Corporate cyber risk governance as a factor in the economic security of defence-industrial enterprises
Abstract
The article substantiates that cyber risks faced by defence-industrial enterprises should not be interpreted only as a technical issue of information security. In the current security environment, they form an integral component of threats to economic security because they can simultaneously affect financial stability, production continuity, fulfillment of defense contracts, protection of intellectual property, integrity of supply chains, regulatory compliance and stakeholder trust. The relevance of the study is determined by the growing digital dependence of defence-industrial enterprises, the spread of hybrid threats, the sensitivity of technological and contractual information, and the increasing role of corporate governance bodies in overseeing non-financial risks that may have material economic consequences. The purpose of the article is to develop a conceptual and methodological approach to integrating cyber risks into the corporate governance system of economic security of defence-industrial enterprises. The methodological basis of the study includes a systems approach, comparative analysis of cybersecurity and corporate governance frameworks, risk-oriented analysis, logical generalization and conceptual modelling. The article clarifies the economic nature of cyber risks for defence-industrial enterprises, classifies cyber-economic threats according to their impact on key components of economic security, and proposes a governance model that distributes responsibilities among the supervisory board, executive management, risk management, cybersecurity, internal audit, procurement and production units. The study also develops a system of key risk indicators for early warning, including indicators of critical vulnerabilities, incident response time, supplier cybersecurity maturity, access control violations, backup recovery readiness and cyber-related contract disruption risk. The practical value of the article lies in the possibility of using the proposed approach as a basis for internal regulations, risk registers, board-level dashboards and audit procedures at defence-industrial enterprises. The scientific novelty of the study lies in the proposed logic of translating a cyber event into corporate-economic consequences through the sequence: critical asset – cyber scenario – economic security component – key risk indicator – escalation level – corporate decision. This approach makes it possible to operationalize cyber risks for board-level oversight, internal audit, risk registers, supplier control and early-warning systems at defence-industrial enterprises. Keywords: cyber risks, economic security of the enterprise, national security, cybersecurity, state defense capability, defense-industrial complex, corporate governance, defense contracts, threats, challenges, cyber resilience, supply chains, compliance.