A Bayesian–Markov Framework for Proactive and Dynamic Cyber Risk Assessment Driven by EPSS
Pavlos Cheimonidis, Konstantinos Rantos · 2025
Cyberattacks continue to evolve in sophistication, posing significant risks to organizations that rely on networked infrastructures. Traditional risk assessment methods, often reliant on static vulnerability metrics, struggle to keep pace with rapidly changing threats. In this paper, we present a dynamic and proactive cyber risk assessment model that leverages the Exploit Prediction Scoring System (EPSS) to quantify short-term (30day) exploit likelihoods. Our framework integrates Bayesian networks to account for both vulnerabilities and network topologies, then constructs absorbing Markov chains for each enumerated attack path using a Depth-First Search (DFS) of the environment. This combination provides (i) day-by-day exploitation probability distributions for individual assets, (ii) time-to-compromise estimates indicating how soon an attacker might reach highvalue targets, and (iii) a continuous risk metric derived from threat likelihoods and asset impact. We apply the method to a representative Industrial Control System (ICS) environment, demonstrating how a single highly exploitable vulnerability can enable an attacker to compromise critical assets in under ten days, while paths with low-probability vulnerabilities may not yield full compromise within the same window. By pinpointing which paths and assets pose the greatest near-term danger, security teams gain actionable insights for prioritizing patches and mitigation strategies. The results highlight the importance of incorporating dynamic exploitation probabilities into risk analyses, especially in high-stakes ICS contexts.