A semi-automated risk analysis tool designed to evaluate OT cybersecurity risks through a multi-layered approach that integrates asset inventories, governance-based questionnaires, and external threat intelligence databases such as MITRE ATT&CK and CVE is presented.
Abstract
The increasing integration of Operational Technology (OT) and Information Technology (IT) systems within industrial environments has introduced significant cybersecurity challenges. Traditional risk assessment approaches often lack the adaptability and scalability needed to address evolving threat landscapes and complex asset interdependencies. This paper presents a semi-automated risk analysis tool designed to evaluate OT cybersecurity risks through a multi-layered approach that integrates asset inventories, governance-based questionnaires, and external threat intelligence databases such as MITRE ATT&CK and CVE. The tool applies fuzzy logic to map potential threats and vulnerabilities, and generates graphical outputs including risk level visualizations, threat distribution charts, and lifecycle-based exposure matrices. Through experimentation on an industrial platform and validation via intrusion testing, the tool demonstrated its capacity to identify high-risk assets and operational stages that require mitigation. The framework provides a practical foundation for structured, scalable, and governance-aligned OT risk assessments.
The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios.
Serge Benoliel, Florence Foudrain· International Conference on...· 0 citations
The rapid digitalization and interconnectivity of global supply chains have significantly increased exposure to cybersecurity risks, particularly through third-party dependencies, IoT integration, remote access, and shared digital infrastructures. Traditional supply chain auditing approaches, which rely heavily on periodic compliance checks and retrospective assessments, are increasingly insufficient for identifying dynamic and systemic cyber risks. This study proposes an integrated machine learning-based cybersecurity risk framework for supply chain auditing and examines how ML models capture multidimensional and time-related cybersecurity risk indicators. A quantitative experimental design was adopted using a hybrid dataset that combines empirically grounded cybersecurity indicators with simulated supply chain cyber risk scenarios. The synthetic data were generated through controlled attack scenarios using AttackIQ and Cymulate simulation platforms and were conceptually aligned with the NIST Cybersecurity Framework, ENISA guidelines, and the Verizon DBIR. IBM Watsonx was used to develop and evaluate supervised and time-series models, including Random Forest and ARIMA. The integrated risk flag was constructed as a composite cybersecurity risk representation derived from standardized audit-relevant indicators. The findings show that the integrated ML-based risk framework achieved strong classification performance, with accuracy = 98.5% and F1 > 0.98. The results primarily reflect the internal consistency of the constructed cybersecurity risk framework rather than direct prediction of real-world cyber incidents. Sensitivity analyses confirmed the robustness of the framework under different synthetic data conditions. Random Forest effectively captured complex nonlinear risk patterns, while ARIMA modeled temporally persistent risk indicators. In contrast, compliance metrics showed limited ability to reflect actual cybersecurity risk exposure.
Hossam Hassan, Rehab Hashem, Ahmad A. Abu-Musa· Future Business Journal· 0 citations
As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance, operational resilience, and assurance in risk reporting. However, most prevalent cybersecurity risk frameworks vary significantly in their intent, design, and analytical approach. This makes it difficult for organizations to understand how each framework may meet their business needs. This study presents an AI-enhanced multi-criteria decision support approach for evaluating cybersecurity risk frameworks. The model incorporates machine learning-driven risk scoring as a conceptual input layer, enhancing the objectivity and analytical rigor of the comparison without executing new predictive algorithms. The methodology includes a hybrid approach of literature review, document analysis, and multi-criteria decision analysis (MCDA) to compare and rank NIST CSF, ISO 27001, FAIR, OCTAVE, and CRAMM based on eight criteria that are designed to represent modern requirements for risk frameworks, including governance, scalability, quantitative focus, and interoperability. These criteria also reflect differences in security metrics supported by each framework to provide an organized means to compare qualitative versus quantitative measurement methodologies. The results indicate that NIST CSF performs the best overall in agility, business alignment, and interoperability. ISO 27001 outperforms all others in established governance and compliance. FAIR outperforms all others in quantitative risk analysis and provides superior analytical depth that other frameworks do not offer. OCTAVE and CRAMM function well in legacy systems but lack scalability and are not well-suited for modern distributed systems. Robustness analysis shows that the ranking of NIST CSF, ISO 27001, and FAIR is consistent under different weighting combinations and industry types. The result of this research demonstrates that a combined or hybrid approach to cybersecurity risk framework selection, such as using NIST CSF with FAIR, can give organizations a more well-rounded foundation for applying machine learning-enabled risk analytics with cyber controls. This research also offers a reusable decision support tool that organizations can leverage when aligning their risk priorities to the features of cybersecurity risk frameworks.
Oluwatosin J. Olaore, Abeer F. Alkhwaldi· Journal of Cybersecurity and...· 0 citations
The digital transformation of Critical Information Infrastructure (CII) and Industrial Control Systems (ICS) through Industry 4.0 technologies introduces significant cybersecurity challenges. While existing research examines technologies individually, little attention has been given to how their combined adoption reshapes the overall threat landscape. This study presents a Multivocal Literature Review, synthesising evidence from 41 academic and industry sources (January 2010–June 2026) and proposes an Integrated Cyber Risk Pathway Model that traces how technology adoption introduces interconnected vulnerabilities, expands threat actor capabilities, produces cyber-physical impacts, and ultimately defines resilience requirements. Three findings emerge: 1) emerging technologies play a dual role, enhancing operational capability while expanding the attack surface; 2) cyber-attacks have evolved from specialist ICS operations to ecosystem-level compromises exploiting supply chains and shared platforms; 3) the resulting vulnerabilities are systemically interconnected, creating risks that prevention-focused cybersecurity alone cannot fully address. The study argues that protecting modern critical infrastructure requires a shift to resilience-centred strategies supported by governance, secure system design and cross-sector collaboration.
Unknown authors· International Journal of Adv...· 0 citations
Small and medium-sized enterprises (SMEs) face increasing exposure to complex and high-impact cyber threats, while operating under significant financial and organizational resource constraints. Unlike large corporations, SMEs often lack the capacity to invest extensively in cybersecurity, making inefficient or poorly prioritized investments particularly costly. Prior research has highlighted scenario-based cyber stress testing as a method for capturing low-probability, high-impact cyber events, as well as exposure-based indices for assessing vulnerabilities of critical SME assets. Building on this line of research, the present study advances the conceptual development of a theoretical pathway that links scenario-based cyber risk assessment with investment-oriented decision logic. Drawing exclusively on the existing literature, the paper synthesizes key theoretical perspectives on cyber stress scenarios, asset criticality, risk exposure, and the economic interpretation of cyber risk in resource-constrained environments. It proposes a conceptual framework illustrating how scenario-based risk assessments and exposure indices can be translated into investment-relevant insights without relying on empirical case studies. Rather than introducing a fully operational investment model, the study represents a conceptual extension of prior work and establishes the theoretical foundations necessary for the future development of decision-support tools aimed at guiding SMEs in allocating scarce resources to strengthen cyber resilience under conditions of uncertainty.
Alona Bahmanova, Nataļja Lāce· International Scientific Con...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.