Real-time Quantification of Cyber-Resilience

No ratings

Presented at SecTor 2023 by

The cyber risk landscape is undergoing a monumental change in its perspective of cyber security. This is made evident due to the massive losses incurred by cyber-insures in recent years, mainly due to their inability to properly quantify and classify the cyber-risk of an organization. The historical method of risk mitigation is based on 'if' scenarios, e.g. 'if' scenario A was to happen, we mitigate using control B. This perspective is losing validity since the probability of any modern organization experiencing a cyber incident approaches 100% over time. Thus, it is no longer acceptable to assess 'if' a cyber-incident will occur, but to think 'when'. This notion of 'when' is embodied in the concept of cyber-resilience, which focuses on an organization's ability to maintain business continuity under cyber stresses (e.g. data breach, ransomware, DDos, etc.). Cyber-resilience is defined as an organization's ability to anticipate, withstand, recover, and adapt to a cyber incident. However, cyber-resiliency is still in its infancy when compared to cyber-risk and remains highly qualitative. In this session, we will be presenting a novel model for quantifying cyber-resilience based on the MITRE Cyber Resilience Engineering Framework (CREF) using graph theory. Using this approach, we automatically formulate a unique computational graph that represents the resilience of an organization. The mathematical properties calculated from these directed acyclic graphs are then capable of quantifying and visualizing in real-time the cyber-resilience of an organization under dynamic conditions. In addition to providing a robust and unique method to quantifying cyber-resilience, the model architecture unlocks new perspectives and deeper insights regarding the constructs of cyber-resilience. This session will begin by contrasting the differences between cyber-risk vs. cyber-resilience. We will then discuss the technical details of the developed cyber resilience model and present some of the insights gained, both theoretically and via a case study. This session will be most interesting to both directors looking to enhance their organization's cyber resilience, and for security engineers looking to implement such quantifiable systems.