A DATA-DRIVEN MULTI-CRITERIA DECISION FRAMEWORK FOR CYBERSECURITY INVESTMENT AND PROJECT PRIORITIZATION IN BANKING

Investments in cybersecurity prioritization by banks are usually determined based on expert judgement, which is hard to audit, reproduce and defend from regulators and boards of directors. We propose a hybrid, data-driven multi-criteria decision framework where two of the eight prioritization criteria (risk reduction and threat-likelihood coverage) are based on actual threat-intelligence data rather than opinion while keeping the other six transparent and analyst-editable. The data layer consists of a combination of 337,705 CVE records, Exploit Prediction Scoring System (EPSS) exploit-probability scores, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities flags, and 893 banking-sector incidents identified over the use of VERIS Community Database (NAICS code 52).This data-driven severity ordering is held in a consistent feature-ordered sense across seven attack-type categories using a GPU-trained feed-forward deep neural network and is subsequently reweighted toward the specific banking threat landscape observable from the incident data. Next, twelve candidate security investments are ranked using five different independent methods such as Analytic Hierarchy Process (AHP), Shannon entropy weighting, TOPSIS, Fuzzy-TOPSIS and VIKOR. Pairwise Spearman correlation from 0.90 to 0.97 and strong cross-method agreement (Kendall's W=0.944), with the highest-ranked solution–vulnerability management platform–is stable across 232 weight-perturbation trials (rank-reversal rate=zero; mean full-ranking Spearman correlation against baseline≥0.997). We present the framework, its validation method and limitations, including a data quality artifact in the KO given in the KEV field and that criteria derived from configurations are illustrative.

Authors

Institutions

Publication Details

Journal
Cuestiones de Fisioterapia
Published
2026-10-06
DOI
https://doi.org/10.48047/xe7af830
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

A DATA-DRIVEN MULTI-CRITERIA DECISION FRAMEWORK FOR CYBERSECURITY INVESTMENT AND PROJECT PRIORITIZATION IN BANKING

Masrufa Tasnim, Dr. Md. Sumsuzzaman, Tanaya Jakir, Rasel Hossain Babu et al.
Cuestiones de Fisioterapia
Information and Cyber Security
article

A DATA-DRIVEN MULTI-CRITERIA DECISION FRAMEWORK FOR CYBERSECURITY INVESTMENT AND PROJECT PRIORITIZATION IN BANKING

Masrufa Tasnim, Dr. Md. Sumsuzzaman, Tanaya Jakir, Rasel Hossain Babu, Kabita Shamia Akter, Md Abdullah Enayet, Mst Anupa Nasrin Khan, Shakila Sultana
article en

Abstract

Investments in cybersecurity prioritization by banks are usually determined based on expert judgement, which is hard to audit, reproduce and defend from regulators and boards of directors. We propose a hybrid, data-driven multi-criteria decision framework where two of the eight prioritization criteria (risk reduction and threat-likelihood coverage) are based on actual threat-intelligence data rather than opinion while keeping the other six transparent and analyst-editable. The data layer consists of a combination of 337,705 CVE records, Exploit Prediction Scoring System (EPSS) exploit-probability scores, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities flags, and 893 banking-sector incidents identified over the use of VERIS Community Database (NAICS code 52).This data-driven severity ordering is held in a consistent feature-ordered sense across seven attack-type categories using a GPU-trained feed-forward deep neural network and is subsequently reweighted toward the specific banking threat landscape observable from the incident data. Next, twelve candidate security investments are ranked using five different independent methods such as Analytic Hierarchy Process (AHP), Shannon entropy weighting, TOPSIS, Fuzzy-TOPSIS and VIKOR. Pairwise Spearman correlation from 0.90 to 0.97 and strong cross-method agreement (Kendall's W=0.944), with the highest-ranked solution–vulnerability management platform–is stable across 232 weight-perturbation trials (rank-reversal rate=zero; mean full-ranking Spearman correlation against baseline≥0.997). We present the framework, its validation method and limitations, including a data quality artifact in the KO given in the KEV field and that criteria derived from configurations are illustrative.

Cuestiones de FisioterapiaVol. 55(2)
American International College (US), University of Dhaka (BD), University of the Cumberlands (US), National University Bangladesh (BD), University of the Potomac (US), University of Rajshahi (BD)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.