Module 2 Book Prose#

Threat likelihood and impact modeling#

How can AI support risk estimation?

🧑‍🌾 SAMWISE — Student note

Pause before you run the notebook. In your own words:

  1. Whose decision does the essential question above affect?

  2. What baseline and result do you predict before seeing the output?

  3. Which observation would change or strengthen your current view?

  4. What will remain uncertain, and what would you check next?

SAMWISE is a reflection guide, not an answer key or grader. Record your own reasoning; the Populi instructions and published rubric remain authoritative.

Professional Scenario#

You are advising a cyber risk committee prioritizing mitigation across assets with different exposure and business value. The immediate task is to decide what evidence would make a recommendation credible, what risks remain unresolved, and what should happen next. The module’s work product is: cyber risk assessment package with scoring rationale, treatment plan, and executive dashboard focused on threat likelihood and impact modeling: Create a likelihood-impact model..

The available lab data is deliberately limited: synthetic asset risk records with exposure, vulnerability severity, control strength, threat activity, and business impact. Treat it as a proxy for reasoning and method practice, not as proof that a real deployment is ready. A graduate-level submission must distinguish between what the proxy exercise demonstrates and what would still require institutional data, stakeholder review, and operational testing.

Core Concepts#

  • Problem framing: define the decision, population, workflow, or system boundary before choosing a method.

  • Baseline discipline: compare the proposed AI-enabled approach with an existing process, simple rule, or manual review pattern.

  • Evidence quality: separate measured results from assumptions, anecdotes, vendor claims, and synthetic-data artifacts.

  • Failure modes: identify where the system can fail technically, operationally, legally, ethically, or socially.

  • Deployment readiness: connect metrics to decision thresholds, monitoring, escalation, and rollback.

Why This Module Matters#

In AINS6302: AI for Risk Assessment, this module contributes to the larger course arc by requiring students to turn a domain problem into an inspectable technical artifact. The standard is not “the notebook ran.” The standard is that another reviewer can understand the decision, reproduce the reasoning, and challenge the assumptions.

Method Pattern#

  1. State the stakeholder decision in one sentence.

  2. Identify the evidence source and why it is adequate or inadequate.

  3. Produce a baseline result using the lab or an equivalent transparent method.

  4. Compare one alternative design, threshold, policy, or model.

  5. Document false positives, false negatives, unintended incentives, and operational constraints.

  6. Recommend a next action: continue research, run a controlled pilot, redesign the system, or stop.

Failure Modes To Check#

  • Measurement mismatch: the metric optimizes something adjacent to, but not identical with, the real decision.

  • Context loss: important operational or human factors are absent from the data.

  • Automation bias: users may over-trust a score, classification, or recommendation.

  • Equity and access risk: affected groups may experience different error rates or burdens.

  • Governance gap: no one owns monitoring, escalation, or rollback after launch.

Study Questions#

  1. What decision does the module artifact support?

  2. What does the proxy lab evidence prove, and what does it not prove?

  3. Which baseline or manual process should the AI-enabled approach be compared against?

  4. Which stakeholder would object to the recommendation, and on what grounds?

  5. What monitoring signal would tell you the system is failing after deployment?

Worked Example: From Evidence to a Decision#

Return to the professional situation for this module: You are advising a cyber risk committee prioritizing mitigation across assets with different exposure and business value. The immediate task is to decide what evidence would make a recommendation credible, what risks remain unresolved, and what should happen next. The module’s work product is: cyber risk assessment package with scoring rationale, treatment plan, and executive dashboard focused on threat likelihood and impact modeling: Create a likelihood-impact model.. The team should not begin by selecting the most sophisticated tool. First, rewrite the situation as a decision: what must be decided, by whom, using which evidence, and under which constraints? That sentence establishes the boundary of the analysis.

Next, create an inspectable baseline. For this module, a useful baseline should make Problem framing: define the decision, population, workflow, or system boundary before choosing a method. visible rather than hiding it inside an unsupported conclusion. Preserve the starting data or case facts, record the initial result, and identify the assumption most likely to change the recommendation. Then make one controlled comparison using Baseline discipline: compare the proposed AI-enabled approach with an existing process, simple rule, or manual review pattern.. Holding the other conditions fixed is what lets a reviewer interpret the difference.

Finally, connect the evidence to action. Use Evidence quality: separate measured results from assumptions, anecdotes, vendor claims, and synthetic-data artifacts. to explain why the observed result matters in the scenario, then state a limitation. The appropriate conclusion is conditional: recommend a next step only if the evidence clears a named threshold or review gate. This pattern—decision, baseline, controlled comparison, limitation, next gate—is the same structure expected in the assignment and rubric.

Comprehension Check#

Before continuing, be able to answer: What is the baseline? What single factor changes? Which evidence would reverse the recommendation? What does the exercise leave unknown?

Authoritative Reading Bridge#

Use one specific section, control, example, or definition from these sources to qualify the worked example above. The complete curated list and source-use expectations are in Authoritative Readings and Resources.

Subject-Matter Lesson#

Likelihood can mean annual frequency, probability within a horizon, or conditional probability; impact may include response, downtime, lost revenue, restoration, legal, customer, safety, and strategic effects. Define terms and avoid multiplying arbitrary 1–5 labels as though the result were money. Evidence may come from internal events, near misses, threat intelligence, industry data, control tests, experts, and scenario workshops.

Use ranges or distributions when evidence is uncertain. Monte Carlo simulation propagates assumptions but does not make them objective. Dependence, heavy tails, changing exposure, reporting bias, and sparse rare events matter. AI can assist document extraction, analog search, calibration diagnostics, and scenario comparison, while accountable experts own assumptions and decisions.

The lab samples frequency and triangular loss for three synthetic scenarios and reports mean, 90th, and 95th percentile annual loss plus scenario contributions. Change the upper loss bound and perform sensitivity rather than presenting false precision. A credible estimate records sources and dates, rationale, confidence, dependence, excluded losses, validation against experience, model version, expert challenge, and how the output changes treatment, transfer, acceptance, avoidance, or further evidence.