Toward an integrative theoretical model of AI-supported cybersecurity governance and organizational resilience
Abstract
Artificial intelligence (AI) increasingly supports cybersecurity work through risk scoring, anomaly detection, alert triage, vulnerability prioritization, threat-intelligence enrichment, and incident-response assistance. Existing research explains important aspects of technical performance, responsible AI, cybersecurity oversight, and organizational decision-making, but it still provides limited explanation of how AI-generated analytical outputs become admissible, reviewable, and actionable within formal cybersecurity decision processes. This conceptual article develops the construct of AI-supported decision structures: the organizational arrangements through which AI-generated cybersecurity inputs are assessed for reliability and context, governed through use rules and escalation paths, embedded in recurring governance routines, connected to accountable decision ownership, and subjected to substantive human oversight. The article differentiates this construct from adjacent concepts in IS governance, AI governance, algorithmic management, human oversight, and digital surveillance governance. It also introduces theoretical tension by showing that stronger governance structures may improve decision quality and legitimacy while also creating trade-offs such as slower response, procedural overload, surveillance expansion, and symbolic compliance. The article develops a conceptual model and five mechanism-based propositions linking AI-supported decision structures to cybersecurity decision quality, decision legitimacy, coordinated response, and organizational resilience understood through anticipation, coping, and adaptation. The contribution is integrative rather than a claim of complete novelty: the framework recontextualizes established governance ideas around a distinct object of governance, namely AI-generated analytical inputs that shape cybersecurity judgment before formal authority is exercised.