Cybersecurity Learning Hub — From Knowledge to Practice
Cyber Hiroshima

Learn with AI

CyBOK is not simply a glossary of individual terms. It organises the knowledge required for cybersecurity into defined areas. This structure could also serve as a knowledge map when an AI system constructs an explanation.

Real cybersecurity problems rarely fit within a single Knowledge Area. AI could help learners move across multiple Knowledge Areas and understand how different areas of knowledge relate to one another.

Rather than stopping at a general AI-generated answer, we want learners to be able to see which part of CyBOK supports an explanation and return to the underlying knowledge themselves.

Using CyBOK with AI does not mean creating an LLM from CyBOK alone. Nor does it necessarily mean training a large language model from scratch.

The direction Cyber Hiroshima is considering is a staged approach: beginning with existing LLMs and retrieval over Japanese-language CyBOK content, then progressively exploring broader trusted sources, greater specialisation and more controlled AI environments.

An existing LLM could be combined with search and retrieval over Japanese-language CyBOK content, allowing explanations to refer to relevant CyBOK material and guide learners back to the source.

This could provide a first step towards answers and explanations grounded in CyBOK.

CyBOK could serve as a structured and trusted foundation alongside standards, technical material, educational content and other relevant cybersecurity information.

This could support more specialised dialogue in Japanese and help explain relationships across multiple Knowledge Areas.

In the longer term, Cyber Hiroshima may evaluate open-source LLMs and other models in a controlled environment, with appropriate management of knowledge sources, data, models, access and permissions.

This could provide greater control where specialist or private AI environments are required.


CyBOK is not intended to provide all of the knowledge used by AI, but to serve as a trusted foundation at its core.

Starting with the structured knowledge of CyBOK, we are considering how it could be combined with up-to-date technical information, threat intelligence and other specialist information as needed, and developed into AI-assisted learning and more advanced agents.

Ask questions about specialist terms and technologies, and deepen your understanding while referring to relevant parts of CyBOK.

Suggest relevant Knowledge Areas and Topics according to the learner’s objectives and level of understanding.

Organise the relationships between a particular technology or incident and multiple Knowledge Areas.

Find SudoRange Labs related to what has been learned through CyBOK and guide the learner towards hands-on practice.

Generate questions to check understanding, summaries and revision points, helping learners assess their own understanding.

In the future, this could develop into a personal learning agent that continuously adjusts the learning pathway according to a learner’s objectives and learning history.

AI technology is evolving rapidly.

Cyber Hiroshima believes it is important not to build a large proprietary AI environment from the outset, but to develop it step by step while assessing its actual value for learning.

  • Make Japanese-language CyBOK content available on the web
  • Structure Knowledge Areas and Topics
  • Map CyBOK to SudoRange Labs
  • Explore data structures that AI can search and reference easily

We are currently at the stage of building this foundation.

Combine an existing LLM with CyBOK search to evaluate:

“AI that explains based on CyBOK.”

What matters is not only the answer, but also being able to return to:

  • the Knowledge Area
  • the Topic
  • related pages
  • the information referenced

Connect CyBOK search, an LLM, SudoRange Lab search and other capabilities as tools, and develop them towards a learning agent using Robutler.

Goal:

From “answering questions” to “supporting the learner’s next learning action”.

Evaluate open-source LLMs and private AI execution environments, with the aim of developing cybersecurity AI with greater specialisation and control.

In the future, we may also explore an environment in which agents such as:

  • CyBOK Learning Agent
  • SudoRange Agent
  • Research Agent
  • Assessment Agent
  • Organisation-specific Agent

Take on different roles and work together as needed.

In cybersecurity, the ability of AI to generate natural-sounding text does not necessarily mean that the information it provides is correct.

Cyber Hiroshima believes that when using AI, it is important not to lose the structure and grounding that CyBOK provides.

Wherever possible, we aim to design the environment so that learners can return to the relevant CyBOK Knowledge Area or Topic.


We will consider both external LLMs and private LLMs, with the aim of being able to select an execution environment appropriate to the information being handled.


We will consider both external LLMs and private LLMs, with the aim of being able to select an execution environment appropriate to the information being handled.


Rather than simply having AI provide the answer, we aim to create a learning environment in which learners consider why something is the case, return to the underlying knowledge and develop their own understanding.