← Latest papers
💻 computer science

Anomaly Detection in Cybersecurity Service Contracts

This paper proposes a machine learning-based approach for detecting anomalies in cybersecurity service contracts between public authorities and private providers, utilizing a case study to categorize and analyze the attributes that signify deviations from established legal practices.

Original authors: Pavol Sokol, Laura Bachňáková Rózenfeldová, Dávid Varga, Simona Rudohradská, Regina Hučková

Published 2026-09-22
📖 5 min read🧠 Deep dive

Original authors: Pavol Sokol, Laura Bachňáková Rózenfeldová, Dávid Varga, Simona Rudohradská, Regina Hučková

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the world of law, predictability is a virtue. When two parties sign a contract, they expect the terms to follow a familiar pattern, much like a well-worn path through a forest. If a clause appears that deviates sharply from this path, it raises a question: is this a necessary adaptation to a unique situation, or is it a sign of something unusual, perhaps even risky? This tension between the standard and the strange is at the heart of a new study exploring cybersecurity service contracts. These are the agreements between public organizations, like cities or hospitals, and private companies hired to protect their digital systems. Because these contracts are often written with great freedom, they can vary wildly. Researchers wanted to know if they could use computers to spot the contracts that look different from the crowd, not to judge them as bad, but to understand what makes them unique. By treating legal documents as data, they applied a method called systematic content analysis, which breaks down text into specific, countable features, and combined it with machine learning, a type of computer program that learns to recognize patterns without being explicitly told what to look for.

The researchers focused on a specific set of 567 contracts signed between public authorities and private cybersecurity providers in Slovakia between 2019 and 2025. They manually read through these documents, translating the complex legal language into a structured list of features. They noted whether a contract included specific elements, such as a clause about monthly payments, a definition of what constitutes a major breach, or a requirement for the provider to deliver software and hardware. They also recorded numerical details like the number of employees at the hiring organization and the total value of the deal. Once this information was organized, they fed it into a machine learning system designed to find outliers. This system did not know beforehand which contracts were "wrong" or "right"; instead, it simply looked for the documents that stood out the most from the typical group. The goal was to identify which specific features made a contract look unusual compared to the hundreds of others in the dataset.

The study revealed that what counts as "normal" in this field is actually quite specific. The most typical contracts, the ones the computer recognized as standard, were usually simple agreements for consulting services. They often involved smaller municipalities or social care facilities and were paid for in regular monthly installments. These standard contracts tended to be brief, relying on general laws to fill in the gaps rather than writing out every possible scenario. In contrast, the contracts that the system flagged as highly anomalous were often much more complex. They frequently involved large, strategic entities like hospitals, regional governments, or major state-owned enterprises. These contracts were not just for advice; they often included the delivery of physical software or hardware, detailed IT monitoring systems, and extensive lists of penalties for various types of failures.

One of the most striking findings was that the complexity of a contract was a major driver of its "anomaly" score. The computer identified contracts with highly detailed regulations on liability, specific sanctions for delays, and strict definitions of material breach as being statistically rare. For instance, a contract between a city and a cybersecurity firm that included a penalty for the city if it delayed payment, or a clause allowing the supplier to withdraw only under very specific conditions, was flagged as unusual because most other contracts in the dataset did not have these specific, heavy-handed details. Similarly, contracts involving healthcare facilities were often seen as outliers, likely because the high stakes of protecting patient data led to more rigorous and specific terms than those found in agreements with smaller towns. The researchers noted that in one extreme case, a contract for a small monthly service was flagged as unusual because the cost represented a disproportionately large share of the supplier's total revenue, a statistical oddity that the computer caught immediately.

However, the researchers were careful to clarify that being "anomalous" does not mean a contract is legally defective or unfair. The term simply means the document looks different from the statistical average. In fact, the study suggests that many of these "strange" contracts are likely the result of parties trying to be more careful. When a contract involves a large sum of money or a critical service like hospital security, it makes sense for the parties to write down more rules to protect themselves. The computer, seeing a pattern of simple, low-risk contracts, interpreted these detailed, high-stakes agreements as deviations. The study also highlighted a potential blind spot in how legal data is recorded. For example, the researchers coded a contract as having "no right to withdraw" if the text did not explicitly mention it, even though the law might already grant that right. This meant the computer was sometimes reacting to the absence of a specific sentence rather than the absence of a legal right.

Ultimately, this work offers a new way to look at legal documents. By using computers to map the landscape of cybersecurity contracts, the researchers created a baseline of what is common and what is rare. This does not mean that the rare contracts should be avoided; rather, it provides a tool for public officials to see when they are venturing into less charted territory. If a city is about to sign a complex deal with a hospital, the system can show them that this type of agreement looks different from the hundreds of simpler ones they usually sign. This awareness allows them to double-check that the unusual terms are intentional and well-considered, rather than accidental. The study concludes that while the machine can spot the outliers, it cannot judge their value. The true work of understanding whether a complex contract is necessary or excessive still belongs to the human experts who must interpret the numbers in the context of real-world needs.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →