Secure Cloud-Native Platforms for Critical Service Continuity: An AI-Driven Framework for National Cyber and Economic Resilience
Abstract
The growing dependence of governments, financial institutions, healthcare organizations, energy providers, transportation networks, and communication systems on “cloud-native” platforms has made it more important than ever that these digital services be delivered continuously and securely. Cloud-native architectures offer scalability, flexibility, and quick deployment using microservices, containers, orchestration, and DevSecOps practices, but they also present complex cybersecurity, operational, and supply chain threats to the country’s critical infrastructure and economic well-being. The existing research focuses on cloud resilience, artificial intelligence for IT operations (AIOps), cybersecurity or governance individually, causing approaches to be disjointed and suboptimal for critical service continuity during large-scale cyber incidents. In this research, the authors introduce the AI-powered Integrated Cyber-Economic Resilience (AICER) Framework, which is a conceptual framework that integrates cloud-native infrastructure, cybersecurity intelligence, AI-assisted operational analytics, secure software delivery, economic impact assessment, and governance into a comprehensive decision-support architecture. The framework is formulated on the basis of Design Science Research Methodology (DSRM) and supported by an integrative literature review encompassing the most recent literature, international cybersecurity standards, and cloud computing best practices. The proposed framework does not introduce new performance metrics but rather builds on existing metrics, such as Service Level Objectives (SLOs), availability and reliability metrics, Mean Time Between Failures (MTBF), Mean Time to Recovery (MTTR), DORA software delivery metrics, Common Vulnerability Scoring System (CVSS), Exploit Prediction Scoring System (EPSS), Software Levels for Supply Chain Security (SLSA), and NIST Cybersecurity Framework (CSF 2.0) and NIST AI Risk Management Framework (AI RMF). The framework also takes economic impact into account to inform decisions on recovery for nationally significant services. The proposed architecture provides a vision for a policy-aware and AI-driven approach to enhancing cyber resilience, bolstering critical infrastructure, and fortifying continuity of essential digital services. The study provides a strong foundation for further prototype implementation, experimental validation, and deployment in public and private critical sectors.