<?xml version="1.0" encoding="UTF-8"?>
<article article-type="brief-report" xml:lang="en" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher">global-journal-of-computer-science-and-technology-g-interdisciplinary</journal-id>
<journal-title-group>
<journal-title>Global Journal of Computer Science and Technology - G: Interdisciplinary</journal-title>
</journal-title-group>
<issn publication-format="print">0975-4350</issn>
<issn publication-format="electronic">0975-4172</issn>
<publisher><publisher-name>Global Journals Publishing Group Incorporated</publisher-name></publisher>
<self-uri xlink:href="https://globaljournals.org/journal-seo-export/jats/276927.xml" />
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">276927</article-id>
<title-group>
<article-title>The Cybersecurity Governance Gap in Ecuadorian SMEs: IT–Management Alignment, Decision Rights, and Incident-Response Accountability</article-title>
<subtitle>SME Cybersecurity Governance Gap</subtitle>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Orellana</surname><given-names>Franklin</given-names></name><xref ref-type="aff" rid="aff1" />
</contrib>
</contrib-group>
<aff id="aff1">United States</aff>
<volume>26</volume>
<abstract><p>Cybersecurity weaknesses in small and medium-sized enterprises (SMEs) are frequently attributed to limited budgets, inadequate training, and obsolete technology. This explanation is incomplete when employees responsible for cybersecurity recognize risks but lack the authority, executive access, and governance routines needed to convert that knowledge into organizational action. This article presents a governance-centered secondary analysis of documentary evidence from a 2020 qualitative study of 50 information technology and cybersecurity managers working in Ecuadorian SMEs. The corpus comprised anonymized participant quotations, thematic tables, and narrative findings preserved in the dissertation. Guided by business–IT strategic alignment and the Govern function of the National Institute of Standards and Technology Cybersecurity Framework 2.0, the analysis identified five interconnected mechanisms: responsibility without decision authority, weak translation of cyber risk into business priorities, fragmented communication and escalation, resource allocation disconnected from risk ownership, and limited monitoring and organizational learning. Negative cases showed that periodic audits, stakeholder monitoring, and direct owner–IT collaboration can partially counter these constraints. The article contributes a resource-sensitive Cybersecurity Governance Alignment Model in which incident-response capability depends on aligning accountability, decision rights, communication, resources, and monitoring. For SME managers, the study proposes a minimum viable governance cycle that can be implemented without enterprise-scale bureaucracy.</p></abstract>
<kwd-group kwd-group-type="author-generated">
<kwd>Business–IT Alignment</kwd>
<kwd>Cybersecurity Governance</kwd>
<kwd>Decision Rights</kwd>
<kwd>ecuadorian smes</kwd>
<kwd>Emerging Economies</kwd>
<kwd>Enterprise Risk Management</kwd>
<kwd>Incident Response</kwd>
<kwd>NIST Cybersecurity Framework</kwd>
</kwd-group>
<self-uri content-type="html" xlink:href="https://globaljournals.org/scholarly-articles/manuscript-by-3/" />
</article-meta>
</front>
<body>
<sec>
<title>Full Text</title>
<p></p>
</sec>
</body>
</article>