Paper Type

ERF

Abstract

Organizations must prioritize remediation across thousands of disclosed vulnerabilities, yet only a small fraction are exploited in practice. This study examines vulnerability prioritization as a socio-technical reliability problem rather than a predictive analytics task. Using exploitation intelligence from the Known Exploited Vulnerabilities (KEV) catalog and the Exploit Prediction Scoring System (EPSS), we evaluate how automated triage and human expertise should share decision responsibility. An interpretable ranking model demonstrates that exploitation likelihood signals effectively concentrate real risk within a small subset of vulnerabilities. Calibration analysis further identifies a reliability boundary in mid-probability cases where automated recommendations become unstable. We propose an uncertainty-aware routing process that directs these cases to analysts while allowing automation to handle clear conditions. Grounded in High Reliability Organization theory, the results suggest reliable cyber defense arises from coordinated human-AI collaboration rather than fully autonomous decision-making.

Paper Number

1338

Comments

NEXTTRANS

Share

COinS
 
Aug 15th, 12:00 AM

Human-AI Collaboration for Cyber Risk Triage: A High Reliability Organization Perspective Using Exploitation Intelligence

Organizations must prioritize remediation across thousands of disclosed vulnerabilities, yet only a small fraction are exploited in practice. This study examines vulnerability prioritization as a socio-technical reliability problem rather than a predictive analytics task. Using exploitation intelligence from the Known Exploited Vulnerabilities (KEV) catalog and the Exploit Prediction Scoring System (EPSS), we evaluate how automated triage and human expertise should share decision responsibility. An interpretable ranking model demonstrates that exploitation likelihood signals effectively concentrate real risk within a small subset of vulnerabilities. Calibration analysis further identifies a reliability boundary in mid-probability cases where automated recommendations become unstable. We propose an uncertainty-aware routing process that directs these cases to analysts while allowing automation to handle clear conditions. Grounded in High Reliability Organization theory, the results suggest reliable cyber defense arises from coordinated human-AI collaboration rather than fully autonomous decision-making.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.