Journal of Cyber Security and Risk Auditing

Journal of Cyber Security and Risk Auditing

ISSN: 3079-5354 (Online)

Publishing model:

: Open access
open accessOpen Access

Article

👁️60views

Adaptive Cyber Risk Scoring Models for Digital Learning Environments

by 

Ruziboy Tangirov ;

Madina Mirzayeva ;

Saidmurod Mamedov ;

Nilufar Niyozmatova ;

Amir Alquataish ;

Hossein Edries ;

Rami Shihab ;

Mansoor Obiedat

PDF logoPDF

Published: 2026/06/30

Abstract

Digital Learning Environments (DLEs) such as Learning Management Systems (LMS), Massive Open Online Courses (MOOCs) and virtual classroom platforms have become an essential piece of education infrastructure around the world. Today, the education industry has seen more than 1,500 confirmed data breaches reported every year, and around 2,300 cyberattacks reported every week.But current static risk assessment models like CVSS v4.0 or NIST SP800-30 do not account for the temporal, behavioral and academic-contextual characteristics that distinguish DLE threat landscapes. In this paper, a new model, ACRSM-DLE (Adaptive Cyber Risk Scoring Model for Digital Learning Environments), that dynamically scores the level of risk in digital learning environments based on the integration of infrastructure vulnerabilities, user behavioral analysis, real-time threat intelligence, and a new Academic Context Risk Factor (ACRF) is presented. A new hybrid machine learning architecture is used in the model, which includes Random Forest, XGBoost, LSTM networks and Isolation Forest, Bayesian score fusion and Adaptive Risk Threshold Recalibration (ARTR) mechanism. Experimental assessment in four institutional DLE deployments, with 187,000+ learners, shows a 41.3% false-positive rate reduction, a 34.7% improvement in detection precision, an F1-Score of 0.939, an AUC-ROC of 0.974, and a mean score update latency of 287 ms, all significantly better than static baselines. The model complies with the requirements of FERPA, GDPR Article 32 and ISO/IEC 27005: 2022.

Keywords

Adaptive risk scoringCyber risk quantificationDigital learning environmentsMachine learningLMS securityAnomaly detectionCVSSBehavioral analyticsEducational cybersecurityThreat intelligence.

How to Cite the Article

Tangirov, R., Mirzayeva, M., Mamedov, S., Niyozmatova, N., Alquataish, A., Edries, H., Shihab, R., & Obiedat, M. (2026). Adaptive Cyber Risk Scoring Models for Digital Learning Environments. Journal of Cyber Security and Risk Auditing, 2026(2), 336–352. https://doi.org/10.63180/jcsra.thestap.2026.2.10

References

  1. Hamidou, S. T., & Mehdi, A. (2025). Enhancing IDS performance through a comparative analysis of Random Forest, XGBoost, and Deep Neural Networks. Machine Learning with Applications, 100738. https://doi.org/10.1016/j.mlwa.2025.100738
  2. Bitton, R., Maman, N., Singh, I., Momiyama, S., Elovici, Y., & Shabtai, A. (2021). A framework for evaluating the cybersecurity risk of real world, machine learning production systems. In Proceedings of the Web Conference 2021 (pp. 1056–1067). ACM.
  3. Cisco Talos Intelligence Group. (2024). Cisco Annual Cybersecurity Report 2024. Cisco Systems Inc.
  4. CISA. (2022). Cybersecurity advisory: Ransomware attacks targeting educational institutions. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov
  5. Almuhanna, R., & Dardouri, S. (2025). A deep learning/machine learning approach for anomaly based network intrusion detection. Frontiers in Artificial Intelligence, 8, 1625891. https://doi.org/10.3389/frai.2025.1625891
  6. Docebo. (2024). eLearning security: How to secure your LMS data. Docebo Learning Network Blog. https://www.docebo.com/learning-network/blog/elearning-security-knowledge-sensitive-data/
  7. Beuran, R., Tang, D., Tan, Z., Hasegawa, S., Tan, Y., & Shinoda, Y. (2019). Supporting cybersecurity education and training via LMS integration: CyLMS. Education and Information Technologies, 24(6), 3619-3643. https://doi.org/10.1007/s10639-019- 09942-y
  8. Greco, D., & Chianese, L. (2024, November). Exploiting llms for e-learning: a cybersecurity perspective on AI-generated tools in education. In 2024 IEEE International Workshop on Technologies for Defense and Security (TechDefense) (pp. 237-242). IEEE.
  9. FIRST. (2023). Common Vulnerability Scoring System version 4.0: Specification document. Forum of Incident Response and Security Teams. https://www.first.org/cvss/v4-0/
  10. Greco, D., & Chianese, L. (2024, November). Exploiting llms for e-learning: a cybersecurity perspective on AI-generated tools in education. In 2024 IEEE International Workshop on Technologies for Defense and Security (TechDefense) (pp. 237-242). IEEE.
  11. IBM Security. (2024). Cost of a data breach report 2024. IBM Corporation. https://www.ibm.com/reports/data-breach
  12. ISO/IEC 27005:2022. (2022). Information security, cybersecurity and privacy protection — Guidance on managing information security risks. International Organization for Standardization.
  13. Kepuska, K., & Tomasevic, M. (2024). A lightweight framework for cyber risk management in Western Balkan higher education institutions. PeerJ Computer Science, 10, e1958. https://doi.org/10.7717/peerj-cs.1958
  14. Maréchal, L., & Monnet, N. (2024). Disentangling the sources of cyber risk premia. arXiv preprint arXiv:2409.08728. https://arxiv.org/abs/2409.08728
  15. Microsoft Security Intelligence. (2023). Digital defense report: Education sector threat analysis. Microsoft Corporation. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2023
  16. Mukherjee, S., et al. (2025). AI-driven IRM: Transforming insider risk management with adaptive scoring and LLM-based threat detection. arXiv preprint arXiv:2505.03796. https://arxiv.org/abs/2505.03796
  17. NIST. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1
  18. Open Group. (2023). The FAIR model: Factor analysis of information risk. The Open Group. https://www.opengroup.org/fair
  19. Salem, A. H., Azzam, S. M., Emam, O. E., & Abohany, A. A. (2024). Advancing cybersecurity: a comprehensive review of AI- driven detection techniques. Journal of Big Data, 11(1), 105. https://doi.org/10.1186/s40537-024-00957-y
  20. Stehr, M.-O., & Kim, M. (2023). Vulnerability clustering and ML applications of semantic vulnerability embeddings. arXiv preprint arXiv:2310.05935. https://arxiv.org/abs/2310.05935
  21. Swinhoe, D., & Bucker, M. (2021). A systematic review of cybersecurity risks in higher education. Future Internet, 13(2), 39. https://doi.org/10.3390/fi13020039
  22. Walkowski, M., Oko, J., & Sujecki, S. (2021). Vulnerability management models using a common vulnerability scoring system. Applied Sciences, 11(18), 8735.
  23. Vasilyev, V., Kirillova, A., Vulfin, A., & Nikonov, A. (2021, September). Cybersecurity risk assessment based on cognitive attack vector modeling with CVSS Score. In 2021 International Conference on Information Technology and Nanotechnology (ITNT) (pp. 1-6). IEEE.
  24. Verizon. (2024). Data breach investigations report 2024. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/
  25. Jiang, J. A., Robledo Yamamoto, F., Nagy, V., Zander, M., & Barker, L. (2023, July). Data privacy in learning management systems: perceptions of students, faculty, and administrative staff. In International Conference on Human-Computer Interaction (pp. 100-115). Cham: Springer Nature Switzerland.
  26. Vykopal, J., Seda, P., Švábenský, V., & Čeleda, P. (2022). Smart environment for adaptive learning of cybersecurity skills. IEEE Transactions on Learning Technologies, 16(1), 98–115. https://doi.org/10.1109/TLT.2022.3213949
  27. Armas, R., & Taherdoost, H. (2025). Building a cybersecurity culture in higher education: Proposing a cybersecurity awareness paradigm. Information, 16(5), 336.
  28. Zamfiroiu, A., Constantinescu, D., Zurini, M., & Toma, C. (2020). Secure learning management system based on user behavior. Applied Sciences, 10(21), 7730.
  29. Mittal, A., Shah, H., & Keshap, P. (2025, November). AI-Augmented Cyber Labs: Enhancing Cloud-Native Security Education through Adaptive Feedback and Threat Simulation. In Proceedings of the 26th ACM Annual Conference on Cybersecurity & Information Technology Education (pp. 174-179).
  30. Zubairu, U., et al. (2024). A review of adaptive learning paradigms and practical cybersecurity applications. In Proceedings of the Workshop on Adaptive Learning and Cybersecurity (Vol. 3978). CEUR-WS. https://ceur-ws.org/Vol-3978/regular-s3-03.pdf.
SCImago Journal & Country Rank