risk mitigation planning

Designing and operationalizing strategies, governance, and engineering controls to reduce ethical, safety, and dual-use risks—e.g., participant protections, regulated deployment sandboxes, and operational procedures for degraded or reconnecting systems.

riskmitigationplanning

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Internal Vulnerabilities, External Threats: A Grounded Framework for Enterprise Open Source Risk Governance

Oct 29, 2025
WY
Wenhao Yang
🏛️ Peking University | Bitergia | Huawei Technologies Co., Ltd.

Conventional open-source risk management overrelies on technical tools, failing to address systemic risks—including upstream “silent fixes,” community conflicts, and sudden license changes—resulting in governance blind spots. Method: This paper proposes a strategic open-source risk governance framework centered on the interaction between external threats and internal vulnerabilities, shifting from tactical response to proactive, strategic prevention. It innovatively introduces a Strategic Objective Matrix and a dual-risk taxonomy, yielding an “Object–Threat–Vulnerability–Mitigation” decision model; integrates grounded theory, strategic mapping, and capability-building principles to support organization-level governance decisions. Contribution/Results: Validated by three domain experts and applied in real-world case studies, the framework significantly enhances risk analytical capability and enables enterprises to establish a systematic, immunizing mechanism against open-source risks.

Addressing systemic open source risks beyond technical vulnerabilitiesDeveloping framework to connect external threats with internal vulnerabilitiesShifting from tactical risk management to holistic risk governance

An Approach to Technical AGI Safety and Security

Apr 02, 2025
RS
Rohin Shah
🏛️ Google DeepMind

Prior to large-scale AGI deployment, misuse and goal misalignment represent two critical safety risks. Method: We propose a dual-track collaborative defense framework: (1) at the model level, integrating amplified supervision, robust training, interpretability analysis, and uncertainty modeling; and (2) at the system level, implementing multi-tiered access control and real-time behavioral monitoring. Contribution/Results: This work is the first to systematically categorize and prioritize four risk types—misuse, misalignment, mistakes, and structural flaws—focusing explicitly on the former two. It introduces the first verifiable safety case framework for AGI, treating interpretability and uncertainty estimation as proactive enablers of safety assurance. The resulting end-to-end methodology comprehensively covers capability identification, safety hardening, dynamic monitoring, and failure containment—thereby enabling high-assurance, auditable, and formally verifiable AGI safety engineering.

Addressing misuse risks in AGI through security and access controlCombining techniques for robust AGI safety and security casesMitigating misalignment risks via model-level and system-level defenses

Analysis of Publicly Accessible Operational Technology and Associated Risks

Aug 04, 2025
MR
Matthew Rodda
🏛️ Defence Science and Technology Group | The Alan Turing Institute

Industrial operational technology (OT) systems—prioritizing functionality over security—are frequently misconfigured and exposed to the public Internet, posing severe cyber-physical risks. Method: We propose a comprehensive framework integrating cyberspace mapping, protocol fingerprinting, firmware version analysis, and a novel automated HMI/SCADA interface screenshot recognition technique to systematically assess global OT exposure. Our methodology correlates findings with vulnerability databases (e.g., NVD, ICS-CERT) and geolocation data across protocols, vendors, software, and regions. Contribution/Results: We identify nearly 70,000 publicly exposed OT devices, predominantly in North America and Europe; many run outdated firmware containing known critical vulnerabilities and remain unpatched for extended periods. Crucially, our interface-based analysis uncovers multiple previously undocumented unauthorized access paths—enabling the first large-scale, visually grounded quantification of real-world industrial attack surfaces and delivering actionable, operationally relevant insights for risk mitigation.

Analyzes geographic and protocol distribution of exposed OT systemsDemonstrates risks from unpatched firmware and exposed interfacesIdentifies vulnerabilities in OT devices exposed to the internet

Limits of Safe AI Deployment: Differentiating Oversight and Control

Jul 04, 2025
DM
David Manheim
🏛️ Association for Long Term Existence and Resilience | Centre for the Governance of AI

This paper addresses the conceptual conflation of “oversight” and “control” in AI safety governance, systematically distinguishing their distinct objectives, operational mechanisms, and temporal scopes. Through a critical cross-disciplinary literature review—and integrating insights from Responsible AI maturity models and risk governance theory—it develops a theoretically rigorous yet policy-actionable analytical framework, introducing the first AI Oversight Maturity Model (AI-OMM). The model identifies critical boundary conditions for oversight failure and establishes a structured, conditional system for assessing the feasibility of meaningful human oversight. Key contributions include: (1) clarifying the normative distinction between oversight and control; (2) diagnosing design gaps and contextual limitations in current oversight mechanisms; and (3) providing regulators, auditors, and developers with a practical tool to evaluate oversight effectiveness, detect capability gaps, and guide technical alignment with governance requirements.

Differentiating oversight and control in AI supervisionIdentifying limitations and needs in AI supervision mechanismsProposing a framework for meaningful human supervision conditions

Enhancing Energy Sector Resilience: Integrating Security by Design Principles

Feb 18, 2024
DS
Dov Shirtz
🏛️ Ben-Gurion University | Shamoon College of Engineering

Energy-sector industrial control systems (ICS) exhibit insufficient security resilience and overreliance on reactive, post-incident remediation. Method: This paper proposes a layered, implementable Security-by-Design (SbD) framework and a deployable set of security requirements tailored to critical infrastructure. Integrating systems engineering, ICS-specific security architecture, organizational behavior principles, and continuous monitoring, the approach spans the entire lifecycle—design, development, deployment, and operations—while ensuring alignment with IEC 62443 and NIST SP 800-82. Contribution/Results: It represents the first systematic, end-to-end operationalization of SbD in energy ICS contexts, enabling a paradigm shift from passive incident response to inherent, “native immunity.” The resulting scalable, auditable, and standards-coordinated SbD implementation guide supports the development of high-assurance, resilient, and sustainably evolvable cybersecurity ecosystems.

Enhancing energy sector resilience through Security by Design (SbD) principlesEstablishing an SbD-driven ecosystem to combat cyber threats effectivelyIntegrating SbD in industrial control systems lifecycle for robust security

Latest Papers

What's happening recently
View more

This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.

critical infrastructurecyber safetycyber-physical systems

This study addresses the inefficiencies in SaaS onboarding within regulated enterprises, where siloed security and compliance controls—spanning third-party risk management, cybersecurity, identity and access management, and disaster recovery—often result in process delays, redundant assessments, and ambiguous accountability. To overcome these challenges, this work proposes an end-to-end, control-driven SaaS onboarding framework that integrates multi-domain controls into a unified lifecycle model encompassing requirement intake, architectural validation, identity design, resilience assessment, and post-deployment governance. By leveraging cross-domain control mapping, phased process modeling, and governance checklists, the framework codifies key design patterns such as secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Empirical implementation demonstrates that the approach significantly reduces onboarding friction, enhances audit traceability, and strengthens both the security posture and operational resilience of SaaS platforms.

disaster recoveryIdentity and Access Managementregulated enterprises

This study addresses the systemic risks posed by on-premises AI coding agents, whose autonomous modifications to code and infrastructure may lead to severe organizational or societal harm due to challenges in timely constraint, auditing, or reversal. For the first time, it systematically applies three systems safety methodologies—STECA, STPA, and FRAM—to model risks in cutting-edge laboratory settings from multiple perspectives. The analysis reveals critical blind spots in current AI governance frameworks, particularly concerning unverifiable accountability, control failure caused by intervention delays, and weakened safeguards due to operational drift. The work underscores the necessity of integrating model-level evaluations with system-level hazard analysis, offering a crucial complementary pathway for robust AI risk management.

Agentic AIAI Risk ManagementLoss of Control

Existing decision graph approaches struggle to effectively model safety and security requirements in adaptive systems. This work proposes an extended decision graph modeling language that, for the first time, incorporates a safety-event dimension within a sustainability-driven framework and enables unified, synergistic modeling of safety, security, and sustainability through multi-granular “safety modes.” The approach supports formal specification and divide-and-conquer fine-grained management of relevant scenarios across the entire system lifecycle. Experimental evaluation on an industrial collaboration use case demonstrates that the proposed extension more accurately captures complex safety and security scenarios, significantly enhancing the overall modeling capability for adaptive systems.

Decision MapsSafetySecurity

Current AI incident governance frameworks lack consistency in defining, categorizing, monitoring, and reporting incidents, which constrains the depth and accuracy of post-deployment failure analysis. This study addresses this gap through a systematic literature review and comparative analysis across multiple governance frameworks, thereby identifying and synthesizing key inconsistencies that span existing mechanisms. The work reveals systemic deficiencies in data collection practices, classification logics, and analytical rigor, and elucidates critical misalignments among core governance components. By clarifying these structural disconnects, the research establishes a theoretical foundation and proposes a coordinated pathway toward a unified, standardized framework for AI incident governance.

AI incident governanceclassificationdefinitions

Hot Scholars

SC

Stephen Casper

PhD student, MIT
AI safetyAI responsibilityred-teamingrobustness
KS

Ken Seng Tan

Nanyang Technological University
Quasi-Monte Carlo methodQuantitative risk managementOptimal reinsuranceLongevity risk
PP

Patricia Paskov

RAND
AI evaluationAI governanceeconomicsinternational development