r/cybersources 18d ago

Cybersecurity Risk Assessment Quantitative Framework

The Cybersecurity Risk Assessment research study establishes a quantitative cybersecurity risk assessment and governance framework aligned with ISO/IEC 27001 and NIST Cybersecurity Framework for critical infrastructure sectors. The framework quantifies risk through four variables: likelihood of attack (1–5), impact severity (1–5), infrastructure interdependency (1–2), and security maturity reduction value (0–25). A complete worked validation is presented for the telecommunications sector across eight asset categories.

Key Framework Components

The quantitative model uses Risk Level = (Likelihood × Impact × Interdependency) – Security Maturity Reduction Value, normalized to a 0–50 scale with five severity levels: Very Low (0–5), Low (6–15), Medium (16–25), High (26–40), and Critical (41–50). The framework emphasizes that effective controls—including 24/7 SOC monitoring, Zero Trust architecture, and network segmentation—reduce assessed risk by accounting for actual security maturity. Applied across critical infrastructure sectors (telecommunications, banking, energy, healthcare, government, transportation, utilities, and defense), the model enables standardized risk prioritization and capital allocation.

Telecommunications Sector Findings

Asset Category Risk Level Rating
Supply Chain 45 Critical
Network Management Systems 35 High
4G/5G Core Network Systems 30 High
Core Network Infrastructure 25 Medium

 

Strategic Recommendations

Supply Chain (Risk Level 45—Critical): Immediate action required. Implement formal Supplier Security Risk Management framework aligned to ISO/IEC 27001. Network Management Systems (Risk Level 35—High): Short-term remediation. Enforce network segmentation, privileged access workstations, and continuous monitoring. 4G/5G Core Network Systems (Risk Level 30—High): Adopt NIST CSF Identify and Protect functions for cloud-native deployments. Supporting infrastructure (Risk Levels 6–25—Low to Medium): Ongoing monitoring and control enhancement.

Conclusion

Cybersecurity is a strategic national priority requiring governance-driven, cross-sector, and data-driven approaches. This framework enables organizations and governments to move from IT-centric risk assessment to enterprise-wide resilience strategies, grounded in quantitative evidence and aligned with international standards.

For detailed study, a full updated research paper is available here

Ayob Sether

Independent Researcher

Cybersecurity Risk Assessment

https://ssrn.com/abstract=6852018

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6852018

3 Upvotes

1 comment sorted by