AI-Driven Cyber Risk Management: A Review of Threat Detection, Prediction, and Mitigation Strategies

Authors

  • Vimlesh Kumar Department of Computer Science and Engineering Teerthankar Mahaveer University, Moradabad U.P., India Author

Keywords:

cyber risk management; artificial intelligence; intrusion detection; explainable AI; advanced persistent threats; machine learning; risk prediction; mitigation strategies

Abstract

As cyberattacks grow more frequent, automated, and difficult to detect using signature-based defenses, artificial intelligence (AI) has become a central pillar of cyber risk management across three interlocking functions: threat detection, risk prediction, and mitigation. This review synthesizes evidence on AI-driven approaches to each function, with particular attention to deep learning-based intrusion detection and the growing role of explainable AI (XAI) in making these systems trustworthy enough for operational deployment. Systematic evidence shows machine learning (ML) techniques — including convolutional neural networks, support vector machines, and Bayesian classifiers — substantially outperform manual, human-driven threat analysis (Alshuaibi et al., 2025), while quantitative research demonstrates that supply-chain network features measurably improve prediction of enterprise data-breach likelihood (Hu et al., 2022). A growing body of XAI research — spanning SHAP- and LIME-based interpretability methods for network intrusion detection systems and dedicated reviews of explainable deep learning for advanced persistent threat (APT) detection — addresses the interpretability gap that has historically limited analyst trust in black-box detection models (Abdul Mutalib et al., 2024; Rjoub et al., 2023). The review also examines the enterprise-architecture and infrastructure layer required to operationalize these capabilities at scale, including real-time event-driven data processing (Sannidhanam, 2021; Event Streaming Architectures for High-Volume Transaction Processing, 2022), configurable and metadata-driven enterprise platforms for embedding mitigation logic into operational workflows (Basireddy, 2022a, 2022b), audit-ready compliance architecture (Basireddy, 2023), and autonomous AI agents for continuous infrastructure remediation (Sannidhanam, 2025). The review concludes that closing the gap between AI’s detection and prediction capabilities and its practical, governed deployment increasingly depends on explainability research and enterprise-architecture maturity in equal measure.

References

1. Abdul Mutalib, N. H., Md Sabri, A. Q., Abdul Wahab, A. W., Mohd

Faizal Abdullah, E. R., & Aldahoul, N. (2024). Explainable deep

learning approach for advanced persistent threats (APTs) detection

in cybersecurity: A review. Artificial Intelligence Review, 57(11).

https://doi.org/10.1007/s10462-024-10890-4

2. Alshuaibi, A., Almaayah, M., & Ali, A. (2025). Machine learning for

cybersecurity issues: A systematic review. Journal of Cyber Security

and Risk Auditing, 2025(1), 1-16. https://doi.org/10.63180/jcsra.

thestap.2025.1.4

3. Basireddy, S. (2022a). Pioneering a future-ready metadata-centric

platform architecture for dynamic configuration intelligent

process automation operational agility and sustainable enterprise

modernization. SAMRIDDHI: A Journal of Physical Sciences,

Engineering and Technolog y, 14(03), 415-429. ht tps://doi.

org/10.18090/samriddhi.v14i03.27

4. Basireddy, S. R. (2022b). Digitizing risk management through

configurable enterprise workflow architecture. SAMRIDDHI: A

Journal of Physical Sciences, Engineering and Technology, 14(4),

231-239.

5. Basireddy, S. (2023). Audit-ready compliance platform architecture

for large language model regulated enterprises. SAMRIDDHI: A

Journal of Physical Sciences, Engineering and Technology, 15(01),

226-232. https://doi.org/10.18090/samriddhi.v15i01.40

6. Event Streaming Architectures for High-Volume Transaction

Processing. (2022). International Journal of Advance Industrial

Engineering, 10(01), 1-8.

7. Hu, K., Levi, R., Yahalom, R., & Zerhouni, E. G. (2022). Supply

chain characteristics as predictors of cyber risk: A machinelearning

assessment (arXiv:2210.15785). arXiv. https://arxiv.org/

abs/2210.15785

8. Kalakoti, R., Vaarandi, R., Bahşi, H., & Nõmm, S. (2025). Evaluating

explainable AI for deep learning-based net work intrusion

detection system alert classification. In Proceedings of the 11th

International Conference on Information Systems Security and

Privacy (ICISSP 2025) (Vol. 1, pp. 47-58). SciTePress. https://doi.

org/10.5220/0013180700003899

9. Loschilin, A. V., Yarikov, V. G., & Nikishova, A. V. (2024). Machine

learning methods in predicting and preventing cyber attacks. NBI

Technologies, 18(2).

10. Rjoub, G., Bentahar, J., Abdel Wahab, O., Mizouni, R., Song, A., Cohen,

R., Otrok, H., & Mourad, A. (2023). A survey on explainable artificialintelligence for cybersecurity. IEEE Transactions on Network and

Service Management, 20(4), 5115-5140.

11. Sannidhanam, A. H. (2021). Real-time claims processing using

event-driven architectures. International Journal of Technology,

Ma nagement a nd Huma nit ies, 7(01), 36 -50. ht t ps://doi .

org/10.21590/07.01.02

12. Sannidhanam, A. H. (2025). Autonomous AI agents for cloud

infrastructure operations. Journal of Contemporary Science and

Technology Management, 1(01), 83-100.

13. Tan, J. K., Ong, L.-Y., & Leow, M.-C. (2025). A comparative study

of deep learning-based network intrusion detection system

with explainable artificial intelligence. International Journal of

Electrical and Computer Engineering, 15(4), 4109-4119. https://

doi.org/10.11591/ijece.v15i4.pp4109-4119

Published

2026-09-18

How to Cite

AI-Driven Cyber Risk Management: A Review of Threat Detection, Prediction, and Mitigation Strategies. (2026). Journal of Integrated Science, Technology and Management, 2(01). https://jistm.info/index.php/jistm/article/view/44