A Threat-Intelligence Driven Methodology to Incorporate Uncertainty in Cyber Risk Analysis and Enhance Decision Making

02/25/2023
by   Martijn Dekker, et al.
0

The predictability and understandability of the world around us is limited, and many events are uncertain. It can be difficult to make decisions in these uncertain circumstances, as demonstrated by the changing measures taken to contain the COVID-19 pandemic. These decisions are not necessarily incorrect, but rather a reflection of the difficulty of decision making under uncertainty, where the probability and impact of events and measures are unknown. Information security is rapidly positioning itself around making decisions in uncertain situations. Which means that, it is not just about preventing or managing probable risks, but rather about dealing with unpredictable probabilities and effects. To contend with, information security leaders should therefore include strategies that reduce uncertainty and hence improve the quality of decision making. Risk assessment is a principal element of evidence-based decision making, especially in an ever-changing cyber threat landscape that constantly introduces uncertainties. Thus, it is essential to recognize that addressing uncertainty requires a new methodology and risk analysis approach that considers both known unknowns and unknown unknowns. To address this challenge, we propose the threat-intelligence based security assessment, and discuss a decision-making strategy under uncertainty, both of which support decision makers in this complex undertaking.

READ FULL TEXT

page 1

page 13

research
02/16/2023

Cyber-risk Perception and Prioritization for Decision-Making and Threat Intelligence

Cyber-risk assessment is gaining momentum due to the wide range of resea...
research
12/16/2017

Uncertainty in Cyber Security Investments

When undertaking cyber security risk assessments, we must assign numeric...
research
02/01/2022

Protection or Peril of Following the Crowd in a Pandemic-Concurrent Flood Evacuation

The decisions of whether and how to evacuate during a climate disaster a...
research
12/29/2017

Threat Modeling Data Analysis in Socio-technical Systems

Our decision-making processes are becoming more data driven, based on da...
research
07/03/2009

Robustness and Adaptiveness Analysis of Future Fleets

Making decisions about the structure of a future military fleet is a cha...
research
09/17/2021

Risk Assessment for Performance-Driven Building Design with BIM-Based Parametric Methods

A growing demand for handling uncertainties and risks in performance-dri...
research
06/15/2020

Accounting for Uncertainty During a Pandemic

We discuss several issues of statistical design, data collection, analys...

Please sign up or login with your details

Forgot password? Click here to reset