{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/124233"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/124233","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Examining approaches to quantifying cyber risk for improved cybersecurity management","abstract":"As technology's societal influence continues to grow, cyber risk management is becoming a serious priority. Individuals are putting their important assets and personal data, such as social security numbers, passwords, medical history, and more into the cloud. As a result, security breaches pose a drastic threat. To properly address this, rigorous risk management needs to be in place, and it is a well-known adage that you can not manage what you can not measure. This thesis first shows that there is room in the industry for better quantitative cyber risk measurement and then provides an assessment of current players that are trying to approach this issue. As one solution to the problem, a Failure Modes and Effects Analysis is performed on well-known cybersecurity breaches to provide common failure modes, causes, and effects within an organization. Cyber risk must be evaluated quantitatively in order to effectively approach it.","abstract_html":"As technology&#x27;s societal influence continues to grow, cyber risk management is becoming a serious priority. Individuals are putting their important assets and personal data, such as social security numbers, passwords, medical history, and more into the cloud. As a result, security breaches pose a drastic threat. To properly address this, rigorous risk management needs to be in place, and it is a well-known adage that you can not manage what you can not measure. This thesis first shows that there is room in the industry for better quantitative cyber risk measurement and then provides an assessment of current players that are trying to approach this issue. As one solution to the problem, a Failure Modes and Effects Analysis is performed on well-known cybersecurity breaches to provide common failure modes, causes, and effects within an organization. Cyber risk must be evaluated quantitatively in order to effectively approach it.","abstract_has_math":false,"creators":["Bhamidipati, Sravya(Sravya M.)"],"institution":"Massachusetts Institute of Technology","degree_name":"Master","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","school":null,"contributors":[],"advisors":["Michael Siegel."],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019","date_published":"2019","updated_at":"2026-07-22T22:22:17Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/124233","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Michael Siegel."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","EECS"]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Bhamidipati, Sravya(Sravya M.)"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2020-03-24T15:35:33Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2020-03-24T15:35:33Z"]},{"key":"dc:date.issued","label":"Date","values":["2019"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/124233"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 63-71)."]},{"key":"dc:description.abstract","label":"Abstract","values":["As technology's societal influence continues to grow, cyber risk management is becoming a serious priority. Individuals are putting their important assets and personal data, such as social security numbers, passwords, medical history, and more into the cloud. As a result, security breaches pose a drastic threat. To properly address this, rigorous risk management needs to be in place, and it is a well-known adage that you can not manage what you can not measure. This thesis first shows that there is room in the industry for better quantitative cyber risk measurement and then provides an assessment of current players that are trying to approach this issue. As one solution to the problem, a Failure Modes and Effects Analysis is performed on well-known cybersecurity breaches to provide common failure modes, causes, and effects within an organization. Cyber risk must be evaluated quantitatively in order to effectively approach it."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M. Eng."]},{"key":"dc:title","label":"Title","values":["Examining approaches to quantifying cyber risk for improved cybersecurity management"]}]}],"canonical_facts":{"dc:contributor.advisor":["Michael Siegel."],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","EECS"],"dc:contributor.other":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:creator":["Bhamidipati, Sravya(Sravya M.)"],"dc:date.accessioned":["2020-03-24T15:35:33Z"],"dc:date.available":["2020-03-24T15:35:33Z"],"dc:date.issued":["2019"],"dc:description":["This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2019","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 63-71)."],"dc:description.abstract":["As technology's societal influence continues to grow, cyber risk management is becoming a serious priority. Individuals are putting their important assets and personal data, such as social security numbers, passwords, medical history, and more into the cloud. As a result, security breaches pose a drastic threat. To properly address this, rigorous risk management needs to be in place, and it is a well-known adage that you can not manage what you can not measure. This thesis first shows that there is room in the industry for better quantitative cyber risk measurement and then provides an assessment of current players that are trying to approach this issue. As one solution to the problem, a Failure Modes and Effects Analysis is performed on well-known cybersecurity breaches to provide common failure modes, causes, and effects within an organization. Cyber risk must be evaluated quantitatively in order to effectively approach it."],"dc:description.degree":["M. Eng."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/124233"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["Examining approaches to quantifying cyber risk for improved cybersecurity management"],"dc:type":["Thesis"],"thesis:degree_name":["Master"]},"updated_at":"2026-07-22T22:22:17Z"}