Back to feed
Review Open access

AI-Driven Predictive Cyber Threat Intelligence Framework for Securing Industrial Digital Infrastructure

Jul 2026 · International Journal of Innovative Science and Research Technology · 0 citations · 60 references

Abstract

The digitalisation of industrial environments and the increasing number of Industrial Internet of Things (IIoT) devices have completely increased the attack surface of critical manufacturing and operational technology (OT) systems. Current signature-based, "reactive" cybersecurity models are clearly failing to keep up with the sophistication and speed of today's Advanced Persistent Threats (APTs), ransomware-as-a-service (RaaS) operations and supply-chain attacks on industrial digital systems. Cyber Threat Intelligence (CTI) is now a strategic field and discipline for predicting adversarial actions, but the frameworks in use are largely tactical, siloed, and reactive, and have very limited ability to conduct realtime predictive analytics in industrial environments. This paper tackles the identified gap by proposing a new conceptual framework called Artificial Intelligence Powered Cyber Threat Intelligence (AIPCTI) Framework specifically designed to facilitate predictive, adaptive, and automated methods of threat intelligence for industrial digital infrastructure. This research uses Design Science Research Methodology (DSRM) that includes Systematic Literature Review (SLR), Knowledge Elicitation from experts and Structured Conceptual Design in order to create the framework artefact. The AIPCTI Framework comprises six interdependent layers: Threat Data Acquisition, Threat Intelligence Fusion, AI Analytics Engine, Predictive Risk Assessment, Automated Response, and Governance and Compliance. These layers support a continuous, intelligence based cyber defence posture that is consistent with Zero Trust Architecture (ZTA) principles, as well as the MITRE ATT&CK for ICS knowledge base. The framework has been developed to incorporate feedback from experts in the field of ICS/OT security and validated using structured scenario-based reasoning using three representative attack patterns: manufacturing ransomware, energysector APT intrusion and IIoT firmware exploitation. The analysis at the architecture level depicts examples of how the layered design of AIPCTI would be expected to close certain detection and response gaps identified by indicator-based CTI platforms and IT-focused SOAR solutions, such as providing the ability for AIPCTI to anticipate attack techniques before they are executed, as well as to limit automated response with safety logic specific to OT. These findings are expressed as a design stage evaluation and not as an actual performance while in operation: the framework is not yet in place, nor is it deployed in a live industrial setting, nor is it claimed to be able to improve the detection rate or response time (even though it can certainly do that). The research provides a theoretically informed conceptual framework for cybersecurity architects, offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational claims.

Read PDF