The Living Citadel: A Generative Framework for Continuous Threat Sensing, Adaptive Enterprise Architecture Hardening, and Perpetual Business Risk-Security Alignment
DOI:
https://doi.org/10.35870/ijsecs.v6i2.7478Keywords:
Living Citadel, Adaptive Enterprise Architecture, Generative Security, Continuous Threat Sensing, Self-Hardening SystemsAbstract
Static Enterprise Architecture frameworks, dependent on infrequent security evaluations, create a significant vulnerability known as the "Periodic Architecture Review Trap," wherein defenses deteriorate and threats advance during the intervals between assessments. This research sought to establish and present a conceptual framework for evolving business security from a static, point-in-time condition into a perpetually adaptive system. The research employed a design science approach to develop the Living Citadel (LC) framework, a generative system grounded in continual adaptation. The framework incorporated five fundamental components: ongoing threat and asset detection; generative artificial intelligence for creating new attack scenarios; adaptive risk exposure recalibration; autonomous architecture fortification through reinforcement learning; and a security ledger that ensures integrity. The findings depict the Living Citadel as a comprehensive theoretical framework that facilitates an ongoing cycle of sensing, synthesis, and self-hardening, thereby effectively addressing the security deficiencies of conventional methods. The study found that the framework enables a transition from a static to a dynamic security architecture, reorienting security governance from periodic compliance to continuous, autonomous resilience and real-time risk-security alignment.
Downloads
References
Boeding, M., Hempel, M., & Sharif, H. (2025). End-to-end framework for identifying vulnerabilities of operational technology protocols and their implementations in industrial IoT. Future Internet, 17(1), Article 34. https://doi.org/10.3390/fi17010034
Cerabona, T., Bénaben, F., Montreuil, B., Lauras, M., Faugère, L., Campos, M. R., & Jeany, J. (2023). The physics of decision approach: A physics-based vision to manage supply chain resilience. International Journal of Production Research, 62(5), 1783–1802. https://doi.org/10.1080/00207543.2023.2201637
Dash, G. S. (2025). Cybersecurity in the era of generative and agentic AI: A reimagined architecture. International Journal of Cloud Computing and Database Management, 6(2), 49–51. https://doi.org/10.33545/27075907.2025.v6.i2a.106
Dhirani, L. L., Armstrong, E., & Newe, T. (2021). Industrial IoT, cyber threats, and standards landscape: Evaluation and roadmap. Sensors, 21(11), Article 3901. https://doi.org/10.3390/s21113901
Dzreke, S. S. (2025a). Bridging the digital-physical divide: Transfer learning for unified threat correlation in converged IT/OT/IoT ecosystems. Economics and Business Journal (ECBIS), 3(6), 476–502. https://doi.org/10.47353/ecbis.v3i6.231
Dzreke, S. S. (2025b). Securing the connected farm: Cyber threats and resilient architectures for the Internet of AgriThings. Engineering Science & Technology Journal, 6(11), 642–659. https://doi.org/10.51594/estj.v6i11.2161
Dzreke, S. S., & Dzreke, S. E. (2025c). Gendered firewalls: Intersectional barriers to women's cybersecurity careers in East Africa. Frontiers in Research, 3(1), 59–77. https://doi.org/10.71350/30624533114
Dzreke, S. S., & Dzreke, S. E. (2026). The generative capability stack: Adaptive supply chain intelligence framework. Engineering Science & Technology Journal, 7(1), 1–18. https://doi.org/10.51594/estj.v7i1.2189
Dzreke, S. S., Dzreke, S. E., Dzreke, E., & Dzreke, F. M. (2025d). The Zoomification effect: How virtual selling is costing enterprise deals 23% in value—and the neuroscience behind why handshakes still matter. International Journal for Multidisciplinary Research, 7(3), 1–35. https://doi.org/10.36948/ijfmr.2025.v07i03.48943
Dzreke, S. S., Dzreke, S. E., Dzreke, E., Dzreke, C., & Dzreke, F. M. (2025e). Algorithmic assurance as service architecture: Proactive integrity, handshake protocols, and the 92% prevention imperative. Global Journal of Engineering and Technology Advances, 24(3), 209–222. https://doi.org/10.30574/gjeta.2025.24.3.0273
Dzreke, S. S., Dzreke, S. E., Dzreke, E., & Dzreke, F. M. (2025f). The 15-minute competitive tipping point: Velocity quotient (VQ), closed-loop automation, and the 12% customer retention imperative. Global Journal of Engineering and Technology Advances, 24(4), 223–235. https://doi.org/10.30574/gjeta.2025.24.3.0274
Gurram, A. (2025). Generative AI for enhanced cybersecurity: Building a zero-trust architecture with agentic AI. World Journal of Advanced Engineering Technology and Sciences, 15(1), 2380–2396. https://doi.org/10.30574/wjaets.2025.15.1.0504
Hassani, S. (2025). Generative AI for future architecture scenario planning [Preprint]. Research Square. https://doi.org/10.21203/rs.3.rs-6449315/v1
Hernès, T., Blagoev, B., Kunisch, S., & Schultz, M. (2024). From bouncing back to bouncing forward: A temporal trajectory model of organizational resilience. Academy of Management Review, 50(1), 72–92. https://doi.org/10.5465/amr.2022.0406
Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–106. https://doi.org/10.2307/25148625
Hinkelmann, K., Gerber, A., Karagiannis, D., Thoenssen, B., van der Merwe, A., & Woitsch, R. (2015). A new paradigm for the continuous alignment of business and IT: Combining enterprise architecture modelling and enterprise ontology. Computers in Industry, 79, 77–86. https://doi.org/10.1016/j.compind.2015.07.009
Husák, M., Komárková, J., Bou-Harb, E., & Čeleda, P. (2018). Survey of attack projection, prediction, and forecasting in cyber security. IEEE Communications Surveys & Tutorials, 21(1), 640–660. https://doi.org/10.1109/comst.2018.2871866
Ivanov, D., & Dolgui, A. (2021). Stress testing supply chains and creating viable ecosystems. Operations Management Research, 15, 475–486. https://doi.org/10.1007/s12063-021-00194-z
Jiang, Y., Jeusfeld, M. A., Ding, J., & Sandahl, E. (2023). Model-based cybersecurity analysis. Business & Information Systems Engineering, 65(6), 643–676. https://doi.org/10.1007/s12599-023-00811-0
Jiang, Y., Jeusfeld, M. A., Mosaad, M., & Oo, N. (2024). Enterprise architecture modeling for cybersecurity analysis in critical infrastructures: A systematic literature review. International Journal of Critical Infrastructure Protection, 46, Article 100700. https://doi.org/10.1016/j.ijcip.2024.100700
Judijanto, L., Hindarto, D., Wahjono, S. I., & Djunarto. (2023). Edge of enterprise architecture in addressing cyber security threats and business risks. International Journal of Software Engineering and Computer Science (IJSECS), 3(3), 386–396. https://doi.org/10.35870/ijsecs.v3i3.1816
Kaisler, S. H., & Armour, F. (2017). 15 years of enterprise architecting at HICSS: Revisiting the critical problems. Proceedings of the 50th Hawaii International Conference on System Sciences. https://doi.org/10.24251/hicss.2017.585
Kayan, H., Nunes, M., Rana, O., Burnap, P., & Perera, C. (2022). Cybersecurity of industrial cyber-physical systems: A review. ACM Computing Surveys, 54(11), 1–35. https://doi.org/10.1145/3510410
Ko, R. K. L. (2022). Cyber autonomy: Automating the hacker—Self-healing, self-adaptive, automatic cyber defense systems and their impact to the industry, society and national security [Preprint]. arXiv. https://doi.org/10.48550/arxiv.2012.04405
Loft, P., He, Y., Yevseyeva, I., & Wagner, I. (2022). CAESAR8: An agile enterprise architecture approach to managing information security risks. Computers & Security, 122, Article 102877. https://doi.org/10.1016/j.cose.2022.102877
Mavi, A. (2024). Empowering HVAC manufacturing with IT/OT convergence for operational excellence. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(6), 2500–2509. https://doi.org/10.32628/cseit24245475
Moura, R. L. de, & Ceotto, L. de L. (2024). Operational technology: The new role of enterprise architecture in the context of IT & OT convergence. Proceedings of the 2024 Annual Enterprise Information Systems Conference (AEIS), 10–16. https://doi.org/10.1109/aeis65978.2024.00010
Nadella, G. S., Addula, S. R., Yadulla, A. R., Sajja, G. S., Meesala, M. K., Maturi, M. H., Meduri, K., & Gonaygunta, H. (2025). Generative AI-enhanced cybersecurity framework for enterprise data privacy management. Computers, 14(2), Article 55. https://doi.org/10.3390/computers14020055
Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/mis0742-1222240302
Perakslis, E. (2018). Understanding cyber time [Preprint]. JMIR Preprints. https://doi.org/10.2196/preprints.9844
Vemuri, N., Thaneeru, N., & Tatikonda, V. M. (2024). Adaptive generative AI for dynamic cybersecurity threat detection in enterprises. International Journal of Science and Research Archive, 11(1), 2259–2265. https://doi.org/10.30574/ijsra.2024.11.1.0313
Venkata, S. K. S. (2025). Enhance your enterprise security and controls through generative AI. World Journal of Advanced Research and Reviews, 26(2), 1287–1297. https://doi.org/10.30574/wjarr.2025.26.2.1680
Warner, K., & Wäger, M. (2018). Building dynamic capabilities for digital transformation: An ongoing process of strategic renewal. Long Range Planning, 52(3), 326–349. https://doi.org/10.1016/j.lrp.2018.12.001
Zahran, B., Hussaini, A., & Ali-Gombe, A. (2023). Security of IT/OT convergence: Design and implementation challenges [Preprint]. arXiv. https://doi.org/10.48550/arxiv.2302.09426.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Simon Suwanzy Dzreke, Semefa Elikplim Dzreke

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
1. Copyright Retention and Open Access License
Authors retain copyright of their work and grant the journal non-exclusive right of first publication under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
This license allows unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
2. Rights Granted Under CC BY 4.0
Under this license, readers are free to:
- Share — copy and redistribute the material in any medium or format
- Adapt — remix, transform, and build upon the material for any purpose, including commercial use
- No additional restrictions — the licensor cannot revoke these freedoms as long as license terms are followed
3. Attribution Requirements
All uses must include:
- Proper citation of the original work
- Link to the Creative Commons license
- Indication if changes were made to the original work
- No suggestion that the licensor endorses the user or their use
4. Additional Distribution Rights
Authors may:
- Deposit the published version in institutional repositories
- Share through academic social networks
- Include in books, monographs, or other publications
- Post on personal or institutional websites
Requirement: All additional distributions must maintain the CC BY 4.0 license and proper attribution.
5. Self-Archiving and Pre-Print Sharing
Authors are encouraged to:
- Share pre-prints and post-prints online
- Deposit in subject-specific repositories (e.g., arXiv, bioRxiv)
- Engage in scholarly communication throughout the publication process
6. Open Access Commitment
This journal provides immediate open access to all content, supporting the global exchange of knowledge without financial, legal, or technical barriers.
