The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security
Emmanouil Mavrofidis, Aikaterini Tsatsaroni, Achilles D. KameasDespite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilience through Evolutionary Governance Theory (EGT) and explore whether information security governance (ISG) co-evolves with the same velocity as the systems it manages. A closed-ended, five-point Likert questionnaire was developed, which was completed by 65 information security professionals recruited through the Global Information Assurance Certification (GIAC) Advisory Board and LinkedIn between October 2024 and March 2025. Responses were analyzed using descriptive statistics and Spearman correlations. Respondents were near-unanimous that technological evolution has increased complexity and interdependence, and that resilience is essential. 41.5% of respondents consider that governance lacks the processes to detect and respond to environmental changes, identifying a gap in governance capacity. Within this sample, no item was significantly associated with tenure, experience, or organization size, though the analysis is underpowered for small effects. This study applies EGT in the domain of information security, and reports practitioner evidence consistent with an interpretation of the ISG gap as an adaptive deficit of co-evolving systems rather than as an implementation failure.