Exportar Publicação

A publicação pode ser exportada nos seguintes formatos: referência da APA (American Psychological Association), referência do IEEE (Institute of Electrical and Electronics Engineers), BibTeX e RIS.

Exportar Referência (APA)
Sherif, E., Yevseyeva, I., Basto-Fernandes, V. & Cook, A. (2026). Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics. Cybersecurity and Cybercrime. 1 (10), 29-53
Exportar Referência (IEEE)
E. Sherif et al.,  "Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics", in Cybersecurity and Cybercrime, vol. 1, no. 10, pp. 29-53, 2026
Exportar BibTeX
@article{sherif2026_1788001547316,
	author = "Sherif, E. and Yevseyeva, I. and Basto-Fernandes, V. and Cook, A.",
	title = "Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics",
	journal = "Cybersecurity and Cybercrime",
	year = "2026",
	volume = "1",
	number = "10",
	doi = "10.5604/01.3001.0055.8282",
	pages = "29-53",
	url = "https://c2.amw.gdynia.pl/cms/forauthorsinfo"
}
Exportar RIS
TY  - JOUR
TI  - Operationalising cyber risk management: Connecting cyber incidents to MITRE ATT&CK techniques, controls, and metrics
T2  - Cybersecurity and Cybercrime
VL  - 1
IS  - 10
AU  - Sherif, E.
AU  - Yevseyeva, I.
AU  - Basto-Fernandes, V.
AU  - Cook, A.
PY  - 2026
SP  - 29-53
SN  - 2720-4251
DO  - 10.5604/01.3001.0055.8282
UR  - https://c2.amw.gdynia.pl/cms/forauthorsinfo
AB  - The escalating frequency of cyber-attacks poses significant challenges for organisations, particularly small enterprises constrained by limited financial resources. This research presents a novel framework leveraging a knowledge base and Natural Language Processing to address these challenges through automated mapping of cyber incidents to adversary techniques. We introduce the Cyber Catalog, a comprehensive knowledge base that systematically integrates CIS Critical Security Controls, MITRE ATT&CK techniques, and SMART metrics, enabling organisations to connect threat intelligence directly to actionable controls and measurable outcomes. To operationalise the framework, we fine-tuned a general-purpose sentence transformer on an augmented dataset of 74,986 incident-technique pairs to enhance semantic similarity between cyber incidents and MITRE ATT&CK techniques. Our fine-tuned model achieved a Spearman correlation of 0.7894 and Pearson correlation of 0.8756, representing improvements of approximately 0.21 over baseline models including all-mpnet-base-v2, all-distilroberta-v1, and all-MiniLM-L12-v2. The model also exhibited significantly lower prediction errors (MAE = 0.135, MSE = 0.027), confirming superior accuracy and consistency with three-fold reductions compared to baselines. This work bridges the gap between threat intelligence and operational security management, providing an actionable tool for cyber incident response and evidence-based risk management.
ER  -