An integrative theoretical model of AI-supported cybersecurity governance and organizational resilience
Abstract This paper develops an integrative theoretical model explaining how and when AI-supported cybersecurity governance may contribute to organizational resilience. Using a theory-synthesis design and an integrative literature review, it connects scholarship on organizational resilience, cybersecurity governance, artificial intelligence governance, human-AI decision-making, adversarial machine learning, risk governance, organizational learning, and dynamic capabilities. AI-supported cybersecurity governance is conceptualized as a formal organizational arrangement through which heterogeneous AI-generated evidence–including predictive scores, anomaly signals, generative summaries, and semi-autonomous recommendations—is institutionally translated into cybersecurity direction, oversight, prioritization, coordination, reporting, accountability, and learning. The model identifies an AI-specific positive pathway: continuous processing at scale, heterogeneous-data fusion, nonlinear and cross-system pattern detection, probabilistic forecasting, rapid updating, and automated synthesis may create incremental governance value beyond periodic rule-based business intelligence or exclusively human analysis. These affordances are converted into organizational resilience through five governance mechanisms: enhanced visibility, improved prioritization, stronger coordination, more informed oversight, and structured organizational learning. Dynamic capabilities explain how these mechanisms support sensing, seizing, and reconfiguring, while organizational resilience is represented through anticipation, coping, and adaptation. The same pathway may be weakened or reversed by automation bias, model opacity, adversarial manipulation, vendor opacity, false prioritization, data-quality failure, and accountability gaps. The paper makes three contributions. First, it defines AI-supported cybersecurity governance as a distinct organizational construct and separates it from conventional cybersecurity governance, cybersecurity maturity, firm-wide AI capability, and isolated operational AI use. Second, it explains what AI changes in the positive pathway while explicitly recognizing heterogeneity across model classes and deployment arrangements. Third, it specifies external scope conditions, internal boundary conditions, and failure modes that make the proposed relationships testable and non-deterministic.
Authors
- Irlenys Josefina Tersek Rodriguez (ORCID: https://orcid.org/0009-0005-4501-9818)
Publication Details
- Journal
- Discover Artificial Intelligence
- Published
- 2026-09-26
- DOI
- https://doi.org/10.1007/s44163-026-02363-0
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00