CYBOK × AI
Cyber Hiroshima is exploring the potential for new approaches to cybersecurity learning, starting with CyBOK content that can be studied in Japanese.
The aim is not simply to ask AI a question and receive an answer. We are considering how structured knowledge from CyBOK, hands-on cybersecurity practice and AI agents could eventually work together to create an environment in which learners can think, experiment and deepen their own understanding.
This is a future direction. Cyber Hiroshima does not currently provide a dedicated CyBOK-based AI learning environment, private LLM or AI agent service.
WHERE WE ARE TODAY
Cyber Hiroshima is currently developing a web-based environment for learning CyBOK in Japanese, together with opportunities for hands-on learning using SudoRange.
At the same time, dedicated LLMs or AI agents using CyBOK are not currently offered as public services.
The next step we are considering is to make the structured knowledge of CyBOK available for use by AI, and to connect it with learning support and practical learning environments.
WHY CYBOK × AI
Generative AI can respond to a very wide range of questions.
Cybersecurity, however, is a highly specialised field involving technology, risk, organisations, law, human factors and many other areas. Simply asking a general-purpose AI a question may therefore not always be enough.
CyBOK systematically organises the knowledge required for cybersecurity into Knowledge Areas.
Cyber Hiroshima sees significant value in this structure itself.
CyBOK is not simply a glossary of individual terms. It organises the knowledge required for cybersecurity into defined areas. This structure could also serve as a knowledge map when an AI system constructs an explanation.
Real cybersecurity problems rarely fit within a single Knowledge Area. AI could help learners move across multiple Knowledge Areas and understand how different areas of knowledge relate to one another.
Rather than stopping at a general AI-generated answer, we want learners to be able to see which part of CyBOK supports an explanation and return to the underlying knowledge themselves.
FROM KNOWLEDGE TO AI
Using CyBOK with AI does not mean creating an LLM from CyBOK alone. Nor does it necessarily mean training a large language model from scratch.
The direction Cyber Hiroshima is considering is a staged approach: beginning with existing LLMs and retrieval over Japanese-language CyBOK content, then progressively exploring broader trusted sources, greater specialisation and more controlled AI environments.
An existing LLM could be combined with search and retrieval over Japanese-language CyBOK content, allowing explanations to refer to relevant CyBOK material and guide learners back to the source.
This could provide a first step towards answers and explanations grounded in CyBOK.
CyBOK could serve as a structured and trusted foundation alongside standards, technical material, educational content and other relevant cybersecurity information.
This could support more specialised dialogue in Japanese and help explain relationships across multiple Knowledge Areas.
In the longer term, Cyber Hiroshima may evaluate open-source LLMs and other models in a controlled environment, with appropriate management of knowledge sources, data, models, access and permissions.
This could provide greater control where specialist or private AI environments are required.
CyBOK is not intended to provide all of the knowledge used by AI, but to serve as a trusted foundation at its core.
Starting with the structured knowledge of CyBOK, we are considering how it could be combined with up-to-date technical information, threat intelligence and other specialist information as needed, and developed into AI-assisted learning and more advanced agents.
FROM AI TO AGENT
LLMs are an important technology for understanding questions and generating explanations and text.
However, Cyber Hiroshima is not aiming to create an environment in which learners simply ask an LLM a question and receive an answer.
One approach we are considering is the use of Robutler to develop AI agents.
Rather than using Robutler as an AI model itself, we envisage using it as an agent platform that connects external capabilities such as LLMs, CyBOK knowledge and SudoRange, and combines the processes required for a particular task.
In addition to CyBOK, the agent could in future connect with SudoRange and other learning resources.
Depending on the question, the agent could select the appropriate process, such as:
Rather than relying on a single LLM for everything, the approach would combine multiple specialised capabilities as needed.
In the future, we may also explore expanding the environment by adding agents for different specialist fields or educational purposes and enabling them to work together.
WHAT COULD BECOME POSSIBLE
The following are not functions currently being offered.
They are examples of the learning environment that Cyber Hiroshima believes could become possible in the future by combining CyBOK, AI, Robutler and SudoRange.
Ask questions about specialist terms and technologies, and deepen your understanding while referring to relevant parts of CyBOK.
Suggest relevant Knowledge Areas and Topics according to the learner’s objectives and level of understanding.
Organise the relationships between a particular technology or incident and multiple Knowledge Areas.
Find SudoRange Labs related to what has been learned through CyBOK and guide the learner towards hands-on practice.
Generate questions to check understanding, summaries and revision points, helping learners assess their own understanding.
In the future, this could develop into a personal learning agent that continuously adjusts the learning pathway according to a learner’s objectives and learning history.
ROADMAP
AI technology is evolving rapidly.
Cyber Hiroshima believes it is important not to build a large proprietary AI environment from the outset, but to develop it step by step while assessing its actual value for learning.
We are currently at the stage of building this foundation.
Combine an existing LLM with CyBOK search to evaluate:
“AI that explains based on CyBOK.”
What matters is not only the answer, but also being able to return to:
Connect CyBOK search, an LLM, SudoRange Lab search and other capabilities as tools, and develop them towards a learning agent using Robutler.
Goal:
From “answering questions” to “supporting the learner’s next learning action”.
Evaluate open-source LLMs and private AI execution environments, with the aim of developing cybersecurity AI with greater specialisation and control.
In the future, we may also explore an environment in which agents such as:
Take on different roles and work together as needed.
RESPONSIBLE AI
In cybersecurity, the ability of AI to generate natural-sounding text does not necessarily mean that the information it provides is correct.
Cyber Hiroshima believes that when using AI, it is important not to lose the structure and grounding that CyBOK provides.
Wherever possible, we aim to design the environment so that learners can return to the relevant CyBOK Knowledge Area or Topic.
We will consider both external LLMs and private LLMs, with the aim of being able to select an execution environment appropriate to the information being handled.
We will consider both external LLMs and private LLMs, with the aim of being able to select an execution environment appropriate to the information being handled.
Rather than simply having AI provide the answer, we aim to create a learning environment in which learners consider why something is the case, return to the underlying knowledge and develop their own understanding.
BUILDING THE NEXT WAY TO LEARN
Introducing AI is not an end in itself.
By combining the structured knowledge of CyBOK, hands-on practice through SudoRange, and dialogue and navigation supported by AI, we aim to create an environment for not only reading about cybersecurity, but also thinking, trying and understanding.
That is the direction Cyber Hiroshima is pursuing through Learn with AI.