DOI: 10.1108/ics-04-2026-0198 ISSN: 2056-4961

Integrating NIST CSF 2.0 governance function with agency theory for enhanced accountability

Muhammad Hasnain, Hilmand Khan, Muhammad Ozair, Sibgha Tahir, Muhammad Umar Akhlaq

Purpose

Recurring cybersecurity breaches are increasingly attributable to governance failures rooted in human behavior, incentive misalignment, information asymmetry and moral hazard, rather than to technical deficiencies. This paper aims to examine why existing governance frameworks fail to enforce behavioral compliance and proposes a conceptual architecture to address this gap.

Design/methodology/approach

This study follows the Design Science Research paradigm, structured around Hevner’s three-cycle view and the six-activity methodology of Peffers et al. Ex ante evaluation combines scenario-based walkthroughs of governance failure modes and comparative feature analysis against existing methods, following the Framework for Evaluation in Design Science.

Findings

This paper proposes the Integrated Behavioral Governance Architecture (IBGA), which reinterprets GV.RR (Roles, Responsibilities and Authorities) through incentive-compatible contracting and augments GV.OV (Oversight) with behavioral monitoring. Analytical evaluation indicates that IBGA is designed to mitigate moral hazard and policy–practice decoupling by rendering agent effort observable and truthful disclosure individually rational, subject to future empirical validation.

Research limitations/implications

As a conceptual artifact, IBGA has not been empirically instantiated; effectiveness claims are analytically derived and require field validation.

Practical implications

IBGA provides CISOs with a phased, GRC-integrable behavioral assurance layer supplementing RACI matrices and NIST CSF 2.0 without displacing them and directly addresses recent board-level disclosure obligations under the SEC 2023 cyber rules and DORA.

Originality/value

This paper contributes a narrow but targeted synthesis: integrating specific agency theory mechanisms into two specific NIST CSF 2.0 Govern categories (GV.RR and GV.OV), bridging organizational economics and cybersecurity governance.