A cloud-ready analytics platform that ingests IT security data to continuously quantify cyber risk in monetary terms, recommend budget-constrained mitigations, and map to compliance frameworks for executives and CISOs.
All India Council for Technical Education (AICTE) · Cyber Security Cell · Software
Signing in saves it for your whole team — everyone on your invite link sees the same two entries. Anything you shortlisted while signed out comes with you.
Decomposed from what the description asks for. Nothing added.
Risk Quantification Engine
Aggregates security telemetry to calculate financial exposure metrics and model asset criticality.
AI Decision Support Layer
Provides predictive analytics, mitigation recommendations, a natural language query interface, and scenario simulations.
Investment Optimization Module
Calculates return on security investment and recommends controls that maximize risk reduction within a budget.
Executive and Technical Dashboards
Displays enterprise risk scores, financial exposure, trends, and drill-down views for technical teams.
Compliance Framework Mapping
Maps findings to frameworks like ISO 27001, NIST, CIS, RBI, and SEBI to generate audit reports.
Both columns are read off the brief's own wording. Nothing here is inferred from the ministry's name.
The jury will check if your platform successfully ingests telemetry from multiple security tools, computes realistic financial exposure numbers like Expected Annual Loss, optimizes spending under budget constraints, and accurately maps risks to specified frameworks like NIST and ISO.
A jury can still ask about these. Decide them deliberately rather than by accident.
Generated from the brief's own wording and the competition's published rules — never from a guess about what this ministry prefers.
What specific mock security tools or APIs must be integrated for the demo?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
What specific financial formulas or baseline cost parameters should be used for loss calculations?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
What exact dataset format the platform needs to parse during evaluation?
The brief never answers this, so a panel will. Whatever you decide, say it the same way twice.
Has any part of this been shown at a previous event, hackathon or college project?
The guidelines are explicit: your solution must not have appeared in any previous event or programme, of any sort. A recycled project is what a team under time pressure reaches for.
Each one is quoted from a gap in the brief, not a guess about your team.
Needs data you may not get
The platform requires enterprise security telemetry from sources like SIEM, EDR, CSPM, and vulnerability scanners that students will not have access to without mock data generation.
What the organisers attached, and what the brief assumes you can get.
Same organisation, same year. Reading two of theirs tells you more about what they care about than reading one.
Pick what you are about to do and copy the prompt. It carries the organisers' own wording, the constraints they never spell out, and an instruction not to invent requirements they never set.
Who has this problem, what already exists, and what you would have to find out.
The brief asks for risk quantification engine. How would you build that?
Decoded from SIH26105 itself — Aggregates security telemetry to calculate financial exposure metrics and model asset criticality. The brief asks for it by name.
The brief asks for ai decision support layer. How would you build that?
Decoded from SIH26105 itself — Provides predictive analytics, mitigation recommendations, a natural language query interface, and scenario simulations. The brief asks for it by name.
The brief asks for investment optimization module. How would you build that?
Decoded from SIH26105 itself — Calculates return on security investment and recommends controls that maximize risk reduction within a budget. The brief asks for it by name.
The brief asks for executive and technical dashboards. How would you build that?
Decoded from SIH26105 itself — Displays enterprise risk scores, financial exposure, trends, and drill-down views for technical teams. The brief asks for it by name.
The brief asks for compliance framework mapping. How would you build that?
Decoded from SIH26105 itself — Maps findings to frameworks like ISO 27001, NIST, CIS, RBI, and SEBI to generate audit reports. The brief asks for it by name.
Where does your data come from — a published source, one you collect, or one you generate?
No dataset is attached to this problem statement, so sourcing it is part of the work and nobody told you that.
Why not use what already exists? Name the closest thing to this that is already running.
A team that has not named the alternative themselves is answering this for the first time in the room.
Which single thing will you demonstrate end to end, start to finish, with nothing skipped?
Ours, not a rule: a narrow thing that fully works survives questioning better than a broad thing that half works. If nobody on the team can name it, that is the finding.
Show me this working: the jury will check if your platform successfully ingests telemetry from multiple security tools, computes realistic financial exposure numbers like Expected Annual Loss, optimizes spending under budget constraints, and accurately maps risks to specified frameworks like NIST and ISO.
This is the evaluator read for your problem statement, decoded from the brief's own wording.