Towards the Integration of Cyber Security and Enterprise Architecture to Improve Cyber Risk Management

The work

AuthorsNick Nieuwenhuis
Editors
Typemastersthesis
Year2025
Citekeynieuwenhuis2025towards

Where it appeared

PublisherHU University of Applied Sciences

Abstract

Enterprises are facing increasingly complex cyber risks that form a threat to business continuity. Prior research suggests that integrating Cyber Security and Enterprise Architecture can improve Risk Management but provides limited guidance on how Cyber Security and Enterprise Architecture should be integrated. This research explores the integration of Cyber Security and Enterprise Architecture and examines its impact on Cyber Risk Management. A qualitative research approach was chosen, with data collected through a Focus Group and four Interviews with experts in the field. Thematic analysis was used to identify key strategies that enterprises employ to facilitate the integration and improve Cyber Risk Management. The findings reveal that Cyber Security and Enterprise Architecture are currently ‘somewhat integrated’. Blockers to this integration include different mindsets and focuses, organizational misalignment, and skills and knowledge gaps. Conversely, embedding security into Enterprise Architecture frameworks, aligning organizational structures, and adopting secure development practices were identified as critical to improving the integration. Four key strategies were derived from the data that contribute to this integration: 1. Embedding Cyber Security into Enterprise Architecture Frameworks: Integrating security considerations, such as principles, viewpoints, and requirements, as a fundamental part of EA frameworks ensures security is a primary concern in the architectural development process and not an afterthought. 2. Leveraging agile and secure development methodologies: Agile and secure development methodologies such as Security by Design and DevSecOps ensure enterprises can implement Cyber Security measures proactively. 3. Improving in-depth knowledge in Cyber Security and Enterprise Architecture teams: Improving architectural knowledge on the Cyber Security level and improving in-depth Cyber Security knowledge at the Enterprise Architecture level is crucial for shared understanding, awareness, and knowledge exchange. 4. Aligning Cyber Security and Enterprise Architecture functions in the Organizational Structure: Creating a shared vision, strategy, mindset, and focus between the Cyber Security and Enterprise Architecture functions can enhance collaboration and joint decision making. Furthermore, this study found that the effective integration of Cyber Security and Enterprise Architecture leads to improved Cyber Risk Management by enabling enterprises to more efficiently identify, assess, and address cyber risks at every stage of the Cyber Risk Management process. This research contributes to the field by providing practical insights and a list of strategies for overcoming integration challenges, supporting enterprises in improving their Cyber Risk Management capabilities.

A copy is held

pdf, 1.8 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-04 00:00 UTC
Approved bya person 2026-08-16 16:18 UTC

Cite it as

@mastersthesis{nieuwenhuis2025towards,
  title        = {Towards the Integration of Cyber Security and Enterprise Architecture to Improve Cyber Risk Management},
  author       = {Nick Nieuwenhuis},
  year         = {2025},
  publisher    = {HU University of Applied Sciences},
  doi          = {10.5281/zenodo.14639415},
}

This record lives at https://refs.drheap.org/nieuwenhuis2025towards/ and will keep doing so.