Actual problems of innovative economy and law

Journal "Actual problems of innovative economy and law" is included in category B for specialties: in the field of knowledge "Management and administration": 073, 076 (order of the Ministry of Education and Science of Ukraine dated 23.08.2023 No. 1035) and 071, 072, 075 (order of the Ministry of Education and Science of Ukraine dated 12.20.2023 No. 1543); in the field of knowledge "Social and behavioral sciences" 051 (order of the Ministry of Education and Science of Ukraine dated August 23, 2023 No. 1035); in the field of knowledge "Law" - 081 and "Public management and administration" - 281 (order of the Ministry of Education and Science of Ukraine dated 12.20.2023 No. 1543).
Registration of an entity in print media: Decision of the National Council of Ukraine on Television and Radio Broadcasting No. 1390 dated 11/16/2023. Media identifier: R30-02018
The journal is indexed in the International Scientific Center of Index Copernicus International

Corporate cyber risk governance as a factor in the economic security of defence-industrial enterprises

УДК: 338.2:004.056:355.4

DOI: https://doi.org/10.36887/2524-0455-2026-3-9

Harmash Oleh,
PhD in Economics, Associate Professor Department of International Business and Logistics,
National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute” (Ukraine), Kyiv, Ukraine,
https://orcid.org/0000-0003-4324-4411
Fedorenko Tetiana,
PhD in Law, Associate Professor, Associate Professor of the Department of Industry Law and General Legal Disciplines, Director of the Institute of Law and Public Relations,
HEI "Open International University of Human Development "Ukraine", Kyiv, Ukraine,
https://orcid.org/ 0000-0002-3447-9078
Gvozdova Olga,
Master’s degree seeker of the Department of Information Warfare,
National Defence University of Ukraine, Kyiv, Ukraine,
https://orcid.org/0009-0009-8000-9796


The article substantiates that cyber risks faced by defence-industrial enterprises should not be interpreted only as a technical issue of information security. In the current security environment, they form an integral component of threats to economic security because they can simultaneously affect financial stability, production continuity, fulfillment of defense contracts, protection of intellectual property, integrity of supply chains, regulatory compliance and stakeholder trust. The relevance of the study is determined by the growing digital dependence of defence-industrial enterprises, the spread of hybrid threats, the sensitivity of technological and contractual information, and the increasing role of corporate governance bodies in overseeing non-financial risks that may have material economic consequences. The purpose of the article is to develop a conceptual and methodological approach to integrating cyber risks into the corporate governance system of economic security of defence-industrial enterprises. The methodological basis of the study includes a systems approach, comparative analysis of cybersecurity and corporate governance frameworks, risk-oriented analysis, logical generalization and conceptual modelling. The article clarifies the economic nature of cyber risks for defence-industrial enterprises, classifies cyber-economic threats according to their impact on key components of economic security, and proposes a governance model that distributes responsibilities among the supervisory board, executive management, risk management, cybersecurity, internal audit, procurement and production units. The study also develops a system of key risk indicators for early warning, including indicators of critical vulnerabilities, incident response time, supplier cybersecurity maturity, access control violations, backup recovery readiness and cyber-related contract disruption risk. The practical value of the article lies in the possibility of using the proposed approach as a basis for internal regulations, risk registers, board-level dashboards and audit procedures at defence-industrial enterprises. The scientific novelty of the study lies in the proposed logic of translating a cyber event into corporate-economic consequences through the sequence: critical asset – cyber scenario – economic security component – key risk indicator – escalation level – corporate decision. This approach makes it possible to operationalize cyber risks for board-level oversight, internal audit, risk registers, supplier control and early-warning systems at defence-industrial enterprises.

Keywords: cyber risks, economic security of the enterprise, national security, cybersecurity, state defense capability, defense-industrial complex, corporate governance, defense contracts, threats, challenges, cyber resilience, supply chains, compliance.

References.

  1. Seleznova, H. O., & Stepanenko, R. D. (2023). Suchasni ryzyky zabezpechennia ekonomichnoi bezpeky pidpryiemstv za umov tsyfrovizatsii [Modern risks of ensuring the economic security of enterprises under digitalization]. Ukrainskyi zhurnal prykladnoi ekonomiky ta tekhniky [Ukrainian Journal of Applied Economics and Technology], (4), 167–173. https://doi.org/10.36887/2415-8453-2023-4-26
  2. Sorokivska, O., Kuzhda, T., & Kinal, N. (2025). Tsyfrovi ryzyky ta informatsiina bezpeka korporatyvnoho sektoru [Digital risks and information security of the corporate sector]. Herald of Khmelnytskyi National University. Economic Sciences, 342(3(1)), 95–105. https://doi.org/10.31891/2307-5740-2025-342-3(1)-14
  3. Ziniuk, M., Dieieva, N., Bohatyrova, K., Melnychenko, S., Faivishenko, D., & Shevchun, M. (2022). Tsyfrova transformatsiia korporatyvnoho upravlinnia [Digital transformation of corporate governance]. Financial and Credit Activity Problems of Theory and Practice, 5(46), 300–310. https://doi.org/10.55643/fcaptp.5.46.2022.3807
  4. Khalina, O., & Shmahalo, V. (2025). Stratehiia rozvytku ekonomichnoi bezpeky pidpryiemstv v umovakh tsyfrovykh transformatsii [Strategy for the development of economic security of enterprises under digital transformation]. Ekonomika ta suspilstvo [Economy and Society], (73). https://doi.org/10.32782/2524-0072/2025-73-138
  5. Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019
  6. Lending, C. C., Minnick, K., & Schorno, P. J. (2018). Corporate governance, social responsibility, and data breaches. Financial Review, 53(2), 413–455. https://doi.org/10.1111/fire.12160
  7. Cortez, E., & Dekker, M. (2022). A corporate governance approach to cybersecurity risk disclosure. European Journal of Risk Regulation, 13(3). https://doi.org/10.1017/err.2022.10
  8. Héroux, S., & Fortin, A. (2024). Board of directors’ attributes and aspects of cybersecurity disclosure. Journal of Management and Governance, 28, 359–404. https://doi.org/10.1007/s10997-022-09660-7
  9. Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274
  10. Krutilla, K., Alexeev, A., Jardine, E., & Good, D. H. (2021). The benefits and costs of cybersecurity risk reduction: A dynamic extension of the Gordon and Loeb model. Risk Analysis. https://doi.org/10.1111/risa.13713
  11. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29
  12. Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2022). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST Special Publication 800-161 Revision 1. https://doi.org/10.6028/NIST.SP.800-161r1
  13. (2023). G20/OECD Principles of Corporate Governance 2023. OECD Publishing. https://doi.org/10.1787/ed750b30-en
  14. Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise Risk Management – Integrating with Strategy and Performance. https://www.coso.org/guidance-erm
  15. S. Department of Defense Chief Information Officer. About CMMC. https://dodcio.defense.gov/CMMC/About
  16. European Commission. (2024). EDIS: Our common defence industrial strategy. https://defence-industry-space.ec.europa.eu/eu-defence-industry/edis-our-common-defence-industrial-strategy_en
  17. Pro vnesennia zmin do deiakykh zakoniv Ukrainy shchodo zakhystu informatsii ta kiberzakhystu derzhavnykh informatsiinykh resursiv, obiektiv krytychnoi informatsiinoi infrastruktury [On Amendments to Certain Laws of Ukraine Regarding Information Protection and Cyber Protection of State Information Resources and Critical Information Infrastructure]. (2025). Law of Ukraine No. 4336-IX of March 27, 2025. https://zakon.rada.gov.ua/go/4336-20
  18. Pro pryiniattia natsionalnykh standartiv, zminy do natsionalnoho standartu ta skasuvannia natsionalnykh standartiv [On Adoption of National Standards, Amendments to a National Standard and Repeal of National Standards]. (2023). Order of SE “UkrNDNC” No. 210 of August 17, 2023. https://zakon.rada.gov.ua/go/v0210774-23
  19. Orhan z sertyfikatsii system menedzhmentu [Management Systems Certification Body]. Derzhavnyi naukovo-doslidnyi instytut tekhnolohii kiberbezpeky ta zakhystu informatsii [State Research Institute of Cybersecurity Technologies and Information Protection]. https://csi.cip.gov.ua/uk/pages/organ-z-sertifikaciyi-sistem-menedzhmentu.

Quote article, APA style

Harmash O. , Fedorenko T. , Gvozdova O. Corporate cyber risk governance as a factor in the economic security of defence-industrial enterprises. Actual problems of innovative economy and law. 2026. №3. 57-64 pp. https://doi.org/10.36887/2524-0455-2026-3-9

Quote article, MLA style

Harmash O. , Fedorenko T. , Gvozdova O. Corporate cyber risk governance as a factor in the economic security of defence-industrial enterprises. Actual problems of innovative economy and law. https://doi.org/10.36887/2524-0455-2026-3-9