Calculating Business Impact Assessment of Cyber-Threats

Diogo Guimaraes Alves, Filipe Apolinário, Bernardo Pacheco, Nelson Escravana, António Grilo · 2023

Organizations are becoming increasingly more reliant on information and communication technology (ICT) to support their day-to-day operations, which includes the storage and access of critical information. Unfortunately, this dependency on ICT systems leaves organizations vulnerable to cyber-attacks, which can cause serious damage to their critical processes. By estimating the impact caused by a given cyber-attack in a particular organization, it is possible to prioritize the mitigation actions and preventative measures to be considered in the risk management procedure. This paper presents the Business Impact Calculator (BusICalc) methodology. BusICalc was designed to offer a method capable of quantifying the impact that a cyber-threat would cause, once exploited, to the organization's critical processes. A proof-of-concept of BusICalc was developed for evaluation purposes and integrated with the risk analysis system, BIA (Business Impact Assessment). The proposed methodology was evaluated using a dataset corresponding to a Critical Infrastructure, and the conducted experiments show that BusICalc is scalable and effective in yielding reasonable values for the impact of cvberthreats,

Read the paper · More papers on PaperTik