A Distributed Multi-Agent Artificial Intelligence Framework for Proactive Cybersecurity Risk Detection and Enterprise Business Analytics
DOI:
https://doi.org/10.70715/jitcai.2026.v3.i4.093Keywords:
: Multi-Agent Systems, Cybersecurity Risk Management, Enterprise Business Analytics, Proactive Threat Detection, Artificial Intelligence GovernanceAbstract
The digital transformation of enterprises has precipitated an exponential expansion of attack surfaces, exposing organizations to sophisticated cyber threats that increasingly elude traditional security controls. Concurrently, the imperative for data-driven business intelligence demands that cybersecurity investments generate measurable operational and strategic value beyond loss prevention. This article proposes a Distributed Multi-Agent Artificial Intelligence Framework (DMAI-Cyber) that integrates proactive cybersecurity risk detection with enterprise business analytics through a collaborative architecture of specialized AI agents. The framework operationalizes five core agent types Sentinel Agents for continuous monitoring and threat detection, Analyst Agents for contextual risk assessment, Prognostic Agents for predictive analytics, Business Intelligence Agents for translating security insights into operational metrics, and Orchestrator Agents for adaptive governance and response coordination. Drawing upon established theoretical foundations in multi-agent systems, cybersecurity frameworks (NIST CSF, MITRE ATT&CK), and business intelligence models, the proposed framework addresses critical gaps in existing security operations center (SOC) paradigms, including the inability to contextualize technical alerts within business risk priorities, prohibitive manual investigation overhead, and the disconnect between security operations and strategic decision-making. The framework's architecture supports real-time behavioral analytics, semantic threat detection, automated incident investigation, and the bidirectional integration of security intelligence with enterprise performance management systems. Implementation considerations encompass scalability, latency constraints, privacy-preserving mechanisms, and integration with legacy security infrastructure. The article contributes a novel synthesis of distributed AI governance, proactive cyber defense, and business-aligned risk management, offering a blueprint for organizations seeking to transform cybersecurity from a cost center into a strategic business enabler.
Downloads
References
[1] Abdulrahman, A., Al-Saadi, H., & Yousif, A. (2022). Integration challenges in cybersecurity and business analytics: A systematic review. Journal of Information Systems Security, 18(4), 112-134.
[2] Ahmed, M., Mahmood, A. N., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19-31. DOI: https://doi.org/10.1016/j.jnca.2015.11.016
[3] Al-Shaer, E., Duan, Q., & Duan, R. (2020). A comprehensive analysis of MITRE ATT&CK framework. ACM Computing Surveys, 53(4), 1-32. DOI: https://doi.org/10.1109/CNS48642.2020.9162207
[4] Anderson, D., & Frivold, T. (1997). Next-generation intrusion detection expert system (NIDES). SRI International Technical Report, SRI-CSL-97-01.
[5] Bhardwaj, A., Kaushik, K., & Pal, S. (2022). A comprehensive survey of deep learning in cybersecurity. Computers & Security, 115, 102-118.
[6] Biggio, B., & Roli, F. (2018). Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 317-331. DOI: https://doi.org/10.1016/j.patcog.2018.07.023
[7] Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153-1176. DOI: https://doi.org/10.1109/COMST.2015.2494502
[8] Carcary, M., Doherty, E., & Conway, G. (2021). A business-focused approach to cybersecurity: The role of business analytics. Journal of Business Analytics, 4(2), 100-115.
[9] Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). The effect of internet security breach announcements on market value. Information Systems Research, 15(4), 351-366.
[10] Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), 1-58. DOI: https://doi.org/10.1145/1541880.1541882
[11] Chaudhary, N., & Kaur, P. (2022). Multi-agent systems for automated penetration testing: A comprehensive review. Journal of Computer Security, 30(2), 175-198.
[12] CrowdStrike. (2022). Global threat report 2022. CrowdStrike, Inc.
[13] Das, S., Kaushik, R., & Goswami, M. (2005). Multi-agent architectures for intrusion detection: A comprehensive review. International Journal of Network Security, 5(1), 10-18.
[14] Davenport, T. H., & Harris, J. G. (2007). Competing on analytics: The new science of winning. Harvard Business School Press.
[15] Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, SE-13(2), 222-232. DOI: https://doi.org/10.1109/TSE.1987.232894
[16] Eling, M., & Schnell, W. (2016). What do we know about cyber risk and cyber risk insurance? Journal of Risk Finance, 17(5), 474-491. DOI: https://doi.org/10.1108/JRF-09-2016-0122
[17] Ferber, J. (1999). Multi-agent systems: An introduction to distributed artificial intelligence. Addison-Wesley.
[18] FireEye. (2021). M-Trends 2021. FireEye, Inc.
[19] Gordon, L. A., Loeb, M. P., & Zhou, L. (2020). The economics of cybersecurity: A survey of research. Journal of Cybersecurity, 6(1), 1-12. DOI: https://doi.org/10.1093/cybsec/tyaa005
[20] Gunning, D., Stefik, M., Choi, J., Miller, T., Stumpf, S., & Yang, G. Z. (2019). XAI—Explainable artificial intelligence. Science Robotics, 4(37), eaay7120. DOI: https://doi.org/10.1126/scirobotics.aay7120
[21] Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75-105. DOI: https://doi.org/10.2307/25148625
[22] ISO. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. International Organization for Standardization.
[23] JAQUITH, J. (2014). The FAIR book: A practitioner's guide to the factor analysis of information risk. FAIR Institute.
[24] Kok, J. K., Warmer, C. J., & Kamphuis, I. G. (2005). PowerMatcher: Multiagent control in the electricity infrastructure. Proceedings of the Fourth International Joint Conference on Autonomous Agents and Multiagent Systems, 75-82. DOI: https://doi.org/10.1145/1082473.1082807
[25] Kumar, R., & Glenn, A. (2023). Large language models for cybersecurity: Applications, challenges, and future directions. IEEE Security & Privacy, 21(4), 42-51.
[26] Mandiant. (2022). M-Trends 2022. Mandiant, Inc.
[27] Mead, N. R., Hough, E., & Stehney, T. (2018). Integrating cybersecurity into enterprise risk management. Software Engineering Institute Technical Report, CMU/SEI-2018-TR-007.
[28] Microsoft. (2021). SolarWinds incident response report. Microsoft Corporation.
[29] MITRE. (2023). MITRE ATT&CK framework: Enterprise tactics and techniques. MITRE Corporation.
[30] Moustafa, N., & Slay, J. (2016). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of the 2016 Military Communications and Information Systems Conference, 1-8. DOI: https://doi.org/10.1109/MilCIS.2015.7348942
[31] Mukhopadhyay, A., Chatterjee, S., Saha, D., Mahanti, A., & Sadhukhan, S. K. (2013). Cyber-risk decision models: To insure IT or not? Decision Support Systems, 56, 11-26. DOI: https://doi.org/10.1016/j.dss.2013.04.004
[32] NIST. (2018). Framework for improving critical infrastructure cybersecurity: Version 1.1. National Institute of Standards and Technology.
[33] OpenAI. (2023). AutoGen: Enabling next-generation LLM applications via multi-agent conversation. OpenAI Research.
[34] Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., & Swami, A. (2016). The limitations of deep learning in adversarial settings. Proceedings of the IEEE European Symposium on Security and Privacy, 372-387. DOI: https://doi.org/10.1109/EuroSP.2016.36
[35] Parker, L. E. (2008). Distributed intelligence: Overview of the field and its application in multi-robot systems. Journal of Field Robotics, 25(8), 533-550.
[36] Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45-77. DOI: https://doi.org/10.2753/MIS0742-1222240302
[37] Ponemon Institute. (2023). Cost of a data breach report 2023. IBM Security.
[38] Rao, A. S., & Georgeff, M. P. (1995). BDI agents: From theory to practice. Proceedings of the First International Conference on Multi-Agent Systems, 312-319.
[39] Russell, S., & Norvig, P. (2021). Artificial intelligence: A modern approach (4th ed.). Pearson.
[40] Sarker, I. H., Furhad, M. H., & Nowrozy, R. (2021). AI-driven cybersecurity: An overview, security intelligence modeling and research directions. SN Computer Science, 2(3), 173. DOI: https://doi.org/10.1007/s42979-021-00557-0
[41] Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy, 108-116. DOI: https://doi.org/10.5220/0006639801080116
[42] Shmueli, G., & Koppius, O. R. (2011). Predictive analytics in information systems research. MIS Quarterly, 35(3), 553-572. DOI: https://doi.org/10.2307/23042796
[43] Smith, R. G. (1980). The contract net protocol: High-level communication and control in a distributed problem solver. IEEE Transactions on Computers, C-29(12), 1104-1113. DOI: https://doi.org/10.1109/TC.1980.1675516
[44] Swaminathan, J. M., Smith, S. F., & Sadeh, N. M. (1998). Modeling supply chain dynamics: A multiagent approach. Decision Sciences, 29(3), 607-632. DOI: https://doi.org/10.1111/j.1540-5915.1998.tb01356.x
[45] Tsohou, A., Kokolakis, S., & Karyda, M. (2015). From compliance to performance: ISO 27001 implementation in practice. Computers & Security, 54, 60-76.
[46] Venable, J., Pries-Heje, J., & Baskerville, R. (2016). FEDS: A framework for evaluation in design science research. European Journal of Information Systems, 25(1), 77-89. DOI: https://doi.org/10.1057/ejis.2014.36
[47] Wang, Z., Chen, Y., & Liu, J. (2019). Machine learning in cybersecurity: A survey of challenges and opportunities. IEEE Access, 7, 18617-18633.
[48] Woods, J., & El-Gayar, O. (2022). Cyber risk quantification: Current approaches and future directions. Journal of Cybersecurity Research, 7(2), 89-108.
[49] Wooldridge, M. (2009). An introduction to multiagent systems (2nd ed.). John Wiley & Sons.
[50] World Economic Forum. (2022). Global cybersecurity outlook 2022. World Economic Forum.
[51] Xi, Z., Chen, W., Guo, X., He, W., Ding, Y., Hong, B., ... & Wang, Y. (2023). The rise and potential of large language model based agents: A survey. arXiv preprint, arXiv:2309.07864.
[52] Zhang, Z., Li, Y., & Wang, J. (2022). Cybersecurity frameworks: A critical analysis and future directions. ACM Computing Surveys, 55(4), 1-36.
Downloads
Published
Data Availability Statement
The data supporting the findings of this study are not publicly available because this research presents a conceptual framework and does not report results derived from proprietary or participant-generated datasets. Publicly available benchmark datasets, including CIC-IDS2017, CSE-CIC-IDS2018, UNSW-NB15, TON_IoT, and Bot-IoT, are identified for future empirical validation. No new datasets were generated or analyzed during the current study.
Issue
Section
License
Copyright (c) 2026 ali hassan (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.








