📄 Abstract
Cybersecurity is an essential governance issue in industries in the United States, yet governance models lack homogeneity and maturity. This paper provides an integrative comparative analysis of cybersecurity governance in five domains, namely financial services, healthcare, energy and operational technology (OT), local government, and higher education. Based on global frameworks (ISO/IEC 27001, NIST Cybersecurity Framework, COBIT 2019), sectoral maturity models, and empirical reviews in recent literature, the research analyzes how boards, executives, and risk functions organize their responsibilities, coordinate their frameworks, and react to regulatory pressure. The convergence around a limited number of multi-framework stacks and governance-risk-compliance logics is demonstrated by the analysis, but the analysis also identifies divergences based on regulatory intensity, resource constraints, organizational culture, and variations in risk profiles (data-centric and safety-critical environments). The public and education sectors, especially, which are under-resourced, find it hard to bring the formal responsibilities to actual practice. The article suggests a three-tier integrative reference model of cybersecurity governance that is aligned to the framework and sensitive sector and points out new requirements to govern AI-enabled security capabilities in addition to traditional controls.
🏷️ Keywords
📚 How to Cite:
Karyn Ekpo , COMPARATIVE ANALYSIS OF CYBERSECURITY GOVERNANCE MODELS ACROSS INDUSTRIES , Volume 11 , Issue 3, March 2026, EPRA International Journal of Research & Development (IJRD) , DOI: https://doi.org/10.36713/epra26769