Back to results

Old Dominion University

Quantifying Impact of Cyber Actions on Missions or Business Processes: A Multilayer Propagative Approach

Abstract

dc:description.abstract

<p>Ensuring the security of cyberspace is one of the most significant challenges of the modern world because of its complexity. As the cyber environment is getting more integrated with the real world, the direct impact of cybersecurity problems on actual business frequently occur. Therefore, operational and strategic decision makers in particular need to understand the cyber environment and its potential impact on business. Cyber risk has become a top agenda item for businesses all over the world and is listed as one of the most serious global risks with significant financial implications for businesses.</p> <p>Risk analysis is one of the primary tools used in this endeavor. Impact assessment, as an integral part of risk analysis, tries to estimate the possible damage of a cyber threat on business. It provides the main insight into risk prioritization as it incorporates business requirements into risk analysis for a better balance of security and usability. Moreover, impact assessment constitutes the main body of information flow between technical people and business leaders. Therefore, it requires the effective synergy of technological and business aspects of cybersecurity for protection against cyber threats.</p> <p>The purpose of this research is to develop a methodology to quantify the impact of cybersecurity events, incidents, and threats. The developed method addresses the issue of impact quantification from an interdependent system of systems point of view. The objectives of this research are (1) developing a quantitative model to determine the impact propagation within a layer of an enterprise (i.e., asset, service or business process layer); (2) developing a quantitative model to determine the impact propagation among different layers within an enterprise; (3) developing an approach to estimate the economic cost of a cyber incident or event.</p> <p>Although there are various studies in cybersecurity risk quantification, only a few studies focus on impact assessment at the business process layer by considering ripple effects at both the horizontal and vertical layers. This research develops an approach that quantifies the economic impact of cyber incidents, events and threats to business processes by considering the horizontal and vertical interdependencies and impact propagation within and among layers.</p>

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy (PhD)
Level thesis:degree_level
Dissertation
Discipline thesis:degree_discipline
Engineering Management & Systems Engineering
Year dc:date.available
2019

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Tatar, Unal
Contributors dc:contributor
  • Adrian Gheorghe
  • C. Ariel Pinto
  • Charles B. Daniels
  • Hayretdin Bahsi

Subjects

dc:subject × 9

Identifiers

dc:identifier.*
Identifier
9781085627788
OAI identifier oai:identifier
oai:digitalcommons.odu.edu:emse_etds-1144

Chain of custody

source
Harvested from
Old Dominion University
Base URL
digitalcommons.odu.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Tatar, Unal. Quantifying Impact of Cyber Actions on Missions or Business Processes: A Multilayer Propagative Approach. Dissertation thesis, 2019. https://digitalcommons.odu.edu/emse_etds/144