ADAPTIVE CYBER INCIDENT RESPONSE METHOD FOR ENSURING DEPENDABILITY OF INFORMATION SYSTEMS IN SITUATION CENTERS

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.038701

Abstract

The paper develops an adaptive cyber incident response method aimed at ensuring the dependability of information
systems used in situation centers under conditions of increasing cyber threats, growing complexity of information system
architectures, and higher requirements for the continuity of critical services. The relevance of the study is determined by
the need for timely detection of cyber incidents, assessment of their impact on the state of information systems, and
automated generation of decisions to maintain the required level of dependability. The purpose of the research is to
develop an adaptive cyber incident response method based on intelligent security event analysis, risk assessment, and
dynamic selection of countermeasures. A review of current approaches to ensuring the dependability of information
systems in situation centers, cyber incident response methods, and decision support technologies is conducted. A
mathematical model for assessing the impact of cyber incidents on dependability indicators is proposed, and the adaptive
response process is formalized. The developed method includes security event monitoring, incident classification,
criticality assessment, threat evolution forecasting, and selection of an optimal response strategy. In addition, an
architecture of an intelligent decision support system for ensuring the dependability of information systems in situation
centers is proposed. Simulation results confirmed the effectiveness of the approach in increasing the level of dependability,
reducing cyber incident response time, decreasing the risk of disruption of information resources, and improving system
resilience to destructive impacts. The obtained results can be applied in the design, modernization, and operation of
information systems in situation centers, as well as in the development of intelligent cybersecurity management tools and
mechanisms for ensuring operational continuity.
Keywords: situation center, dependability, cyber incident, adaptive response, information system, intelligent
system, decision support, mathematical model, risk management, cybersecurity.

References
1. Ren, S., Jin, J., Niu, G., & Liu, Y. (2025). ARCS: Adaptive reinforcement learning framework for automated
cybersecurity incident response strategy optimization. Applied Sciences, 15(2), Article 951.
https://doi.org/10.3390/app15020951.
2. Klein, T., & Romano, G. (2025). Optimizing cybersecurity incident response via adaptive reinforcement
learning. Journal of Advances in Engineering and Technology, 2(1). https://doi.org/10.62177/jaet.v2i1.212.
3. Jha, N. N. (2025). Accelerating cloud outage recovery through adaptive AI: A reinforcement learning approach.
European Journal of Computer Science and Information Technology, 13(26), 1–10. https://doi.org/10.37745/
ejcsit.2013/vol13n26110.
4. Lin, X., Zhang, J., Deng, G., Liu, T., Zhang, T., Guo, Q., & Chen, R. (2025). IRCopilot: Automated incident
response with large language models. arXiv. https://arxiv.org/abs/2505.20945.
5. Tellache, A., Korba, A. A., Mokhtari, A., Moldovan, H., & Ghamri-Doudane, Y. (2025). Advancing
autonomous incident response: Leveraging LLMs and cyber threat intelligence (arXiv:2508.10677). arXiv.
https://arxiv.org/abs/2508.10677.
6. Maynard, P., Cherdantseva, Y., Shaked, A., Burnap, P., & Mehmood, A. (2025). Consistent and compatible
modelling of cyber intrusions and incident response demonstrated in the context of malware attacks on critical
infrastructure (arXiv:2505.16398). arXiv. https://arxiv.org/abs/2505.16398.
7. Liu, Z., & Anwar, A. (2025). AutoBnB-RAG: Enhancing multi-agent incident response with retrievalaugmented generation (arXiv:2508.13118). arXiv. https://arxiv.org/abs/2508.13118.
8. Nelson, A., et al. (2025). Incident response recommendations and considerations for cybersecurity risk
management (NIST SP 800-61 Rev. 3). National Institute of Standards and Technology. https://csrc.nist.gov/pubs/
sp/800/61/r3/final.
9. Складанний, П. М., Костюк, Ю. В., Рзаєва, С. Л., Самойленко, Ю. В., & Савченко, Т. В. (2025). Розробка
модульних нейронних мереж для виявлення різних класів мережевих атак. Кібербезпека: освіта, наука, техніка,
3(27), 534-548. https://doi.org/10.28925/2663-4023.2025.27.772.
10. Mohamed, N. (2025). Artificial intelligence and machine learning in cybersecurity: A deep dive into state-ofthe-art techniques and future paradigms. Knowledge and Information Systems, 67, 6969–7055. https://doi.org/10.
1007/s10115-025-02429-y.
11. Костюк, Ю. В., Складанний, П. М., Рзаєва, С. Л., Самойленко, Ю. В., & Коршун, Н. В. (2025).
Інтелектуальні системи керування та захисту в кіберфізичних і хмарних середовищах Smart Grid. Кібербезпека:
освіта, наука, техніка, 2(30), 125–156. https://doi.org/10.28925/2663-4023.2025.30.956.
12. Khatri, V., Agarwal, G., Gupta, A., & Sanghi, A. (2024). Machine learning and artificial intelligence in
cybersecurity: Innovations and challenges. In Proceedings of the International Conference on Advances in Computing,
Communication and Technology (pp. 732–737). IEEE. https://doi.org/10.1109/ICACCTech65084.2024.00122.
13. Складанний, П. М., Костюк, Ю. В., & Рзаєва, С. Л. (2026). Безперервна оцінка доступу в Zero Trust
Access Management на основі подієвих сигналів безпеки та динамічного керування сесіями. Математичні машини
і системи, 1, 29-46. https://doi.org/10.34121/1028-9763-2026-1-29-46.
14. Alhidaifi, S. M., Asghar, M. R., & Ansari, I. S. (2024). A survey on cyber resilience: Key strategies, research
challenges, and future directions. ACM Computing Surveys, 56(8), 1–48. https://doi.org/10.1145/3649218.
15. Костюк, Ю. В., Рзаєва, С. Л., & Рзаєв, Д. О. (2026). Інтелектуальний аналіз мережевого трафіку для
виявлення інцидентів інформаційної безпеки. Наука і техніка сьогодні, 2(56), 1909-1928. https://doi.org/10.52058/
2786-6025-2026-2(56)-1909-1928.
16. Calvo Ibañez, A., Preetam, S., & Compastié, M. (2025). Explainable AI for cybersecurity decisions: Challenges
and opportunities. In Artificial Intelligence for Cybersecurity (pp. 385–408). Elsevier. https://doi.org/10.1016/B978-0-
44-329135-7.00018-7.
17. Костюк, Ю. В., & Складанний, П. М. (2026). Криптографічна модель довіри до подій безпеки в SIEM
для інтелектуального формування мережевих інцидентів. Сучасний захист інформації, 1(65), 103-118.
https://doi.org/10.31673/2409-7292.2026.011393.
18.Joseph, J., Aleke, N., & Onyeanisi, O. P. (2025). Intelligent incident response systems using machine learning.
Mikailalsys Journal of Advanced Engineering International, 2(1). https://doi.org/10.58578/MJAEI.v2i1.4540.
19. Костюк, Ю. В., Складанний, П. М., & Рзаєва, С. Л. (2026). Управління якістю сповіщень у SIEM на
основі ризик-орієнтованого оцінювання та зворотного зв'язку SOC. Український науковий журнал інформаційної
безпеки, 31(3), 151–163. https://doi.org/10.18372/2225-5036.31.21161.
20. Hammad, A. A., Ahmed, S. R., Abdul-Hussein, M. K., Ahmed, M. R., Majeed, D. A., & Algburi, S. (2024).
Deep reinforcement learning for adaptive cyber defense in network security. In Proceedings of the Cognitive Models and
Artificial Intelligence Conference (pp. 292–297).
21. Рзаєва, С. Л., Литвин, О. С., Складанний, П. М., Костюк, Ю. В., & Рзаєв, Д. О. (2026). Модель
адаптивного управління кібербезпекою інформаційно-комунікаційних систем на основі ризик-орієнтованого
підходу. Математичні машини і системи, 2, 92–109. https://doi.org/10.34121/1028-9763-2026-2-92-109.
22. Kostiuk, Y., Skladannyi, P., Sokolov, V., Hulak, H., & Korshun, N. (2024). Models and algorithms for
analyzing information risks during the security audit of personal data information system. In Proceedings of the Third
International Conference on Cyber Hygiene & Conflict Management in Global Information Networks (CH&CMiGIN
2024) (Vol. 3925, pp. 155–171). CEUR Workshop Proceedings.
23. Farzaan, M. A. M., Ghanem, M. C., El-Hajjar, A., & Ratnayake, D. N. (2025). AI-powered system for an
efficient and effective cyber incidents detection and response in cloud environments. IEEE Transactions on Machine
Learning in Communications and Networking, 3, 623–643. https://doi.org/10.1109/TMLCN.2025.3564912.
24. Kostiuk, Y., Skladannyi, P., Sokolov, V., & Vorokhob, M. (2025). Models and technologies of cognitive agents
for decision-making with integration of artificial intelligence. In Proceedings of the Modern Data Science Technologies
Doctoral Consortium (MoDaST 2025) (Vol. 4005, pp. 82-96). CEUR Workshop Proceedings.
25. Shevchenko, S., Zhdanova, Y., Kryvytska, O., & Shevchenko, H. (2024). Fuzzy cognitive mapping as a
scenario approach for information security risk analysis. In Cybersecurity Providing in Information and
Telecommunication Systems II (Vol. 3826, pp. 356–362).
26. Kostiuk, Y. (2025). Multi-agent system for detecting and counteracting attacks on the enterprise information
system. In Insider Threats and Security in Corporations (pp. 205–232). https://doi.org/10.36690/ITSC-205-232.
27. Dacorogna, M., Debbabi, N., & Kratz, M. (2023). Building up cyber resilience by better grasping cyber risk
via a new algorithm for modelling heavy-tailed data. European Journal of Operational Research, 311(2), 707–721.
https://doi.org/10.1016/j.ejor.2023.05.003.

Published

2026-09-15

Issue

Section

Articles