Skip to content
Review Open access

Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems

Aug 2026 · Journal of Intelligent Decision Making and Information Science · 0 citations · 10 references

TL;DR

A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.

Abstract

Security Information and Event Management (SIEM) systems are a key part of modern cybersecurity operations, especially in government settings where they are responsible for protecting sensitive data and making sure that important national services keep running. Even though traditional SIEM platforms are used a lot, they mostly use rule-based detection methods and manual incident response workflows. This makes it take longer to contain threats and keeps the false positive rate high. This paper systematically analyzes the operational difficulties encountered during SIEM implementations at the General Administration of Government Computer (GAGC) and the Palestinian Computer Emergency Response Team (PALCERT), both functioning under the Ministry of Telecommunications and Information Technology in Palestine. A mixed-methods research methodology—incorporating semi-structured expert interviews, focus group discussions, structured surveys, and quantitative log analysis—is utilized to assess current operational constraints and system limitations. Based on these results, we suggest a better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up. Experimental assessment utilizing simulated cyberattack scenarios indicates statistically significant enhancements: detection accuracy rose from 79.1% to 91.5%, the false positive rate diminished from 32.4% to 20.2%, and the average incident response time decreased from 18.7 to 11.0 minutes, reflecting a 41% reduction. These results show that adding AI and automation to SIEM operations can make national cybersecurity much stronger, make analysts less tired, and make government digital infrastructure more resilient overall.

Read PDF

Similar papers

Review Open access Jul 2026

Cybersecurity Challenges and Centralized Monitoring Solutions for e-Governance in Zambia: A Literature Review

Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.

Lukumba Phiri, Steve Muwowo · 0 citations
Review Open access 2026

A Risk-Based Cybersecurity Auditing Framework for Smart Grid Infrastructure Using Explainable Artificial Intelligence (XAI)

This study suggests a framework for cybersecurity auditing of smart grid infrastructure, which is based on the concept of risk and the use of Explainable Artificial Intelligence (XAI) to produce transparent, prioritized and audit-ready security evidence. The information from public smart grid cybersecurity events was mapped to event labels, asset classes, security-control status, compliance indicators, and cyber-physical impact variables, which were then used to create audit-relevant records. Attack likelihood estimates were made using machine learning models. The attack likelihood, asset criticality, control deficiency score, compliance condition and operational impact were all added together to calculate the final audit risk score. Explainability was used as a technique to identify the most important features that affected each audit decision by applying the SHAP method. The proposed framework achieved 96.38% accuracy, 96.51% precision, 96.38% recall, 96.42% F1-score, and 0.996 ROC-AUC. The results of the ablation showed that the inclusion of the risk component and the XAI component resulted in an improvement in the risk ranking, audit traceability and explanation consistency. The framework translates the cybersecurity detection results into an understandable audit decision, enabling risk-based remediation, compliance review, and an understandable smart grid cybersecurity governance.

Udit Mamodiya, I. Kishor, Hastimal Jangid et al. · 0 citations
Open access Aug 2026

NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking

The rapid digitalization of business processes has heightened organizational vulnerability to cybersecurity threats, particularly customer data breaches, unauthorized access, malware, phishing, and cyberattacks. These threats can compromise sensitive information, disrupt operations, cause financial losses, and erode customer trust. This study aims to examine the implementation of the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) for mitigating customer data breaches and cybersecurity threats. A qualitative research approach is employed to analyze cybersecurity risks, vulnerabilities, security controls, and risk mitigation practices in accordance with the NIST RMF. The framework encompasses a systematic process for categorizing information systems, selecting and implementing security controls, assessing control effectiveness, authorizing systems, and continuously monitoring risks. The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring. The findings suggest that strengthening customer data protection requires a holistic approach integrating technological safeguards, organizational governance, employee awareness, risk assessment, and effective incident response mechanisms. This study contributes to the cybersecurity risk management literature by proposing a structured approach to strengthening organizational resilience against customer data breaches and evolving cyber threats.

M. B. Legowo, Budi Indiarto, Adzrani Haura Badzlinaya Novianto et al. · 0 citations
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations
Review 2026

Components and Utilities of Cybersecurity

This paper examines the multifaceted field of cybersecurity, covering key domains such as network, information, cloud, endpoint, and application security, as well as cryptography, ethical hacking, security operations, and emerging technologies like AI/ML. We review current literature, industry standards, and real-world case studies to analyze best practices and challenges across these domains. Emphasis is placed on evolving threat landscapes including ransomware, phishing, and supply-chain attacks, and the regulatory frameworks (GDPR, HIPAA, CCPA) and security standards (NIST CSF, ISO/IEC 27001) that guide organisational defences. We discuss the role of incident response and threat intelligence, and outline future trends such as AI-driven threats and defences, quantum-resistant cryptography, and zero-trust architectures. This comprehensive survey provides industry-level insights and strategic guidance for practitioners, emphasising defence-in-depth and continuous improvement to protect digital assets.

Sunil Kumar Upadhyay, Sanjeev Kumar · 0 citations
Review Open access Jul 2026

Integrating security monitoring into uptime assurance workflows: A methodology for enterprise IT infrastructure

The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols and produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs.

Oladele Adekunle Awonusi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.