MARATTO

article · Gradiva

Artificial Intelligence-Driven Dynamic Cyber Risk Assessment Framework for Real-Time Organizational Security Management

Abstract

Abstract The increasingly complex nature of vulnerabilities in information technology systems has made effective risk assessment a critical challenge for enterprise organizations. From the literature reviewed, conventional solutions did not integrate risk identification, evaluation, and prioritization as a single pipeline for adaptive risk assessment. To this end, the aim of this paper is an artificial intelligence-driven dynamic cyber risk assessment framework for real-time organization security management. The methodology used is quantitative. Vulnerability data were collected from the 2026 National Vulnerability Database (NVD), pre-processed, and balanced into four severity classes: Low, Medium, High, and Critical. Four machine learning models, namely Random Forest (RF), Feedforward Neural Network (FFNN), K-Nearest Neighbor (KNN), and Support Vector Machine (SVM), were trained and compared to identify the best risk identification model. This was integrated with a risk evaluation and prioritization model to create the adaptive risk assessment framework. The metrics for performance evaluation are accuracy, precision, recall, F1-score, confusion matrices, and Receiver Operating Characteristic (ROC) curve analysis. The experimental results demonstrate that all models achieved high predictive performance, with the RF classifier recording the best accuracy of 98.1%, FFNN reported 97.1%, KNN reported 95.3%, and SVM reported 92.2%. To demonstrate practical applicability, the trained models were integrated into an adaptive risk assessment software prototype capable of automatically classifying vulnerabilities, evaluating and prioritizing cybersecurity risks using Python programming language and Replit cloud-based integrated development environment. Practical validation using real 2026 CVE records demonstrated the framework's capability to accurately classify different classes of vulnerabilities and evaluate and prioritize cybersecurity risks.

Research topics

  • Information and Cyber Security
  • Supply Chain Resilience and Risk Management
  • Organizational and Employee Performance

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.5281/zenodo.22078824

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.