Recurring cybersecurity breaches are increasingly attributable to governance failures rooted in human behavior, incentive misalignment, information asymmetry and moral hazard, rather than to technical deficiencies. This paper aims to examine why existing governance frameworks fail to enforce behavioral compliance and proposes a conceptual architecture to address this gap.
This study follows the Design Science Research paradigm, structured around Hevner’s three-cycle view and the six-activity methodology of Peffers et al. Ex ante evaluation combines scenario-based walkthroughs of governance failure modes and comparative feature analysis against existing methods, following the Framework for Evaluation in Design Science.
This paper proposes the Integrated Behavioral Governance Architecture (IBGA), which reinterprets GV.RR (Roles, Responsibilities and Authorities) through incentive-compatible contracting and augments GV.OV (Oversight) with behavioral monitoring. Analytical evaluation indicates that IBGA is designed to mitigate moral hazard and policy–practice decoupling by rendering agent effort observable and truthful disclosure individually rational, subject to future empirical validation.
As a conceptual artifact, IBGA has not been empirically instantiated; effectiveness claims are analytically derived and require field validation.
IBGA provides CISOs with a phased, GRC-integrable behavioral assurance layer supplementing RACI matrices and NIST CSF 2.0 without displacing them and directly addresses recent board-level disclosure obligations under the SEC 2023 cyber rules and DORA.
This paper contributes a narrow but targeted synthesis: integrating specific agency theory mechanisms into two specific NIST CSF 2.0 Govern categories (GV.RR and GV.OV), bridging organizational economics and cybersecurity governance.
