AI-Powered Continuous Cyber Risk Quantification and Investment Optimization Platform
All India Council for Technical Education (AICTE) · Blockchain & Cybersecurity · Software
You would invent the security telemetry and the loss figures and then present cyber risk as a precise rupee amount, which is the exact criticism this field already faces — the one part worth building is the budget optimisation, and that does not need the rest of the platform around it.
What it actually is
Boards are told their cyber risk is high or medium, which tells them nothing about whether the money they are spending on security is enough or spent in the right places. The ask is a platform that expresses cyber risk as an actual rupee figure, updates it continuously from the organisation's security tooling, and recommends where to spend a fixed budget for the most risk reduction.
What to build
A risk quantification and optimisation platform in three layers: an ingestion and normalisation layer taking findings from the enterprise security tools the statement names and weighting them by asset criticality and control effectiveness; a quantification engine estimating incident likelihood and financial impact and expressing exposure as annualised loss at organisation, unit and asset level, ideally following an established open risk quantification methodology so the calculation rests on documented practice rather than an arbitrary formula; and an optimisation module which is the genuinely interesting part, since selecting the set of remediations that maximises risk reduction under a fixed budget is a real constrained optimisation problem with an honest answer, plus scenario simulation, framework mapping and executive dashboards.
Smallest thing that wins the room
Set a fixed budget, run the optimiser, and show the selected remediation set against the naive highest-severity-first approach, with the risk reduction curve making the diminishing returns visible.
How crowded this one gets
A guess, projected from the 2025 statements — the last year where both the submission counts and the winners were published.
Quieter than 76% of the 226 · #54 of 226 by expected field
Few teams are likely to go here. The best odds on the board come from statements like this.
Why: central ministry statements sat below the average.
This is a guess, not a fact
Nobody has published 2026’s numbers yet. This is an analysed estimate from last year’s pattern, so please do not take it as the truth — check the live counter on the SIH portal before you decide anything. The range covers the middle half of likely outcomes, so one statement in two lands outside it. Entry closes at 500 ideas per statement, so no range goes past that — a statement that reaches the cap fills and shuts rather than drawing an unlimited crowd. The model reads only three things a team can see before choosing — software or hardware, the theme, and what kind of body posted it — and those explain about a quarter of the variation in last year’s field sizes (R² 0.25 on held-out statements). Trust the band more than the number, and the ordering more than either. It cannot see how good your idea is, which is the part that actually decides it.
The scores
The number is the shorthand. The line under it is the reason.
Acceptance potential
2/5The platform needs enterprise security telemetry you cannot obtain and actuarial loss data that is not published, so you would be inventing both inputs and then presenting cyber risk as a precise rupee figure — and precision derived from invented inputs is the specific failure mode a security professional on the panel will identify immediately.
Feasibility
2/5Both ends of this are unavailable — the input side requires live telemetry from enterprise vulnerability scanners, event management, identity, endpoint and cloud posture tooling that no student team has access to, and the output side requires loss magnitude data such as breach and downtime costs that is not published for Indian organisations, so you would invent the inputs and then report a monetary figure derived from them.
Innovation scope
3/5The components are enumerated thoroughly but the statement does not name a risk quantification methodology, so how you model likelihood and impact and how you formulate the budget optimisation are genuinely open decisions.
Clarity
5/5Exhaustively detailed across the quantification engine, the decision support layer, the optimisation module, both dashboard audiences and the compliance framework mapping, with the regulatory frameworks to map against all named individually.
Effort
MassiveMulti-source security telemetry ingestion, a quantification engine, predictive analytics, a natural language query layer, scenario simulation, an optimisation module, two dashboard audiences and mapping against five compliance frameworks is an enterprise product several teams wide.
Demo-ability
MediumThe investment versus risk reduction curve is a genuinely good visual and the what-if simulation is engaging, but every number feeding it is one you generated, so the demo shows a well-built calculator operating on fiction.
In its favour
- Green flag: The budget-constrained remediation selection is a genuine constrained optimisation problem with a correct answer, and demonstrating that it beats the naive highest-severity-first approach is a real result that holds even on synthetic inputs, because the optimisation logic is what you are proving rather than the numbers
- Green flag: An established open risk quantification methodology exists and is documented, so you can build on published practice rather than inventing a likelihood-times-impact formula and defending it
- Green flag: Expressing risk as a distribution with uncertainty bounds rather than a single figure is both more honest and better practice, and a team that resists giving a precise number is showing the better judgement
- Green flag: The compliance frameworks are named individually and are all publicly documented, so the mapping layer can be built accurately
Against it
- Red flag: The input telemetry from vulnerability, event management, identity, endpoint and cloud tooling is enterprise infrastructure you have no access to, so the continuous part of continuous risk quantification cannot be demonstrated
- Red flag: Loss magnitude data for Indian organisations is not published, so breach costs, downtime costs and penalty estimates are figures you selected — and the whole product's output is a rupee number built on them
- Red flag: Presenting invented inputs as a precise financial exposure is exactly the criticism this entire discipline attracts, so surface the input uncertainty prominently rather than letting the dashboard imply confidence
- Red flag: Eight enumerated components including a natural language query layer and five framework mappings means the optimisation module, which is the only part with real substance, will get built last if at all
What you will be writing
- FAIR-style risk quantification with loss distributions
- Monte Carlo simulation of annualised loss exposure
- knapsack optimisation of remediation under budget
- asset criticality and control effectiveness weighting
- compliance framework control mapping
- scenario simulation and ROSI computation
- Cyber risk quantification
- Security investment decision-making
- Governance risk and compliance
Prior art to read before you start
monetary cyber risk exposure modelling · budget-constrained remediation optimisation · framework-mapped compliance reporting
Analysed by Claude Opus. Every score above is a judgment call with its reasoning attached — kindly cross-check this against the official statement on the SIH portal before your team commits to it.