<mods:mods version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><mods:titleInfo><mods:title>Cybersecurity leadership as governance: a constructivist&#13;
grounded theory of digital risk stewardship in public education</mods:title></mods:titleInfo><mods:name type="personal"><mods:namePart type="given">Zul Afida</mods:namePart><mods:namePart type="family">Abdullah</mods:namePart><mods:role><mods:roleTerm type="text">author</mods:roleTerm></mods:role></mods:name><mods:name type="personal"><mods:namePart type="given">Roshafiza</mods:namePart><mods:namePart type="family">Hassan</mods:namePart><mods:role><mods:roleTerm type="text">author</mods:roleTerm></mods:role></mods:name><mods:abstract>Digital transformation has intensified reliance on digital infrastructures within public education while&#13;
simultaneously amplifying institutional exposure to cybersecurity risks. Yet educational leadership scholarship continues to privilege innovation and digital maturity, leaving cybersecurity under-theorised as a governance responsibility. Addressing this gap, this study developed a constructivist grounded theory of Cybersecurity Leadership within Malaysia’s public education system. Drawing on 26 semi-structured interviews across school, district, and policy levels, constant comparative analysis generated a multidimensional governance model. Findings reveal a governance internalisation process in which digital risk shifts from delegated technical management to executive accountability. Six interdependent dimensions were identified: strategic governance integration, risk-informed decision-making, cultural reinforcement, capability development, crisis leadership, and ethical stewardship. Through their recursive interaction, these dimensions generate institutional resilience and digital trust. The study reframes cybersecurity as a core executive leadership competency embedded within strategic direction-setting rather than a peripheral compliance function. By integrating socio-technical systems and organizational resilience perspectives, it advances digital leadership theory beyond innovation-centric paradigms and positions risk-informed governance as a foundational principle of sustainable digital transformation in public education.</mods:abstract><mods:classification authority="lcc">L Education (General)</mods:classification><mods:originInfo><mods:dateIssued encoding="iso8061">2026-03-09</mods:dateIssued></mods:originInfo><mods:genre>Article</mods:genre></mods:mods>