Digital transformation has become an institutional requirement for local governments, yet the expansion of digital reporting, licensing, supervision, and public-service systems also creates operational, informational, organizational, and accountability risks. This study examines how risk management is embedded in the digital governance of the Lingga Regency Fisheries Office, an agency operating in an archipelagic jurisdiction where dispersed settlements, uneven connectivity, and cross-agency dependence intensify the consequences of digital disruption. A qualitative document-analysis design was employed. The evidence corpus comprised the agency’s 2024 Government Agency Performance Report, applicable national and regional regulations, organizational documents, statistical publications, and peer-reviewed studies on digital government, data governance, information security, and enterprise risk management. Data were reduced, coded, compared, and synthesized into a risk register, an indicative maturity profile, and a phased governance roadmap. The findings reveal a performance–risk paradox. The agency reported aggregate programme achievement of 99.71%, with several output indicators reaching or exceeding their targets, but the available documentation does not demonstrate a fully institutionalized digital-risk management cycle. Risk identification and operational control are visible in fragmented forms, whereas continuous monitoring, incident response, tested recovery, explicit risk ownership, interoperability governance, and systematic workforce development remain underdeveloped or insufficiently documented. The study argues that high output achievement should not be treated as evidence of digital resilience. It proposes a risk-based digital governance model that connects Indonesia’s Electronic-Based Government System, performance accountability, One Data principles, information-security controls, and inter-agency coordination.