Operationalising Cyber Risk Management Using AI: Connecting Cyber Incidents to MITRE ATT&CK Techniques, Security Controls, and Metrics
Emad Sherif, Iryna Yevseyeva, Vitor Basto-Fernandes, Allan Cook

TL;DR
This paper introduces a novel AI-driven framework that automates mapping cyber incidents to adversary techniques, integrating security controls and metrics to enhance cyber risk management, especially for resource-limited organizations.
Contribution
It presents the Cyber Catalog and a fine-tuned sentence-transformers model that significantly improves semantic matching of cyber incidents to MITRE ATT&CK techniques, enabling better operational security.
Findings
Model achieved Spearman correlation of 0.7894 and Pearson of 0.8756.
Significantly lower prediction errors (MAE=0.135, MSE=0.027) than baselines.
Publicly available dataset, trained model, and code for practical deployment.
Abstract
The escalating frequency of cyber-attacks poses significant challenges for organisations, particularly small enterprises constrained by limited in-house expertise, insufficient knowledge, and financial resources. This research presents a novel framework that leverages Natural Language Processing to address these challenges through automated mapping of cyber incidents to adversary techniques. We introduce the Cyber Catalog, a knowledge base that systematically integrates CIS Critical Security Controls, MITRE ATT&CK techniques, and SMART metrics. This integrated resource enables organisations to connect threat intelligence directly to actionable controls and measurable outcomes. To operationalise the framework, we fine-tuned all-mpnet-base-v2, a highly regarded sentence-transformers model used to convert text into numerical vectors on an augmented dataset comprising 74,986…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Cybercrime and Law Enforcement Studies
