AI-Driven Cyber Risk Management: A Review of Threat Detection, Prediction, and Mitigation Strategies
Keywords:
cyber risk management; artificial intelligence; intrusion detection; explainable AI; advanced persistent threats; machine learning; risk prediction; mitigation strategiesAbstract
As cyberattacks grow more frequent, automated, and difficult to detect using signature-based defenses, artificial intelligence (AI) has become a central pillar of cyber risk management across three interlocking functions: threat detection, risk prediction, and mitigation. This review synthesizes evidence on AI-driven approaches to each function, with particular attention to deep learning-based intrusion detection and the growing role of explainable AI (XAI) in making these systems trustworthy enough for operational deployment. Systematic evidence shows machine learning (ML) techniques — including convolutional neural networks, support vector machines, and Bayesian classifiers — substantially outperform manual, human-driven threat analysis (Alshuaibi et al., 2025), while quantitative research demonstrates that supply-chain network features measurably improve prediction of enterprise data-breach likelihood (Hu et al., 2022). A growing body of XAI research — spanning SHAP- and LIME-based interpretability methods for network intrusion detection systems and dedicated reviews of explainable deep learning for advanced persistent threat (APT) detection — addresses the interpretability gap that has historically limited analyst trust in black-box detection models (Abdul Mutalib et al., 2024; Rjoub et al., 2023). The review also examines the enterprise-architecture and infrastructure layer required to operationalize these capabilities at scale, including real-time event-driven data processing (Sannidhanam, 2021; Event Streaming Architectures for High-Volume Transaction Processing, 2022), configurable and metadata-driven enterprise platforms for embedding mitigation logic into operational workflows (Basireddy, 2022a, 2022b), audit-ready compliance architecture (Basireddy, 2023), and autonomous AI agents for continuous infrastructure remediation (Sannidhanam, 2025). The review concludes that closing the gap between AI’s detection and prediction capabilities and its practical, governed deployment increasingly depends on explainability research and enterprise-architecture maturity in equal measure.References
1. Abdul Mutalib, N. H., Md Sabri, A. Q., Abdul Wahab, A. W., Mohd
Faizal Abdullah, E. R., & Aldahoul, N. (2024). Explainable deep
learning approach for advanced persistent threats (APTs) detection
in cybersecurity: A review. Artificial Intelligence Review, 57(11).
https://doi.org/10.1007/s10462-024-10890-4
2. Alshuaibi, A., Almaayah, M., & Ali, A. (2025). Machine learning for
cybersecurity issues: A systematic review. Journal of Cyber Security
and Risk Auditing, 2025(1), 1-16. https://doi.org/10.63180/jcsra.
thestap.2025.1.4
3. Basireddy, S. (2022a). Pioneering a future-ready metadata-centric
platform architecture for dynamic configuration intelligent
process automation operational agility and sustainable enterprise
modernization. SAMRIDDHI: A Journal of Physical Sciences,
Engineering and Technolog y, 14(03), 415-429. ht tps://doi.
org/10.18090/samriddhi.v14i03.27
4. Basireddy, S. R. (2022b). Digitizing risk management through
configurable enterprise workflow architecture. SAMRIDDHI: A
Journal of Physical Sciences, Engineering and Technology, 14(4),
231-239.
5. Basireddy, S. (2023). Audit-ready compliance platform architecture
for large language model regulated enterprises. SAMRIDDHI: A
Journal of Physical Sciences, Engineering and Technology, 15(01),
226-232. https://doi.org/10.18090/samriddhi.v15i01.40
6. Event Streaming Architectures for High-Volume Transaction
Processing. (2022). International Journal of Advance Industrial
Engineering, 10(01), 1-8.
7. Hu, K., Levi, R., Yahalom, R., & Zerhouni, E. G. (2022). Supply
chain characteristics as predictors of cyber risk: A machinelearning
assessment (arXiv:2210.15785). arXiv. https://arxiv.org/
abs/2210.15785
8. Kalakoti, R., Vaarandi, R., Bahşi, H., & Nõmm, S. (2025). Evaluating
explainable AI for deep learning-based net work intrusion
detection system alert classification. In Proceedings of the 11th
International Conference on Information Systems Security and
Privacy (ICISSP 2025) (Vol. 1, pp. 47-58). SciTePress. https://doi.
org/10.5220/0013180700003899
9. Loschilin, A. V., Yarikov, V. G., & Nikishova, A. V. (2024). Machine
learning methods in predicting and preventing cyber attacks. NBI
Technologies, 18(2).
10. Rjoub, G., Bentahar, J., Abdel Wahab, O., Mizouni, R., Song, A., Cohen,
R., Otrok, H., & Mourad, A. (2023). A survey on explainable artificialintelligence for cybersecurity. IEEE Transactions on Network and
Service Management, 20(4), 5115-5140.
11. Sannidhanam, A. H. (2021). Real-time claims processing using
event-driven architectures. International Journal of Technology,
Ma nagement a nd Huma nit ies, 7(01), 36 -50. ht t ps://doi .
org/10.21590/07.01.02
12. Sannidhanam, A. H. (2025). Autonomous AI agents for cloud
infrastructure operations. Journal of Contemporary Science and
Technology Management, 1(01), 83-100.
13. Tan, J. K., Ong, L.-Y., & Leow, M.-C. (2025). A comparative study
of deep learning-based network intrusion detection system
with explainable artificial intelligence. International Journal of
Electrical and Computer Engineering, 15(4), 4109-4119. https://
doi.org/10.11591/ijece.v15i4.pp4109-4119