DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence
Computer Science and Information Systems, Tome 23 (2026) no. 1
Voir la notice de l'article provenant de la source Computer Science and Information Systems website
The accelerated pace of digital transformation has significantly reshaped the cybersecurity domain, fostering an interconnected ecosystem in which cyber threats have expanded in both their complexity and scope. Traditional cybersecurity methods are increasingly inadequate for addressing the rapidly evolving threat landscape, emphasizing the critical need for intelligent, adaptive, and proactive defensive strategies. This study introduces Dynamic Industrial Cyber Risk Modelling Based on Evidence (DICYME), a comprehensive system that integrates diverse analytical techniques to identify patterns and characteristics that reveal emerging threat trends, enabling organizations to proactively defend against potential future attacks. Beyond threat detection, DICYME operates as a pipeline that retrieves data from diverse cyber incident reports, specialized databases, and other relevant sources of cyber-related information, applies specialized techniques for victim identification, indicator computation, threat actor profiling, Common Vulnerability and Exposure (CVE) relationship mapping, and ultimately performs the Cyber Risk Quantification (CRQ). This final stage represents the system’s most distinctive contribution, as it translates complex analytical outputs into actionable risk insights, empowering organizations to make informed strategic decisions in the face of evolving cyber threats. Alternatively, the system implements an automatic workflow that constructs new datasets of compromised entities, enabling these datasets to be used by all components of the system. Experiments on real cyber incident datasets demonstrate the system’s ability to automatically construct high-quality victim profiles and estimate annualized financial risk, offering a scalable and data-driven approach for proactive cybersecurity management.
Keywords:
Cyber risk quantification, Machine Learning, Large Language Models, Indicators, Firmographics, Threat actors, Vulnerabilities
Javier Garcı́a-Ochoa; Jaime Rueda; Rubén R. Fernández; Alberto Fernández-Isabel; Isaac Martı́n de Diego; Emilio L. Cano; Romy R. Ravines; Ovidio López Espinosa; Jaume Puigbó Sanvisens. DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence. Computer Science and Information Systems, Tome 23 (2026) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/
@article{CSIS_2026_23_1_a17,
author = {Javier Garc{\i}́a-Ochoa and Jaime Rueda and Rub\'en R. Fern\'andez and Alberto Fern\'andez-Isabel and Isaac Mart{\i}́n de Diego and Emilio L. Cano and Romy R. Ravines and Ovidio L\'opez Espinosa and Jaume Puigb\'o Sanvisens},
title = {DICYME: {Dynamic} {Industrial} {Cyber} {Risk} {Modelling} {Based} on {Evidence}},
journal = {Computer Science and Information Systems},
year = {2026},
volume = {23},
number = {1},
url = {http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/}
}
TY - JOUR AU - Javier Garcı́a-Ochoa AU - Jaime Rueda AU - Rubén R. Fernández AU - Alberto Fernández-Isabel AU - Isaac Martı́n de Diego AU - Emilio L. Cano AU - Romy R. Ravines AU - Ovidio López Espinosa AU - Jaume Puigbó Sanvisens TI - DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence JO - Computer Science and Information Systems PY - 2026 VL - 23 IS - 1 UR - http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/ ID - CSIS_2026_23_1_a17 ER -
%0 Journal Article %A Javier Garcı́a-Ochoa %A Jaime Rueda %A Rubén R. Fernández %A Alberto Fernández-Isabel %A Isaac Martı́n de Diego %A Emilio L. Cano %A Romy R. Ravines %A Ovidio López Espinosa %A Jaume Puigbó Sanvisens %T DICYME: Dynamic Industrial Cyber Risk Modelling Based on Evidence %J Computer Science and Information Systems %D 2026 %V 23 %N 1 %U http://geodesic.mathdoc.fr/item/CSIS_2026_23_1_a17/ %F CSIS_2026_23_1_a17