From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms
Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke
Abstract
Cybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors’ knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board Cyber Governance Model that integrates targeted education, strategic interventions, and structured board–CISO engagement to improve governance capability. By situating cyber governance at the intersection of executive decision-making, risk perception, and digital security, this work contributes to human-computer interaction by highlighting socio-organisational challenges and offering actionable insights for stronger board-level engagement.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 1e5ea0e5-f778-44dc-86bb-de90ade151feRelated papers
- "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision MakingJens Opdenbusch, Jonas Hielscher, M. Angela SasseNDSS 2025
- "Cyber security is a dark art": The CISO as SoothsayerJoseph Da Silva, Rikke Bjerg JensenCSCW 2022 · 25 citations
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 18 citations
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm et al.CHI 2026 · 2 citations
- "Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business EnablerKimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass et al.CHI 2025 · 1 citation
