Uppsats

AI-supported cybersecurity risk management and risk assessment : A systematic literature review of approaches, governance mechanisms, challenges, and mitigations

Master-uppsats

Högskolan i Skövde/Institutionen för informationsteknologi

Publicerad: 2026

Språk: Engelska

Sammanfattning

Cybersecurity and information security risk management are increasingly challenged by complex systems, rapidly changing threats, and the need for timely, traceable, and well-documented assessment outputs. At the same time, artificial intelligence (AI), including machine learning, large language models (LLMs), retrieval-augmented generation (RAG), and AI agents, is increasingly explored as a way to support and optimize risk assessment activities. This thesis presents a systematic literature review of how AI-supported approaches automate or assist cybersecurity risk management and risk assessment processes. The review followed a staged selection process based on searches in IEEE Xplore, ACM Digital Library, and Web of Science for peer-reviewed studies published between 2016 and 2026. After title and abstract screening, full-text eligibility assessment, focused AI-eligibility refinement, quality and relevance appraisal, and final evidence-set construction, 48 studies were selected for detailed synthesis. The analysis used a concept-centric approach to examine supported risk management stages, generated artifacts, governance mechanisms, reported challenges, mitigation strategies, and evaluation evidence. The findings show that AI most commonly supports risk identification, risk analysis, risk evaluation, prioritization, and risk treatment recommendation. The reviewed studies generated artifacts such as risk scores, threat scenarios, attack graphs, vulnerability rankings, mitigation suggestions, and structured documentation. Earlier AI-supported approaches, including Bayesian networks, expert systems, knowledge graphs, and reinforcement learning, mainly provided structured reasoning and prioritization. More recent LLM-, RAG-, and agent-based approaches extended support toward threat modeling, documentation, interactive assistance, and workflow orchestration. However, important limitations remain concerning context dependence, data quality, hallucination, confidentiality, scalability, and incomplete auditability. Overall, the evidence suggests that AI is best understood as decision support for risk managemen

Information

Författare
Rashdan, Adam
Lärosäte / institution
Högskolan i Skövde/Institutionen för informationsteknologi
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.