Paper Type
ERF
Abstract
We propose a Machine Learning Cyberattack Risk Management (ML-CRM) model. The model is based on Protection Motivation Theory (PMT) and Rational Choice Theory (RCT) and consists of three sections: Cyberattack Risk Assessment (CRA), Cyberattack Risk Quantification (CRQ), and Cyberattack Risk Mitigation (CRM). Drawing upon Protection Motivation Theory, the CRA module assess the likelihood of occurrence of cyberattacks on Critical Infrastructure Information (CII) organisations with following inputs: (i) attack duration, (ii) attack bandwidth rate, and (iii) attack transmission rate strategized by hackers, and to understand organisational dimension we include (iv) cybersecurity posture of organisation, and (v) organisation’s IT governance. Next in the CRQ module, we compute the expected loss an organisation suffers when a cyberattack occurs. Finally, in our CRM module, we recommend various mitigation strategies to the CISO of an organisation to reduce, accept, or transfer cyber risk.
Paper Number
1545
Recommended Citation
Srivastava, Priyanka and Mukhopadhyay, Arunabha, "Cyberattack Risk Management Framework for Organisations: A Machine Learning Based Approach" (2026). AMCIS 2026 Proceedings. 24.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/24
Cyberattack Risk Management Framework for Organisations: A Machine Learning Based Approach
We propose a Machine Learning Cyberattack Risk Management (ML-CRM) model. The model is based on Protection Motivation Theory (PMT) and Rational Choice Theory (RCT) and consists of three sections: Cyberattack Risk Assessment (CRA), Cyberattack Risk Quantification (CRQ), and Cyberattack Risk Mitigation (CRM). Drawing upon Protection Motivation Theory, the CRA module assess the likelihood of occurrence of cyberattacks on Critical Infrastructure Information (CII) organisations with following inputs: (i) attack duration, (ii) attack bandwidth rate, and (iii) attack transmission rate strategized by hackers, and to understand organisational dimension we include (iv) cybersecurity posture of organisation, and (v) organisation’s IT governance. Next in the CRQ module, we compute the expected loss an organisation suffers when a cyberattack occurs. Finally, in our CRM module, we recommend various mitigation strategies to the CISO of an organisation to reduce, accept, or transfer cyber risk.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC