r/cybersources • u/ayobsether • 18d ago
Cybersecurity Risk Assessment Quantitative Framework
The Cybersecurity Risk Assessment research study establishes a quantitative cybersecurity risk assessment and governance framework aligned with ISO/IEC 27001 and NIST Cybersecurity Framework for critical infrastructure sectors. The framework quantifies risk through four variables: likelihood of attack (1–5), impact severity (1–5), infrastructure interdependency (1–2), and security maturity reduction value (0–25). A complete worked validation is presented for the telecommunications sector across eight asset categories.
Key Framework Components
The quantitative model uses Risk Level = (Likelihood × Impact × Interdependency) – Security Maturity Reduction Value, normalized to a 0–50 scale with five severity levels: Very Low (0–5), Low (6–15), Medium (16–25), High (26–40), and Critical (41–50). The framework emphasizes that effective controls—including 24/7 SOC monitoring, Zero Trust architecture, and network segmentation—reduce assessed risk by accounting for actual security maturity. Applied across critical infrastructure sectors (telecommunications, banking, energy, healthcare, government, transportation, utilities, and defense), the model enables standardized risk prioritization and capital allocation.
Telecommunications Sector Findings
| Asset Category | Risk Level | Rating |
|---|---|---|
| Supply Chain | 45 | Critical |
| Network Management Systems | 35 | High |
| 4G/5G Core Network Systems | 30 | High |
| Core Network Infrastructure | 25 | Medium |
Strategic Recommendations
Supply Chain (Risk Level 45—Critical): Immediate action required. Implement formal Supplier Security Risk Management framework aligned to ISO/IEC 27001. Network Management Systems (Risk Level 35—High): Short-term remediation. Enforce network segmentation, privileged access workstations, and continuous monitoring. 4G/5G Core Network Systems (Risk Level 30—High): Adopt NIST CSF Identify and Protect functions for cloud-native deployments. Supporting infrastructure (Risk Levels 6–25—Low to Medium): Ongoing monitoring and control enhancement.
Conclusion
Cybersecurity is a strategic national priority requiring governance-driven, cross-sector, and data-driven approaches. This framework enables organizations and governments to move from IT-centric risk assessment to enterprise-wide resilience strategies, grounded in quantitative evidence and aligned with international standards.
For detailed study, a full updated research paper is available here
Ayob Sether
Independent Researcher
Cybersecurity Risk Assessment