Cybersecurity Governance in the Ministry of Communications and Information Technology in Yemen: Empirical Evidence and a Context-Sensitive Framework
Public sector institutions in developing countries increasingly adopt cybersecurity governance frameworks, yet a persistent gap remains between formal adoption and strategic cybersecurity effectiveness. This study investigates this gap through a case study of the Ministry of Communications and Information Technology in Yemen, guided by ISO/IEC 27014. Using a descriptive-analytical approach, data were collected from 30 cybersecurity decision-makers across six governance dimensions and analyzed using PLS-SEM. The findings reveal a cybersecurity governance maturity gap, as none of the governance dimensions showed a significant impact on strategic effectiveness despite moderate to high implementation levels. Risk assessment and management exhibited a negative, non-significant relationship, indicating symbolic practices. The study proposes a context-sensitive framework to enhance strategic alignment and effectiveness. The findings offer practical guidance for policymakers in developing countries seeking to transition from compliance-oriented cybersecurity governance toward strategically integrated governance frameworks.