A Bounded Threat–Actor-Conditioned Cyber Risk Assessment Framework for Networked Systems Under Data-Scarce Conditions
Cyber risk assessment often combines likelihood and impact, but likelihood is difficult to justify when incident data are scarce and threat relevance depends on a specific actor. Existing attacker-aware methods improve context but frequently require attack graphs, vulnerability inventories, threat-intelligence feeds, exploit scores, telemetry, or calibrated probabilistic models. We propose a lightweight, auditable method that converts a multi-factor threat–actor profile into an actor–threat compatibility score and conditions a baseline likelihood through a bounded log-odds transformation. The model distinguishes uncertainty about which actor class is relevant from concurrent exposure to several active actor classes and propagates parameter uncertainty into decision-oriented rank robustness. Evaluation uses a reconstructed 35-scenario networked-system benchmark with 17 adversarial and 18 non-adversarial threats. Reproduction of the legacy calculation identifies three adjusted probability-like values above one, with a maximum of 1.54. The proposed formulation produces no boundedness or monotonicity violations in one million randomized stress tests. Compared with a static baseline, the resulting ranking remains globally stable (Spearman ρ=0.982; Kendall τb=0.911) while selectively reprioritizing actor-sensitive threats. A 20,000-run Monte Carlo analysis quantifies uncertainty intervals and top-five membership probabilities. At the reference κ=ln4, a transfer evaluation on an independent published video-conferencing case yields strong rank agreement with the source capability-based method (Spearman ρ=0.986; Kendall τb=0.966). These results establish mathematical and scenario-based robustness and portability, not calibration against observed incident frequencies. The method provides a transparent bridge between static ordinal risk matrices and data-intensive probabilistic cyber-risk models.
Authors
- Victor Zhora (ORCID: https://orcid.org/0000-0003-2679-3056)
- Volodymyr O. Artemchuk (ORCID: https://orcid.org/0000-0001-8819-4564)
- С. Матвєєв (ORCID: https://orcid.org/0009-0002-4779-9350)
- Anatolii Antoniuk (ORCID: https://orcid.org/0009-0001-9903-5021)
Institutions
- Pukhov Institute for Modelling in Energy Engineering (UA)
- Academician Yuriy Bugay International Scientific and Technical University (UA)
- Institute of Software Systems (UA)
Publication Details
- Journal
- Computers
- Published
- 2026-09-24
- DOI
- https://doi.org/10.3390/computers15100649
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00