Static Enterprise Architecture frameworks, dependent on infrequent security evaluations, create a significant vulnerability known as the "Periodic Architecture Review Trap," wherein defenses deteriorate and threats advance during the intervals between assessments. This research sought to establish and present a conceptual framework for evolving business security from a static, point-in-time condition into a perpetually adaptive system. The research employed a design science approach to develop the Living Citadel (LC) framework, a generative system grounded in continual adaptation. The framework incorporated five fundamental components: ongoing threat and asset detection; generative artificial intelligence for creating new attack scenarios; adaptive risk exposure recalibration; autonomous architecture fortification through reinforcement learning; and a security ledger that ensures integrity. The findings depict the Living Citadel as a comprehensive theoretical framework that facilitates an ongoing cycle of sensing, synthesis, and self-hardening, thereby effectively addressing the security deficiencies of conventional methods. The study found that the framework enables a transition from a static to a dynamic security architecture, reorienting security governance from periodic compliance to continuous, autonomous resilience and real-time risk-security alignment.
Copyrights © 2026