Design and Preliminary Evaluation of a Hybrid Edge–Cloud Framework for Resilient Cybersecurity Monitoring and Organizational Security Assessment
Abstract
Organizations increasingly operate across interconnected endpoints, network services, cloud applications, remote access channels, and third-party platforms. Security-relevant information is consequently distributed across heterogeneous sources, while timely interpretation often depends on centralized infrastructure and continuous connectivity. This paper presents a hybrid edge–cloud framework for resilient cybersecurity monitoring and organizational security assessment. The framework places telemetry acquisition, normalization, and initial analysis close to the monitored environment while retaining an optional centralized layer for aggregation, historical analysis, visualization, and future model improvement. The architecture separates security telemetry collection, local processing, security assessment, and centralized reporting into distinct functional layers. A multi-dimensional assessment mechanism is proposed to represent security posture, exposure or trust conditions, and control or compliance readiness without reducing organizational security to a single undifferentiated indicator. Preliminary prototype validation focuses on telemetry ingestion, event processing, local assessment, dashboard representation, and continued operation of core monitoring functions during temporary loss of external connectivity. The framework is intentionally technology-agnostic so that it can be extended with different sensors, endpoint sources, security controls, analytical models, and security-operations integrations. The work provides a foundational architecture for further research into resilient, privacy-conscious, and deployable organizational cybersecurity systems.