Exportar Publicação
A publicação pode ser exportada nos seguintes formatos: referência da APA (American Psychological Association), referência do IEEE (Institute of Electrical and Electronics Engineers), BibTeX e RIS.
Sherif, E., Yevseyeva, I., Basto-Fernandes, V. & Cook, A. (2026). Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics. Cybersecurity and Cybercrime. 1 (10), 29-53
E. Sherif et al., "Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics", in Cybersecurity and Cybercrime, vol. 1, no. 10, pp. 29-53, 2026
@article{sherif2026_1788001547316,
author = "Sherif, E. and Yevseyeva, I. and Basto-Fernandes, V. and Cook, A.",
title = "Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics",
journal = "Cybersecurity and Cybercrime",
year = "2026",
volume = "1",
number = "10",
doi = "10.5604/01.3001.0055.8282",
pages = "29-53",
url = "https://c2.amw.gdynia.pl/cms/forauthorsinfo"
}
TY - JOUR TI - Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics T2 - Cybersecurity and Cybercrime VL - 1 IS - 10 AU - Sherif, E. AU - Yevseyeva, I. AU - Basto-Fernandes, V. AU - Cook, A. PY - 2026 SP - 29-53 SN - 2720-4251 DO - 10.5604/01.3001.0055.8282 UR - https://c2.amw.gdynia.pl/cms/forauthorsinfo AB - The escalating frequency of cyber-attacks poses significant challenges for organisations, particularly small enterprises constrained by limited financial resources. This research presents a novel framework leveraging a knowledge base and Natural Language Processing to address these challenges through automated mapping of cyber incidents to adversary techniques. We introduce the Cyber Catalog, a comprehensive knowledge base that systematically integrates CIS Critical Security Controls, MITRE ATT&CK techniques, and SMART metrics, enabling organisations to connect threat intelligence directly to actionable controls and measurable outcomes. To operationalise the framework, we fine-tuned a general-purpose sentence transformer on an augmented dataset of 74,986 incident-technique pairs to enhance semantic similarity between cyber incidents and MITRE ATT&CK techniques. Our fine-tuned model achieved a Spearman correlation of 0.7894 and Pearson correlation of 0.8756, representing improvements of approximately 0.21 over baseline models including all-mpnet-base-v2, all-distilroberta-v1, and all-MiniLM-L12-v2. The model also exhibited significantly lower prediction errors (MAE = 0.135, MSE = 0.027), confirming superior accuracy and consistency with three-fold reductions compared to baselines. This work bridges the gap between threat intelligence and operational security management, providing an actionable tool for cyber incident response and evidence-based risk management. ER -
English