Aug 2026· International Conference on Cyber Security And Protection Of Digital Services· 0 citations
TL;DR
The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios.
Abstract
The rapid digitisation of critical infrastructure has made traditional fragmented risk assessment practices increasingly challenging to scale. For global industrial leaders managing hundreds of diverse projects, there is a real need for a unified methodology that ensures technical rigour, cross-project reproducibility, and scalability. This paper introduces the Advanced Risk Assessment Methodology for Industrial Systems (ARAMIS), an innovative framework developed through a strategic partnership between Airbus Protect and Alstom. ARAMIS merges the structured, requirement-driven security levels of ISA/IEC 62443 with the scenario-based approach of Expression des Besoins et Identification des Objectifs de Sécurité Risk Manager (EBIOS RM). The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T). Finally, it discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Distributed Denial of Service (DDoS) attacks on critical information infrastructures (CII) cause operational disruptions and result in financial and reputational damage to organisations. Our study provides an integrated framework to assess, quantify and mitigate the cyber-risk of DDoS attacks on CII organisations in the energy and power sectors. Our model adopts a socio-technological perspective and draws on protection motivation theory (PMT) and rational choice theory (RCT).
Our study adopts a mixed-method approach. In the quantitative section, we estimate the likelihood of misdetection of different DDoS attacks by using observable attackers’ strategy. These observations influence how CISOs implement the organisation’s cybersecurity posture and IT governance. Next, we compute the expected loss. Lastly, the study recommends CISO for various mitigation strategies based on the NIST Cybersecurity Framework by creating a 2×2 risk-impact heat matrix. Subsequently, Linear Programming is used to determine the priority of optimal allocation of investment across different mitigation strategies. In qualitative section, in-depth interviews with cybersecurity executives corroborate findings.
The likelihood of the misdetection of DDoS attacks by the CISO of an organisation is low. Most DDoS attacks result in small financial losses, but rare, severe incidents can cause disproportionately serious damage. The study further finds that organisations must invest in technological interventions, complemented by financial tools, to mitigate DDoS attacks.
The study uses a mixed-methods approach, combining quantitative analysis with executive interviews to assess the CISO's misdetection rate for DDoS attacks, compute the expected financial loss, and recommend a mitigation and investment strategy based on the NIST framework for CII organisations.
Priyanka Srivastava, Arunabha Mukhopadhyay· Journal of Enterprise Inform...· 0 citations
The increasing frequency of cyber threats poses substantial challenges for organizations in both the private and public sectors. This systematic literature review evaluates and categorizes current cyber risk assessment methodologies and frameworks, supporting the selection of suitable approaches for practical and academic applications. Utilizing the PRISMA framework, 712 relevant studies were filtered from an initial pool of 1900 academic publications and subsequently analyzed and organized into a structured database, providing an overview of the advantages and limitations of widely cited approaches in this domain. The findings indicate a strong preference for established risk management frameworks, including the ISO 27000 family, OCTAVE, and NIST Special Publications, as well as mathematical approaches such as Bayesian networks, fuzzy logic, and multi-criteria decision-making techniques. The 217 approaches identified were grouped into two primary categories:
Standards, Frameworks, and Guidelines
and
Risk Assessment Methods
, with further classification by the application sectors addressed in the literature. Analysis suggests that no single approach offers universal applicability. The choice of methodology should therefore be informed by an organization’s specific resources, size, and sectoral requirements. A cross-analysis of methods and sectors reveals gaps in sector-specific coverage, particularly for healthcare, finance, and small and medium-sized enterprises. The review identifies a trend toward hybrid approaches that combine organizational frameworks with quantitative methods and documents persistent barriers to adoption, including cost, data scarcity, and insufficient management engagement. Based on these findings, a conceptual framework is developed to evaluate approaches across five dimensions and to derive a typology of governance-oriented, quantitative, and hybrid methods. Implications for practitioners, regulators, and researchers are discussed in relation to current regulatory frameworks, including the NIS-2 Directive and the Digital Operational Resilience Act (DORA).
Phillip Sampson, Barry Sheehan, D. Shannon et al.· Geneva papers on risk and in...· 0 citations
A systematic evaluation framework for LLM-driven threat modelling tools to support tool selection, observing the general LLM-integration, governance risks, and allowing for comparison of tool output is introduced.
Josephine Bakka, A. Brandhøj, T. Bøgedal et al.· International Conference on...· 0 citations
The digital transformation of nuclear facilities increases the interdependence of information technologies, operational systems, physical devices, and human actors, while existing risk-assessment approaches often remain domain-specific. This study aims to design an integrated framework for dynamic cyber-physical risk assessment. Design Science Research is adopted as the overarching methodology, supported by a systematic review structured according to PRISMA 2020 to identify scientific gaps and derive design requirements. The resulting artifact is the Nuclear Integrated Cyber-Physical Risk Assessment Framework (NICPRAF), which connects nuclear safety, nuclear security, cybersecurity, IT/OT environments, human factors, and governance. The framework organizes multi-source data qualification and fusion, evolving risk assessment, and decision support under human supervision. Its contribution lies in integrating dimensions commonly addressed separately and in establishing traceability between literature gaps and the functions of the proposed artifact. NICPRAF remains conceptual and has not yet undergone operational validation. Future work will focus on prototype development, representative case studies and digital twins, and evaluation of its integration with security-monitoring platforms.
Hervé T. A. Buanga, Nathanaël M. Kasoro, Selain K. Kasereka· Journal Africain des Science...· 0 citations
The case is made for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit are offered.
Aaron Aubrey Ng· International Conference on...· 0 citations
The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure and explains why periodic assessment loses completeness when asset states change between review cycles.
Kolchin Rustam· International Research Journ...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.