Abstract
This postgraduate-level teaching case explores the governance challenges that arise when artificial intelligence becomes embedded within enterprise cybersecurity and operational decision-making. Set in a mid-sized European IT services firm, NovexTech Solutions, the case examines how a ransomware incident affecting AI-enabled analytics systems exposes limitations in existing governance arrangements. While the organisation successfully restores services using established incident response and business continuity procedures, post-incident reviews reveal deeper concerns related to AI model integrity, accountability, and oversight across the AI development and operational lifecycle. As regulatory expectations intensify under frameworks such as the General Data Protection Regulation (GDPR), the Network and Information Systems Directive 2 (NIS2 Directive), and the European Union Artificial Intelligence Act (EU AI Act), NovexTech faces growing pressure from clients, partners, and broader societal stakeholders to demonstrate coherent and defensible governance. Students are invited to analyse governance fragmentation, evaluate trade-offs between control and innovation, and assess how organisations can structure responsible and resilient governance in AI-enabled environments. The case culminates in a board-level governance dilemma requiring senior leadership to determine whether to maintain parallel cybersecurity and AI governance structures or redesign governance into an integrated framework capable of managing AI-enabled cyber risk while sustaining innovation and regulatory accountability.
| Original language | English |
|---|---|
| Pages (from-to) | (In-Press) |
| Number of pages | 9 |
| Journal | Journal of Information Technology Teaching Cases |
| Volume | (In-Press) |
| Early online date | 6 May 2026 |
| DOIs | |
| Publication status | E-pub ahead of print - 6 May 2026 |
Bibliographical note
© Association for Information Technology Trust 2026. This article is distributed under the terms of the Creative Commons Attribution 4.0 License (https://creativecommons.org/licenses/by/4.0/) which permits any use, reproduction and distribution of the work without further permission provided the original work is attributed as specified on the SAGE and Open Access page (https://us.sagepub.com/en-us/nam/open-access-at-sage).Keywords
- AI risk management
- artificial intelligence governance
- cybersecurity governance
- enterprise governance design
- governance integration
- organisational accountability
- regulatory compliance
ASJC Scopus subject areas
- Education
- Library and Information Sciences
Fingerprint
Dive into the research topics of 'Securing responsible AI: Integrating cybersecurity and AI governance at NovexTech solutions'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS