Cyber Resilience Maturity Model for Government Organisations: A Secondary Data Analysis and Outcome-Based Framework
DOI:
https://doi.org/10.59075/tamsaal.v4i4.154Keywords:
Cyber resilience; cybersecurity maturity; government organizations; public sector; maturity model; digital government; cybersecurity governanceAbstract
Government entities are becoming more reliant on the interconnected digital infrastructure to perform the fundamental government roles, but traditional cybersecurity maturity measurements tend to capture most effectively the implementation of controls rather than the potential to withstand and recover valuable operations in the wake of havoc. The paper builds a Government Cyber Resilience Maturity Model (G-CRMM) based on systematic secondary research. The evidence base incorporates global cybersecurity frameworks, government strategies and assurance efforts, findings of audits by the government in the public sector, various surveys of sector maturity and occurrences, as well as peer-reviewed research published or modified since 2021 and August 2026. Directed content analysis mapped the evidence to the resilience cycle of anticipation, resistance, recovery and adaptation with consideration of government-specific issues such as statutory continuity of services, outdated technology, inter-organisational dependencies, supplier concentration, accountability, cyber workforce capacity and societal trust. Instances of secondary evidence portray ongoing incompatibility of the criticality of public administration with its maturity in cybersecurity. European evidence still has public administration in the risk zone of cybersecurity, and audit outcomes by the UK government show material weaknesses of critical systems, legacy workforce and capacity, and legacy assets. According to the principles of cross-source synthesis, the G-CRMM is characterised by five levels of maturity and eight dimensions: Reactive, Repeatable, Managed, Resilient and Adaptive. It suggests a non-compensatory scoring scheme based on geometric aggregation, and a critical-dimension ceiling that ensures that powerful technical regulations cannot hide critical flaws in mission visibility, governance or recovery capacity. The model adds a public-service-oriented model that relates cybersecurity maturity to operational continuity, collective defence and institutional learning. It offers a falsifiable way by which government organisations can calibrate capabilities, risk-aware target maturity and cyber-resilience funding priorities.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ibtihajul Islam

This work is licensed under a Creative Commons Attribution 4.0 International License.




