An Agentic Multi-Agent Architecture for Cybersecurity Risk Management
Ravish Gupta (1), Saket Kumar (2), Shreeya Sharma (3), Maulik Dang (4), Abhishek Aggarwal (4) ((1) BigCommerce, (2) University at Buffalo, The State University of New York, Buffalo, NY, USA, (3) Microsoft, (4) Amazon)

TL;DR
This paper presents a multi-agent AI system for rapid, cost-effective cybersecurity risk assessment that outperforms traditional methods in accuracy and speed, but faces challenges with context limitations on standard hardware.
Contribution
Introduces a novel multi-agent architecture for cybersecurity risk assessment that integrates sequential analytical stages with shared context, improving efficiency and accuracy.
Findings
Achieved 85% agreement with expert assessments on severity classifications.
Covered 92% of identified risks in real-world healthcare setting.
Failed to complete assessments on standard hardware due to context window limitations.
Abstract
Getting a real cybersecurity risk assessment for a small organization is expensive -- a NIST CSF-aligned engagement runs $15,000 on the low end, takes weeks, and depends on practitioners who are genuinely scarce. Most small companies skip it entirely. We built a six-agent AI system where each agent handles one analytical stage: profiling the organization, mapping assets, analyzing threats, evaluating controls, scoring risks, and generating recommendations. Agents share a persistent context that grows as the assessment proceeds, so later agents build on what earlier ones concluded -- the mechanism that distinguishes this from standard sequential agent pipelines. We tested it on a 15-person HIPAA-covered healthcare company and compared outputs to independent assessments by three CISSP practitioners -- the system agreed with them 85% of the time on severity classifications, covered 92% of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Multi-Agent Systems and Negotiation · Mobile Agent-Based Network Management
