Operationalising Cyber Risk Management Using AI: Connecting Cyber Incidents to MITRE ATT&CK Techniques, Security Controls, and Metrics
arXiv cs.AI / 3/16/2026
📰 NewsIdeas & Deep AnalysisTools & Practical UsageModels & Research
Key Points
- The paper introduces a Cyber Catalog and an AI-driven framework that maps cyber incidents to MITRE ATT&CK techniques by integrating CIS Controls and SMART metrics, enabling a direct link from threat intelligence to actionable controls and measurable outcomes.
- They fine-tuned all-mpnet-base-v2 on an augmented dataset of 74,986 incident-technique pairs, achieving a Spearman correlation of 0.7894 and a Pearson correlation of 0.8756 with lower MAE and MSE than baseline models.
- The Cyber Catalog, along with the training data, trained model, and implementation code, is publicly available to support research and practical deployment in resource-constrained environments.
- The work bridges threat intelligence and operational security management, promoting evidence-based cyber risk management and actionable incident response.
Related Articles

I built an autonomous AI Courtroom using Llama 3.1 8B and CrewAI running 100% locally on my 5070 Ti. The agents debate each other through contextual collaboration.
Reddit r/LocalLLaMA
The Honest Guide to AI Writing Tools in 2026 (What Actually Works)
Dev.to
The Honest Guide to AI Writing Tools in 2026 (What Actually Works)
Dev.to
AI Cybersecurity
Dev.to
Next-Generation LLM Inference Technology: From Flash-MoE to Gemini Flash-Lite, and Local GPU Utilization
Dev.to