Inspiration

Small businesses rely on email, computers, Wi-Fi, cloud services, and digital accounts every day, but many do not have dedicated cybersecurity staff to help them understand what needs attention first.

We wanted to explore a simple way to turn everyday cybersecurity questions into understandable priorities and practical next steps, without pretending to perform a technical security audit.

What it does

CyberShield AI is a guided cybersecurity self-assessment for small-business owners and managers.

The experience follows Assess → Understand → Act.

Users answer eight plain-language questions covering passwords, multi-factor authentication, backups, software and system updates, user access, network and Wi-Fi security, device protection, and employee security practices.

Django then applies deterministic rules to calculate a self-reported score, identify findings, and prioritize them. The dashboard distinguishes confirmed gaps from areas that require verification.

The application then provides a structured action plan with up to three prioritized actions. Each action explains what to do, why it matters, which finding it addresses, and how to get started.

AI is optional. It works as an explanation layer rather than controlling the score, findings, priorities, or action selection. If AI is unavailable, the complete rules-based assessment and predefined action plan remain available.

How we built it

We built CyberShield AI as a focused proof of concept using Python, Django, HTML, CSS, and vanilla JavaScript.

The project was developed using the Devpost Learn Skill Pack and a plan-first workflow. We defined the scope first, then created the product requirements and technical specification before implementing the application in separate development slices.

The core assessment logic is deterministic. Django calculates the score and prioritizes findings before any optional AI guidance is requested. The AI layer is constrained to approved explanation styles, while Django controls the user-visible wording and actions through fixed catalogs.

The application does not require user accounts, a database, or an AI API key to demonstrate its core functionality.

Challenges we ran into

One of the main challenges was deciding how to use AI without allowing it to control critical application logic.

An unrestricted AI response could potentially change the meaning of a finding, invent a risk, or recommend an action that was not part of the approved assessment. We therefore designed the architecture so that scoring, prioritization, and action selection remain under application control.

Another challenge was keeping the proof of concept focused. It would have been easy to expand it into a scanner, security monitoring platform, or full SaaS product, but we deliberately kept the scope around one complete self-assessment experience.

Accomplishments that we're proud of

We are proud of building a complete end-to-end cybersecurity assessment experience rather than just an AI chatbot.

The application takes a user from simple assessment questions to a transparent score, prioritized findings, and actionable next steps.

We are also proud that the core experience remains functional without an AI API key. This demonstrates that AI is an enhancement to the product rather than a dependency for its critical logic.

What we learned

The biggest lesson was that AI does not need to control the critical logic of an application.

By keeping scoring, findings, prioritization, and action selection deterministic, the application remains predictable and testable. AI can then focus on explaining information without becoming the source of truth for the assessment.

We also learned the value of planning before implementation. Using the Devpost Learn Skill Pack helped us move from scope to product requirements, technical specification, implementation, verification, and final review in a structured way.

What's next for CyberShield AI

The next step would be to validate the concept with real small-business owners and learn which parts of the assessment and guidance are most useful.

A future version could evolve toward a broader platform while keeping the same principle of transparent risk prioritization. Possible directions include persistent accounts, assessment history, stronger organization-level workflows, and additional cybersecurity guidance.

These features are outside the scope of this proof of concept and were intentionally not included in the hackathon version.

Built With

Share this project:

Updates

Submission history