Building Operational Resilience in Egyptian Banks through Information Security Governance: The Role of Cyber Resilience Culture and Top Management Support
Main Article Content
Abstract
The accelerating digitalization of banking services has increased both operational efficiency and exposure to sophisticated cyber threats. Although financial institutions continue to invest in cybersecurity technologies, the literature remains comparatively fragmented across technical security, risk management, business continuity, governance, and operational resilience. This conceptual paper develops the Banking Information Security Governance and Operational Resilience (BISGOR) Framework to explain how Information Security Governance (ISG) can strengthen Operational Resilience (OR) in Egyptian banks. The framework positions Cyber Resilience Culture (CRC) as a mediating mechanism and Top Management Support (TMS) as a moderating condition. Grounded in the Resource-Based View (RBV) and Dynamic Capability Theory (DCT), the study integrates peer-reviewed research on information security governance, cyber resilience, operational resilience, security culture, and executive support. It argues that ISG establishes strategic alignment, accountability, risk ownership, oversight, and cross-functional coordination; CRC translates these formal mechanisms into shared preparedness, reporting, collaboration, learning, and adaptive behavior; and TMS strengthens this translation through visible commitment, resources, authority, and strategic direction. Five hypotheses are developed and a 30-item proposed operationalization is provided for subsequent empirical validation. The paper contributes to Information Security Management research by shifting the unit of analysis from isolated technical protection to governance-driven continuity of critical banking services and by addressing a geographically underrepresented African banking context.