risk prioritization

Assessing, ranking, and selecting the most vulnerable stages, components, or threats to target mitigations under resource constraints (cost, power). It encompasses designing prioritization frameworks that guide efficient selective hardening and identify research or defense priorities.

riskprioritization

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the challenge of optimizing resource allocation for multi-hazard risk mitigation in U.S. homeland security and emergency management. We propose an integer linear programming (ILP) decision-support model that integrates probabilistic risk assessment (PRA) with multi-criteria consequence quantification. Methodologically, the model innovatively fuses heterogeneous historical data and publicly available information to enable joint modeling across 16 hazard types and six consequence dimensions, while selecting optimal mitigation projects under budget constraints. It further introduces a sensitivity-driven framework that jointly optimizes robustness and cost-effectiveness. Applied empirically in Iowa, the model generates a high-value portfolio of 52 mitigation projects, achieving an average 37% reduction in expected risk. Multi-scenario sensitivity analysis confirms solution robustness. The approach provides a scalable, methodologically rigorous foundation for evidence-based resilience investment.

Develop decision model for cost-effective risk mitigationEvaluate project selection under budget and hazard constraintsOptimize resource allocation for homeland security risks

A Systematic Approach to Estimate the Security Posture of a Cyber Infrastructure: A Technical Report

Aug 29, 2025
QS
Qishen Sam Liang
🏛️ USC Information Sciences Institute

Scientific research cyberinfrastructure (CI) faces unique challenges—including high collaboration requirements, component heterogeneity, and the absence of adaptable security assessment frameworks. To address these, we propose a mission-centric security posture assessment method: first, top-down identification of critical assets and unacceptable losses; second, construction of a security knowledge graph integrating system components, dependencies, and threat behaviors; and third, integration with directed attack graphs to quantify multi-hop attack paths from entry points to critical assets—enabling visualization of attacker-defender relationships and identification of security blind spots. Unlike conventional generic standards, our approach is the first to deeply couple mission-driven assessment, knowledge graphs, and attack graphs. It supports risk prioritization and generation of actionable defensive strategies, significantly enhancing the precision and effectiveness of CI security defense.

Addressing lack of practical security assessment frameworksEstimating security posture of collaborative cyber infrastructuresSystematically mapping adversary attack paths to critical assets

Offensive tool determination strategy R.I.D.D.L.E. + (C)

Nov 16, 2025
HE
Herman Errico
🏛️ Italian Association of Critical Infrastructures’ Experts

Conventional critical infrastructure risk assessments inadequately characterize deliberate threats, particularly regarding attacker tooling. Method: This paper proposes an embedded attack-tool identification strategy, introducing the first R.I.D.D.L.E.+C seven-dimensional analytical framework—encompassing Resistance, Intrusion Timing, Destruction Timing, Delay, Efficiency, Cost, and Concealment—to systematically integrate attack-tool characteristics and augment them with open-source intelligence (OSINT) for fine-grained, quantitative modeling. Contribution/Results: The approach shifts risk assessment from asset- or attacker-centric paradigms to treating attack tools as independent analytical units; significantly enhances detection of latent vulnerabilities; and delivers an actionable, forward-looking security decision-support framework. Experimental evaluation demonstrates substantial improvements in both precision and comprehensiveness of risk assessment, confirming its practical engineering applicability.

Analyzing intentional threats to critical infrastructure vulnerabilities through risk assessmentEvaluating threat variables using open-source intelligence for improved decision-makingIntroducing offensive tool characteristics as analytical parameters in security evaluation

Prompting the Priorities: A First Look at Evaluating LLMs for Vulnerability Triage and Prioritization

Oct 21, 2025
OA
Osama Al Haddad
🏛️ Macquarie University | Data61, CSIRO

Security analysts face mounting challenges in efficiently processing massive, heterogeneous vulnerability data, while the potential of large language models (LLMs) for automated vulnerability semantic parsing and prioritization remains empirically underexplored. This work presents the first systematic evaluation of four LLMs—ChatGPT, Claude, Gemini, and DeepSeek—on their ability to predict four SSVC (Stakeholder-Specific Vulnerability Categorization) decision points: Exploitation, Automatable, Technical Impact, and Mission and Wellbeing. Leveraging the VulZoo dataset and 12 prompt engineering strategies—including zero-shot, few-shot, and chain-of-thought—we conduct over 165,000 inference queries. Results show Gemini with exemplar-based prompting achieves top performance on three decision points; DeepSeek attains fair-level agreement under weighted consistency metrics; overall model effectiveness is moderate but exhibits a systematic bias toward overestimating risk severity. The study establishes a reproducible methodology and empirical benchmark for LLM-augmented vulnerability response.

Assessing LLM performance in interpreting semi-structured vulnerability informationEvaluating LLMs for automating vulnerability triage and prioritization processesTesting models' ability to predict SSVC framework decision points accurately

VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs

Feb 16, 2025
YJ
Yuning Jiang
🏛️ National University of Singapore | NCS Cyber Special Ops R&D

Prioritizing security patches in complex interconnected systems suffers from insufficient fine-grained modeling and poor interpretability. Method: This paper proposes a graph-driven, multi-granularity risk assessment framework that jointly models network communication graphs and system dependency graphs, establishing a three-tiered component–asset–system collaborative modeling mechanism. It introduces novel techniques for attack path identification, quantitative risk propagation analysis, and root-cause attribution under multi-source heterogeneous data fusion, leveraging graph neural networks and attack graph modeling for dynamic risk assessment. Contribution/Results: The framework significantly improves both accuracy and interpretability of patch prioritization. In benchmark evaluations, it achieves an average 12.7% improvement in patch ranking accuracy over state-of-the-art methods, while enabling clear risk provenance tracing and generating human-readable, auditable ranking justifications.

Enhance explainability in vulnerability rankingModel attack paths and risk propagationPrioritize vulnerability patches effectively

Latest Papers

What's happening recently
View more

This study addresses the vulnerability of AI-driven resource allocation to aleatoric uncertainty inherent in individual risk assessments, which can lead to misallocation. The authors propose a two-stage framework: first conducting ground-truth screening for a subset of individuals, then performing targeted allocation under a fixed budget. Theoretical analysis reveals that the optimal strategy screens individuals near the algorithmic assignment boundary while directly covering the highest-risk group. Depending on the level of uncertainty, screening and algorithmic targeting act either as complements or substitutes. Leveraging probabilistic modeling and optimization theory, the framework is empirically validated using real-world data from social protection and humanitarian demining programs in Colombia, demonstrating significantly improved allocation efficiency under high uncertainty.

aleatoric uncertaintyalgorithmic targetingmisallocation

This study addresses the prohibitive computational cost of high-fidelity simulations in evaluating cascading failures of power-communication coupled systems under large-scale N-k contingencies, which hinders resilience planning. To overcome this challenge, the authors propose a structure-based machine learning surrogate model that, for the first time, integrates leak-free topological centrality measures with cross-layer dependency information to rapidly predict failure severity and generate component criticality rankings. This surrogate model forms the first stage of a two-stage workflow paired with high-fidelity MIIM simulations for prioritized hardening analysis. Evaluated on the IEEE 118-bus system, the model achieves Spearman correlation coefficients of 0.849 and 0.853 for failure severity prediction and criticality ranking, respectively—significantly outperforming purely topological baselines and closely approaching the empirical upper bound of high-fidelity simulation, thereby substantially improving assessment efficiency without compromising accuracy.

cascading failurescomponent criticalityinterdependent networks

This study addresses the challenge faced by resource-constrained organizations in translating cybersecurity governance frameworks—such as the NIST Cybersecurity Framework (CSF)—into actionable defense decisions. The authors propose an integrated optimization approach that synergistically combines governance requirements, adversary knowledge from MITRE ATT&CK, and adversarially aware learning. By establishing a mapping between NIST CSF maturity levels and ATT&CK mitigations, modeling attack paths via a variable-order Markov model, and formulating a deep reinforcement learning framework, the method generates cost-effective and risk-balanced defense strategies under budget constraints. This work represents the first effort to cohesively unify governance frameworks, ATT&CK-based threat intelligence, and interpretable reinforcement learning, yielding operationally viable mitigation plans that align with an organization’s security maturity and exhibit robustness against adaptive adversaries.

Adversarial BehaviorCybersecurity GovernanceMitigation Planning

This study addresses the lack of a systematic framework for identifying critical input variables and conducting sensitivity analysis under uncertainty in complex simulations, particularly in military decision-making contexts. The authors propose a unified sensitivity analysis framework that integrates local and global methods—including variance-based, derivative-based, screening, and uncertainty quantification techniques—and strategically maps these approaches to specific decision objectives such as factor prioritization, fixing, variance reduction, and mapping. Innovatively, the framework introduces a “sensitivity audit” mechanism to enhance traceability of model assumptions and promote responsible model usage. By providing a structured guide for high-dimensional, complex simulation systems, this work significantly improves model interpretability, transparency, and the credibility of decisions derived from such models.

military applicationssensitivity analysissensitivity auditing

A Comparison for Non-Specialists of Workflow Steps and Similarity of Factor Rankings for Several Global Sensitivity Analysis Methods

Oct 24, 2025
KN
Ken Newman
🏛️ Biomathematics and Statistics Scotland | The James Hutton Institute | Norwegian Institute for Water Research | Scotland’s Rural College

This study addresses non-expert users by systematically evaluating the workflow feasibility and factor ranking consistency of multiple global sensitivity analysis (GSA) methods across simulation models of varying complexity. Method: It integrates Sobol’ first-order and total-effect indices with regression tree analysis, and—novelty—employs Kendall’s W to quantify inter-method ranking similarity; special attention is given to how parameter range specification affects result robustness. Contribution/Results: (1) Major GSA methods exhibit high consistency in factor importance ranking; (2) Sobol’ indices offer both interpretability and information richness, while regression trees effectively detect interaction effects; (3) Parameter range specification is identified as a critical practical determinant of GSA reliability. Collectively, these findings significantly enhance operationality and methodological rationality for non-experts in tasks such as factor screening, freezing, and prioritization.

Addresses method selection challenges for non-specialists in sensitivity analysisCompares workflow steps and factor ranking similarity across GSA methodsEvaluates implementation issues and interpretation of sensitivity indices

Hot Scholars

DP

David Piorkowski

IBM Research
Human-Computer InteractionAI GovernanceAI SafetyHuman-AI Collaboration
LW

Laurie Williams

North Carolina State University, Computer Science, Distinguished Univ Prof, IEEE Fellow, ACM Fellow
Software EngineeringSoftware SecurityAgile Software DevelopmentEmpirical Software Engineering
ND

Nicholas Diakopoulos

Professor, Northwestern University
Computational JournalismAlgorithmic AccountabilityHuman Computer InteractionAI Ethics