{"id":{"repo_id":"embry-riddle","oai_identifier":"oai:commons.erau.edu:edt-2040"},"canonical_url":"https://search.dev.ndltd.org/etd/embry-riddle/oai:commons.erau.edu:edt-2040","repository":{"repo_id":"embry-riddle","name":"Embry Riddle Aeronautical University","base_url":"https://commons.erau.edu/do/oai/"},"display":{"title":"Quantitative Assessment of Cybersecurity Risk Variability Across Transportation Modes","abstract":"<p>Transportation systems are increasingly dependent on digital technologies, networked communications, and cyber-physical integration, making cybersecurity an important issue for operational continuity, resilience, and safety. Although cybersecurity risks in transportation are widely recognized, much of the existing research remains mode-specific and lacks a standardized quantitative framework for comparing risk across transportation systems. This study develops a quantitative, incident-based approach for assessing cybersecurity risk variability across four major transportation modes: Aviation, Maritime, Rail, and Road. The study is based on a manually constructed dataset of 189 publicly reported transportation cybersecurity incidents collected from 2000 to 2025. Each incident was coded into structured variables representing vulnerability, threat, detection speed, cost impact, severity, and success rate. Descriptive statistics, pairwise z-tests, and ordered logistic regression were used to evaluate how cybersecurity risk differs across transportation modes and which factors are associated with higher vulnerability and higher severity outcomes. The results show that transportation mode is a significant predictor of vulnerability. Relative to Maritime, Aviation, Rail, and Road had significantly greater odds of falling into higher vulnerability categories, with Aviation showing the strongest contrast. Threat complexity, slower detection, and greater severity were also associated with higher vulnerability. In contrast, transportation mode was not statistically significant overall in the Severity model after adjustment. Instead, severity was more strongly explained by incident-level characteristics, especially success rate, as well as vulnerability and detection speed. These findings suggest that transportation modes differ more clearly in vulnerability structure than in severity once other predictors are taken into account. This study contributes a cross-modal and data-driven framework for transportation cybersecurity analysis by converting fragmented incident narratives into measurable variables and applying ordinal logistic regression to structured risk outcomes. The findings support the need for transportation agencies to distinguish between exposure-related risk and consequence-related risk, and they highlight the importance of detection capability, incident success prevention, and structured comparative analysis in future transportation cybersecurity planning.</p>","abstract_html":"&lt;p&gt;Transportation systems are increasingly dependent on digital technologies, networked communications, and cyber-physical integration, making cybersecurity an important issue for operational continuity, resilience, and safety. Although cybersecurity risks in transportation are widely recognized, much of the existing research remains mode-specific and lacks a standardized quantitative framework for comparing risk across transportation systems. This study develops a quantitative, incident-based approach for assessing cybersecurity risk variability across four major transportation modes: Aviation, Maritime, Rail, and Road. The study is based on a manually constructed dataset of 189 publicly reported transportation cybersecurity incidents collected from 2000 to 2025. Each incident was coded into structured variables representing vulnerability, threat, detection speed, cost impact, severity, and success rate. Descriptive statistics, pairwise z-tests, and ordered logistic regression were used to evaluate how cybersecurity risk differs across transportation modes and which factors are associated with higher vulnerability and higher severity outcomes. The results show that transportation mode is a significant predictor of vulnerability. Relative to Maritime, Aviation, Rail, and Road had significantly greater odds of falling into higher vulnerability categories, with Aviation showing the strongest contrast. Threat complexity, slower detection, and greater severity were also associated with higher vulnerability. In contrast, transportation mode was not statistically significant overall in the Severity model after adjustment. Instead, severity was more strongly explained by incident-level characteristics, especially success rate, as well as vulnerability and detection speed. These findings suggest that transportation modes differ more clearly in vulnerability structure than in severity once other predictors are taken into account. This study contributes a cross-modal and data-driven framework for transportation cybersecurity analysis by converting fragmented incident narratives into measurable variables and applying ordinal logistic regression to structured risk outcomes. The findings support the need for transportation agencies to distinguish between exposure-related risk and consequence-related risk, and they highlight the importance of detection capability, incident success prevention, and structured comparative analysis in future transportation cybersecurity planning.&lt;/p&gt;","abstract_has_math":false,"creators":["Carreon, Paulo"],"institution":null,"degree_name":"Master of Science in Civil Engineering","degree_level":"Thesis - Open Access","degree_discipline":"Civil Engineering","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026-05-07T07:00:00Z","date_published":"2026-05-07T07:00:00Z","updated_at":"2026-07-27T19:26:22Z","subjects":["Transportation Cybersecurity; Cyber Risk Assessment; Critical Infrastructure Security; Aviation Cybersecurity; Road Cybersecurity; Transportation Cyber Threats; Transportation Infrastructure Protection; Cyber Vulnerability Analysis; Transportation Risk Modeling; Cyber Incident Analysis","Civil Engineering","Risk Analysis","Transportation","Transportation Engineering"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://commons.erau.edu/edt/996","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Carreon, Paulo"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"thesis:degree_discipline","label":"Discipline","values":["Civil Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis - Open Access"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science in Civil Engineering"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Transportation Cybersecurity; Cyber Risk Assessment; Critical Infrastructure Security; Aviation Cybersecurity; Road Cybersecurity; Transportation Cyber Threats; Transportation Infrastructure Protection; Cyber Vulnerability Analysis; Transportation Risk Modeling; Cyber Incident Analysis","Civil Engineering","Risk Analysis","Transportation","Transportation Engineering"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://commons.erau.edu/edt/996"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Transportation systems are increasingly dependent on digital technologies, networked communications, and cyber-physical integration, making cybersecurity an important issue for operational continuity, resilience, and safety. Although cybersecurity risks in transportation are widely recognized, much of the existing research remains mode-specific and lacks a standardized quantitative framework for comparing risk across transportation systems. This study develops a quantitative, incident-based approach for assessing cybersecurity risk variability across four major transportation modes: Aviation, Maritime, Rail, and Road. The study is based on a manually constructed dataset of 189 publicly reported transportation cybersecurity incidents collected from 2000 to 2025. Each incident was coded into structured variables representing vulnerability, threat, detection speed, cost impact, severity, and success rate. Descriptive statistics, pairwise z-tests, and ordered logistic regression were used to evaluate how cybersecurity risk differs across transportation modes and which factors are associated with higher vulnerability and higher severity outcomes. The results show that transportation mode is a significant predictor of vulnerability. Relative to Maritime, Aviation, Rail, and Road had significantly greater odds of falling into higher vulnerability categories, with Aviation showing the strongest contrast. Threat complexity, slower detection, and greater severity were also associated with higher vulnerability. In contrast, transportation mode was not statistically significant overall in the Severity model after adjustment. Instead, severity was more strongly explained by incident-level characteristics, especially success rate, as well as vulnerability and detection speed. These findings suggest that transportation modes differ more clearly in vulnerability structure than in severity once other predictors are taken into account. This study contributes a cross-modal and data-driven framework for transportation cybersecurity analysis by converting fragmented incident narratives into measurable variables and applying ordinal logistic regression to structured risk outcomes. The findings support the need for transportation agencies to distinguish between exposure-related risk and consequence-related risk, and they highlight the importance of detection capability, incident success prevention, and structured comparative analysis in future transportation cybersecurity planning.</p>"]},{"key":"dc:title","label":"Title","values":["Quantitative Assessment of Cybersecurity Risk Variability Across Transportation Modes"]}]}],"canonical_facts":{"dc:creator":["Carreon, Paulo"],"dc:description.abstract":["<p>Transportation systems are increasingly dependent on digital technologies, networked communications, and cyber-physical integration, making cybersecurity an important issue for operational continuity, resilience, and safety. Although cybersecurity risks in transportation are widely recognized, much of the existing research remains mode-specific and lacks a standardized quantitative framework for comparing risk across transportation systems. This study develops a quantitative, incident-based approach for assessing cybersecurity risk variability across four major transportation modes: Aviation, Maritime, Rail, and Road. The study is based on a manually constructed dataset of 189 publicly reported transportation cybersecurity incidents collected from 2000 to 2025. Each incident was coded into structured variables representing vulnerability, threat, detection speed, cost impact, severity, and success rate. Descriptive statistics, pairwise z-tests, and ordered logistic regression were used to evaluate how cybersecurity risk differs across transportation modes and which factors are associated with higher vulnerability and higher severity outcomes. The results show that transportation mode is a significant predictor of vulnerability. Relative to Maritime, Aviation, Rail, and Road had significantly greater odds of falling into higher vulnerability categories, with Aviation showing the strongest contrast. Threat complexity, slower detection, and greater severity were also associated with higher vulnerability. In contrast, transportation mode was not statistically significant overall in the Severity model after adjustment. Instead, severity was more strongly explained by incident-level characteristics, especially success rate, as well as vulnerability and detection speed. These findings suggest that transportation modes differ more clearly in vulnerability structure than in severity once other predictors are taken into account. This study contributes a cross-modal and data-driven framework for transportation cybersecurity analysis by converting fragmented incident narratives into measurable variables and applying ordinal logistic regression to structured risk outcomes. The findings support the need for transportation agencies to distinguish between exposure-related risk and consequence-related risk, and they highlight the importance of detection capability, incident success prevention, and structured comparative analysis in future transportation cybersecurity planning.</p>"],"dc:identifier":["https://commons.erau.edu/edt/996"],"dc:subject":["Transportation Cybersecurity; Cyber Risk Assessment; Critical Infrastructure Security; Aviation Cybersecurity; Road Cybersecurity; Transportation Cyber Threats; Transportation Infrastructure Protection; Cyber Vulnerability Analysis; Transportation Risk Modeling; Cyber Incident Analysis","Civil Engineering","Risk Analysis","Transportation","Transportation Engineering"],"dc:title":["Quantitative Assessment of Cybersecurity Risk Variability Across Transportation Modes"],"thesis:degree_discipline":["Civil Engineering"],"thesis:degree_level":["Thesis - Open Access"],"thesis:degree_name":["Master of Science in Civil Engineering"]},"updated_at":"2026-07-27T19:26:22Z"}