Information Security Governance in Not-for-Profit Organisations: A Critical Review and Research Agenda
DOI:
https://doi.org/10.70917/ijcisim-2026-2270Keywords:
Information security governance, cybersecurity, not-for-profit organisations, non-governmental organisations, charity sector, critical review, research agenda, stakeholder theory, resource-based view, legitimacy theoryAbstract
Information Security Governance (ISG) — the system by which an organisation directs and controls its information security activities — has accumulated a substantial empirical base in corporate and public-sector settings but remains under-examined in not-for-profit organisations (NFPs). Not-for-profits are simultaneously high-value targets for cyber threat actors and structurally resource-constrained, with around one-third of UK charities reporting cyber incidents in 2024 and the proportion rising to two-thirds among charities with annual income above £500,000. This article presents a critical review of the published evidence on ISG in NFPs and articulates a structured research agenda for the field. The review makes three contributions. First, it maps the literature against the eight components of the ISO/IEC 27014:2020 ISG construct and exposes a systematic imbalance: operational and protective components (risk management, policy, organisation and roles, compliance) are reasonably well evidenced, while strategic and oversight components (board oversight, security strategy, performance measurement, stakeholder communication) remain under-researched. Second, it critically examines the portability of corporate-derived ISG constructs to the resource, accountability, and mission conditions of the non-profit sector. Third, it articulates a four-stream research agenda — conceptual, methodological, empirical, and theoretical — with specific research questions to advance NFP ISG research over the next three to five years. The review draws on Stakeholder Theory, the Resource-Based View, and Legitimacy Theory to frame both the critique and the agenda. The article argues that NFP ISG should be treated not as a weaker version of corporate ISG, but as a distinct governance problem shaped by mission accountability, resource scarcity, and beneficiary protection.