00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

Cybersecurity Analytics and Cyber Threat Intelligence in Business Information Systems: A Systematic Literature Review Protocol and Proposed Conceptual Framework

Authors

Dr. Manusankar C

PG & Research Department of Computer Science, S S V College, Valayanchirangara (India)

Article Information

DOI: 10.51583/IJLTEMAS.2026.150800109

Subject Category: Cybersecurity

Volume/Issue: 15/8 | Page No: 1518-1530

Publication Timeline

Submitted: 2026-08-30

Accepted: 2026-09-09

Published: 2026-09-19

Abstract

Security teams usually describe cybersecurity analytics and cyber threat intelligence (CTI) in practical terms: they are what lets an organization turn uneven, scattered data into a decision that has to be made before the window closes. The managerial side of that account is spread thin across three literatures — technical security research, information systems scholarship, and organizational studies — which, for whatever reason, rarely cite one another. This paper sets out a protocol for a systematic literature review (SLR) on cybersecurity analytics, CTI, decision processes, governance, and organizational cyber resilience in business information systems, along with some preliminary background. The window runs from 1 January 2015 to 31 December 2025. It should be read as a plan, not a finding. No searches have been completed, so there are no screening numbers, no PRISMA counts, no results from included studies, and — this matters most — no validated causal model. When the review is run, it will draw on Scopus, Web of Science Core Collection, IEEE Xplore, and ACM Digital Library, topped up with a few publisher platforms and with citation chasing in both directions to catch what the databases miss. Two reviewers will screen and extract independently, then compare, so that disagreements get logged and argued out rather than quietly averaged. During synthesis, technical analytics outcomes stay apart from organizational and managerial ones; quality is judged against criteria fitted to each study design rather than one blanket scale; and the work leans on narrative and thematic synthesis, with meta-analysis deliberately left out at this stage. A preliminary conceptual framework comes with the protocol, offered only as a proposition: data governance may support intelligence quality, which may support decision quality, which may in turn feed organizational cyber resilience — with context and feedback loops acknowledged rather than assumed away. None of those links has been tested. The sharp line drawn between protocol and results is intentional — it gives a later, auditable review something stable to stand on, and gives the empirical management research that follows a defined place to start.

Keywords

cybersecurity analytics; cyber threat intelligence; business information systems; cyber resilience; systematic literature review protocol

Downloads

References

1. Ainslie, S., Thompson, D., Maynard, S. B., & Ahmad, A. (2023). Cyber-threat intelligence for security decision-making: A review and research agenda for practice. Computers & Security, 132, 103352. https://doi.org/10.1016/j.cose.2023.103352 [Google Scholar] [Crossref]

2. Ahmad, A., Desouza, K. C., Maynard, S. B., Naseer, H., & Baskerville, R. L. (2020). How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, 71(8), 939–953. [Google Scholar] [Crossref]

3. Ahmad, A., Maynard, S. B., Desouza, K. C., Kotsias, J., Whitty, M. T., & Baskerville, R. L. (2021). How can organizations develop situation awareness for incident response: A case study of management practice. Computers & Security, 101. [Google Scholar] [Crossref]

4. Brown, S., Gommers, J., & Serrano, O. (2015). From cyber security information sharing to threat management. Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security. [Google Scholar] [Crossref]

5. Bromander, S., Swimmer, M., Pijnenburg Muller, L. J., Audun, E., Skjotskift, G., & Borg, F. (2021). Investigating sharing of cyber threat intelligence and proposing a new data model for enabling automation in knowledge representation and exchange. Digital Threats: Research and Practice, 3(1), 1–22. [Google Scholar] [Crossref]

6. Kotsias, J., Ahmad, A., & Scheepers, R. (2022). Adopting and integrating cyber-threat intelligence in a commercial organization. European Journal of Information Systems. [Google Scholar] [Crossref]

7. Oosthoek, K., & Doerr, C. (2021). Cyber threat intelligence: A product without a process? International Journal of Intelligence and CounterIntelligence, 34(2), 300–315. [Google Scholar] [Crossref]

8. Rantos, K., Spyros, A., Papanikolaou, A., Kritsas, A., Ilioudis, C., & Katos, V. (2020). Interoperability challenges in the cybersecurity information sharing ecosystem. Computers, 9(1), 18. [Google Scholar] [Crossref]

9. Moher, D., Shamseer, L., Clarke, M., Ghersi, D., Liberati, A., Petticrew, M., Shekelle, P., Stewart, L. A., & PRISMA-P Group. (2015). Preferred reporting items for systematic review and meta-analysis protocols (PRISMA-P) 2015 statement. Systematic Reviews, 4, 1. https://doi.org/10.1186/2046-4053-4-1 [Google Scholar] [Crossref]

10. Page, M. J., McKenzie, J. E., Bossuyt, P. M., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71 [Google Scholar] [Crossref]

11. Hong, Q. N., Pluye, P., Fàbregues, S., et al. (2018). Mixed Methods Appraisal Tool (MMAT), version 2018: User guide. McGill University. [Google Scholar] [Crossref]

12. Shea, B. J., Reeves, B. C., Wells, G., et al. (2017). AMSTAR 2: A critical appraisal tool for systematic reviews that include randomised or non-randomised studies of healthcare interventions, or both. BMJ, 358, j4008. https://doi.org/10.1136/bmj.j4008 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.