{"id":{"repo_id":"de-montfort","oai_identifier":"oai:dora.dmu.ac.uk:2086/24369"},"canonical_url":"https://search.dev.ndltd.org/etd/de-montfort/oai:dora.dmu.ac.uk:2086/24369","repository":{"repo_id":"de-montfort","name":"De Montfort University","base_url":"https://dora.dmu.ac.uk/server/oai/request"},"display":{"title":"An SME-Focused Cyber Security and Risk Management Ontology Informed by Threat Intelligence","abstract":"As we witness a proliferating increase in the number of cyber threats targeting individuals, businesses, and organisations both large and small, the necessity for comprehensive security and, most especially, Cyber Threat Intelligence (CTI) becomes more paramount. It is no surprise that large-scale organisations are well equipped to protect themselves from cyber threats. However, small-scale organisations often find themselves at a disadvantage due to the cost, complexity, and high granularity of existing cyber security tools. Works of literature have demonstrated ontology-based semantic knowledge modelling as a potential approach, offering both machine-readable and human-readable solutions for addressing cybersecurity challenges in downstream applications. Thus, this research addresses the aforementioned disparity by introducing a tailored and simplified ontology named CYDETI. The CYber security DEcision-making informed by Threat Intelligence (CYDETI) ontology is based on a CTI standard- Structured Threat Information Expression (STIX), in order to explore avenues that small-scale organisations can utilise CTI in the protection of their organisational IT assets. The ontology was developed using the Stanford University Methodology, popularly known as Ontology Development 101. It was evaluated and validated using two different approaches and also including a use case, and the culmination of our research presents an actionable tool and framework for small-scale organisations to enhance their cyber security decision-making process. By offering a direct link between technical cyber threats and organisational risks, our CYDETI ontology empowers these entities to make more informed, agile decisions to protect their organisational IT assets. By addressing this significant gap in the current CTI ecosystem, our research contributes to knowledge by fostering a more inclusive digital landscape where organisations of all sizes are equipped to protect and defend themselves against evolving cyber threats.","abstract_html":"As we witness a proliferating increase in the number of cyber threats targeting individuals, businesses, and organisations both large and small, the necessity for comprehensive security and, most especially, Cyber Threat Intelligence (CTI) becomes more paramount. It is no surprise that large-scale organisations are well equipped to protect themselves from cyber threats. However, small-scale organisations often find themselves at a disadvantage due to the cost, complexity, and high granularity of existing cyber security tools. Works of literature have demonstrated ontology-based semantic knowledge modelling as a potential approach, offering both machine-readable and human-readable solutions for addressing cybersecurity challenges in downstream applications. Thus, this research addresses the aforementioned disparity by introducing a tailored and simplified ontology named CYDETI. The CYber security DEcision-making informed by Threat Intelligence (CYDETI) ontology is based on a CTI standard- Structured Threat Information Expression (STIX), in order to explore avenues that small-scale organisations can utilise CTI in the protection of their organisational IT assets. The ontology was developed using the Stanford University Methodology, popularly known as Ontology Development 101. It was evaluated and validated using two different approaches and also including a use case, and the culmination of our research presents an actionable tool and framework for small-scale organisations to enhance their cyber security decision-making process. By offering a direct link between technical cyber threats and organisational risks, our CYDETI ontology empowers these entities to make more informed, agile decisions to protect their organisational IT assets. By addressing this significant gap in the current CTI ecosystem, our research contributes to knowledge by fostering a more inclusive digital landscape where organisations of all sizes are equipped to protect and defend themselves against evolving cyber threats.","abstract_has_math":false,"creators":["Aliyu, Aliyu Abdullahi"],"institution":"De Montfort University","degree_name":"PhD","degree_level":"Doctoral","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-06","date_published":"2024-06","updated_at":"2026-07-24T06:18:24Z","subjects":[],"languages":[],"rights":[],"rights_urls":["https://dora.dmu.ac.uk/bitstreams/0d6cc103-3365-4271-a286-e15b65467c7c/download"],"identifier_entries":[]},"links":{"outbound_url":null,"outbound_label":null,"outbound_source":null},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Aliyu, Aliyu Abdullahi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.issued","label":"Date","values":["2024-06"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["Faculty of Computing, Engineering and Media"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["De Montfort University"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://hdl.handle.net/2086/24369"]},{"key":"dc:type","label":"Dc Type","values":["Thesis or dissertation"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Doctoral"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["PhD"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["https://dora.dmu.ac.uk/bitstreams/0d6cc103-3365-4271-a286-e15b65467c7c/download"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://dora.dmu.ac.uk/bitstreams/2b46ae3f-de6a-4465-ab80-99f2fe950d57/download"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["As we witness a proliferating increase in the number of cyber threats targeting individuals, businesses, and organisations both large and small, the necessity for comprehensive security and, most especially, Cyber Threat Intelligence (CTI) becomes more paramount. It is no surprise that large-scale organisations are well equipped to protect themselves from cyber threats. However, small-scale organisations often find themselves at a disadvantage due to the cost, complexity, and high granularity of existing cyber security tools. Works of literature have demonstrated ontology-based semantic knowledge modelling as a potential approach, offering both machine-readable and human-readable solutions for addressing cybersecurity challenges in downstream applications. Thus, this research addresses the aforementioned disparity by introducing a tailored and simplified ontology named CYDETI. The CYber security DEcision-making informed by Threat Intelligence (CYDETI) ontology is based on a CTI standard- Structured Threat Information Expression (STIX), in order to explore avenues that small-scale organisations can utilise CTI in the protection of their organisational IT assets. The ontology was developed using the Stanford University Methodology, popularly known as Ontology Development 101. It was evaluated and validated using two different approaches and also including a use case, and the culmination of our research presents an actionable tool and framework for small-scale organisations to enhance their cyber security decision-making process. By offering a direct link between technical cyber threats and organisational risks, our CYDETI ontology empowers these entities to make more informed, agile decisions to protect their organisational IT assets. By addressing this significant gap in the current CTI ecosystem, our research contributes to knowledge by fostering a more inclusive digital landscape where organisations of all sizes are equipped to protect and defend themselves against evolving cyber threats."]},{"key":"dc:format.checksum.md5","label":"Dc Format Checksum Md5","values":["7f2b4c256f4930b65237047f95b7ffe5","bd41181d9a4c38b5ebacc69a027024d9","73c0fe6318867ae74228bb9cb6f7213b"]},{"key":"dc:title","label":"Title","values":["An SME-Focused Cyber Security and Risk Management Ontology Informed by Threat Intelligence"]}]}],"canonical_facts":{"dc:creator":["Aliyu, Aliyu Abdullahi"],"dc:date.issued":["2024-06"],"dc:description.abstract":["As we witness a proliferating increase in the number of cyber threats targeting individuals, businesses, and organisations both large and small, the necessity for comprehensive security and, most especially, Cyber Threat Intelligence (CTI) becomes more paramount. It is no surprise that large-scale organisations are well equipped to protect themselves from cyber threats. However, small-scale organisations often find themselves at a disadvantage due to the cost, complexity, and high granularity of existing cyber security tools. Works of literature have demonstrated ontology-based semantic knowledge modelling as a potential approach, offering both machine-readable and human-readable solutions for addressing cybersecurity challenges in downstream applications. Thus, this research addresses the aforementioned disparity by introducing a tailored and simplified ontology named CYDETI. The CYber security DEcision-making informed by Threat Intelligence (CYDETI) ontology is based on a CTI standard- Structured Threat Information Expression (STIX), in order to explore avenues that small-scale organisations can utilise CTI in the protection of their organisational IT assets. The ontology was developed using the Stanford University Methodology, popularly known as Ontology Development 101. It was evaluated and validated using two different approaches and also including a use case, and the culmination of our research presents an actionable tool and framework for small-scale organisations to enhance their cyber security decision-making process. By offering a direct link between technical cyber threats and organisational risks, our CYDETI ontology empowers these entities to make more informed, agile decisions to protect their organisational IT assets. By addressing this significant gap in the current CTI ecosystem, our research contributes to knowledge by fostering a more inclusive digital landscape where organisations of all sizes are equipped to protect and defend themselves against evolving cyber threats."],"dc:format.checksum.md5":["7f2b4c256f4930b65237047f95b7ffe5","bd41181d9a4c38b5ebacc69a027024d9","73c0fe6318867ae74228bb9cb6f7213b"],"dc:identifier.uri":["https://dora.dmu.ac.uk/bitstreams/2b46ae3f-de6a-4465-ab80-99f2fe950d57/download"],"dc:publisher.department":["Faculty of Computing, Engineering and Media"],"dc:publisher.institution":["De Montfort University"],"dc:relation.isreferencedby":["https://hdl.handle.net/2086/24369"],"dc:rights":["https://dora.dmu.ac.uk/bitstreams/0d6cc103-3365-4271-a286-e15b65467c7c/download"],"dc:title":["An SME-Focused Cyber Security and Risk Management Ontology Informed by Threat Intelligence"],"dc:type":["Thesis or dissertation"],"dc:type.qualificationlevel":["Doctoral"],"dc:type.qualificationname":["PhD"]},"updated_at":"2026-07-24T06:18:24Z"}