Graduate research paper

An Integrated Approach to Cybersecurity Governance for Organizations with Established Cybersecurity Programs

A practical framework for organizations that already have cybersecurity programs—but need those programs to remain adaptive, defensible, and useful as threats, technology, regulations, and AI adoption continue to change.

Originally prepared for CMAP 635 Cybersecurity Governance at the University of Maryland Global Campus. Public portfolio edition preserves the paper’s research and argument while presenting a cleaner title page.

Core argument

Compliance at one point in time does not guarantee continued security.

The paper argues that established organizations should treat cybersecurity modernization as an ongoing governance responsibility rather than a one-time technical project. Governance, risk management, and compliance provide the foundation, but the program must also account for leadership communication, human factors, regulatory obligations, incident readiness, and emerging AI risk.

Central question: “Are we protected?” cannot be answered with a permanent yes or no. The more useful question is whether the organization can continuously understand, communicate, reduce, and reevaluate its risk.

Modernization challenges

Where established programs become vulnerable.

Outdated policy

Past compliance can create false confidence when requirements, systems, and threats have moved on.

Human blame

Annual training alone does not address the organizational conditions that make ordinary mistakes dangerous.

Executive buy-in

Cybersecurity leaders must explain risk and investment without overselling certainty or relying on abstract fear.

AI integration

Organizations need documented, risk-aware adoption before sensitive information and untested tools become operational defaults.

The PAPER approach

A simple modernization cycle.

P

Plan

Establish stakeholders, communication, milestones, partners, and decision paths.

A

Assess

Understand the current posture through document, control, technical, and operational review.

P

Produce

Create the policies, technology, training, communications, and other improvements the assessment requires.

E

Execute

Release, implement, teach, replace, and operationalize the approved changes.

R

Reevaluate

Define review cycles so modernization does not become the next outdated one-time effort.

Recommendations

Six practical actions for organizational leaders.

  1. Use NIST and CISA guidance as a foundation for building or updating cybersecurity programs.
  2. Establish clear GRC ownership and make cybersecurity efforts visible.
  3. Review existing policies and identify critical tasks first.
  4. Allocate funding according to organizational risk and mission needs.
  5. Build human-centered training and AI governance into modernization.
  6. Treat modernization as an ongoing cycle rather than a finishable project.

What this work demonstrates

Research translated into a decision framework.

The paper synthesizes primary government guidance, industry research, legal and regulatory considerations, a critical-infrastructure case study, and emerging AI governance into one argument written for organizational leaders. It demonstrates source evaluation, structured reasoning, risk communication, and the ability to turn a broad cybersecurity problem into a usable model.