A Bounded Threat–Actor-Conditioned Cyber Risk Assessment Framework for Networked Systems Under Data-Scarce Conditions

Cyber risk assessment often combines likelihood and impact, but likelihood is difficult to justify when incident data are scarce and threat relevance depends on a specific actor. Existing attacker-aware methods improve context but frequently require attack graphs, vulnerability inventories, threat-intelligence feeds, exploit scores, telemetry, or calibrated probabilistic models. We propose a lightweight, auditable method that converts a multi-factor threat–actor profile into an actor–threat compatibility score and conditions a baseline likelihood through a bounded log-odds transformation. The model distinguishes uncertainty about which actor class is relevant from concurrent exposure to several active actor classes and propagates parameter uncertainty into decision-oriented rank robustness. Evaluation uses a reconstructed 35-scenario networked-system benchmark with 17 adversarial and 18 non-adversarial threats. Reproduction of the legacy calculation identifies three adjusted probability-like values above one, with a maximum of 1.54. The proposed formulation produces no boundedness or monotonicity violations in one million randomized stress tests. Compared with a static baseline, the resulting ranking remains globally stable (Spearman ρ=0.982; Kendall τb=0.911) while selectively reprioritizing actor-sensitive threats. A 20,000-run Monte Carlo analysis quantifies uncertainty intervals and top-five membership probabilities. At the reference κ=ln4, a transfer evaluation on an independent published video-conferencing case yields strong rank agreement with the source capability-based method (Spearman ρ=0.986; Kendall τb=0.966). These results establish mathematical and scenario-based robustness and portability, not calibration against observed incident frequencies. The method provides a transparent bridge between static ordinal risk matrices and data-intensive probabilistic cyber-risk models.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-09-24
DOI
https://doi.org/10.3390/computers15100649
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A Bounded Threat–Actor-Conditioned Cyber Risk Assessment Framework for Networked Systems Under Data-Scarce Conditions

Victor Zhora, Volodymyr O. Artemchuk, С. Матвєєв, Anatolii Antoniuk
Computers
Information and Cyber Security
article

A Bounded Threat–Actor-Conditioned Cyber Risk Assessment Framework for Networked Systems Under Data-Scarce Conditions

Victor Zhora, Volodymyr O. Artemchuk, С. Матвєєв, Anatolii Antoniuk
article en

Abstract

Cyber risk assessment often combines likelihood and impact, but likelihood is difficult to justify when incident data are scarce and threat relevance depends on a specific actor. Existing attacker-aware methods improve context but frequently require attack graphs, vulnerability inventories, threat-intelligence feeds, exploit scores, telemetry, or calibrated probabilistic models. We propose a lightweight, auditable method that converts a multi-factor threat–actor profile into an actor–threat compatibility score and conditions a baseline likelihood through a bounded log-odds transformation. The model distinguishes uncertainty about which actor class is relevant from concurrent exposure to several active actor classes and propagates parameter uncertainty into decision-oriented rank robustness. Evaluation uses a reconstructed 35-scenario networked-system benchmark with 17 adversarial and 18 non-adversarial threats. Reproduction of the legacy calculation identifies three adjusted probability-like values above one, with a maximum of 1.54. The proposed formulation produces no boundedness or monotonicity violations in one million randomized stress tests. Compared with a static baseline, the resulting ranking remains globally stable (Spearman ρ=0.982; Kendall τb=0.911) while selectively reprioritizing actor-sensitive threats. A 20,000-run Monte Carlo analysis quantifies uncertainty intervals and top-five membership probabilities. At the reference κ=ln4, a transfer evaluation on an independent published video-conferencing case yields strong rank agreement with the source capability-based method (Spearman ρ=0.986; Kendall τb=0.966). These results establish mathematical and scenario-based robustness and portability, not calibration against observed incident frequencies. The method provides a transparent bridge between static ordinal risk matrices and data-intensive probabilistic cyber-risk models.

ComputersVol. 15(10)
Pukhov Institute for Modelling in Energy Engineering (UA), Academician Yuriy Bugay International Scientific and Technical University (UA), Institute of Software Systems (UA)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.