Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems
Aug 2026· Journal of Intelligent Decision Making and Information Science· 0 citations· 10 references
TL;DR
A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.
Abstract
Security Information and Event Management (SIEM) systems are a key part of modern cybersecurity operations, especially in government settings where they are responsible for protecting sensitive data and making sure that important national services keep running. Even though traditional SIEM platforms are used a lot, they mostly use rule-based detection methods and manual incident response workflows. This makes it take longer to contain threats and keeps the false positive rate high. This paper systematically analyzes the operational difficulties encountered during SIEM implementations at the General Administration of Government Computer (GAGC) and the Palestinian Computer Emergency Response Team (PALCERT), both functioning under the Ministry of Telecommunications and Information Technology in Palestine. A mixed-methods research methodology—incorporating semi-structured expert interviews, focus group discussions, structured surveys, and quantitative log analysis—is utilized to assess current operational constraints and system limitations. Based on these results, we suggest a better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up. Experimental assessment utilizing simulated cyberattack scenarios indicates statistically significant enhancements: detection accuracy rose from 79.1% to 91.5%, the false positive rate diminished from 32.4% to 20.2%, and the average incident response time decreased from 18.7 to 11.0 minutes, reflecting a 41% reduction. These results show that adding AI and automation to SIEM operations can make national cybersecurity much stronger, make analysts less tired, and make government digital infrastructure more resilient overall.
Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.
Lukumba Phiri, Steve Muwowo· International Journal of Ele...· 0 citations
This study suggests a framework for cybersecurity auditing of smart grid infrastructure, which is based on the concept of risk and the use of Explainable Artificial Intelligence (XAI) to produce transparent, prioritized and audit-ready security evidence. The information from public smart grid cybersecurity events was mapped to event labels, asset classes, security-control status, compliance indicators, and cyber-physical impact variables, which were then used to create audit-relevant records. Attack likelihood estimates were made using machine learning models. The attack likelihood, asset criticality, control deficiency score, compliance condition and operational impact were all added together to calculate the final audit risk score. Explainability was used as a technique to identify the most important features that affected each audit decision by applying the SHAP method. The proposed framework achieved 96.38% accuracy, 96.51% precision, 96.38% recall, 96.42% F1-score, and 0.996 ROC-AUC. The results of the ablation showed that the inclusion of the risk component and the XAI component resulted in an improvement in the risk ranking, audit traceability and explanation consistency. The framework translates the cybersecurity detection results into an understandable audit decision, enabling risk-based remediation, compliance review, and an understandable smart grid cybersecurity governance.
Udit Mamodiya, I. Kishor, Hastimal Jangid et al.· Journal of Cyber Security an...· 0 citations
The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity
threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can
compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to
examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework
(RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to
analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST
RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing
security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results
indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks,
strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.
The findings suggest that strengthening customer data protection requires a holistic approach integrating technological
safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms.
This study contributes to the cybersecurity risk management literature by proposing a structured approach to
strengthening organizational resilience against customer data breaches and evolving cyber threats.
M. B. Legowo, Budi Indiarto, Adzrani Haura Badzlinaya Novianto et al.· International Journal of Inn...· 0 citations
A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.
Enrique Castellares Cuya, José Rengifo Espinal· International Journal of Com...· 0 citations
This paper examines the multifaceted field of cybersecurity, covering key domains such as network, information, cloud, endpoint, and application security, as well as cryptography, ethical hacking, security operations, and emerging technologies like AI/ML. We review current literature, industry standards, and real-world case studies to analyze best practices and challenges across these domains. Emphasis is placed on evolving threat landscapes including ransomware, phishing, and supply-chain attacks, and the regulatory frameworks (GDPR, HIPAA, CCPA) and security standards (NIST CSF, ISO/IEC 27001) that guide organisational defences. We discuss the role of incident response and threat intelligence, and outline future trends such as AI-driven threats and defences, quantum-resistant cryptography, and zero-trust architectures. This comprehensive survey provides industry-level insights and strategic guidance for practitioners, emphasising defence-in-depth and continuous improvement to protect digital assets.
Sunil Kumar Upadhyay, Sanjeev Kumar· Journal of Library and Infor...· 0 citations
The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols and produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs.
Oladele Adekunle Awonusi· Computer Science & IT Re...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.