpose This study adopts the theoretical lens of psychological contracts to explain information security policy (ISP) noncompliance and empirically examine the link between noncompliance and security breach. Design/methodology/approach Data for this empirical research were gathered via an online survey with non-IT employees as participants. Data were analyzed using partial least squares structural equation modeling. Findings Psychological contract breach (PCB) leads to ISP noncompliance, following an intense emotional reaction. A link between ISP noncompliance and security breach is supported. Research limitations/implications The findings of this study may not apply to economies and countries where perceptions of PCB may differ because of cultural differences. Originality/value This research identifies a path to ISP noncompliance resulting from a negative emotional reaction to social reciprocity. By identifying the factors that cause such emotional reactions, this research offers practical steps that information systems (IS) professionals may take to reduce the likelihood of employee-perceived PCB and resulting ISP noncompliance. The study also provides design suggestions to minimize security breaches resulting from ISP noncompliance.
Purpose This study aims to investigate the impact of Security Operations Center (SOC) onboarding in Operational Technology (OT) systems. The research seeks new insights into tailored OT SOC monitoring, contributing to a deeper understanding of integrating a SOC platform in industrial environments. Design/methodology/approach This paper presents findings from a longitudinal qualitative study examining the onboarding process between a SOC-as-a-Service (SOCaaS) provider and a Norwegian petroleum company, using observations and interviews. Data were collected from a Norwegian petroleum company and analyzed using Empirically Closed (EC) coding. Findings The study examines how industrial legacy systems, safety-critical operations, and cross-organizational collaboration shape SOC onboarding practices. It identifies key enablers, such as dedicated ticket triage, collaborative meetings and domain-specific knowledge sharing, as well as barriers, including limited trust between the SOCaaS provider and OT personnel and the need for standardized log-collection practices. Originality/value The paper proposes a revised onboarding framework tailored to ICS environments. This framework emphasizes system hardening, alert fine-tuning and stakeholder alignment to enhance SOC effectiveness and help SOCaaS providers better understand industrial customers’ needs. The findings offer practical guidance for both SOCaaS providers and industrial customers, addressing human and organizational challenges in cybersecurity practices, particularly in safety-critical sectors where operational continuity and trust are essential.
Purpose Small-to-medium enterprises (SMEs) remain vulnerable to cyber incidents because of resource constraints. While incident response plans exist, they are often untested, creating a critical readiness gap. This paper aims to introduce the Incident Response Readiness Score (IRRS), a scenario-based framework designed to empirically evaluate organisational incident response (IR) capability under simulated conditions.Design/methodology/approach The IRRS applies a structured scoring rubric calibrated through a Scenario Risk Index to evaluate performance. The authors further introduce human-centric telemetry - decision latency, communication entropy and authority drift - which operate as diagnostic lenses to explain observed readiness outcomes and identify organisational friction without altering IRRS scoring.Findings The study diagnosed an SME with a "Reactive" maturity level, revealing a stark contrast between technical potential and operational reality. In spite of modern tooling, response capability was compromised by human-system friction. Telemetry isolated extended decision latency and significant authority drift as root causes. These findings confirm that readiness is defined by decision clarity rather than tool ownership and that the IRRS successfully exposes cognitive failures that static audits miss.Originality/value This paper presents the first empirical framework specifically designed to quantify SME IR readiness using risk-weighted simulations. Unlike static compliance audits, IRRS isolates the gap between documented policy and operational execution. The introduction of diagnostic telemetry offers a novel method for distinguishing between technical deficits and human-process failures.
PurposeThere is an acknowledged and documented lag in the pick-up of governmental digital services, particularly among older adults. Existing research on the topic identifies practical and psychological factors creating that tentativeness among older adults to embrace moving to operating in a digital space. This paper aims to (i) highlight the digital gap between local governmental services and older adults, and (ii) identify key challenges faced by older adults while interacting with the technology. Design/methodology/approachA systematic literature review including (n = 62) academic publications was conducted to identify the challenges faced by older adults while interacting with online governmental services. FindingsAn analysis of the existing literature revealed key challenges faced by older adults when interacting with technology, including valuing technologies from the past, privacy and security concerns, anxiety, cognitive impairment, motivation, mode of participation and trust in government. Originality/valueThe study has implications for research, for instance, for developing effective cybersecurity awareness and training content, where success is measured by creating an environment of inclusivity for all.
PurposeThis study aims to provide a conceptual multidimensional classification of individual awareness, risk management, cyber resilience and technology adoption in a coherent synthetic framework. Design/methodology/approachThe research questions were formulated to answer the research objectives following the PRISMA guidelines through identification, screening, eligibility and inclusion of 24 articles that matched the research theme from the initial 325 articles. FindingsThis study reveals the supporting factors and threats to the main vulnerabilities of consumers and MSMEs in digital commerce, in addition to consumer self-protection strategies and holistic and sustainable cyber resilience in facing the evolution of cybersecurity threats. Research limitations/implicationsResearch on cybersecurity awareness needs to be expanded and not only focused on developed countries, where SMEs in developing countries are experiencing rapid e-commerce growth but are faced with resource and governance challenges. Originality/valueTo the best of the authors’ knowledge, this literature study is the first to conceptually design a multidimensional classification structure related to individual awareness, mitigation strategies, cyber resilience and a coherent synthesis framework.
PurposeAll US defense contractors were required to have fully implemented the 110 security requirements included in NIST Special Publication 800-171 entitled “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” by 1 January 2018 whenever a system owned or operated by or for a contractor processes, stores or transmits controlled unclassified information. Despite the mandate, adoption has been minimal, mostly because the requirement is so costly and time consuming that medium and small firms cannot afford to comply. Because the adoption of security precautions is costly and time consuming, the purpose of this paper is to propose a constrained optimization methodology to examine this issue. Design/methodology/approachIn this paper, the authors introduce a method to significantly reduce the number of required precautions by soliciting expert opinion as to the perceived benefits and costs of all precautions. The authors defined the difference between benefits and costs as value. FindingsIn the key constrained optimization exercise conducted, the authors show that including only the top 50 security precautions (out of the 110 security precautions) led to just a very small decline in value. Originality/valueThis paper makes an important contribution to information security research. To the best of the authors’ knowledge, no one has conducted similar analysis on the 110 proposed precautions.
PurposeThis study aims to bridge the gap between user-centered psychological insights and attacker-oriented strategic modeling in cybersecurity. It proposes an integrated framework combining cyberpsychology, adversarial thinking and cultural analysis to inform a more holistic, proactive and human-centered cybersecurity strategy. Design/methodology/approachThis paper follows the PRISMA (Preferred Reporting Items for Systematic reviews and Meta-Analyses) procedure to conduct a systematic literature review on the intersection of cyberpsychology and adversarial thinking, with particular emphasis on cultural influences to inform cybersecurity strategies. A thematic synthesis of 47 peer-reviewed studies was undertaken to identify trends, research gaps and interdisciplinary challenges. FindingsThe review identifies four central themes: (1) psychological models are frequently used to understand user behavior but are rarely applied to adversarial modeling; (2) profiling methods remain largely technical and reactive, lacking integration with behavioral science; (3) cultural factors, while occasionally considered in victim studies, are underexplored in relation to attacker behavior; and (4) cybersecurity strategies remain predominantly reactive, with limited development of proactive models. Together, these findings underscore a fragmented literature landscape and the need for integrative, forward-looking cybersecurity approaches. Originality/valueThis paper contributes a novel interdisciplinary framework that reconceptualizes adversarial thinking by embedding psychological and cultural aspects. It extends the theoretical scope of cybersecurity beyond technical defenses and highlights the value of behaviorally informed, proactive strategies to anticipate and mitigate threats.
Purpose This study aims to investigate the impact of cybersecurity vulnerabilities on the effective implementation of distributed ledger technologies (DLTs), addressing a critical gap in the existing literature. This research seeks new insights into the detection and mitigation of specific attacks, such as selfish mining and Sybil attacks, contributing to a deeper understanding of cybersecurity risk assessment in DLT applications. Design/methodology/approach This study uses a mixed-methods approach, using a literature review combined with method engineering. Data were collected from an extensive database of known security threats, documented attacks on DLTs and associated countermeasures. The proposed method was evaluated through three case studies, with each organization applying the security risk assessment method developed in this study. Findings The results of this study reveal that the proposed security risk assessment method effectively identifies and addresses cybersecurity threats specific to distributed ledger applications. Case studies demonstrate that the method enables organizations to systematically evaluate and mitigate risks, offering evidence that comprehensive countermeasures can significantly enhance security. These findings confirm the practicality of the proposed method and reveal new patterns in organizational responses to cybersecurity threats in distributed ledger environments. Originality/value This research offers a novel perspective on the intersection of cybersecurity and DLTs, providing valuable insights into risk assessment frameworks tailored for this domain. This study’s findings contribute to the advancement of cybersecurity practices in distributed ledger applications, highlighting critical areas for future research and practical guidelines for organizations aiming to enhance their cybersecurity posture.
Purpose The purpose of this study was to examine whether employees' cyberaggressive behaviors outside the workplace and lack of perceived social support, online or offline, predict insider threat behaviors.Design/methodology/approach In total, 206 MTurk participants completed an anonymous, online survey measuring self-reported insider threat behaviors within the workplace (cyber intrusion and data exploitation; low-level cyber misconduct), cyberaggressive behaviors outside the workplace (cybersexual and interpersonal aggression; cyber verbal aggression) and perceived lack of online or offline social support.Findings Controlling for age and gender, the results showed that both forms of cyberaggression outside the workplace (i.e. cybersexual and interpersonal aggression; cyber verbal aggression) and lower levels of offline perceived social support were associated with increased "cyber intrusion and data exploitation" behaviors in the workplace (Delta R 2 = 0.65). For "low-level cyber misconduct" behaviors in the workplace, only cybersexual and interpersonal aggression and perceived offline support were significant predictors after controlling for age and gender (Delta R 2 = 0.61).Originality/value The authors conclude that cyberaggressive behaviors outside the workplace and lack of perceived offline social support predict insider threat behaviors. These findings underscore the importance of considering other forms of online deviance (e.g. nonconsensual image-based harms) and perceived social support in preventing or reducing insider threats.
Purpose Most prior studies focused on the negative side of users’ activity logs, such as users’ lack of awareness about the logs’ privacy controls and users’ privacy concerns about their data. This paper aims to provide a balanced view of users’ perceptions regarding activity logs by considering the positive, negative and extremely negative sides, as well as the misconceptions of activity logs. Design/methodology/approach The author conducted a secondary analysis of interview data from 30 Google personal account holders in Saudi Arabia. Using template analysis, the author analyzed the data from the lens of four key themes: the good, the bad, the misconception and the disastrous aspects of users’ activity logs from the users’ perspective. Findings Participants identified positive aspects of Google’s Activity controls, such as saving browsing history and bookmarks, synchronization, security and safety and parental control. They also identified negative aspects, such as a lack of knowledge of Google’s data practices and the presence of Google’s Activity controls, privacy concerns and biased content. Some features, such as tailored ads, were controversial. The author identified misconceptions among participants, such as confusion between local browsing history and cloud-based activity logs and between security and privacy measures. Participants raised serious concerns about Google’s Activity controls, such as unauthorized logins and data breaches. Originality/value The main contribution of this paper is offering a balanced view of users’ perceptions of activity logs and providing a better understanding and a useful source for subsequent studies on related topics. The author offers a set of practical recommendations for service providers, security and privacy researchers and experts and users alike.
Purpose Evidence suggests that the majority of cyberattacks have been made possible because of erroneous or noncompliant human behavior. Nevertheless, many organizations tend to focus their cybersecurity programs on technology, often overlooking the importance of socio-technical cybersecurity controls and practices. The reasons for this and processes to remedy it in organizations making use of IT have been examined in the literature. However, in organizations using integrated IT and operational technology (OT) systems, such as the digitalized manufacturing industry, cybersecurity is often treated with less rigor and attention. This paper aims to identify and analyze socio-technical challenges of cybersecurity in such organizations, with an eye toward improving their cybersecurity posture. Design/methodology/approach Two data sources have been used, namely, interviews and a survey, both with participants from the Norwegian Industry. The aim of both instruments was to investigate how cybersecurity is organized and how threats are mitigated, focusing on socio-technical aspects. The interviews investigated how organizations work with cybersecurity and what motivates cybersecurity-compliant behavior. The survey measured the usage and importance of the different security controls found in the NIST Special Publication SP800 - 82r3 “Guide to Operational Technology.” Findings The results show that organizations should include their OT personnel together with IT in the governance of OT cybersecurity. Communication between IT and OT is found to be a significant challenge. Communication barriers could stem from a lack of cybersecurity knowledge among personnel working with OT. Organizations should, therefore, invest more in specific OT cybersecurity training to bridge the communication gap. With increased efforts in specific training, it is expected that the extent of workarounds should decrease and that deviations found between best practices and the current usage of security controls should improve. By investing more in training, classified as a social element of the socio-technical system (STS), the needle will move toward a balance between the socio- and the technical dimensions of STS, which should yield the highest security outcome. Research limitations/implications This study does not give explicit advice nor does it uncover new in-depth knowledge regarding how organizations communicate internally and to what extent IT and OT cooperate; it only reports and discusses the views of the participants. The results of this study should be of interest to practitioners in both IT and OT cybersecurity. Future research should investigate, among others, how cybersecurity is organized and how communication is done within OT organizations. Originality/value This study uncovers new information as to how OT industry organizations organize and prioritize their cybersecurity efforts with a focus on socio-technical aspects; it examines if there are deviations between IT and OT systems cybersecurity and investigates how these affect the overall organizational goal of cybersecurity; and it reveals some of the challenges that such organizations face in achieving improved cybersecurity.
Purpose This paper aims to provide an outline and description of cognitive dissonance theory (CDT); an overview of cognitive dissonance interventions; a high-level view of CDT research; a review of existing mentions of cognitive dissonance and studies meaningfully applying CDT to cybersecurity; and suggestions for future research.Design/methodology/approach The authors conducted a general review of cognitive dissonance research and three literature reviews of cognitive dissonance at a high level, cognitive-dissonance interventions and cognitive dissonance in cybersecurity.Findings Cognitive-dissonance theory is compact and widely applicable. Cognitive-dissonance theory paradigms provide a basis for interventions across domains. Awareness of cognitive dissonance is relatively widespread in the cybersecurity literature. Many publications mentioned cognitive dissonance in passing. However, less than 13% of publications meaningfully focused on cognitive dissonance.Research limitations/implications CDT provides concepts and techniques to develop further insight into the cybersecurity attitude-behaviour gap. These have the potential to help bridge the gap and thereby increase cybersecure behaviour. Such interventions should be designed and evaluated in future research.Originality/value This paper makes an original contribution to cybersecurity research by identifying: cognitive-dissonance paradigms that form the potential basis for interventions to increase cybersecure behaviour; cybersecurity areas that potentially benefit from such interventions and other areas in which cognitive-dissonance theory has been meaningfully applied; and directions for future research, most notably focusing on how to apply cognitive-dissonance-based interventions.
Purpose This study aims to examine how organizations communicate security compliance in mandatory data breach announcements. It investigates how compliance-related dimensions - internal/external investigations, internal compliance, legal enforcement, and customer protection - are embedded in publicly disclosed breach communications. By shifting attention from the market consequences of breach announcements to their informational content and structure, the study advances understanding of compliance as a central and explicitly communicated component of post-breach disclosure.Design/methodology/approach The authors use a large-scale text-mining approach using Latent Dirichlet Allocation (LDA) topic modeling to analyze 292 publicly disclosed data breach announcements filed between 2015 and 2022. After preprocessing the documents with natural language processing techniques, the authors applied an LDA MALLET model to identify latent thematic structures. Topic coherence scores guided the selection of the optimal number of topics, which were consolidated into six higher-level thematic categories through iterative interpretation.Findings The analysis identified 13 latent topic groups consolidated into six thematic categories: incident description, incident content, investigation activities, internal compliance, legal and regulatory enforcement and customer protection and remediation. Four dimensions - internal/external investigation, internal compliance, legal enforcement, and customer protection - emerged as central to security compliance. The findings show that compliance is structurally embedded in breach disclosures and communicated as evidence of accountability, governance maturity and regulatory alignment, rather than treated as a peripheral condition of breach management.Originality/value This study introduces a content-centric perspective to data breach research by analyzing the textual structure of data breach announcements rather than focusing solely on market reactions. It conceptualizes security compliance as a multidimensional, communicative construct that integrates governance, regulation, investigation, and remediation. By combining topic modeling with security governance theory, the study provides novel theoretical insights and practical guidance for organizations, regulators and policymakers regarding data breach disclosure practices.
Purpose Cyberthreats are a global phenomenon, exposing societies to economic, social and political risks. The most effective strategy for combating cybercrimes is to adopt a robust cybersecurity governance framework. However, epistemological challenges associated with cyber governance impose significant methodological limitations on cybersecurity research. Thus, this study aims to assess the extent of methodological rigour in cybersecurity culture research through the lens of reporting transparency. Design/methodology/approach To address the identified problem, the authors conducted a systematic literature review following the Preferred Reporting Items for Systematic and Meta-analysis framework, analysing publications from 2015 to 2024 retrieved from two leading databases (Web of Science and Google Scholar). This scientific approach ensures the inclusion of high-quality studies and facilitates a comprehensive assessment of validity and reliability in cybersecurity culture research. Findings The findings show that none of the reviewed studies fulfilled all the criteria. Furthermore, the findings indicate that the area most in need of methodological reporting transparency is the data analysis and reporting dimension. Originality/value This study applies a structured framework to assess methodological rigour in cybersecurity research by evaluating reporting transparency across research design, data collection procedures and data analysis and reporting. It further proposes guidelines to improve the quality and reliability of future studies.
Purpose This study aims to extend prior research on psychological empowerment and information security policy (ISP) compliance by examining whether transformational and transactional leadership influence employees’ compliance intentions indirectly through psychological empowerment. Design/methodology/approach Data were collected from a convenience sample of 119 used individuals enrolled in a US MBA program. The model was estimated using partial least squares structural equation modeling. Psychological empowerment was modeled as a second-order construct comprising meaning, competence, self-determination and impact. Indirect effects were assessed with 5,000 bootstrap resamples and 95% bootstrap confidence intervals. Findings Both transformational and transactional leadership were positively associated with psychological empowerment, and psychological empowerment strongly predicted ISP compliance intention. Mediation tests showed significant indirect effects for both leadership styles, while direct effects on compliance intention were not significant, consistent with full mediation. Transactional leadership showed a larger effect size on empowerment than transformational leadership in this sample. Practical implications Security programs can benefit from aligning clear expectations and reinforcement with leadership practices that enhance employees’ perception of meaning, autonomy, competence and impact within security-related tasks. Originality/value The study offers a theory-extending extension of prior empowerment-compliance work by positioning transformational and transactional leadership as upstream antecedents in a single mediation model. Rather than proposing an entirely new compliance theory, it clarifies a specific motivational pathway through which supervisory behavior may shape security-related intentions.
PurposeThe purpose of this paper is to investigate the determinants of individuals' acceptance of cybersecurity chatbots (CSCs). Integrating theories of protection motivation and institutional trust, this study examines the effects of threat appraisals, coping appraisals and trust in the CSC provider on the intention to use CSCs, thereby extending chatbot acceptance research into the cybersecurity domain.Design/methodology/approachThe authors empirically test the research model using data from two field studies conducted in Europe and the United States. Data were analyzed using partial least squares structural equation modeling (PLS-SEM). Study 1 tests the role of threat and coping appraisals, while Study 2 replicates the model and incorporates trust in the CSC provider.FindingsThe findings show that CSC acceptance is shaped by threat appraisals (e.g. perceived susceptibility) and coping appraisals (e.g. self-efficacy), as well as by trust in the CSC provider.Originality/valueBy conceptualizing CSCs as awareness-supporting tools in voluntary, citizen-level contexts, the study advances cybersecurity awareness research beyond organizational settings and enriches Protection Motivation Theory by introducing institutional trust as a provider-focused appraisal influencing acceptance. This study also extends chatbot acceptance research by demonstrating that CSC acceptance is explained by protection motivation processes beyond traditional technology acceptance factors. It integrates institutional trust as a provider-related determinant, showing that trust in the CSC provider shapes coping appraisals and, in turn, CSC acceptance.
PurposeThis study aims to deal with the long-standing disparity in conventional cybersecurity training and effective behavioral alteration by creating and testing a Reward-Driven Bloom's Taxonomy Framework. The framework by incorporating the elements of gamification and the principle of cognitive learning contributes to improving cybersecurity awareness, knowledge retention and security-conscious behaviour in organizations.Design/methodology/approachThe mixed-methods quasi-experimental design were used through three stages: expert validation of the pre-implementation (n = 18), the implementation of the training through Proofpoint Learning Management System (LMS) (n = 414 enrolled, 100% completion rate) and the evaluation of the post-implementation (n = 100). The elements of gamification such as badges, certificates, leaderboards and tiered challenges were combined with the six levels of cognition introduced by Bloom. T-tests, ANOVA and chi-square were used as quantitative analysis and thematic analysis as the qualitative data were analyzed using the framework by Braun and Clarke (2006).FindingsThe findings indicate statistically significant gains in knowledge retention of cybersecurity (18.4% increase, p = 0.01), motivation (27% increase of gamified competition participants, p = 0.013) and self-reported behavioral intent (33.5% increase in positive acceptable use policy (AUP) compliance responses). The chi-square tests proved that there were significant correlations between competition participation and motivation (chi & sup2; = 22.51, p = 0.001). ANOVA noted that there existed a significant difference between the departmental differences (p = 0.045) and there was also a difference in age in terms of risk perception (F(2,93) = 3.176, p = 0.017). The sizes of the effects were small to medium (Cohen d = 0.34-0.58). Applied practice was found to be the most prevailing reason for knowledge retention (62% of participants).Research limitations/implicationsThe single-organization type of design in the context of Saudi Arabia restricts generalizability. This is because lack of a control group limits causal inference but pre- post comparisons and triangulation enhance validity. The self-reported behavioral measures will have to be validated by the objective indicators in future like the phishing performance. Future research would involve longitudinal evaluation of behaviour persistence and not just in the aftermath of post-training.Originality/valueThe research is an original contribution, as it will systematically combine the application of Bloom-cognitive taxonomy with the theory of gamification based on the framework proposed by Deterding et al. (2011). Compared to previous studies that have concentrated on either cognitive progression or gamified interaction as an independent variable, this framework shows the synergistic impact of a particular game feature (points, badges, leaderboards, certificates) and a particular level of cognitive performance (Remember through Create) on attitudinal and behavioral outcomes. The study provides a tested framework that fills the gap between educational psychology and incentive-based learning, promoting sustainable cybersecurity behavior change. While the research was conducted within a single organization in Saudi Arabia, the framework offers a scalable model that can be adapted to other organizational contexts for broader implementation.
PurposeWhere one in three women worldwide experience some form of intimate partner violence, the rise of technology facilitated abuse means that abusers have increased access and control over their victims. This extension paper aims to examine the threat potential for technology misuse as pertains to item finder devices that make up part of the Internet-of-Things. Item finders have increasingly become the weapon of choice for abusers leveraging technological advantages against their victims.Design/methodology/approachThis study uses a mixed-methods approach, combining digital ethnography with 12 individuals engaged in a participant study to evaluate the misuse potential of Apple AirTag, Chipolo One and Tile Sticker item finders.FindingsThe study shows a concerning lack of preventative measures imposed by device vendors to prevent device misuse; highlighting how easily perpetrators can repurpose item finder devices as a mechanism for stalking. This suggests an urgent need for review regarding the provision of guidance and support to victims of domestic abuse.Originality/valueThe authors present novel findings through a simulated stalking scenario in which participants provided informed consent to have their movements remotely monitored over a total of four weeks in the participant study. Whilst previous studies on item finders in a domestic violence context have focused on software or hardware architecture, the participant study examines the practical implications of device misuse upon victims of digital coercive control.
Purpose - This paper aims to examine three cybersecurity and governance frameworks, namely, NIST Cybersecurity Framework (CSF) 2.0, ISO/IEC 27001:2022 and COBIT 2019, in relation to South Africa's e-government systems. It explores how context-sensitive integration of global standards may inform cyber resilience thinking in developing-country public-sector environments, with relevance to reducing digital inequalities (SDG 10) and supporting sustainable urban digital infrastructure (SDG 11). Design/methodology/approach - A qualitative, literature-based comparative evaluation is used. The frameworks are assessed against analytically derived dimensions, including governance alignment, operational usability, adaptability, resource and capacity sensitivity, resilience orientation and performance monitoring. Peer-reviewed literature, framework documentation and policy sources inform the conceptual comparative analysis. Findings - The analysis indicates that no single framework is sufficient in isolation. NIST CSF 2.0 contributes modularity and adaptability, ISO/IEC 27001 provides structured controls and continuous improvement mechanisms, and COBIT 2019 embeds governance and oversight. Their complementary characteristics inform the development of a conceptual hybrid cyber resilience framework. Research limitations/implications - The study is conceptual and literature-based. An empirical investigation through practitioner engagement or case-based analysis is required to examine contextual feasibility and operational relevance. Practical implications - The proposed hybrid framework serves as a conceptual reference model to inform policy dialogue, institutional analysis and future empirical research on cybersecurity governance. Social implications - The study contributes to discussions on inclusive access to secure e-government services and resilient digital public infrastructure, with relevance to SDG 10 and SDG 11. Originality/value - To the best of the authors' knowledge, this study provides one of the first literature-based comparative evaluations of NIST CSF 2.0, ISO/IEC 27001:2022 and COBIT 2019 within a developing-country e-government context, contributing a conceptually grounded hybrid framework for cyber resilience analysis.