Authors: Kasun Jayawardena
Abstract: In the contemporary digital landscape, enterprise security has transitioned from a perimeter-centric defense model to a data-driven, risk-aware paradigm. Traditional risk assessment methodologies, which often rely on static qualitative heat maps and manual vulnerability scoring, are increasingly unable to keep pace with the velocity and sophistication of modern cyber threats. This review article explores the emergence and integration of Machine Learning (ML)-based risk scoring within enterprise security frameworks. By leveraging advanced algorithms—ranging from supervised ensemble methods to unsupervised anomaly detection and deep learning—organizations can now generate dynamic, real-time risk scores for users, devices, and network entities. These scores facilitate a "Zero Trust" architecture by providing the granular intelligence necessary for automated access decisions and incident prioritization. This article categorizes current ML methodologies, including the use of Random Forests for vulnerability prioritization and Recurrent Neural Networks (RNNs) for behavioral risk modeling. We examine the critical role of feature engineering in synthesizing telemetry data from diverse sources such as Endpoint Detection and Response (EDR) systems, Identity and Access Management (IAM) logs, and Threat Intelligence feeds. Furthermore, the review addresses the challenges of model interpretability, data bias, and the necessity for Explainable AI (XAI) in security operations. By synthesizing recent academic research and industrial case studies, this paper provides a strategic roadmap for the implementation of predictive risk scoring. The findings suggest that ML-based scoring significantly reduces the "Mean Time to Respond" (MTTR) by filtering noise and highlighting high-probability threats, thereby fortifying the enterprise’s overall resilience.
DOI: https://doi.org/10.5281/zenodo.19417256
International Journal of Science, Engineering and Technology