[Home ] [Archive]   [ فارسی ]  
:: Main :: About :: Current Issue :: Archive :: Search :: Submit :: Contact ::
Main Menu
Home::
Journal Information::
Articles archive::
For Authors::
For Reviewers::
Registration::
Site Facilities::
Indexing::
Contact us::
::
Search in website

Advanced Search
..
Receive site information
Enter your Email in the following box to receive the site news and information.
..
Print ISSN
Print ISSN: 2476-3047
..
:: Volume 14, Issue 2 (3-2026) ::
منادی 2026, 14(2): 98-110 Back to browse issues page
A Systematic Review of Cybersecurity Governance in the Age of Artificial Intelligence: From Transparency to Resilience
Peyman Hajizadeh *1 , Hamed Naderi1
1- Department of Management, Faculty of Management, Islamic Azad University, South Tehran Branch, Tehran, Iran
Abstract:   (1125 Views)
In the contemporary business landscape, digital transformation has fundamentally reshaped the operational DNA of organizations, evolving from a strategic option for competitive advantage into an absolute survival necessity. As entities increasingly integrate data-driven technologies—such as cloud computing, large-scale big data analytics, and the Internet of Things (IoT)—into their core infrastructure, their digital footprint expands, leading to an exponentially larger and more porous attack surface. In this volatile context, cybersecurity incidents no longer result merely in isolated technical failures or limited financial losses; they increasingly generate systemic consequences, including severe reputational damage, erosion of stakeholder trust, regulatory sanctions, and long-term impacts on organizational viability. Consequently, cybersecurity has transitioned from a purely technical function nested within IT departments to a critical pillar of corporate governance and enterprise risk management, demanding direct oversight from the board of directors and C-suite executives. To counter these sophisticated and adaptive threats, Artificial Intelligence (AI) has emerged as a cornerstone of modern defense. AI capabilities—particularly Machine Learning (ML) and Deep Learning (DL)—promise a paradigm shift from reactive approaches toward proactive, anticipatory security systems capable of automating complex tasks, detecting anomalies in real-time, and predicting attacks before they materialize.
However, despite these transformative technical advantages, the organizational adoption of AI in cybersecurity remains limited, uneven, and fraught with a significant paradox: while AI serves as a robust defense mechanism, its deployment introduces profound managerial and governance challenges. The "black box" nature of many advanced models creates a severe lack of transparency and explainability, acting as a formidable barrier to managerial trust and accountability. Decision-makers often find themselves unable to justify AI-driven security investments or actions when the underlying model logic is opaque, particularly in high-stakes environments involving strict regulatory scrutiny. Furthermore, intelligent systems themselves have become targets for adversarial attacks, where malicious actors manipulate input data to deceive machine learning models, thereby undermining the very integrity of the automated defense systems. Existing literature on this subject is extensive but suffers from structural fragmentation; studies often address isolated technical applications without embedding them in a coherent governance framework, or they focus on high-level management theories without accounting for the granular technical realities of AI. This study aims to bridge these critical gaps by conducting a systematic review to develop an integrated conceptual framework that aligns AI’s technical capabilities with the managerial requirements of the NIST Cybersecurity Framework (CSF) 2.0.
To achieve this objective, this research employs a rigorous Systematic Literature Review (SLR) methodology adhering to the PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) guidelines. A comprehensive and multi-stage search strategy was executed in the Web of Science (WoS) Core Collection database in January 2025. The search query combined three key conceptual clusters: AI technologies (e.g., machine learning, deep learning, neural networks), cybersecurity domains, and managerial constructs (e.g., governance, risk management, ROI, decision-making). The initial search yielded 50 academic records. After removing duplicates and applying strict inclusion and exclusion criteria—specifically prioritizing peer-reviewed articles that explicitly addressed the intersection of AI, cybersecurity, and governance—24 high-quality articles were selected for in-depth analysis. These articles were systematically coded and mapped against the functions of the NIST Cybersecurity Framework (CSF) 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. This structured coding process allowed for a quantitative assessment of research focus and the identification of specific gaps in the current body of knowledge.
The findings of the systematic analysis reveal significant and concerning imbalances in the research landscape. Firstly, regarding technological trends, Machine Learning (ML) and Deep Learning (DL) remain the dominant technologies, appearing in over 79% of the reviewed studies. However, the analysis also detects a nascent but critical shift towards adaptive and generative solutions, with Generative AI (GenAI) and Reinforcement Learning (RL) appearing in approximately 29% of the papers. This indicates a gradual transition from static detection models to dynamic, decision-centric capabilities. Secondly, the distribution of research across the NIST CSF 2.0 functions is highly skewed. The analysis demonstrates a heavy concentration of research on the Govern function (96%) and the Detect function (88%). This reflects a strong academic and industrial focus on high-level policy formulation and technical threat detection algorithms. In stark contrast, the Recover function is addressed in only 25% of the articles. This functional imbalance highlights a critical "Resilience Gap" in the literature regarding the automation of post-incident recovery processes, which are essential for maintaining business continuity and minimizing downtime. Thirdly, the study quantitatively confirms that the "Trust Gap" is the most pervasive barrier to adoption. The lack of Explainable AI (XAI) was cited in 96% of the studies as a primary hindrance to managerial trust. Additionally, the risk of adversarial attacks—where AI models are fooled by perturbed inputs—was identified in 67% of the papers, underscoring the vulnerability of AI models and the need for "robustness" to be treated as a key governance metric.
Building on these insights, this study proposes the "Transparency–Resilience Dual Framework," an integrated conceptual model designed to reconcile AI’s technical potential with governance imperatives. The framework posits that sustainable success in AI cybersecurity requires a positive feedback loop between two complementary dimensions. The first pillar, "Transparency in Governance," directly addresses the trust gap by integrating Explainable AI (XAI) into the 'Govern' and 'Identify' functions of the NIST framework. XAI serves as a governance enabler by providing interpretable rationales for AI decisions, which is essential for auditability, regulatory compliance, and establishing "Managerial Trust." When managers understand why an AI model flags a threat or recommends an action, they can accurately calculate the Return on Security Investment (ROSI) and justify the allocation of resources to advanced defense systems. The second pillar, "Resilience in Operations," addresses the resilience gap by leveraging advanced, autonomous AI techniques—specifically Generative AI and Reinforcement Learning—to optimize the 'Respond' and 'Recover' functions. The framework advocates for using Generative AI to automate time-consuming documentation tasks, such as incident reporting and the dynamic updating of recovery plans, and employing Reinforcement Learning to optimize decision-making during containment. The operational goal is to minimize the Mean Time to Recover (MTTR) and ensure the rapid restoration of services following an incident.
The proposed framework operates as a dynamic cycle: transparent governance secures the necessary budget and trust to invest in resilient operations, while effective operational resilience generates valuable post-incident data that feeds back into the models, continuously improving the system's accuracy and transparency. Theoretically, this study implies that future cybersecurity maturity models must include "Algorithmic Trustworthiness" as a core variable independent of technical performance accuracy. Practically, the study provides a roadmap for Chief Information Security Officers (CISOs) and organizational leaders. It recommends moving beyond fragmented tool adoption to a strategic approach that prioritizes AI solutions offering explainability features. Furthermore, it urges organizations to investigate the use of Generative AI for automating the neglected recovery function. By linking the transparency required for strategic governance with the agility required for tactical operations, organizations can evolve their cybersecurity posture from a reactive stance to a resilient, AI-empowered state, capable of withstanding the complexities of the modern threat landscape.
Keywords: Cybersecurity, Artificial Intelligence (AI), Explainable AI (XAI), Cybersecurity governance, NIST Cybersecurity Framework (CSF) 2.0
Full-Text [PDF 1449 kb]   (1759 Downloads)    
Type of Study: Review Article | Subject: Cryptology and Information Security
Received: 2025/12/22 | Accepted: 2026/01/21 | Published: 2026/03/19
Send email to the article author

Add your comments about this article
Your username or Email:

CAPTCHA


XML   Persian Abstract   Print


Download citation:
BibTeX | RIS | EndNote | Medlars | ProCite | Reference Manager | RefWorks
Send citation to:

Hajizadeh P, Naderi H. A Systematic Review of Cybersecurity Governance in the Age of Artificial Intelligence: From Transparency to Resilience. منادی 2026; 14 (2) :98-110
URL: http://monadi.isc.org.ir/article-1-335-en.html


Rights and permissions
Creative Commons License This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Volume 14, Issue 2 (3-2026) Back to browse issues page
دوفصل نامه علمی  منادی امنیت فضای تولید و تبادل اطلاعات( افتا) Biannual Journal Monadi for Cyberspace Security (AFTA)
Persian site map - English site map - Created in 0.21 seconds with 39 queries by YEKTAWEB 4772