Reading progress
0 of 17 sections read
4 / 17

SECTION 02

02Research methodology

1 min read4 of 17

The research follows a pragmatist paradigm: the value of the model lies in whether it works in practice. A mixed-methods explanatory design was adopted — quantitative data first establish the relationships among variables; qualitative interviews then explain how organisations experience them.

The model was built in a design-science logic: identify the gap, construct the artefact, evaluate it against evidence.

ParadigmPragmatism
DesignMixed-methods explanatory (quantitative → qualitative)
QuantitativeStructured survey, N = 212 technology, security and business leaders
QualitativeSemi-structured interviews with CISOs and risk experts
AnalysisCFA and SEM; thematic analysis (NVivo)
TABLE A — RESEARCH DESIGN

2.1 Research stages

  1. 1Literature and framework review to establish the gap.
  2. 2Conceptual model and hypotheses H1–H5.
  3. 3Instrument design, survey and statistical testing.
  4. 4Expert interviews to interpret and refine.
  5. 5Synthesis into the UCSMM model and roadmap.

2.2 Hypotheses and results

Five hypotheses link five constructs: AI integration intensity (independent), enterprise security complexity (H1 outcome), cognitive security capabilities (mediator), AI governance (moderator) and enterprise security resilience (outcome). Structural paths were estimated with SEM (N = 212). Reliability: α = 0.84–0.89; convergent validity: AVE = 0.59–0.65; fit: CFI and TLI > 0.90, RMSEA and SRMR < 0.08. Indirect effect (H4): β = 0.35, t = 6.41, p < 0.001.

PathβtpResult
H1AI integration intensity → security complexity0.487.12<0.001Supported
H2AI integration intensity → cognitive security capabilities0.568.34<0.001Supported
H3Cognitive security capabilities → enterprise resilience0.629.21<0.001Supported
H4Capabilities mediate AI integration → resilience0.356.41<0.001Supported
H5AI governance moderates capabilities → resilience0.213.760.002Supported
TABLE B — HYPOTHESIS TESTING (SEM)

The strongest path is H3 (β = 0.62): cognitive security capability, not AI adoption itself, decides whether the enterprise becomes more resilient. Governance adds a significant, smaller effect (H5), making capabilities work more consistently. These results define the four dimensions of the model that follows.

Tip: use ← → to move between sections.