Articles published on Global Cybersecurity
Authors
Select Authors
Journals
Select Journals
Duration
Select Duration
312 Search results
Sort by Recency
- Research Article
- 10.1080/23738871.2026.2675665
- May 21, 2026
- Journal of Cyber Policy
- Nevena Stojakovic + 1 more
ABSTRACT Digital transformation has improved commerce, connectivity and access to government services, but it has also increased cyber-related issues and online offending. In response, governments and international organisations have implemented cybersecurity capacity-building initiatives to improve national cybersecurity capacities and strengthen cyber resilience. These initiatives include formulating cybersecurity laws, establishing national Computer Emergency Response Teams, improving law enforcement capabilities to address cybercrime and increasing cyber awareness among internet users. Despite their widespread implementation, it remains empirically unclear whether such government-led initiatives can shape individual-level behaviours such as digital piracy. Moreover, little is known about whether the dosage (amount) and content (type) of these initiatives influence online piracy rates. To address this gap, this study uses a novel sample of global cybersecurity capacity-building initiatives across 104 countries between 2009 and 2017. The results indicate that both the dosage and content of cybersecurity capacity-building initiatives significantly affect online piracy, and that countries engaging in internet user awareness initiatives have lower digital piracy rates. The findings further show that these initiatives are most successful in countries with greater absorptive capacity. These findings offer guidance for future cybersecurity capacity-building initiatives, particularly in countries with significant budgetary constraints.
- Research Article
- 10.54648/eerr2026019
- May 1, 2026
- European Foreign Affairs Review
- Carlos Fonseca-Diaz + 1 more
Cyber Capacity Building (CCB) has become a key instrument in the external dimension of the European Union (EU) cybersecurity policies. This paper examines how the EU operationalizes its strategic and geopolitical interests through cyber cooperation with three key neighbouring regions: the Southern Neighbourhood (SN), the Eastern Neighbourhood (EN), and the Western Balkans (WB). Drawing on a comparative analysis of CCB projects funded by the EU and its Member States, the study identifies three differentiated scripts in cyber cooperation: law enforcement, governance, and resilience. The paper argues that the EU’s approach to CCB is strategically instrumentalized and differentiated to reflect broader geopolitical, security, and integration objectives, ranging from stabilizing border regions and managing external threats to extending its regulatory influence. These findings contribute to a better understanding of the EU’s evolving ambition to act as a geopolitical and normative actor in global cybersecurity governance, and they underscore how differentiated regional engagement reflects the EU’s strategic priorities in the digital age.
- Research Article
- 10.1109/jbhi.2026.3687103
- Apr 23, 2026
- IEEE journal of biomedical and health informatics
- Michael Winter + 6 more
Healthcare ranks among the most vulnerable sectors to cybersecurity threats, experiencing widespread security incidents and substantial data breach costs. Despite growing global cybersecurity expenditures, health care systems remain distinctively vulnerable. This paper presents a scoping review of research on cybersecurity in eHealth. Following PRISMA-ScR guidelines, we searched and analyzed literature across four major databases: ACM Digital Library, IEEE Xplore, PubMed, and Web of Science. From an initial 3,146 identified papers, 567 met inclusion criteria and underwent detailed analysis. The analysis iden tifies blockchain as the most researched technical solution, with system and communication protection dominating cybersecurity categories. Geographically, research output has shifted significantly toward India and China. However, the study highlights critical gaps in real-world implemen tations, user-centric perspectives, and evaluation studies. This comprehensive review offers insights for researchers, healthcare professionals, and policy makers to develop targeted, evidence-based cybersecurity strategies that protect sensitive health data and ensure the integrity of digital health systems.
- Research Article
- 10.1108/ics-08-2025-0294
- Mar 30, 2026
- Information & Computer Security
- Erik Etsushi Miyashita + 1 more
Purpose This study aims to introduce a multi-criteria model to assess cybersecurity maturity in Latin America’s ten largest economies, addressing the limitations of traditional indices. By integrating the Global Cybersecurity Index pillars with socioeconomic indicators such as gross domestic product (GDP) and internet penetration, the model provides a more contextualized analysis. Design/methodology/approach Using the CRiteria Importance Through Intercriteria Correlation-Weighted Integrated Sum-Product method, the research objectively weighs the evaluation criteria, identifying GDP (C7), organizational measures (C3) and internet usage (C6) as the most significant factors in differentiating maturity levels. Findings The results rank Brazil and Mexico as leaders but also highlight Ecuador’s strong institutional performance, which ranks third despite its smaller economy. The model reveals important insights, such as Argentina’s underperformance relative to its economic size, pointing to gaps in specific capacities. Research limitations/implications This study only assessed the ten largest economies in the region. In addition, a limited number of criteria were used for scope limitation. Practical implications The results of this study offer a valuable diagnostic tool for policymakers, highlighting the necessity of including more dimensions in cybersecurity maturity analysis. Social implications The findings suggest that uneven cybersecurity maturity can amplify social vulnerabilities, influencing citizens’ exposure to cybercrime and their safe access to essential digital services in emerging economies. Originality/value This approach offers a robust diagnostic tool for policymakers to develop targeted strategies and enhance regional digital resilience.
- Research Article
- 10.63978/3083-6476.2026.1.4.06
- Mar 30, 2026
- MILITARY STRATEGY AND TECHNOLOGY
- Yevhen Romanenko + 2 more
The article examines the systemic disproportion between the accelerated evolution of hybrid (subthreshold) threats and the conservative vertical-hierarchical model of governance of Ukraine’s security and defence sector (SDS). Drawing on CSIS data (2025), ENISA Threat Landscape 2025, RAND “From Policy to Victory” (2025), NATO StratCom COE “The Collage of the Kremlin’s Communication Strategy” (2025), and WEF Global Cybersecurity Outlook 2025, the authors demonstrate that traditional inter-agency “silos” have become the primary vulnerability of the state. The aggressor operates non-linearly and networked, exploiting the “seams” between the RNBO, MoD, SBU, State Special Communications Service, and private critical infrastructure operators (over 80 % of objects). The existing normative framework (Law on National Security 2018, Cybersecurity Strategy 2021, CMU Order No. 853-r 2025) lacks effective mechanisms for horizontal coordination and real-time data exchange. This results in a chronic institutional lag, whereby intelligence information fails to translate into preventive action. The central proposal is the establishment of a Joint Analytical Centre for Hybrid Threats (JACHT) – a compact hub (55–65 specialists) directly subordinated to the RNBO. The Centre integrates three functional blocks: AI-driven predictive monitoring, legal-attribution assessment, and a public-private interface based on Data Sharing Agreements. Implementation requires targeted amendments to Article 12 of the Law on National Security and updates to the Cybersecurity Strategy incorporating Active Defence elements. The practical value of the study lies in substantiating the transition from a reactive to a predictive SDS governance model and providing concrete recommendations for the pilot launch of JACHT in 2027.
- Research Article
- 10.1145/3802591
- Mar 27, 2026
- Journal of Data and Information Quality
- Angelica Marotta + 1 more
An important goal of Chief Data Officers (CDOs) and data quality efforts is to increase the value of an organization's data. But that increased value makes the data an even more desirable target for cyberattacks, which have become more frequent, sophisticated, and impactful. In addition to the efforts that individual companies have made, the governments worldwide are responding by introducing or proposing new cybersecurity regulations to help protect that data, making security an important aspect of data quality. This study offers a novel perspective on the evolving global cybersecurity regulatory environment. Drawing on a comprehensive comparative analysis of nearly 200 regulatory frameworks from a wide array of international and national jurisdictions, the research identifies a core group of regulatory features that are systematically organized into five principal thematic categories. In particular, this research employs an integrated classification schema and a multidimensional taxonomy to facilitate more precise navigation of the complex regulatory landscape. Using a structured qualitative synthesis approach combining elements of review and cross-jurisdictional mapping, the analysis highlights notable disparities in regional regulatory focus, with Data Privacy, Incident Reporting, and Security by Design standing out as the most recurrent regulatory priorities. A significant outcome of the study is the identification of varying synergy levels between regulatory features, with high integration observed in Data Privacy and Cross-Border Data Transfer, medium synergy in areas such as Incident Reporting and Risk Management, and low synergy between Security by Design and Emerging Technologies. Therefore, by examining how various regulatory features align—or fail to align—across jurisdictions, the study provides critical insights for legislators, regulators, and data quality leaders and researchers. The paper concludes with targeted recommendations to support more consistent, adaptive, and future-resilient cybersecurity governance worldwide to further improve data quality.
- Research Article
- 10.36948/ijfmr.2026.v08i02.71557
- Mar 16, 2026
- International Journal For Multidisciplinary Research
- Rituporna Das + 1 more
Digital Forensics has become an indispensable tool in contemporary cybercrime investigations, which ensures systematic identification, collection, preservation, and presentation of electronic evidence in a legally admissible manner. As cybercrimes continue to escalate, investigative authorities are required to operate across multiple digital domains, including personal devices, mobile platforms, cloud infrastructures, and transnational communication networks, with strict adherence to the law. Digital forensics is important not only because it can recover the deleted or concealed data, but also because it ensures that the evidence remains authentic and untouched throughout the investigation. Due to its dual emphasis on both technology and law, it effectively bridges the gap between technical accuracy and legal accountability. Despite being so advanced in the contemporary world, the field of digital forensics still faces persistent challenges. The extensive reliance on data encryption, rapid technological innovations, and the issue of complex jurisdiction in cross-border investigations complicate and hamper the effective use of digital forensics. Moreover, the escalation of data generated in the digital age raises concerns about privacy, transparency, and the timely administration of justice. Addressing these concerns requires some advanced and well-developed standardized forensic frameworks, legal protocols, and greater international cooperation to harmonize investigative procedures. This paper shall dwell upon the continuous evolution of the role of digital forensics in cybercrimes in the contemporary world. It shall particular ly focus on the foundations, challenges, evidentiary value, and implications for law enforcement and global cybersecurity. It shall also emphasize the strengthening of digital forensics so that harmonious international relations and global cybersecurity can be achieved.
- Research Article
- 10.64706/8pfwzg81
- Feb 24, 2026
- Global E-Journal of Social Scientific Research
- Dr Neelam Dey
Cybersecurity has transcended its traditional technical boundaries to become a fundamental social, economic, and ethical concern in the digital age. As the distinction between physical and virtual life continues to diminish, digital systems now underpin governance, healthcare, education, finance, and interpersonal communication. This paper examines cybersecurity as a pillar of societal resilience, emphasizing its direct connection to human rights, democratic integrity, economic stability, and social inclusion. The increasing frequency of cyberattacks, data breaches, ransomware incidents, and online harassment demonstrates that digital vulnerabilities have far-reaching consequences beyond financial loss, affecting public trust, mental health, and institutional credibility. Particular attention is given to the disproportionate impact of cyber threats on youth, women, and marginalized communities, highlighting the intersection of cybersecurity with social justice and psychological well-being. The study further explores the economic implications of cybercrime, the expansion of the global cybersecurity market, and the role of governments and organizations in strengthening regulatory and technological frameworks. Ultimately, the paper argues that cybersecurity must be understood not merely as a defensive technological mechanism but as a collective societal responsibility grounded in ethical governance, digital literacy, and proactive policy integration. Safeguarding data and digital infrastructure is inseparable from protecting human dignity and ensuring sustainable social development in an increasingly interconnected world.
- Research Article
1
- 10.1177/02633957261422133
- Feb 12, 2026
- Politics
- James Shires + 1 more
Over the past few decades, cyber warfare has become what the Advocacy Coalition Framework (ACF) calls a ‘policy subsystem’. This article asks: how far can ACF explain the policy dynamics of cyber warfare? The article argues that understanding key camps in global cybersecurity negotiations as advocacy coalitions has three theoretical benefits for scholarship on cyber warfare. First, the ACF’s detailed account of coalition formation helps explain the interplay between normative and strategic considerations on cyber warfare at different levels of coalition commitment. Second, the ACF’s emphasis on internal and external ‘subsystem shocks’ as catalysts for policy change helps to identify key events in each coalition’s narrative of cyber warfare and the framing power of these events on negotiations over policy. Third, the ACF stresses the role of coalition building as a necessary step to achieve policy change, and thus sheds a fresh light on recent diplomatic initiatives related to cyber warfare, from commercial spyware regulation to counter-ransomware campaigns. Finally, we highlight some conceptual challenges posed by cyber warfare to the ACF, as cyberspace offers wider – and more effective – possibilities for coalition action beyond advocacy.
- Research Article
- 10.21474/ijar01/22515
- Jan 31, 2026
- International Journal of Advanced Research
- Zidida Damekhaly Turay + 3 more
The study provides a comprehensive review of cybersecurity detection methods within Industry 4.0, focusing on enhancing system resilience and user trust. The research uses a qualitative approach to analyze nine case studies from Africa, Asia, and the West to identify key challenges, detection strategies,and region-specific insights.The findings emphasize the critical role of AI-driven and hybrid detection systems, which have proven effective in mitigating advanced cyber threats such as ransomware, distributed denial of service (DDoS), and false data injection attacks. Comparative analysis highlights common global challenges,including resource limitations,human-related vulnerabilities, and compliance issues, while addressing unique regional factors such as infrastructure gaps and evolving threat sophistication.The study proposes a cybersecurity taxonomy integrating machine learning, real-time anomaly detection, and adaptive threat response mechanisms for Industry 4.0 environments. Recommendations for practitioners include adopting AI-enhanced intrusion detection systems (IDS), implementing energy-efficient IoT security solutions, and conducting regular system audits. Policymakers are encouraged to mandate adherence to global cybersecurity standards, foster international collaboration, and invest in workforce capacity building initiatives. The review, therefore, strengthens global cybersecurity frameworks,improves organizational resilience, and fosters public trust in the secure integration of Industry 4.0 technologies.
- Research Article
- 10.63939/ajts.sr7yj978
- Jan 11, 2026
- Arabic Journal for Translation Studies
- Souhila Imansouren
This research examines the correlation between e-government advancement and digital transaction expenses in Arab nations, highlighting the influence of cybersecurity maturity as a moderating factor. The analysis employs panel data from twenty Arab League member states spanning 2005 to 2023, incorporating the United Nations E-Government Development Index (EGDI) and the International Telecommunication Union’s Global Cybersecurity Index (GCI) as principal indicators. A two-way fixed-effects model is utilized to examine whether cybersecurity maturity enhances the efficiency improvements of digital governance. Results show that e-government development cuts down on the costs of searching for information, negotiating, and enforcing rules. This relationship, on the other hand, gets a lot stronger in places where cybersecurity frameworks are well- established and trustworthy. The results show that digital transformation and cyber resilience go hand in hand, and that for digitalization to be sustainable, investments in both cybersecurity capacity building and regulatory coherence must be made at the same time. Policy suggestions call for a coordinated approach to speed up e-government and improve cybersecurity maturity in order to create safe, low-cost digital economies.
- Research Article
- 10.37634/efp.2026.1.9
- Jan 5, 2026
- Economics Finances Law
- Liudmyla Budnyk + 1 more
The paper examines the security aspects of international cooperation in combating cybercrime, emphasizing the growing complexity and transnational nature of digital threats. The introductory section outlines how global digitalization and the rapid evolution of cyberattacks create challenges that no state can address independently. The materials and methods of the study are based on international legal instruments, analytical reports, and comparative and content analysis, enabling an assessment of existing cooperation mechanisms. The purpose of the paper is to analyze security-oriented approaches to international interaction and identify effective tools for strengthening collective resilience. The results demonstrate that cybercrime has evolved into a multilayered global phenomenon marked by advanced attack techniques, difficulties in attribution, uneven cybersecurity capacities, and political constraints that hinder information exchange. The study reviews key legal frameworks, including the Budapest Convention and its protocols, UN initiatives, and regional mechanisms of the EU, NATO, and G7, highlighting their fragmented implementation. It further analyzes technical, legal, and trust-related barriers to information sharing, alongside security risks such as data leaks, political misuse of shared intelligence, and the dual-use nature of cyber tools. Based on this assessment, the paper proposes harmonization of legislation, establishment of rapid-response mechanisms, enhancement of trust-building practices, improvement of technical interoperability, and expanded public–private partnerships as essential components of effective cooperation. The conclusions emphasize that only coordinated international action, grounded in shared standards and mutual responsibility, can ensure sustainable global cybersecurity in the face of escalating digital threats.
- Research Article
- 10.54151/27382559-25.2pa-175
- Dec 29, 2025
- SUSh Scientific Proceedings
- A Tumanyan
The article analyzes the level of cybersecurity in the Republic of Armenia based on data from the Global Cybersecurity Index (GCI) and the National Cybersecurity Index (NCSI). Special attention is given to Armenia‘s position in the regional context compared to Georgia, Azerbaijan, Turkey, and Iran. The results show that Armenia has made some progress, but it continues to lag behind neighboring countries, particularly in organizational and strategic components, which limits the effectiveness of its cybersecurity. The study indicates that in recent years, digital infrastructures in Armenia have been developing rapidly: the number of mobile subscribers is increasing, the volume of e-commerce is growing, and internet user activity is rising daily. This growth in digital activity creates new and more complex challenges in cybersecurity, requiring systemic solutions, clear strategies, and robust technical measures. The article emphasizes that Armenia‘s digital development process should be comprehensively aligned with the formulation of strict cybersecurity policies, the implementation of modern technical tools, and the continuous development of expert capacities, in order to ensure effective protection of information infrastructures, secure, uninterrupted, and accessible delivery of digital services, while simultaneously enhancing the trust of citizens, public, and private sectors in the digital environment.
- Research Article
- 10.62051/tr5f2089
- Dec 25, 2025
- Transactions on Computer Science and Intelligent Systems Research
- Xin Yu + 2 more
Against the backdrop of deep global digital integration, the transnational nature and spatial heterogeneity of cybercrime have intensified governance challenges. This study employs a Geographically Weighted Regression (GWR) model to integrate cybercrime data from 129 countries (including 12 indicators such as crime incidents, success rate, and prevention rate) from the International Telecommunication Union (ITU) 2023 Global Cybersecurity Index (GCI) and the VERIS Community Database (VCDB), constructing a three-dimensional analytical framework of "Spatial Distribution - Influencing Factors - Policy Efficacy". The results show that four countries including the United States and the United Kingdom are high-incidence target countries for cybercrime (crime incidents ≥ 138 times), while five countries such as Singapore and South Korea achieve a crime prevention rate of over 89%. Economic level (GDP), internet penetration, and cybersecurity policy efficacy (GCI index) exhibit significant spatially heterogeneous impacts on crime distribution, with well-developed and strictly enforced legal policies accounting for 80% of the crime inhibition effect. Geospatial proximity and technical investment intensity show positive inhibitory effects, and regional collaboration mechanisms can enhance prevention efficiency by over 30%. The study reveals the dual laws of cybercrime—"economic centers attracting crime" and "spatial differentiation of policy efficacy"—providing data support for optimizing global cybersecurity policies.
- Research Article
- 10.62051/5qz0pa22
- Dec 25, 2025
- Transactions on Computer Science and Intelligent Systems Research
- Yufei Wu + 2 more
With the acceleration of the global informatization process, cybercrime has increasingly become a serious challenge for the world. The transnational nature of cybercrime makes the response of a single country inadequate, and there is an urgent need for global policy coordination and optimization. Through an in-depth analysis of VCDB data, this paper reveals the distribution characteristics of global cybercrime, and points out the significant differences between developed and developing countries in terms of cybersecurity incident reporting and transparency. Then, use the Grey Relational Analysis method and the five key indicators of the Global Cybersecurity Index (GCI)to evaluate the effectiveness of their national security policies. The results show that technical capability and organizational management are the core factors affecting the effectiveness of cybersecurity policies. In addition, this paper uses the entropy-weighted TOPSIS method to further analyze the relationship between demographic data and network security indicators to verify the previous conclusions. By fostering a unified approach, the international community can better address the evolving landscape of cybercrime and safeguard the digital ecosystem.
- Research Article
1
- 10.54878/nctb6w37
- Dec 24, 2025
- International Journal of Information & Digital Security
- Wael Badawy
Quantum Key Distribution (QKD) offers a revolutionary method for achieving information-theoretic security in communication systems by leveraging quantum mechanical principles. With foundational protocols like BB84 and newer innovations such as phase-matching and device-independent QKD, the field has rapidly progressed from theoretical constructs to real-world prototypes. Recent advancements in integrated photonics, high-speed key generation, and satellite-based systems suggest a transformative potential for global cybersecurity infrastructure. However, significant challenges remain in extending secure communication distances, ensuring practical implementation security, reducing cost and size of components, and integrating QKD into existing network architectures. This paper reviews the state-of-the-art in QKD, discusses emerging trends such as chip-based and layered QKD systems, evaluates satellite and free-space deployments, and examines the practical limitations and solutions for long-distance and high-rate secure communications. It concludes by highlighting future directions including standardization, hybrid classical-quantum infrastructures, and software-defined QKD networks.
- Research Article
- 10.36874/riesw.2025.3.10
- Dec 22, 2025
- Rocznik Instytutu Europy Środkowo-Wschodniej
- Tomasz Kijek + 2 more
The paper aims to investigate the relationship between economic innovativeness and cybersecurity performance in the context of Central and Eastern European Countries (CEECs). Using a panel dataset for eleven CEECs over the 2014–2024 period, the empirical approach combines the Global Cybersecurity Index by the International Telecommunication Union, the European Innovation Scoreboard Summary Innovation Index, and an originally developed composite ICT Innovation Performance Index based on patent activity, R&D sector performance, and firm-level innovation metrics. The model is estimated using a Tobit regression with random effects, controlling for GDP per capita and tertiary education attainment. The results support the developed hypotheses, suggesting that general innovativeness is negatively associated with cybersecurity performance, whereas ICT-sector-specific innovation performance improves national cybersecurity resilience. These findings offer relevant implications for the innovation policies and digitalisation strategies of CEECs. In this light, innovation policy should prioritise investments in cybersecurity R&D and cross-sectoral technology transfer mechanisms that strengthen digital resilience. As digital transformation accelerates, these policy dimensions become not only complementary but also essential for sustainable, innovation-led growth in the region.
- Research Article
- 10.30574/ijsra.2025.17.2.3051
- Nov 30, 2025
- International Journal of Science and Research Archive
- Olubukola Sanni
The increasing digitalization of global trade and finance has profoundly transformed cross-border taxation systems, introducing new efficiencies but also escalating cybersecurity vulnerabilities. As tax authorities and multinational corporations adopt digital reporting, blockchain-enabled auditing, and AI-based compliance tools, the risk of data breaches, ransomware attacks, and identity theft has multiplied. This paper examines the impact of cybersecurity threats on cross-border taxation, focusing on how cyber incidents undermine fiscal transparency, disrupt revenue collection, and erode taxpayer trust. It explores the interplay between international data exchange mechanisms—such as the OECD’s Common Reporting Standard (CRS)—and the evolving landscape of cyber risks that accompany these digital tax frameworks. The study also highlights how inconsistent cybersecurity standards among jurisdictions create systemic weaknesses that can be exploited by cybercriminals to manipulate tax information or evade compliance. Furthermore, it discusses the emerging role of regulatory cooperation, digital sovereignty, and data protection frameworks like GDPR in safeguarding tax ecosystems. By integrating insights from cyber risk management, digital governance, and international tax law, this research emphasizes the necessity of a unified global cybersecurity approach to ensure tax integrity and equitable revenue administration in an increasingly digital economy. The findings contribute to policy discussions on how technological resilience and secure digital infrastructures can reinforce trust and accountability in cross-border taxation systems.
- Research Article
- 10.30574/wjaets.2025.17.2.1503
- Nov 30, 2025
- World Journal of Advanced Engineering Technology and Sciences
- Ifeyinwa Nkemdilim Obiokafor + 2 more
In the contemporary digital landscape, cyber threats have become a pervasive and formidable challenge, transcending national borders and posing significant risks to critical infrastructures, economies, and societies worldwide. Cyber Threat Intelligence (CTI) sharing has emerged as a crucial strategy in fortifying both national and global cybersecurity frameworks. This review provides a comprehensive examination of CTI sharing, synthesizing current research on its mechanisms, models, and challenges across governmental, industrial, and international domains. By facilitating the exchange of threat-related information among stakeholders, CTI sharing enhances situational awareness, expedites incident response, and fosters a collaborative defense posture. The strategic importance of CTI sharing lies in its ability to provide timely and actionable intelligence, enabling organizations and nations to detect, prevent, and respond to cyber threats more effectively. This review identifies significant barriers to CTI sharing, including legal constraints, trust deficits, and technological disparities. Despite these challenges, emerging trends such as automation, AI-driven threat detection, and blockchain-facilitated trust models offer promising solutions to enhance the efficacy of CTI sharing. The findings of this review advocate for a globally coordinated, standardized, and incentivized approach to CTI sharing as an indispensable tool in modern cybersecurity policy and practice. By leveraging CTI sharing, organizations and nations can foster collective resilience against evolving cyber threats, ultimately enhancing national and global security postures. This review provides valuable insights for researchers, policymakers, and practitioners seeking to enhance cybersecurity frameworks through CTI sharing.
- Research Article
- 10.38124/ijisrt/25nov619
- Nov 28, 2025
- International Journal of Innovative Science and Research Technology
- Muneer Abduallh Saeed Hazaa + 1 more
The accelerating digital transformation of higher education has expanded institutions’ exposure to cyber threats, a challenge that is particularly acute in resource-constrained settings where budgets, regulatory guidance, and security awareness remain limited. While international frameworks such as ISO/IEC 27001 and the NIST Cybersecurity Framework (CSF) are robust, their complexity, cost, and limited contextual fit often hinder effective adoption in low- resource environments. This study introduces ISOGMAF—an Institutional Security Governance Maturity Assessment Framework tailored to Yemeni higher-education institutions (HEIs). ISOGMAF is developed through a multi-stage methodology that integrates international best practices, local regulatory considerations, and sector-specific requirements, translating controls into measurable components spanning 34 governance/control domains. The framework is empirically validated via a survey administered across Yemeni HEIs using a six-point Likert scale maturity instrument to rate and classify cybersecurity governance levels. Findings reveal substantive gaps across governance, awareness, and technical preparedness, yet indicate tangible potential for phased improvement guided by a context-aware, scalable roadmap. The contribution is twofold: (i) it operationalizes the localization of global cybersecurity frameworks for developing-country HEI contexts, and (ii) it provides an objective self-assessment mechanism that supports benchmarking and targeted enhancement of institutional cyber resilience.