Advancing risk management with cybersecurity intelligence: a design science approach

Joshua T. Lavoie & Xiang Liu

Journal of Systems and Information Technology2026https://doi.org/10.1108/jsit-05-2025-0223article
AJG 1ABDC B
Weight
0.50

What the paper says

Purpose Cyber threat intelligence (CTI) and risk management (RM) remain fragmented across tools, formats and governance processes, limiting interoperability and consistent decision-making. This study aims to develop unified risk and intelligence messaging (URIM), a governance-oriented artifact that standardizes risk and intelligence communication across heterogeneous organizational contexts. Design/methodology/approach Following design science research (DSR), the authors elicited requirements from cybersecurity professionals. A pilot study refined the survey instrument, followed by a qualitative survey using purposive and snowball sampling. Thematic analysis informed the URIM artifact specification, which was appraised through a qualitative ex ante expert review, with recommendations registered for subsequent cycles. Findings Three recurring barriers to effective cyber risk governance emerged: fragmented toolchains, limited data interoperability and inconsistent governance practices. Participants highlighted vendor lock-in, incompatible protocols and weak standardization as constraints on intelligence sharing. They supported a vendor-neutral approach combining canonical governance messages, semantic alignment and modular compliance features. Originality/value URIM extends cybersecurity governance research by providing a user-informed, model-level DSR artifact that links CTI and RM through standardized governance messaging and explicit interface specifications. It makes interoperability requirements explicit by defining canonical messages and semantic alignment rules that existing CTI-sharing and RM approaches often leave implicit.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1108/jsit-05-2025-0223

Or copy a formatted citation

@article{joshua2026,
  title        = {{Advancing risk management with cybersecurity intelligence: a design science approach}},
  author       = {Joshua T. Lavoie & Xiang Liu},
  journal      = {Journal of Systems and Information Technology},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1108/jsit-05-2025-0223},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Advancing risk management with cybersecurity intelligence: a design science approach

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.