Fuzzy Logic–Based Cybersecurity Risk Assessment Using CODAS and WASPAS with Circular Linguistic T-Spherical Fuzzy Aggregation Operators
Abstract Cybersecurity risk assessment has become increasingly complex in modern digital environments due to rapid technological advancements, strong interdependencies among system components, and the presence of uncertain, incomplete, and imprecise threat information. Consequently, effective cybersecurity decision-making requires advanced analytical frameworks capable of simultaneously evaluating multiple, often conflicting, factors, including threat severity, system vulnerabilities, asset criticality, attack likelihood, defense effectiveness, and potential consequences. To address these challenges, this study introduces a novel fuzzy modeling framework, termed circular linguistic T-spherical fuzzy sets (CLT-SFSs), which is specifically designed to capture the ambiguity, uncertainty, and hesitation inherent in cybersecurity evaluations. By integrating linguistic variables within the fuzzy framework, the proposed model enables experts to express their assessments using intuitive and flexible linguistic terms, thereby enhancing the practicality and reliability of qualitative and semi-quantitative decision-making. Furthermore, several weighted and ordered weighted arithmetic and geometric aggregation operators are developed based on newly established operational laws for circular linguistic T-spherical fuzzy information. Their fundamental mathematical properties and special cases are investigated to demonstrate their robustness, flexibility, and suitability for dynamic cybersecurity environments. These aggregation operators are subsequently incorporated into the CODAS and WASPAS multi-criteria decision-making methods to prioritize cybersecurity risks and evaluate appropriate defensive strategies. In addition, a group decision-making framework is proposed to facilitate collaborative risk assessment by incorporating the opinions of multiple experts. To validate the effectiveness of the proposed methodology, practical case studies involving cybersecurity risk assessment and the selection of suitable security countermeasures under uncertain conditions are presented. Comparative and analytical results demonstrate that the proposed framework outperforms existing approaches in managing uncertainty, vagueness, and conflicting evaluation criteria. Overall, the proposed methodology provides a flexible, robust, and reliable decision-support framework for effective cybersecurity risk management in complex and uncertain digital environments.
Authors
- Abbas Ali
- Kaleem Ullah (ORCID: https://orcid.org/0009-0005-6793-9172)
- Zabihullah Movaheedi
- Noor Rehman
Institutions
- Bacha Khan University (PK)
- Riphah International University (PK)
- Herat University (AF)
Publication Details
- Journal
- International Journal of Computational Intelligence Systems
- Published
- 2026-09-21
- DOI
- https://doi.org/10.1007/s44196-026-01558-8
- Primary Topic
- Infrastructure Resilience and Vulnerability Analysis
- Type
- article
- Field-Weighted Citation Impact
- 0.00