Skip to content

Author

Nitin Bodade

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access Jul 2026

AI-Driven Predictive Cyber Threat Intelligence Framework for Securing Industrial Digital Infrastructure

The digitalisation of industrial environments and the increasing number of Industrial Internet of Things (IIoT) devices have completely increased the attack surface of critical manufacturing and operational technology (OT) systems. Current signature-based, "reactive" cybersecurity models are clearly failing to keep up with the sophistication and speed of today's Advanced Persistent Threats (APTs), ransomware-as-a-service (RaaS) operations and supply-chain attacks on industrial digital systems. Cyber Threat Intelligence (CTI) is now a strategic field and discipline for predicting adversarial actions, but the frameworks in use are largely tactical, siloed, and reactive, and have very limited ability to conduct realtime predictive analytics in industrial environments. This paper tackles the identified gap by proposing a new conceptual framework called Artificial Intelligence Powered Cyber Threat Intelligence (AIPCTI) Framework specifically designed to facilitate predictive, adaptive, and automated methods of threat intelligence for industrial digital infrastructure. This research uses Design Science Research Methodology (DSRM) that includes Systematic Literature Review (SLR), Knowledge Elicitation from experts and Structured Conceptual Design in order to create the framework artefact. The AIPCTI Framework comprises six interdependent layers: Threat Data Acquisition, Threat Intelligence Fusion, AI Analytics Engine, Predictive Risk Assessment, Automated Response, and Governance and Compliance. These layers support a continuous, intelligence based cyber defence posture that is consistent with Zero Trust Architecture (ZTA) principles, as well as the MITRE ATT&CK for ICS knowledge base. The framework has been developed to incorporate feedback from experts in the field of ICS/OT security and validated using structured scenario-based reasoning using three representative attack patterns: manufacturing ransomware, energysector APT intrusion and IIoT firmware exploitation. The analysis at the architecture level depicts examples of how the layered design of AIPCTI would be expected to close certain detection and response gaps identified by indicator-based CTI platforms and IT-focused SOAR solutions, such as providing the ability for AIPCTI to anticipate attack techniques before they are executed, as well as to limit automated response with safety logic specific to OT. These findings are expressed as a design stage evaluation and not as an actual performance while in operation: the framework is not yet in place, nor is it deployed in a live industrial setting, nor is it claimed to be able to improve the detection rate or response time (even though it can certainly do that). The research provides a theoretically informed conceptual framework for cybersecurity architects, offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational claims.

Nitin Bodade · 0 citations
Open access Jul 2026

An Adaptive Risk-Driven DevSecOps Framework for Securing Multi-Cloud Enterprise Systems in the Era of Agentic AI

The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security by embedding security practices into development and operations workflows, yet organizations continue to face challenges related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle. Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified, adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale software delivery environments.

Nitin Bodade · 0 citations