Skip to content
Review Open access

AI-Driven Predictive Cyber Threat Intelligence Framework for Securing Industrial Digital Infrastructure

Jul 2026 · International Journal of Innovative Science and Research Technology · pp. 104 · 0 citations · 60 references

TL;DR

The research provides a theoretically informed conceptual framework for cybersecurity architects, offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational claims.

Abstract

The digitalisation of industrial environments and the increasing number of Industrial Internet of Things (IIoT) devices have completely increased the attack surface of critical manufacturing and operational technology (OT) systems. Current signature-based, "reactive" cybersecurity models are clearly failing to keep up with the sophistication and speed of today's Advanced Persistent Threats (APTs), ransomware-as-a-service (RaaS) operations and supply-chain attacks on industrial digital systems. Cyber Threat Intelligence (CTI) is now a strategic field and discipline for predicting adversarial actions, but the frameworks in use are largely tactical, siloed, and reactive, and have very limited ability to conduct realtime predictive analytics in industrial environments. This paper tackles the identified gap by proposing a new conceptual framework called Artificial Intelligence Powered Cyber Threat Intelligence (AIPCTI) Framework specifically designed to facilitate predictive, adaptive, and automated methods of threat intelligence for industrial digital infrastructure. This research uses Design Science Research Methodology (DSRM) that includes Systematic Literature Review (SLR), Knowledge Elicitation from experts and Structured Conceptual Design in order to create the framework artefact. The AIPCTI Framework comprises six interdependent layers: Threat Data Acquisition, Threat Intelligence Fusion, AI Analytics Engine, Predictive Risk Assessment, Automated Response, and Governance and Compliance. These layers support a continuous, intelligence based cyber defence posture that is consistent with Zero Trust Architecture (ZTA) principles, as well as the MITRE ATT&CK for ICS knowledge base. The framework has been developed to incorporate feedback from experts in the field of ICS/OT security and validated using structured scenario-based reasoning using three representative attack patterns: manufacturing ransomware, energysector APT intrusion and IIoT firmware exploitation. The analysis at the architecture level depicts examples of how the layered design of AIPCTI would be expected to close certain detection and response gaps identified by indicator-based CTI platforms and IT-focused SOAR solutions, such as providing the ability for AIPCTI to anticipate attack techniques before they are executed, as well as to limit automated response with safety logic specific to OT. These findings are expressed as a design stage evaluation and not as an actual performance while in operation: the framework is not yet in place, nor is it deployed in a live industrial setting, nor is it claimed to be able to improve the detection rate or response time (even though it can certainly do that). The research provides a theoretically informed conceptual framework for cybersecurity architects, offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational claims.

Read PDF

Similar papers

Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations
Open access 2021

AI-Driven Cyber Defense Systems Using Real-Time Analytics

The findings indicate that AI-powered cyber defense significantly enhances threat detection, reduces response time, and improves overall cyber resilience compared to traditional security models, highlighting its critical role in next-generation cybersecurity infrastructures.

Chinedu Eze · 0 citations
Open access Jul 2026

Role of Artificial Intelligence in Preventing and Predicting Cybersecurity Threats

It is concluded that AI has become an indispensable component of modern cybersecurity strategies and will play a critical role in safeguarding digital infrastructure against emerging cyber threats.

Shaurya Gupta · 0 citations
Aug 2026

AI-Powered Adaptive Threat Intelligence and Risk Mitigation Framework for Secure SAP S/4HANA Manufacturing Integration

The increasing integration of SAP S/4HANA manufacturing environments with enterprise applications, supply-chain platforms, industrial systems, and external digital services has expanded the attack surface of manufacturing organizations. Traditional security approaches based primarily on static rules and isolated monitoring are insufficient for identifying dynamically evolving threats across heterogeneous integration channels. This research proposes an AI-Powered Adaptive Threat Intelligence and Risk Mitigation Framework for secure SAP S/4HANA manufacturing integration. The framework combines threat intelligence, machine-learning-based anomaly detection, supply-network risk propagation, contextual risk scoring, and adaptive mitigation across RFC, IDoc, and API communication channels. The conceptual foundation integrates supply-chain analytics, predictive intelligence, dynamic manufacturing coordination, and probabilistic risk assessment. The proposed framework is structured around six functional layers: integration telemetry, threat-intelligence enrichment, AI-based detection, contextual risk analysis, adaptive response, and continuous learning. The analysis indicates that combining communication-level security with operational and supply-network context can improve the prioritization of integration threats compared with isolated event detection. The framework also emphasizes explainability, controlled automation, and risk-aware response to reduce the possibility of disrupting legitimate manufacturing processes. Kalal's SAP manufacturing integration threat-modeling approach provides a direct security foundation for identifying and mitigating risks associated with RFC, IDoc, and API communication (Kalal, 2024). The resulting architecture provides a research-oriented foundation for adaptive cybersecurity in digitally integrated SAP S/4HANA manufacturing environments.

Daniel Okonkwo · 0 citations
Open access Aug 2026

Designing an AI-Assisted Cyber Threat Intelligence Framework for Industry 4.0: A Human-in-the-Loop Design Science Approach

The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments.

Majed Albarrak, Sandeep Jagtap · 0 citations
Review Open access Aug 2026

AI-DRIVEN THREAT DETECTION AND AUTOMATED RESPONSE IN MODERN CYBERSECURITY SYSTEMS: A SYSTEMATIC REVIEW AND FRAMEWORK

As the number and sophistication of cyberattacks increase, including those like ransomware, advanced persistent threats (APTs), and zero-day exploits, the structural weaknesses of signature-based and static intrusion detection systems (IDS) become evident as they fail to generalize to novel or adversarially crafted attack patterns Agbroko (2024), Hakke et al. (2025). The paper provides a systematic review of the application of modern security operations in threat detection and automated incident response using classical machine learning (ML), deep learning (DL), reinforcement learning (RL), and metaheuristic optimization. A review of some of the benchmark sets shows that the ensemble and hybrid AI models consistently yield detection accuracy rates of 97–99% on curated datasets like NSL-KDD, CICIDS2017, and UNSW-NB15, which is significantly higher than the detection accuracy rates of legacy rule-based tools Waghmode and Kanumuri (2025), Sah et al. (2023), Jairu (2021). The paper also reviews Security Orchestration, Automation and Response (SOAR) integration, reinforcement-learning-driven adaptive defense policies, and threat-intelligence feedback loops that will allow for continuous retraining of the model. Some persistent challenges include adversarial evasion and data-poisoning attacks, false positives causing alert fatigue, interpretability problems in deep models, and autopilot restrictions on autonomous response actions Jha (2025), Dong et al. (2018). The most significant frontiers for making this leap from high laboratory accuracy to robust, audit- and legally sound operational deployments are explainable AI (XAI), federated and privacy-preserving learning, and standardized benchmarking Hermosilla et al. (2025), Bi et al. (2024). A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments Silva (2026).

Jayesh Dalmet · 0 citations