Threat-Informed Cyber Resilience Index: A Probabilistic Quantitative Approach to Measure Defence Effectiveness Against Cyber Attacks
Lampis Alevizos, Vinh-Thong Ta

TL;DR
This paper presents a probabilistic, threat-informed Cyber Resilience Index (CRI) that quantifies an organization's defense effectiveness against cyber-attacks, aiding strategic decision-making under uncertainty.
Contribution
It introduces a novel mathematical model based on POMDPs that translates complex threat intelligence into an actionable, unified resilience metric for organizations.
Findings
The CRI provides a dynamic measure of cyber resilience.
The model incorporates real-world attacker tactics and uncertainties.
It enables data-driven resource allocation and strategic planning.
Abstract
In the dynamic cyber threat landscape, effective decision-making under uncertainty is crucial for maintaining robust information security. This paper introduces the Cyber Resilience Index (CRI), a threat-informed probabilistic approach to quantifying an organisation's defence effectiveness against cyber-attacks (campaigns). Building upon the Threat-Intelligence Based Security Assessment (TIBSA) methodology, we present a mathematical model that translates complex threat intelligence into an actionable, unified metric similar to a stock market index, that executives can understand and interact with while teams can act upon. Our method leverages Partially Observable Markov Decision Processes (POMDPs) to simulate attacker behaviour considering real-world uncertainties and the latest threat actor tactics, techniques, and procedures (TTPs). This allows for dynamic, context-aware evaluation of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInfrastructure Resilience and Vulnerability Analysis · Information and Cyber Security
