IT governance has become a common theme within enterprises, as made evident by the inclusion of governance as a key component of the COBIT® framework and the publication of innumerable articles addressing the importance of implementing in-house governance frameworks.1 However, various forms of governance are relevant when reviewing current trends.2 Cybersecurity risk management governance takes a front seat in the US National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0.3 A review of NIST CSF 2.0 from an agency theory perspective provides cybersecurity and governance professionals with a conceptual understanding of how governance can be extended to cybersecurity risk management.4 This level of understanding allows decision makers the opportunity to identify the potential motivation of organization members, predict where potential conflicts of interest may occur, and address cybersecurity risk management governance to reduce these issues.
To achieve robust security governance, NIST CSF 2.0 lists 31 separate outcomes. Implementing policies and processes to achieve every outcome can be overwhelming for both enterprises and their staff members. One approach is to review governance from an agency theory perspective.
Agency Theory and Cybersecurity Risk Management
At the core of agency theory is the notion that one person—the agent—acts on behalf of another person or enterprise—the principal. The principal has self-interests but needs the agent to perform actions because of the principal’s limited capacity, regulations, or common practice. Examples include employees (agents) working for the enterprise’s owner or founder (principal), a lawyer (agent) representing a client (principal), and a real estate agent listing a home for a seller (principal). The agent in the case of cybersecurity risk management is likely to be the chief information security officer (CISO), but the agent can be anyone inside the enterprise acting on its behalf.
A problem with the principal-agent relationship is that the agent also has self-interests. These interests often cause the agent to perform actions that are beneficial to both the principal and the agent or, if the opportunity exists, to perform hidden actions that benefit only the agent.
Decades of agency theory research show that the best-maintained principal-agent relationships are governed by formal contracts whereby the principal delegates specific tasks and then monitors the agent’s actions.
A review of cybersecurity risk management from an agency theory perspective identifies three potential scenarios that may cause the agent to make decisions that are not beneficial to the enterprise.
Scenario 1—Lack of Information
The structures of some enterprises do not give the agent access to all the information necessary to make the best risk management decisions. However, in many cases the agent does not fully understand the principal’s interests. This lack of understanding may be because the enterprise does not fully understand its own interests, the agent is not present when the principal is discussing or deciding issues that guide the principal’s interests, or the agent is embedded in the organizational structure and receives misinformation about the principal’s interests.
Organizations can strengthen their cybersecurity governance by creating organizational structures that ensure that the agent managing cybersecurity risk fully understands the principal’s interests and is present when the principal is making decisions that may affect cybersecurity risk. The NIST 2.0 Roles, Responsibilities, and Authorities section can be useful in further organizing thoughts about organization structure.
Scenario 2—Lack of Resources
The top two reasons enterprises do not complete cyberrisk assessments are time commitments and a lack of qualified personnel.5 Agency theory shows the need for contracts between agents and principals, but good contracts require significant negotiations between the parties. The principal states the desired outcomes, the agent informs the principal what resources are needed, the agent performs the work, and the principal monitors the results. Organizational risk is created when there are inadequate resources to perform each of these tasks.
Organizations can reduce cybersecurity risk by incorporating strong contracts between principals and agents and by monitoring these actions. The NIST 2.0 Policy and Oversight sections provide further information in these areas.
Scenario 3—Agent’s Self-Interest
Agents’ self-interests can affect their actions. Agents may perform hidden tasks that fulfill their own self-interests but harm the principal. However, the CISO is not the enterprise’s only agent. Based on the organizational structure, the CISO may answer to a myriad of other managers, each of whom is a principal to the CISO and an agent to the manager’s supervisor. Every management layer therefore has a principal-agent relationship, and self-interests can lead to hidden actions that increase organizational cybersecurity risk.
Organizations can address this issue by evaluating the actions of their staff members to ensure that each member is considering the effect of their actions on the other staff members. Developing a practice of discussing the impact of individual actions on the organization’s cybersecurity risk during board meetings and key organizational events can help staff members see the importance of each member’s actions in cybersecurity risk management governance.
Organizations can strengthen cybersecurity governance by creating organizational structures that ensure that the agent managing cybersecurity risk fully understands the principal’s interests and is present when the principal is making decisions that may affect cybersecurity risk.Using Agency Theory Concepts to Guide Cybersecurity Governance
The NIST CSF 2.0 governance function can be analyzed from an agency theory perspective to help enterprises develop policies and take actions that ensure the proper management of cybersecurity risk. Each of the six NIST CSF 2.0 governance categories can help organizations understand and attain adequate cybersecurity risk governance:
- Organizational context—“The circumstances—mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements—surrounding the organization’s cybersecurity risk management decisions are understood.”6
- Risk management strategy—“The organization’s priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions.”7
- Roles, responsibilities, and authorities—“Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated.”8
- Policy—“Organizational policy is established, communicated, and enforced.”9
- Oversight—“Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy.”10
- Cybersecurity supply chain risk management—“Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders.”11
Principal-agent relationships also exist whenever one enterprise acts on behalf of another. This is evident in NIST CSF 2.0, which added cybersecurity supply chain management as a new category. There is considerable cybersecurity risk in every external relationship. In some cases, one enterprise acts as the agent for another enterprise. In other cases, the enterprise is the principal. Each of these relationships involves organizational self-interests that may not be in alignment. Similarly, the parties’ risk appetites will likely not be the same. Each of these relationships requires organizational leaders to consider how the other enterprise affects their cybersecurity risk. Developing contracts, delegating work, and monitoring actions are necessary steps to ensure that the principal’s self-interests are met.
Conclusion
The process of developing a cybersecurity risk management strategy, establishing policies, outlining roles and responsibilities, and changing the organizational structure may seem daunting. Taking an agency theory approach allows enterprises to have open dialogues, use a common language, and make these risk-management decisions based on conceptual understandings.
NIST CSF 2.0 can help organizations with managing some of these concerns. When deciding on an organizational structure, it is important to view everyone as an independent agent. Similarly, each principal should have the tools necessary to monitor the activities of the agents, and agents should not have conflicting responsibilities.
Similarly, organizations should strive to make cybersecurity governance accountability a key aspect of organizational culture. Policies, procedures, and direct work orders are only effective if organization members adhere to them. Creating a culture of accountability prompts even the most junior staff member to feel empowered to question why a procedure was not followed. These actions therefore help reduce the opportunity for agents to act on self-interest instead of the organization’s interest. Incorporating the conceptual understanding of agency theory with the NIST CSF 2.0 framework may be a reasonable way to start making these adjustments and ultimately decrease cybersecurity risk through strong governance.
Editor’s Note
This article is excerpted from an article that was published as an ISACA® Journal article. Read the full Journal article, “Cybersecurity Risk Management Governance: An Agency Theory Perspective,” available online.
Endnotes
1 ISACA® “COBIT 2019 Framework: Introduction and Methodology,”; Wilkin, C. L.; Chenhall, R. H.; “Information Technology Governance: Reflections on the Past and Future Directions,” Journal of Information Systems, 2020
2 Pearce, G.; “Five Things for Governance Professionals to Put on Their 2024 To-Do List,” ISACA, 15 December 2023
3 National Institute of Standards and Technology (NIST), “The NIST Cybersecurity Framework (CSF) 2.0,” USA, 26 February 2024
4 Cyert, R. M.; March, J. G.; A Behavioral Theory of the Firm, Prentice Hall, USA, 1963
5 ISACA, State of Cybersecurity 2023 Global Update on Workforce Efforts, Resources and Cyberoperations, 2023
6 NIST, “NIST CSF 2.0”
7 NIST, “NIST CSF 2.0”
8 NIST, “NIST CSF 2.0”
9 NIST, “NIST CSF 2.0”
10 NIST, “NIST CSF 2.0”
11 NIST, “NIST CSF 2.0”
Gerald F. Burch
Is an assistant professor at the University of Florida (Pensacola, Florida, USA). He teaches courses in information systems and business analytics at both the graduate and undergraduate levels. His research has been published in the ISACA® Journal and several other leading peer-reviewed journals. He has helped more than 100 enterprises with his strategic management consulting.
Jordan Burch
Is the chief technology officer at Foster Care to Success, where his focus is monitoring system availability, logging system event data, and reporting. He has implemented monitoring platforms for both the private and public sectors, including entire state digital infrastructures and international pharmaceutical and agricultural ventures. Burch has a strong background in network engineering and the difficulties faced by large enterprises attempting to collect usable system statistics from the far reaches of their infrastructures. He is involved in projects related to the Internet of Things, wherein he collects data from embedded systems that allow greater visibility of environmental factors at a much larger scale.
Mike McGarry
Is an information systems instructor at Virginia Commonwealth University (Richmond, Virginia, USA). He conducts research related to the economic analysis of cybersecurity. He has more than 30 years of experience and was the chief information officer of a Fortune 300 company when he retired from the industry.