SECTION 02
02Research methodology
The research follows a pragmatist paradigm: the value of the model lies in whether it works in practice. A mixed-methods explanatory design was adopted — quantitative data first establish the relationships among variables; qualitative interviews then explain how organisations experience them.
The model was built in a design-science logic: identify the gap, construct the artefact, evaluate it against evidence.
| Paradigm | Pragmatism |
| Design | Mixed-methods explanatory (quantitative → qualitative) |
| Quantitative | Structured survey, N = 212 technology, security and business leaders |
| Qualitative | Semi-structured interviews with CISOs and risk experts |
| Analysis | CFA and SEM; thematic analysis (NVivo) |
2.1 Research stages
- 1Literature and framework review to establish the gap.
- 2Conceptual model and hypotheses H1–H5.
- 3Instrument design, survey and statistical testing.
- 4Expert interviews to interpret and refine.
- 5Synthesis into the UCSMM model and roadmap.
2.2 Hypotheses and results
Five hypotheses link five constructs: AI integration intensity (independent), enterprise security complexity (H1 outcome), cognitive security capabilities (mediator), AI governance (moderator) and enterprise security resilience (outcome). Structural paths were estimated with SEM (N = 212). Reliability: α = 0.84–0.89; convergent validity: AVE = 0.59–0.65; fit: CFI and TLI > 0.90, RMSEA and SRMR < 0.08. Indirect effect (H4): β = 0.35, t = 6.41, p < 0.001.
| Path | β | t | p | Result | |
|---|---|---|---|---|---|
| H1 | AI integration intensity → security complexity | 0.48 | 7.12 | <0.001 | Supported |
| H2 | AI integration intensity → cognitive security capabilities | 0.56 | 8.34 | <0.001 | Supported |
| H3 | Cognitive security capabilities → enterprise resilience | 0.62 | 9.21 | <0.001 | Supported |
| H4 | Capabilities mediate AI integration → resilience | 0.35 | 6.41 | <0.001 | Supported |
| H5 | AI governance moderates capabilities → resilience | 0.21 | 3.76 | 0.002 | Supported |
The strongest path is H3 (β = 0.62): cognitive security capability, not AI adoption itself, decides whether the enterprise becomes more resilient. Governance adds a significant, smaller effect (H5), making capabilities work more consistently. These results define the four dimensions of the model that follows.
Tip: use ← → to move between sections.
