MAGIC: A Method for Assessing Cyber Incidents Occurrence

06/23/2022
by   Massimo Battaglioni, et al.
0

The assessment of cyber risk plays a crucial role for cybersecurity management, and has become a compulsory task for certain types of companies and organizations. This makes the demand for reliable cyber risk assessment tools continuously increasing, especially concerning quantitative tools based on statistical approaches. Probabilistic cyber risk assessment methods, however, follow the general paradigm of probabilistic risk assessment, which requires the magnitude and the likelihood of incidents as inputs. Unfortunately, for cyber incidents, the likelihood of occurrence is hard to estimate based on historical and publicly available data; so, expert evaluations are commonly used, which however leave space to subjectivity. In this paper, we propose a novel probabilistic model, called MAGIC (Method for AssessinG cyber Incidents oCcurrence), to compute the likelihood of occurrence of a cyber incident, based on the evaluation of the cyber posture of the target organization. This allows deriving tailor-made inputs for probabilistic risk assessment methods, like HTMA (How To Measure Anything in cybersecurity risk), FAIR (Factor Analysis of Information Risk) and others, thus considerably reducing the margin of subjectivity in the assessment of cyber risk. We corroborate our approach through a qualitative and a quantitative comparison with several classical methods.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/15/2022

Epistemological Equation for Analysing Uncontrollable States in Complex Systems: Quantifying Cyber Risks from the Internet of Things

To enable quantitative risk assessment of uncontrollable risk states in ...
research
05/17/2022

Cyber Risk Assessment for Capital Management

Cyber risk is an omnipresent risk in the increasingly digitized world th...
research
11/26/2019

Assessing Supply Chain Cyber Risks

Risk assessment is a major challenge for supply chain managers, as it po...
research
06/26/2023

Probabilistic Risk Assessment of an Obstacle Detection System for GoA 4 Freight Trains

In this paper, a quantitative risk assessment approach is discussed for ...
research
12/16/2017

Uncertainty in Cyber Security Investments

When undertaking cyber security risk assessments, we must assign numeric...
research
02/09/2023

Pricing cyber-insurance for systems via maturity models

Risks associated with information technology systems present a complex m...
research
06/21/2018

Towards a Reconceptualisation of Cyber Risk: An Empirical and Ontological Study

The prominence and use of the concept of cyber risk has been rising in r...

Please sign up or login with your details

Forgot password? Click here to reset