Automating internal cybersecurity risk audit procedures using machine learning and big data
DOI:
https://doi.org/10.5281/zenodo.19657428Keywords:
cyber threats, algorithms, classification, anomalies, prediction, modeling, incidents, optimization, context, adaptability.Abstract
Ukrainian enterprises are actively integrating digital technologies into business processes, which is accompanied by an increase in cyber threats and heightens the need for efficient internal audit to detect anomalies in a timely manner and minimize potential losses. The purpose of the article is to develop a model for automating internal audit procedures for cybersecurity risks using machine learning methods and big data technologies, and to define criteria for assessing their effectiveness. Methods. The work uses general scientific methods of analysis, synthesis, induction, and deduction to develop theoretical approaches to the automation of internal audit of cybersecurity risks, to model the structure of an automated system, and to experimentally verify the effectiveness of the proposed model on practical data. Results. The features of automating internal audit procedures for cybersecurity risks using machine learning and big data analysis technologies are characterized, enabling greater accuracy and faster cyber incident detection and threat assessment. It has been established that modern approaches to internal audit in Ukrainian and international practices are formed on the basis of ISO standards (ISO/IEC 27001 series), NIST Cybersecurity Framework (CSF), COBIT 2019/ISACA, ITAF/ISACA, COSO (ERM 2017), which provides a structured basis for controlling cyber risks and supporting management decisions. It has been found that the Random Forest and SVM classification algorithms are effective for automated detection of security incidents, and the K-means and DBSCAN clustering methods allow identifying anomalies in user behavior and network flows. It has been shown that the use of deep learning methods for analyzing multidimensional cyber threats and natural language processing technologies for processing text policies and audit reports provides comprehensive identification and assessment of cybersecurity risks. It was found that implementing a digital audit twin, adaptive real-time risk scoring, self-learning audit controls, and an AI assistant for the internal auditor ensures the integration of data analysis algorithms into the enterprise's information security management system and increases the effectiveness of continuous risk monitoring. Conclusions. It was found that integrating machine learning methods and big data technologies into internal audit procedures for cybersecurity risks increases the accuracy of threat identification and forecasting, and transforms the audit from a retrospective control to a continuous monitoring and adaptive risk management model.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Інна Володимирівна Куницька, Наталія Михайлівна Жидовська, Ірина Георгіївна Фадєєва

This work is licensed under a Creative Commons Attribution 4.0 International License.