Event-Based Cybersecurity Risk Assessment: Identifying Potential Cyber-Attacks in Organisations

Wan Azlena Wan Mohamad, Noor Hayani Abd Rahim, Nurul Nuha Abdul Molok · International Journal on Perceptive and Cognitive Computing · 2025

Cybersecurity risk assessment is crucial for organisations since cyber threats are becoming increasingly sophisticated and dynamic. This study investigates how organisations identify potential cyber-attacks within an event-based risk assessment context. Using a qualitative approach, semi-structured interviews were conducted with ten cybersecurity experts from diverse organisations. The experts possess extensive strategic, technical, and advisory expertise in the field. Thematic analysis of the data revealed four key practices: (i)collaborative brainstorming involving diverse stakeholders, (ii)referring to historical data and past incident logs, (iii)staying updated on current cyber-attacks trends, and (iv)using established frameworks such as ISO/IEC 27005 supplemented with dynamic resources. These findings underscore the importance of integrating diverse methods and perspectives into event-based cybersecurity risk assessments to address evolving threats. The study contributes to theory and practice by offering actionable insights for organisations to identify potential cyber-attacks within an event-based cybersecurity risk assessment framework. Limitations are acknowledged, including reliance on self-reported data and a small sample size, with recommendations provided for future research.

Read the paper · More papers on PaperTik