Paper Type

ERF

Abstract

We propose a Machine Learning Cyberattack Risk Management (ML-CRM) model. The model is based on Protection Motivation Theory (PMT) and Rational Choice Theory (RCT) and consists of three sections: Cyberattack Risk Assessment (CRA), Cyberattack Risk Quantification (CRQ), and Cyberattack Risk Mitigation (CRM). Drawing upon Protection Motivation Theory, the CRA module assess the likelihood of occurrence of cyberattacks on Critical Infrastructure Information (CII) organisations with following inputs: (i) attack duration, (ii) attack bandwidth rate, and (iii) attack transmission rate strategized by hackers, and to understand organisational dimension we include (iv) cybersecurity posture of organisation, and (v) organisation’s IT governance. Next in the CRQ module, we compute the expected loss an organisation suffers when a cyberattack occurs. Finally, in our CRM module, we recommend various mitigation strategies to the CISO of an organisation to reduce, accept, or transfer cyber risk.

Paper Number

1545

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Cyberattack Risk Management Framework for Organisations: A Machine Learning Based Approach

We propose a Machine Learning Cyberattack Risk Management (ML-CRM) model. The model is based on Protection Motivation Theory (PMT) and Rational Choice Theory (RCT) and consists of three sections: Cyberattack Risk Assessment (CRA), Cyberattack Risk Quantification (CRQ), and Cyberattack Risk Mitigation (CRM). Drawing upon Protection Motivation Theory, the CRA module assess the likelihood of occurrence of cyberattacks on Critical Infrastructure Information (CII) organisations with following inputs: (i) attack duration, (ii) attack bandwidth rate, and (iii) attack transmission rate strategized by hackers, and to understand organisational dimension we include (iv) cybersecurity posture of organisation, and (v) organisation’s IT governance. Next in the CRQ module, we compute the expected loss an organisation suffers when a cyberattack occurs. Finally, in our CRM module, we recommend various mitigation strategies to the CISO of an organisation to reduce, accept, or transfer cyber risk.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.