**Peer Review Journal ** DOI on demand of Author (Charges Apply) ** Fast Review and Publicaton Process ** Free E-Certificate to Each Author

Current Issues
     2026:7/3

International Journal of Multidisciplinary Research and Growth Evaluation

ISSN: (Print) | 2582-7138 (Online) | Impact Factor: 9.54 | Open Access

A Quantitative Cyber Risk Valuation Model for Board-Level Decision Making in Critical Infrastructure

Full Text (PDF)

Open Access - Free to Download

Download Full Article (PDF)

Abstract

Critical infrastructure organizations face a growing gap between the sophistication of cybersecurity threats and the ability of governance frameworks to translate that risk into financially grounded intelligence for board-level decisions. This gap reflects not a lack of technical risk data but a failure to translate threat intelligence and vulnerability information into monetary probabilistic expressions that boards need to oversee cybersecurity investment alongside other enterprise risks. This paper proposes a Quantitative Cyber Risk Valuation model. It integrates Factor Analysis of Information Risk's probabilistic decomposition Gordon-Loeb investment optimization and the NIST Risk Management Framework. The model is structured for governance output and is intended for critical infrastructure operators in energy water financial services transportation and healthcare. The model produces probability-weighted annual loss expectancies specified at tenth fiftieth and ninetieth percentile confidence intervals. It also provides an investment efficiency frontier so organizations can identify security allocations that maximize risk reduction per capital unit in line with Gordon-Loeb optimality. Furthermore it provides a structured risk appetite framework that helps boards define enforce and monitor quantitative risk thresholds aligned with risk tolerance and regulatory requirements. The paper reviews the literature on security economics quantitative risk board governance industrial control system security and enterprise IT frameworks to develop a model applicable to regulated organizations across sectors and jurisdictions

How to Cite This Article

Beloved D Smart SSCP (2020). A Quantitative Cyber Risk Valuation Model for Board-Level Decision Making in Critical Infrastructure . International Journal of Multidisciplinary Research and Growth Evaluation (IJMRGE), 1(5), 984-991. DOI: https://doi.org/10.54660/.IJMRGE.2020.1.5.984-991

Share This Article: