DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence
Computer Science and Information Systems, Tome 23 (2026) no. 1

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

The accelerated pace of digital transformation has significantly reshaped the cybersecurity domain, fostering an interconnected ecosystem in which cyber threats have expanded in both their complexity and scope. Traditional cybersecurity methods are increasingly inadequate for addressing the rapidly evolving threat landscape, emphasizing the critical need for intelligent, adaptive, and proactive defensive strategies. This study introduces Dynamic Industrial Cyber Risk Modelling Based on Evidence (DICYME), a comprehensive system that integrates diverse analytical techniques to identify patterns and characteristics that reveal emerging threat trends, enabling organizations to proactively defend against potential future attacks. Beyond threat detection, DICYME operates as a pipeline that retrieves data from diverse cyber incident reports, specialized databases, and other relevant sources of cyber-related information, applies specialized techniques for victim identification, indicator computation, threat actor profiling, Common Vulnerability and Exposure (CVE) relationship mapping, and ultimately performs the Cyber Risk Quantification (CRQ). This final stage represents the system’s most distinctive contribution, as it translates complex analytical outputs into actionable risk insights, empowering organizations to make informed strategic decisions in the face of evolving cyber threats. Alternatively, the system implements an automatic workflow that constructs new datasets of compromised entities, enabling these datasets to be used by all components of the system. Experiments on real cyber incident datasets demonstrate the system’s ability to automatically construct high-quality victim profiles and estimate annualized financial risk, offering a scalable and data-driven approach for proactive cybersecurity management.
Keywords: Cyber risk quantification, Machine Learning, Large Language Models, Indicators, Firmographics, Threat actors, Vulnerabilities
Javier Garcı́a-Ochoa; Jaime Rueda; Rubén R. Fernández; Alberto Fernández-Isabel; Isaac Martı́n de Diego; Emilio L. Cano; Romy R. Ravines; Ovidio López Espinosa; Jaume Puigbó Sanvisens. DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence. Computer Science and Information Systems, Tome 23 (2026) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/
@article{CSIS_2026_23_1_a17,
     author = {Javier Garc{\i}́a-Ochoa and Jaime Rueda and Rub\'en R. Fern\'andez and Alberto Fern\'andez-Isabel and Isaac Mart{\i}́n de Diego and Emilio L. Cano and Romy R. Ravines and Ovidio L\'opez Espinosa and Jaume Puigb\'o Sanvisens},
     title = {DICYME: {Dynamic} {Industrial} {Cyber} {Risk} {Modelling} {Based} on {Evidence}},
     journal = {Computer Science and Information Systems},
     year = {2026},
     volume = {23},
     number = {1},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/}
}
TY  - JOUR
AU  - Javier Garcı́a-Ochoa
AU  - Jaime Rueda
AU  - Rubén R. Fernández
AU  - Alberto Fernández-Isabel
AU  - Isaac Martı́n de Diego
AU  - Emilio L. Cano
AU  - Romy R. Ravines
AU  - Ovidio López Espinosa
AU  - Jaume Puigbó Sanvisens
TI  - DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence
JO  - Computer Science and Information Systems
PY  - 2026
VL  - 23
IS  - 1
UR  - http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/
ID  - CSIS_2026_23_1_a17
ER  - 
%0 Journal Article
%A Javier Garcı́a-Ochoa
%A Jaime Rueda
%A Rubén R. Fernández
%A Alberto Fernández-Isabel
%A Isaac Martı́n de Diego
%A Emilio L. Cano
%A Romy R. Ravines
%A Ovidio López Espinosa
%A Jaume Puigbó Sanvisens
%T DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence
%J Computer Science and Information Systems
%D 2026
%V 23
%N 1
%U http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/
%F CSIS_2026_23_1_a17