AI-Driven Agentic Framework for Insider Threats Prevention and Detection in Secure Software Development Organizations: A Fuzzy AHP Approach | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Article AI-Driven Agentic Framework for Insider Threats Prevention and Detection in Secure Software Development Organizations: A Fuzzy AHP Approach Muhammad Shafiq, Mujtaba Awan, Hathal Salamah Alwageed, Umar ., and 2 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8756821/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 15 You are reading this latest preprint version Abstract Background Insider threats remain a persistent and complex risk in secure software development organizations because they emerge from a mix of malicious intent, negligence, credential compromise, and process weaknesses across the software development lifecycle. AI-driven, agentic security approaches are increasingly proposed to strengthen prevention and detection; however, organizations still lack a transparent, decision-ready method to prioritize agentic mitigation practices under uncertainty. Objectives This study proposes and prioritizes an AI-driven agentic framework for insider threats mitigation in secure software development organizations using the Fuzzy Analytic Hierarchy Process (Fuzzy AHP). It aims to (i) structure insider-threat mitigation into a hierarchical decision model, (ii) compute priority weights for AI-driven agentic practices, and (iii) support actionable adoption decisions for different insider-threat categories. Methods Initially a systematic mapping study (SMS) was conducted to study the state-of-the-art of insider threats in software development organization. In the second phase, an empirical survey was conducted with cybersecurity professionals to validate the findings of SMS and identify types of insider threats and AI-driven agentic practices for prevention and mitigation of these threats. ANOVA test was then used for comparing the findings of MLR and empirical survey. In the last phase a fuzzy analytical hierarchy process (FAHP) was performed to derive weights and ranking of insider threats and AI-Driven agentic practices. Consistency was checked through standard FAHP validation steps, and a sensitivity analysis was conducted to test ranking stability under small perturbations of criterion weights. Results A hierarchical decision model was developed with the overall goal of insider threats mitigation in secure software development organizations, decomposed into nine insider-threat types (e.g., malicious insiders, negligent insiders, credential theft, inadvertent misuse of access, privilege escalation, social engineering, software piracy/code theft, insider data exfiltration, and abuse of development tools). Ninety-one AI-driven agentic practices were identified for prevention and detection of these insider threats. Using FAHP credential theft with final weight 0.1262 were considered the most highlighted insider threat for software development organizations. Similarly, the most cited AI-driven agentic practice were identified “machine learning driven anomaly detection” with final weight 0.020580 and global rank-1. Conclusion The proposed AI-driven agentic framework, operationalized through Fuzzy AHP, offers a systematic and explainable mechanism to prioritize insider-threat mitigation practices in secure software development organizations. By accounting for uncertainty in expert judgments, the framework supports more defensible security investment decisions and helps align agentic controls with threat-specific needs across the development environment. Physical sciences/Engineering Physical sciences/Mathematics and computing Insider Threats Secure Software Development Agentic AI Practices Systematic Mapping Study Empirical Survey Fuzzy AHP Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 20 Apr, 2026 Reviews received at journal 16 Apr, 2026 Reviews received at journal 10 Apr, 2026 Reviews received at journal 27 Mar, 2026 Reviewers agreed at journal 24 Mar, 2026 Reviewers agreed at journal 23 Mar, 2026 Reviewers agreed at journal 23 Mar, 2026 Reviewers agreed at journal 03 Mar, 2026 Reviews received at journal 28 Feb, 2026 Reviewers agreed at journal 26 Feb, 2026 Reviewers invited by journal 26 Feb, 2026 Editor assigned by journal 14 Feb, 2026 Editor invited by journal 13 Feb, 2026 Submission checks completed at journal 06 Feb, 2026 First submitted to journal 06 Feb, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8756821","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Article","associatedPublications":[],"authors":[{"id":598793197,"identity":"bae96059-3581-4830-882e-a985aa789231","order_by":0,"name":"Muhammad Shafiq","email":"","orcid":"","institution":"Shandong Xiehe University","correspondingAuthor":false,"prefix":"","firstName":"Muhammad","middleName":"","lastName":"Shafiq","suffix":""},{"id":598793198,"identity":"6e0cc6c1-2051-4ac8-860b-ea474e099065","order_by":1,"name":"Mujtaba Awan","email":"","orcid":"","institution":"University of Gloucestershire","correspondingAuthor":false,"prefix":"","firstName":"Mujtaba","middleName":"","lastName":"Awan","suffix":""},{"id":598793199,"identity":"e6f1da46-1fad-4239-961b-fb12a0a94bd6","order_by":2,"name":"Hathal Salamah Alwageed","email":"","orcid":"","institution":"Al Jouf University","correspondingAuthor":false,"prefix":"","firstName":"Hathal","middleName":"Salamah","lastName":"Alwageed","suffix":""},{"id":598793200,"identity":"9d36b79e-ea1f-4a86-888a-14e1f4cef733","order_by":3,"name":"Umar .","email":"","orcid":"","institution":"Teesside University","correspondingAuthor":false,"prefix":"","firstName":"Umar","middleName":"","lastName":".","suffix":""},{"id":598793201,"identity":"e18fad3f-3d9e-4238-bf19-ab3c00848a68","order_by":4,"name":"Mohammad Mehidi Hassan","email":"","orcid":"","institution":"King Saud University","correspondingAuthor":false,"prefix":"","firstName":"Mohammad","middleName":"Mehidi","lastName":"Hassan","suffix":""},{"id":598793202,"identity":"c481d48b-29f8-4dba-815b-6dab8995f94d","order_by":5,"name":"Rafiq Ahmad Khan","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA8klEQVRIiWNgGAWjYFACxgcHGBiAiCGN8QGQ5OEjrIXZAKaF2QCkhY0YLQxQLWwSID5BLebthxkPvKm5E83fnpZW+TXHToaNgfnhoxt4tMicSWY4OOfYs9wZZ54duy27LRnoMDZj4xw8WiQY8g8c5mE7nNtwI73ttuQ2ZqAWHjZpvFr4HzMc5vl3OHc+UEux5LZ6IrRIJDMc5m07nLvhRtoxxo/bDhOj5THDwbl9h3M3nnmWLM247TgPGzMhv/AnM3948+1w7rzjaYYff26rtudnb374GJ8WMOCB0sxgBjMh5chaGH8Qo3oUjIJRMApGHAAAMfBOdIwLYrMAAAAASUVORK5CYII=","orcid":"","institution":"University of Malakand","correspondingAuthor":true,"prefix":"","firstName":"Rafiq","middleName":"Ahmad","lastName":"Khan","suffix":""}],"badges":[],"createdAt":"2026-02-01 14:23:33","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8756821/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8756821/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":103883365,"identity":"83acb7f5-13ca-4f4c-af95-86499fecf859","added_by":"auto","created_at":"2026-03-04 06:10:56","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":2985832,"visible":true,"origin":"","legend":"","description":"","filename":"InsiderThreatsinSSDV1006022026.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8756821/v1_covered_9c9bb3a8-5cef-4fd8-b326-09d3626de40d.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"AI-Driven Agentic Framework for Insider Threats Prevention and Detection in Secure Software Development Organizations: A Fuzzy AHP Approach","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"scientific-reports","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"scirep","sideBox":"Learn more about [Scientific Reports](http://www.nature.com/srep/)","snPcode":"","submissionUrl":"","title":"Scientific Reports","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Scientific Reports","inReviewEnabled":true,"inReviewRevisionsEnabled":true},"keywords":"Insider Threats, Secure Software Development, Agentic AI Practices, Systematic Mapping Study, Empirical Survey, Fuzzy AHP","lastPublishedDoi":"10.21203/rs.3.rs-8756821/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8756821/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003ch2\u003eBackground\u003c/h2\u003e \u003cp\u003eInsider threats remain a persistent and complex risk in secure software development organizations because they emerge from a mix of malicious intent, negligence, credential compromise, and process weaknesses across the software development lifecycle. AI-driven, agentic security approaches are increasingly proposed to strengthen prevention and detection; however, organizations still lack a transparent, decision-ready method to prioritize agentic mitigation practices under uncertainty.\u003c/p\u003e\u003ch2\u003eObjectives\u003c/h2\u003e \u003cp\u003eThis study proposes and prioritizes an AI-driven agentic framework for insider threats mitigation in secure software development organizations using the Fuzzy Analytic Hierarchy Process (Fuzzy AHP). It aims to (i) structure insider-threat mitigation into a hierarchical decision model, (ii) compute priority weights for AI-driven agentic practices, and (iii) support actionable adoption decisions for different insider-threat categories.\u003c/p\u003e\u003ch2\u003eMethods\u003c/h2\u003e \u003cp\u003eInitially a systematic mapping study (SMS) was conducted to study the state-of-the-art of insider threats in software development organization. In the second phase, an empirical survey was conducted with cybersecurity professionals to validate the findings of SMS and identify types of insider threats and AI-driven agentic practices for prevention and mitigation of these threats. ANOVA test was then used for comparing the findings of MLR and empirical survey. In the last phase a fuzzy analytical hierarchy process (FAHP) was performed to derive weights and ranking of insider threats and AI-Driven agentic practices. Consistency was checked through standard FAHP validation steps, and a sensitivity analysis was conducted to test ranking stability under small perturbations of criterion weights.\u003c/p\u003e\u003ch2\u003eResults\u003c/h2\u003e \u003cp\u003eA hierarchical decision model was developed with the overall goal of insider threats mitigation in secure software development organizations, decomposed into nine insider-threat types (e.g., malicious insiders, negligent insiders, credential theft, inadvertent misuse of access, privilege escalation, social engineering, software piracy/code theft, insider data exfiltration, and abuse of development tools). Ninety-one AI-driven agentic practices were identified for prevention and detection of these insider threats. Using FAHP credential theft with final weight 0.1262 were considered the most highlighted insider threat for software development organizations. Similarly, the most cited AI-driven agentic practice were identified \u0026ldquo;machine learning driven anomaly detection\u0026rdquo; with final weight 0.020580 and global rank-1.\u003c/p\u003e\u003ch2\u003eConclusion\u003c/h2\u003e \u003cp\u003eThe proposed AI-driven agentic framework, operationalized through Fuzzy AHP, offers a systematic and explainable mechanism to prioritize insider-threat mitigation practices in secure software development organizations. By accounting for uncertainty in expert judgments, the framework supports more defensible security investment decisions and helps align agentic controls with threat-specific needs across the development environment.\u003c/p\u003e","manuscriptTitle":"AI-Driven Agentic Framework for Insider Threats Prevention and Detection in Secure Software Development Organizations: A Fuzzy AHP Approach","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-03-04 06:09:35","doi":"10.21203/rs.3.rs-8756821/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2026-04-20T15:55:10+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-04-16T13:33:31+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-04-10T17:51:17+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-03-27T06:58:57+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"36262367788307660252659054204757588714","date":"2026-03-24T04:07:35+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"27181016525400047817338155657194762261","date":"2026-03-23T08:36:59+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"1742071913276063169216147021518268619","date":"2026-03-23T05:43:03+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"218493172885237474886804702868273321123","date":"2026-03-04T04:39:52+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-02-28T20:58:11+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"39341376723116948655675398794573176450","date":"2026-02-27T04:53:59+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-02-27T03:03:04+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-02-14T16:56:09+00:00","index":"","fulltext":""},{"type":"editorInvited","content":"","date":"2026-02-13T12:05:03+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-02-06T14:16:31+00:00","index":"","fulltext":""},{"type":"submitted","content":"Scientific Reports","date":"2026-02-06T13:47:25+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"scientific-reports","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"scirep","sideBox":"Learn more about [Scientific Reports](http://www.nature.com/srep/)","snPcode":"","submissionUrl":"","title":"Scientific Reports","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Scientific Reports","inReviewEnabled":true,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"3d15f82a-0220-41db-a83a-2de78d4f674b","owner":[],"postedDate":"March 4th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[{"id":63719849,"name":"Physical sciences/Engineering"},{"id":63719850,"name":"Physical sciences/Mathematics and computing"}],"tags":[],"updatedAt":"2026-04-26T05:38:11+00:00","versionOfRecord":[],"versionCreatedAt":"2026-03-04 06:09:35","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8756821","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8756821","identity":"rs-8756821","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.