AI-Enabled Framework for Continuous Cybersecurity Awareness in Healthcare SMEs: A Behavior-Centered Approach
DOI:
https://doi.org/10.55084/gcp/001501Keywords:
Cybersecurity awareness, artificial intelligence, machine learning, healthcare SMEs, behavioral nudgesAbstract
Cybersecurity awareness programs in healthcare small and medium-sized enterprises (SMEs) continue to rely on static, periodic training that offers minimal evaluation of long-term behavioral change. Research indicates that over 90% of security training content is forgotten shortly after one-time sessions, yet existing approaches rarely employ artificial intelligence for real-time assessment or behavioral reinforcement. This paper proposes an AI-enabled framework for continuous evaluation of security awareness programs in healthcare SMEs. Through a systematic review of 20 peer-reviewed studies published between 2018 and 2025, we synthesize how machine learning is applied to monitor employee actions, identify risk behaviors such as phishing susceptibility and policy violations, and deliver real-time feedback through nudges and personalized alerts. Grounded in Kirkpatrick’s Four Levels of Evaluation and Nudge Theory, our framework categorizes AI tools by their ability to measure and influence security outcomes across knowledge, behavior, and incident reduction. Findings indicate that AI-based feedback loops significantly enhance training effectiveness by reinforcing lessons in context, identifying vulnerable users, and enabling curriculum adaptation. For resource-constrained healthcare SMEs, the proposed framework provides scalable, behavior-informed interventions that sustain organizational cybersecurity readiness and foster a human-centric security culture.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Grinrey Conference Proceedings

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.