DOI: 10.3390/jcp6040138 ISSN: 2624-800X

Separating Probabilistic Inference from Deterministic Governance in Cyber Risk Automation

Tope Olufon, Stilianos Vidalis, Deepthi Ratnayake, Alexios Mylonas, Muyiwa Olufon

Risk registers remain static governance artefacts, manually maintained and weakly coupled to operational evidence. While organisations generate continuous security telemetry from vulnerability scanners, incident reports, and audit findings, this evidence is rarely synthesised into coherent, evolving risk structures. Existing approaches address fragments of the problem: SIEM systems correlate events but do not construct risk registers; GRC platforms manage risk documentation but depend on manual entry; and LLM applications assist with summarisation but introduce non-determinism incompatible with governance requirements. This paper presents a hybrid architecture that separates stochastic LLM-based extraction from deterministic risk correlation and aggregation. The system ingests heterogeneous evidence, extracts structured claims via schema-bounded LLM processing, and correlates events into stable risk trees using anchor-based tiered matching. All correlation and projection operations are deterministic and replayable. The contribution is an architectural design pattern for integrating probabilistic inference into governance systems without compromising auditability. The walkthroughs run on a reference prototype. Replaying the stored evidence three times rebuilt the same register state, and admission scores matched the values the rules predict. An injected malformed extraction was quarantined; the register did not change.

More from our Archive