All problem statements
SIH26105SoftwareBlockchain & Cybersecurity

AI-Powered Continuous Cyber Risk Quantification and Investment Optimization Platform

All India Council for Technical Education (Cyber Security Cell)

Ideas submitted
73 / 500
Deadline
30 September 2026
Category
Software
Theme
Blockchain & Cybersecurity

Looks like it needs

AI / MLWeb (React / Node)BlockchainCybersecurity

• Background Enterprises and institutions invest heavily in cybersecurity tools, compliance programs, and risk management initiatives, yet cyber risk is still predominantly communicated using qualitative ratings such as 'Low','Medium', or 'High'.

These coarse categories fail to express the potential financial impact of cyber threats,making it difficult for senior management, boards, and regulators to evaluate whether current cyber investments are adequate or optimally allocated.

Cyber risk is inherently dynamic: new vulnerabilities emerge, threat actors change tactics, business services are added or retired, and security controls mature over time. Most current risk assessment practices rely on periodic, manual exercises, resulting in stale risk registers and limited visibility into the organization’s real-time cyber exposure. This gap leads to suboptimal prioritization of remediation efforts, under- or over-spending on security controls, and weak alignment between technical risk metrics and business decision-making.

• Problem Statement Design and develop an AI-powered platform that continuously quantifies cyber risk in monetary terms by correlating technical security telemetry with business asset criticality and control effectiveness. The platform must estimate the likelihood and financial impact of cyber incidents, identify key risk drivers, and recommend cost-effective mitigation strategies under explicit budget constraints.The solution should bridge the gap between technical cybersecurity metrics and business language, enabling CISOs, risk officers, and executive leadership to make informed, data-driven decisions about cyber risk and security investment. • Proposed Solution Develop a cloud-ready cyber risk analytics platform that ingests data from multiple enterprise security and IT sources—such as vulnerability management, SIEM, IAM, EDR, CSPM, asset inventories, and threat intelligence feeds—and uses AI/ML models to compute continuous risk scores and estimated financial exposure, such as Expected Annual Loss. The system should provide interactive dashboards and decision-support tools that allow stakeholders to simulate remediation scenarios, evaluate investment options, and understand the return on security investment.The platform must be capable of mapping risk metrics to established cybersecurity frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, RBI Cyber Security Framework, and SEBI Cybersecurity and Cyber Resilience Framework, supporting both regulatory reporting and internal governance. • Key Components • Risk Quantification Engine o Continuous aggregation and normalization of data from vulnerability scanners, SIEM, IAM, EDR,CSPM, asset inventory, and other security tools.

o Statistical and ML-based estimation of incident likelihood and potential business impact, including downtime costs, data breach costs, regulatory penalties, and reputational effects.

o Calculation of enterprise cyber risk as financial exposure metrics (for example, Expected Annual Loss and Value at Risk) at organization, business unit, and asset levels.

o Asset criticality modeling to weigh technical findings based on business importance and service dependencies.

o Control effectiveness evaluation using telemetry about configuration strength,incident history, and compliance status.

• AI Decision Support Layer o Predictive analytics for emerging threats and evolving risk based on trends in vulnerabilities, threat intelligence, and control performance.

o AI-generated mitigation recommendations that propose prioritized actions—such as patch deployment, access control tightening, network segmentation, and additional monitoring—with quantified risk reduction.

o Natural language query interface for non-technical stakeholders, enabling questions like 'What is our highest financial cyber risk today?' or 'Which vulnerabilities contribute most to our expected losses?'.

o Scenario simulation tools for exploring 'what-if' analyses, such as 'What happens if MFA is implemented across all privileged accounts?' or 'How will delaying remediation by 30 days affect our financial exposure?'.

• Investment Optimization Module o Optimization models that recommend sets of controls and remediation actions delivering maximum risk reduction for a specified budget (for example, ?1 crore).

o Computation of ROSI and cost-benefit metrics for different security initiatives to support strategic planning and board-level approvals.

o Visualization of 'Investment vs. Risk Reduction' curves to highlight diminishing returns and optimal spend zones.

• Executive and Technical Dashboards o Unified views for CISOs and executives, including Enterprise Risk Score, total Financial Exposure, Risk Trend Analysis, Top Risk Contributors, and Risk Reduction Opportunities.

o Drill-down capability for technical teams to see control-level and asset-level findings, remediation backlogs, and mapping to frameworks and policies.

• Compliance and Framework Mapping o Built-in mapping against frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, RBI Cyber Security Framework, and SEBI Cybersecurity and Cyber Resilience Framework.

o Support for generating evidence-based reports and dashboards for audits, regulatory filings, and internal governance committees.

• Expected Outcomes • Continuous, near real-time visibility into enterprise cyber risk, expressed in monetary terms understandable to business stakeholders. • Improved prioritization of cybersecurity initiatives based on quantified impact rather than subjective risk ratings. • Enhanced communication of cyber risk to executive management, boards, and regulators through intuitive, data-driven dashboards and narratives. • More rational and optimized cybersecurity investment decisions, maximizing risk reduction per unit of spend. • Reduction in both the likelihood and financial impact of cyber incidents through targeted remediation and investment strategies.

How contested this one is

as of 28 Sept
73ideas submitted+17 in 2 days

That puts it 142nd of the 240 statements that have any ideas at all, out of 240 on the board. It is moving, so the field here is already forming.

See what the whole field is picking →

Counted from the official portal twice a day. The portal itself only shows today.

What a jury will ask about this

  1. 01“Who actually faces this problem today?”

    What works: Naming one real person and what they do instead right now. Reading the statement back is not an answer, they already read it.

  2. 02“This already exists. Why yours?”

    What works: That existing tools are consumer products. Yours is built for the ministry, works offline, in the local language, on official data.

  3. 03“Then why has nobody solved it yet?”

    What works: The real blocker. No connectivity, no incentive, nobody owns the data. You only know this if you read the ministry's own reports.

All 18 questions, with the trap answers →

More in Blockchain & Cybersecurity

See all →