Skip to main navigation Skip to search Skip to main content

ENHANCING CYBERSECURITY RISK GOVERNANCE THROUGH EFFECTIVE RISK APPETITE FRAMEWORK AND METRICS

  • Rashid Al-Obaidli

Student thesis: Master's Dissertation

Abstract

ABSTRACT The accelerating digital transformation across the media and entertainment sector has expanded both opportunity and exposure to cyber threats. As online broadcasting, subscription platforms, and digital distribution networks grow in scale, so too does the complexity of cyber risk governance. This thesis aims to enhance cybersecurity risk governance by developing an effective Risk Appetite Framework (RAF) and quantifiable cyber risk metrics tailored to the media industry. Drawing upon internationally recognized standards, specifically ISO/IEC 31010:2019 and COSO ERM 2017, the study introduces a risk matrix-based methodology to measure, classify, and prioritize cyber risks using likelihood-and-impact scoring. To ensure empirical grounding, the model incorporates data from the IBM Cost of a Data Breach Report 2025, which benchmarks the average financial and reputational losses across industries, including the media sector. The research employs a mixed-methods approach that includes a literature review, secondary data analysis, and informal expert consultation. The outcome is a structured Cybersecurity Impact Matrix that enables organizations to quantify their exposure, align risk decisions with corporate objectives, and maintain consistency between risk appetite and operational resilience. Ultimately, this work contributes a practical framework that bridges governance theory with actionable metrics, strengthening cybersecurity maturity and decision-making within the evolving media landscape.
Date of Award2026
Original languageAmerican English
Awarding Institution
  • HBKU College of Science and Engineering

Keywords

  • Cybersecurity

Cite this

'