The ICRIM framework: an integrated conceptual model of cyber resilience indicators
Abstract Cyber resilience measurement remains conceptually fragmented across technical, organizational, and human-oriented research traditions. Existing approaches differ in terminology, level of analysis, form of operationalization, and evidence basis, while indicators are often not clearly distinguished from the metrics used to assess them. This study conducts a structured, theory-informed conceptual synthesis of 33 publications issued between 2011 and 2024 to examine how cyber resilience indicators have been conceptualized, operationalized, demonstrated, and validated. Using the a priori theory-informed structure described in the methodology, the analysis organizes the reviewed indicator families into three interdependent domains: technical, organizational, and socio-psychological and relational. Within the corpus, technical contributions typically use mathematical, temporal, structural, or probabilistic metrics. Organizational contributions rely mainly on maturity criteria, questionnaires, expert judgment, mission-oriented models, or hybrid approaches. Socio-psychological and relational constructs generally appear within broader cognitive, social, workforce, or organizational assessment structures rather than as standalone cyber resilience measures. Based on this synthesis, the study proposes the Integrated Cyber Resilience Indicators Model (ICRIM), a non-hierarchical conceptual structure for organizing heterogeneous indicator families, distinguishing indicators from operational metrics, and clarifying cross-domain relationships. ICRIM is not presented as a validated assessment instrument and does not prescribe universal metrics, weights, thresholds, or scoring procedures. Its contribution is to provide a transparent analytical basis for the future development and empirical testing of context-appropriate cyber resilience measures.
Authors
- Vassiliadis Savvas
- Vasiliki Tzavara
Institutions
- University of West Attica (GR)
Publication Details
- Journal
- International Journal of Information Security
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1007/s10207-026-01341-y
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00