{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:34:40Z","timestamp":1760060080337,"version":"build-2065373602"},"reference-count":50,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,7,31]],"date-time":"2025-07-31T00:00:00Z","timestamp":1753920000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Minciencias","award":["82299"],"award-info":[{"award-number":["82299"]}]},{"name":"Juan Velez-Ocampo and Jeferson Mart\u00ednez Lozano","award":["82299"],"award-info":[{"award-number":["82299"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>This study explores the emergent dynamics of knowledge sovereignty within organisations following data breach incidents. Using qualitative analysis based on Benoit\u2019s image restoration theory, this study shows that employees do more than relay official messages\u2014they actively shape information governance after a cyberattack. Employees adapt Benoit\u2019s response strategies (denial, evasion of responsibility, reducing offensiveness, corrective action, and mortification) based on how authentic they perceive the organisation\u2019s response, their identification with the company, and their sense of fairness in crisis management. This investigation substantively extends extant crisis communication theory by showing how knowledge sovereignty is shaped through negotiation, as employees manage their dual role as breach victims and organisational representatives. The findings suggest that employees are key actors in post-breach information governance, and that their authentic engagement is critical to organisational recovery after cybersecurity incidents.<\/jats:p>","DOI":"10.3390\/jcp5030051","type":"journal-article","created":{"date-parts":[[2025,8,5]],"date-time":"2025-08-05T07:49:58Z","timestamp":1754380198000},"page":"51","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["The Knowledge Sovereignty Paradigm: Mapping Employee-Driven Information Governance Following Organisational Data Breaches"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4743-3500","authenticated-orcid":false,"given":"Jeferson","family":"Mart\u00ednez Lozano","sequence":"first","affiliation":[{"name":"Facultad de Ingenier\u00edas, Instituto Tecnol\u00f3gico Metropolitano, Medellin 050001, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin","family":"Restrepo Bedoya","sequence":"additional","affiliation":[{"name":"Facultad de Ingenier\u00edas, Instituto Tecnol\u00f3gico Metropolitano, Medellin 050001, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juan","family":"Velez-Ocampo","sequence":"additional","affiliation":[{"name":"Facultad de Ciencias Economicas, Universidad de Antioquia, Medellin 050001, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,7,31]]},"reference":[{"key":"ref_1","first-page":"410","article-title":"When enough is enough: Investigating the antecedents and consequences of information security fatigue","volume":"32","author":"Cram","year":"2021","journal-title":"Inf. Syst. Res."},{"key":"ref_2","unstructured":"Ahmad, A., and Maynard, S.B. (2022). Employee responses to cybersecurity policy communication: A longitudinal analysis of sovereignty-asserting behaviours. Comput. Secur."},{"key":"ref_3","unstructured":"Benoit, W.L. (1995). Accounts, Excuses, and Apologies: A Theory of Image Restoration Strategies, University of New York Press."},{"key":"ref_4","unstructured":"Karlsson, F., Hedstr\u00f6m, K., and Goldkuhl, G. (2020). Knowledge governance vacuums: Information security breaches and shifts in organisational knowledge networks. J. Strateg. Inf. Syst., 29."},{"key":"ref_5","unstructured":"Coombs, W.T., and Holladay, S.J. (2012). The Handbook of Crisis Communication, Wiley-Blackwell."},{"key":"ref_6","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022)."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"349","DOI":"10.1007\/s11023-019-09507-5","article-title":"Is Cybersecurity a Public Good?","volume":"29","author":"Taddeo","year":"2019","journal-title":"Minds Mach."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1177\/0007650317727540","article-title":"The Governance of Digital Technology, Big Data, and the Internet: New Roles and Responsibilities for Business","volume":"58","author":"Flyverbom","year":"2019","journal-title":"Bus. Soc."},{"key":"ref_9","first-page":"315","article-title":"Exploring the tension between employee victimhood and organisational representation following data breaches","volume":"31","author":"Safa","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_10","first-page":"309","article-title":"Leveraging fairness and reactance theories to deter reactive computer abuse following enhanced organisational information security policies","volume":"31","author":"Lowry","year":"2021","journal-title":"Inf. Syst. J."},{"key":"ref_11","first-page":"236","article-title":"Knowledge resilience during cybersecurity incidents: Linking employee agency to organisational recovery","volume":"26","author":"Chen","year":"2022","journal-title":"J. Knowl. Manag."},{"key":"ref_12","first-page":"602","article-title":"Post-breach agency restoration: Four strategies for psychological self-protection following data breaches","volume":"29","author":"Renaud","year":"2021","journal-title":"Inf. Comput. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Nonaka, I., and Takeuchi, H. (1995). The Knowledge-Creating Company: How Japanese Companies Create the Dynamics of Innovation, Oxford University Press.","DOI":"10.1093\/oso\/9780195092691.001.0001"},{"key":"ref_14","first-page":"417","article-title":"Information security knowledge sharing after data breaches: A comparative analysis of explicit and tacit knowledge disruption","volume":"62","author":"Belsis","year":"2022","journal-title":"Int. J. Inf. Manag."},{"key":"ref_15","first-page":"203","article-title":"Information governance maturity in the post-breach era: An empirical examination of knowledge disruption and recovery","volume":"44","author":"Stafford","year":"2020","journal-title":"MIS Q."},{"key":"ref_16","unstructured":"Fombrun, C.J., and Van Riel, C.B.M. (2004). Fame Fortune: How Successful Companies Build Winning Reputations, Prentice Hall."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1057\/palgrave.crr.1550012","article-title":"Corporate reputation: The definitional landscape","volume":"9","author":"Barnett","year":"2006","journal-title":"Corp. Reput. Rev."},{"key":"ref_18","unstructured":"National Security Agency (2024, January 30). StopRansomware Guide Released by NSA and Partners, Available online: https:\/\/media.defense.gov\/2023\/May\/23\/2003227891\/-1\/-1\/0\/CSI-StopRansomware-Guide.PDF."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.3233\/THC-161263","article-title":"Cybersecurity in healthcare: A systematic review of modern threats and trends","volume":"25","author":"Kruse","year":"2017","journal-title":"Technol. Health Care"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"65520","DOI":"10.1109\/ACCESS.2020.2985089","article-title":"IMPACT: Impersonation attack detection via edge computing using deep autoencoder and feature abstraction","volume":"8","author":"Lee","year":"2020","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"205","DOI":"10.3390\/fi5020205","article-title":"A review of cyber threats and defence approaches in emergency management","volume":"5","author":"Loukas","year":"2013","journal-title":"Future Internet"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Ulven, J.B., and Wangen, G. (2021). A systematic review of cybersecurity risks in higher education. Future Internet, 13.","DOI":"10.3390\/fi13020039"},{"key":"ref_23","unstructured":"Cybersecurity Glossary (2024, January 30). Homeland Security, Available online: https:\/\/niccs.cisa.gov\/cybersecurity-career-resources\/vocabulary."},{"key":"ref_24","unstructured":"(2024, January 30). NIST, Available online: https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/cybersecurity-basics\/glossary."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"102974","DOI":"10.1016\/j.cose.2022.102974","article-title":"Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity","volume":"124","author":"Shaikh","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_26","unstructured":"Whitman, M.E., and Mattord, H.J. (2021). Principles of Incident Response and Disaster Recovery, Cengage Learning."},{"key":"ref_27","unstructured":"Santos (2018). Desarrollar programas y pol\u00edticas de ciberseguridad. Publicaci\u00f3n De TI De Pearson, 3, 127."},{"key":"ref_28","unstructured":"Shedden, P., Smith, W., and Ahmad, A. (2010). Information Security Risk Assessment: Towards a Business Practice Perspective, Edith Cowan University."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1109\/MC.2017.107","article-title":"Information Security Risk Assessment: A Method Comparison","volume":"50","author":"Wangen","year":"2017","journal-title":"Computer"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"103392","DOI":"10.1016\/j.im.2020.103392","article-title":"DATA BREACH MANAGEMENT: AN INTEGRATED RISK MODEL","volume":"58","author":"Khan","year":"2021","journal-title":"Inf. Manag."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1201\/1078\/44432.21.3.20040601\/82480.11","article-title":"Business continuity planning: A comprehensive approach","volume":"21","author":"Cerullo","year":"2004","journal-title":"Inf. Syst. Manag."},{"key":"ref_32","first-page":"102498","article-title":"Security breaches and organization response strategy: Exploring consumers\u2019 threat and coping appraisals","volume":"65","author":"Ou","year":"2022","journal-title":"Int. J. Inf. Manag."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"532","DOI":"10.2307\/258557","article-title":"Building theories from case study research","volume":"14","author":"Eisenhardt","year":"1989","journal-title":"Acad Manage Rev."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1291","DOI":"10.1002\/smj.3015","article-title":"Transparency and replicability in qualitative research: The case of interviews with elite informants","volume":"40","author":"Aguinis","year":"2019","journal-title":"Strateg. Manag. J."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"740","DOI":"10.1057\/jibs.2010.55","article-title":"Theorising from case studies: Towards a pluralist future for international business research","volume":"42","author":"Welch","year":"2010","journal-title":"J. Int. Bus. Stud."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1017\/mor.2019.27","article-title":"Rethinking Qualitative Scholarship in Emerging Markets: Researching, Theorizing, and Reporting","volume":"15","author":"Plakoyiannaki","year":"2019","journal-title":"Manag. Organ. Rev."},{"key":"ref_37","first-page":"441","article-title":"Desarrollar la teor\u00eda de la gesti\u00f3n de operaciones a trav\u00e9s de la investigaci\u00f3n de casos y de campo","volume":"16","author":"Meredith","year":"1998","journal-title":"Rev. De Gesti\u00f3n De Oper."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"63","DOI":"10.3316\/QRJ1102063","article-title":"Purposeful Sampling in Qualitative Research Synthesis","volume":"11","author":"Suri","year":"2011","journal-title":"Qual. Res. J."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"2005","DOI":"10.1016\/j.jbusres.2015.10.146","article-title":"Unpacking the ambidexterity implementation process in the internationalization of emerging market multinationals","volume":"69","author":"Fleury","year":"2016","journal-title":"J. Bus. Res."},{"key":"ref_40","unstructured":"Miles, M.B., Huberman, A.M., and Salda\u00f1a, J. (2014). Qualitative Data Analysis: A Methods Sourcebook, Sage Publications."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"683","DOI":"10.1080\/07421222.2018.1451962","article-title":"The Role of Corporate Reputation and Crisis Response Strategies in Data Breach Management","volume":"35","author":"Gwebu","year":"2018","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1057\/palgrave.crr.1550049","article-title":"Protecting Organization Reputations During a Crisis: The Development and Application of Situational Crisis Communication Theory","volume":"10","author":"Coombs","year":"2007","journal-title":"Corp. Reput. Rev."},{"key":"ref_43","first-page":"1","article-title":"The influence of negative online word-of-mouth on fear: A cognitive appraisal model","volume":"103","author":"Kim","year":"2019","journal-title":"J. Bus. Res."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Weiner, B. (2006). Social Motivation, Justice, and the Moral Emotions, Psychology Press.","DOI":"10.4324\/9781410615749"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"101773","DOI":"10.1016\/j.pubrev.2019.04.006","article-title":"E-Racing together: How starbucks reshaped and deflected racial conversations on social media","volume":"45","author":"Novak","year":"2019","journal-title":"Public Relat. Rev."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1002\/smj.2232","article-title":"The thin red line between success and failure: Path dependence in the diffusion of innovative production technologies","volume":"36","author":"Greve","year":"2015","journal-title":"Strateg. Manag. J."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"127","DOI":"10.5465\/amr.2009.35713319","article-title":"Trust Repair After An Organization-Level Failure","volume":"34","author":"Gillespie","year":"2009","journal-title":"Acad. Manag. Rev."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"660","DOI":"10.1108\/01437721011073364","article-title":"The impact of organizational justice on work performance: Mediating effects of organizational commitment and leader-member exchange","volume":"31","author":"Wang","year":"2010","journal-title":"Int. J. Manpow."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1111\/ijmr.12002","article-title":"Researching tomorrow\u2019s crisis: Methodological innovations and wider implications","volume":"15","author":"Buchanan","year":"2013","journal-title":"Int. J. Manag. Rev."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1057\/crr.2014.13","article-title":"Sustainability Dimensions: A Source to Enhance Corporate Reputation","volume":"17","year":"2014","journal-title":"Corp. Reput. Rev."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/51\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:19:39Z","timestamp":1760033979000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/51"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,31]]},"references-count":50,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030051"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030051","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,7,31]]}}}