Skip to content
Review Open access

A Risk-Based Cybersecurity Auditing Framework for Smart Grid Infrastructure Using Explainable Artificial Intelligence (XAI)

2026 · Journal of Cyber Security and Risk Auditing · Vol 2026, pp. 238-264 · 0 citations

Abstract

This study suggests a framework for cybersecurity auditing of smart grid infrastructure, which is based on the concept of risk and the use of Explainable Artificial Intelligence (XAI) to produce transparent, prioritized and audit-ready security evidence. The information from public smart grid cybersecurity events was mapped to event labels, asset classes, security-control status, compliance indicators, and cyber-physical impact variables, which were then used to create audit-relevant records. Attack likelihood estimates were made using machine learning models. The attack likelihood, asset criticality, control deficiency score, compliance condition and operational impact were all added together to calculate the final audit risk score. Explainability was used as a technique to identify the most important features that affected each audit decision by applying the SHAP method. The proposed framework achieved 96.38% accuracy, 96.51% precision, 96.38% recall, 96.42% F1-score, and 0.996 ROC-AUC. The results of the ablation showed that the inclusion of the risk component and the XAI component resulted in an improvement in the risk ranking, audit traceability and explanation consistency. The framework translates the cybersecurity detection results into an understandable audit decision, enabling risk-based remediation, compliance review, and an understandable smart grid cybersecurity governance.

Read PDF

Similar papers

Open access Jul 2026

Machine learning-based validation of an integrated cybersecurity risk framework for supply chain auditing

The rapid digitalization and interconnectivity of global supply chains have significantly increased exposure to cybersecurity risks, particularly through third-party dependencies, IoT integration, remote access, and shared digital infrastructures. Traditional supply chain auditing approaches, which rely heavily on periodic compliance checks and retrospective assessments, are increasingly insufficient for identifying dynamic and systemic cyber risks. This study proposes an integrated machine learning-based cybersecurity risk framework for supply chain auditing and examines how ML models capture multidimensional and time-related cybersecurity risk indicators. A quantitative experimental design was adopted using a hybrid dataset that combines empirically grounded cybersecurity indicators with simulated supply chain cyber risk scenarios. The synthetic data were generated through controlled attack scenarios using AttackIQ and Cymulate simulation platforms and were conceptually aligned with the NIST Cybersecurity Framework, ENISA guidelines, and the Verizon DBIR. IBM Watsonx was used to develop and evaluate supervised and time-series models, including Random Forest and ARIMA. The integrated risk flag was constructed as a composite cybersecurity risk representation derived from standardized audit-relevant indicators. The findings show that the integrated ML-based risk framework achieved strong classification performance, with accuracy = 98.5% and F1 > 0.98. The results primarily reflect the internal consistency of the constructed cybersecurity risk framework rather than direct prediction of real-world cyber incidents. Sensitivity analyses confirmed the robustness of the framework under different synthetic data conditions. Random Forest effectively captured complex nonlinear risk patterns, while ARIMA modeled temporally persistent risk indicators. In contrast, compliance metrics showed limited ability to reflect actual cybersecurity risk exposure.

Hossam Hassan, Rehab Hashem, Ahmad A. Abu-Musa · 0 citations
Review Open access Aug 2026

Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems

A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.

Mohammed AbuTaha · 0 citations
Review Open access Sep 2026

Towards distinguishing cybersecurity attacks and safety faults in distributed energy resources-rich smart grids: a systematic literature review

This study presents a Systematic Literature Review (SLR) of methods and challenges related to distinguishing cybersecurity attacks and safety faults in Distributed Energy Resources (DER)-rich smart grids. The increasing integration of DERs has improved grid flexibility and sustainability, but has also introduced greater operational complexity and expanded the attack surface of smart grid infrastructures. In such environments, cyber-attacks and safety faults may produce similar anomalies, making accurate distinction a critical requirement for resilient and secure grid operation. This review examines the literature on anomaly detection and event classification in DER-rich smart grids towards distinguishing these anomalies and events, with a particular focus on approaches that could support the differentiation of malicious and non-malicious events. It analyzes the main categories of data used in the literature, including sensor data, smart meter data, network traffic, phasor measurements, and weather-related information. It also reviews machine learning and artificial intelligence techniques, including supervised, unsupervised, and deep learning approaches, and discusses their applicability, strengths, and limitations within different contexts. Furthermore, the review synthesizes evaluation practices, operational application domains, and key open challenges, including limited dataset realism, data quality issues, explainability, scalability, and model generalization. Existing testbeds are highlighted as essential for reproducing realistic grid conditions and validating approaches; however, in their current state, no testbed framework is directly applicable to distinguishing cybersecurity attacks from operational safety faults in an informed manner. Importantly, only 6 of the 25 included primary studies explicitly attempt to distinguish cyber-attacks from physical safety faults within a single evaluation setting. The review is therefore explicitly positioned as a combined systematic mapping and gap analysis: rather than demonstrating a mature solution space, it documents how sparsely the central distinction problem is addressed, characterizes the few existing attempts in depth, and derives a research agenda from this gap. Overall, the review identifies major research gaps and outlines directions for developing more safe and secure solutions for DER-rich smart grids.

Fabien Sechi, Nadia Saad Noori, Charu Sharma et al. · 0 citations
Open access Sep 2026

An Organizational Decision-Support System for Cybersecurity Risk Management: Classifying Breach Types Using XGBoost and Real-World Incident Data

Financial institutions face an escalating volume of cybersecurity threats, yet existing decision frameworks rarely link predictive analytics to operational security priorities. Drawing on Task-Technology Fit theory, this study develops a machine learning-based decision-support framework to classify cybersecurity breach types in financial institutions and to identify the organizational risk factors that determine them. Analyzing 935 publicly disclosed incidents from the VERIS Community Database (VCDB, NAICS 52), we compare XGBoost against Random Forest, Logistic Regression, and Decision Tree. XGBoost achieves the most balanced performance (accuracy: 95.19%; weighted F1: 0.9519; 5-fold CV: 96.68% ± 0.21%). Feature importance analysis reveals ATM/kiosk infrastructure and breach pattern as the strongest predictors, translating into concrete SOC monitoring priorities. This framework supports UN/SDG 9 (Industry, Innovation and Infrastructure) and UN/SDG 16 (Peace, Justice and Strong Institutions) by strengthening the cyber resilience of financial institutions through open, replicable, data-driven methods. The open-data framework is replicable without commercial threat intelligence licenses.

Muhammed Samancı, Emrah Noyan, Nuri Avşarlıgil · 0 citations
Aug 2026

Cyber-risk assessment and mitigation framework for critical information infrastructure: mixed-methods approach

Distributed Denial of Service (DDoS) attacks on critical information infrastructures (CII) cause operational disruptions and result in financial and reputational damage to organisations. Our study provides an integrated framework to assess, quantify and mitigate the cyber-risk of DDoS attacks on CII organisations in the energy and power sectors. Our model adopts a socio-technological perspective and draws on protection motivation theory (PMT) and rational choice theory (RCT). Our study adopts a mixed-method approach. In the quantitative section, we estimate the likelihood of misdetection of different DDoS attacks by using observable attackers’ strategy. These observations influence how CISOs implement the organisation’s cybersecurity posture and IT governance. Next, we compute the expected loss. Lastly, the study recommends CISO for various mitigation strategies based on the NIST Cybersecurity Framework by creating a 2×2 risk-impact heat matrix. Subsequently, Linear Programming is used to determine the priority of optimal allocation of investment across different mitigation strategies. In qualitative section, in-depth interviews with cybersecurity executives corroborate findings. The likelihood of the misdetection of DDoS attacks by the CISO of an organisation is low. Most DDoS attacks result in small financial losses, but rare, severe incidents can cause disproportionately serious damage. The study further finds that organisations must invest in technological interventions, complemented by financial tools, to mitigate DDoS attacks. The study uses a mixed-methods approach, combining quantitative analysis with executive interviews to assess the CISO's misdetection rate for DDoS attacks, compute the expected financial loss, and recommend a mitigation and investment strategy based on the NIST framework for CII organisations.

Priyanka Srivastava, Arunabha Mukhopadhyay · 0 citations
Open access Aug 2026

NIST-Based Cybersecurity Risk Management for Mitigating Customer Data Breaches and Cyber Threats in Banking

The results indicate that a NIST-based approach can assist organizations in identifying and prioritizing cybersecurity risks, strengthening data protection mechanisms, enhancing incident readiness, and optimizing continuous security monitoring.

M. B. Legowo, Budi Indiarto, Adzrani Haura Badzlinaya Novianto et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.