The growing attack surface and resource constraints of IoT devices require advanced cryptographic solutions that balance high security with lightweight efficiency. This paper presents a hybrid lightweight image encryption approach that integrates Arnold’s Cat Map for pixel scrambling, dynamic key-dependent S-box substitutions, bitwise rotations, and selective AES-CBC encryption with HMAC integrity verification. A novel key generation mechanism ensures an expanded key space ( \(2^{673}\) ), robustly defending against brute force and side-channel attacks while maintaining efficiency. The method partitions images into blocks, applying varying encryption techniques to selected columns to optimize the security performance trade-off by decreasing the overall encryption and decryption time and maintaining security robustness against different security attacks. The approach ensures robustness against classical cryptanalysis, such as differential, statistical, and known-plaintext attacks, while maintaining lightweight operation suitable for IoT devices and supporting parallel encryption for real-time processing. Experimental evaluations demonstrate \(\text {NPCR}> 99.5\%\) , \(\text {UACI} \approx 33.4\%\) , and a near-ideal entropy of \(7.997\) , confirming strong confusion and diffusion. The results also demonstrate high efficiency, with an average encryption time of 2 ms for a standard \(512 \times 512\) image size. Security analysis highlights resistance to brute-force attacks and algebraic cryptanalysis due to dynamic key-dependent S-boxes and a large key space.