{
  "id": 5453,
  "url": "https://arxiv.org/abs/2604.21604v1",
  "title": "Mitigate or Fail: How Risk Management Shapes Cybersecurity Competency",
  "summary": "Contemporary cybersecurity governance assumes that professionals apply risk reasoning. Yet major organisational failures persist despite investment in tools, staffing, and credentials. This study investigates the structural source of that paradox. Cybersecurity speaks the language of risk, but its training architecture has shaped the profession to think in terms of threats. A sequential mixed-methods design integrated four analyses; NLP of the NIST NICE Framework v2.0.0 (2,111 TKS statements), S",
  "authors": "Jeffrey T. Gardiner",
  "category": "research",
  "topics": "regulation,finance-investment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-04-23T12:27:03.000Z",
  "fetched_at": "2026-07-14T16:31:44.627Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/5453",
  "original_url": "https://arxiv.org/abs/2604.21604v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}