A Quantitative Framework for Dynamic Cyber Risk Assessment in Hybrid Enterprise Networks
Published: 2026/06/30
Abstract
Cyber risk estimation in hybrid enterprise networks, which integrate cloud-native services with legacy on-premises infrastructure, is increasingly challenging due to their distributed architecture and complex interdependencies. Traditional risk assessment approaches often fail to capture real-time exposure dynamics arising from service-level interactions and context-dependent infrastructure relationships. To address this limitation, this study proposes the Dynamic Enterprise Cyber Risk Estimation with Service Topology (DECRE-ST) framework, an adaptive and quantitative approach for real-time cyber risk estimation in hybrid enterprise environments. The proposed framework models enterprise infrastructure as a weighted interaction graph and incorporates contextual exposure factors to compute dynamic asset risk scores. Experimental validation was performed using enterprise telemetry datasets comprising 120 interconnected assets deployed within simulated hybrid cloud environments. Results demonstrate that the DECRE-ST framework improves risk prediction consistency by 17.6% and reduces estimation variance by 21.3% compared with Bayesian-based dynamic risk estimation models. Furthermore, the framework decreases mean risk estimation latency by 14.2% under fluctuating threat conditions. Ablation analysis further confirms the effectiveness of contextual service dependency modeling, contributing nearly 11% to overall estimation stability. These findings indicate that the DECRE-ST framework provides a more accurate, adaptive, and context-aware approach to cyber risk estimation. By enabling continuous assessment of evolving enterprise environments, the framework supports adaptive security governance and enhances decision-making for organizations operating hybrid cloud infrastructures.
Keywords
How to Cite the Article
Mamodiya, U., Kishor, I., Vidyullatha, P., Shehab, R., Alqatish, A., & Alradwan, G. (2026). A Quantitative Framework for Dynamic Cyber Risk Assessment in Hybrid Enterprise Networks. Journal of Cyber Security and Risk Auditing, 2026(2), 148–182. https://doi.org/10.63180/jcsra.thestap.2026.2.2
A Quantitative Framework for Dynamic Cyber Risk Assessment in Hybrid Enterprise Networks is licensed under CC BY 4.0
References
- Deaver-Vazquez, C., Taylor, E., Rowley, D., & Langis, B. (2024). A quantitative approach to assessing and managing cybersecurity risks. EDPACS. Advance online publication. https://doi.org/10.1080/07366981.2024.2340849
- Behbehani, D., Komninos, N., Al-Begain, K., & Rajarajan, M. (2023). Cloud enterprise dynamic risk assessment (CEDRA): A dynamic risk assessment using dynamic Bayesian networks for cloud environment. Journal of Cloud Computing, 12(1). https://doi.org/10.1186/s13677-023-00454-2
- Šijan, A., Viduka, D., Ilić, L., Predić, B., & Karabašević, D. (2024). Modeling cybersecurity risk: The integration of decision theory and pivot pairwise relative criteria importance assessment with scale for cybersecurity threat evaluation. Electronics, 13(21), Article 4209. https://doi.org/10.3390/electronics13214209
- Natsheh, E., & Tabook, F. B. (2025). AI-enhanced Cybersecurity Risk Assessment with Multi-Fuzzy Inference. Journal of ICT Research & Applications, 19(1). https://doi.org/10.5614/itbj.ict.res.appl.2025.19.1.1
- Cano, J. J. (2024). RAFA model: Rethinking cyber risk management in organizations. In Artificial Intelligence and Cybersecurity (pp. 231–243). Springer. https://doi.org/10.1007/978-3-031-47594-8_12
- Burnap, P., Anthi, E., Reineckea, P., Williams, L., Cao, F., Aldmoura, R., & Jones, K. (2024). Mapping automated cyber attack intelligence to context-based impact on system-level goals. Journal of Cybersecurity and Privacy, 4(2), 340-356. https://doi.org/10.3390/jcp4020017
- Mamodiya, U., Kishor, I., Vidyullatha, P., Alqutaesh, A., Alradwan, G., & Obedat, M. (2026). A hybrid fuzzy–deep learning framework for real-time cyber-attack detection in smart energy grids. International Journal of Data and Network Science, 10. https://doi.org/10.5267/j.ijdns.2026.2.007
- Xie, J., Zhang, S., Wang, H., & Chen, L. (2023). Multiobjective network security dynamic assessment method based on Bayesian network attack graph. International Journal of Intelligent Computing and Cybernetics, 17, 38–60. https://doi.org/10.1108/IJICC-05-2023-0121
- Figueredo Franco, M., Künzler, F., von der Assen, J., Feng, C., & Stiller, B. (2024). RCVaR: An economic approach to estimate cyberattack costs using data from industry reports. Computers & Security, 139, Article 103737. https://doi.org/10.1016/j.cose.2024.103737
- Mishra, A., Sarat, P., & Afza, R. (2024). A factual study on hybrid multi-cloud cybersecurity threats and proposed methodologies to enable cyber resilience. In Proceedings of the IEEE International Conference on Electronics, Computing and Communication Technologies (CONECCT) (pp. 1–6). IEEE. https://doi.org/10.1109/CONECCT62155.2024.10677052
- Safarzadehvahed, M., Abazari, F., & Shabani, F. (2023). QR-SACP: Quantitative risk-based situational awareness calculation and projection through threat information sharing. In Cyber Security and Digital Transformation (pp. 170–193). Springer. https://doi.org/10.1007/978-981-99-7032-2_11
- Khosravi-Farmad, M., & Ghaemi-Bafghi, A. Dynamic Security Risk Management Considering Systems Structural and Probabilistic Attributes. Methods, 4, 5. https://doi.org/10.22067/cke.2023.83744.1102
- Song, Y., Jiang, S., Shan, Q., Yang, Y., Yu, Y., Shen, W., & Guo, Q. (2024). Hierarchical-Based Dynamic Scenario-Adaptive Risk Assessment for Power Data Lifecycle. Electronics, 13(3), 631. https://doi.org/10.3390/electronics13030631
- Kuo, C. T., Chen, H. Y., & Lin, T. N. (2023). RAIN: risk assessment framework based on an interdependent-input propagation network for a 5G network. IEEE Access, 11, 54881-54896. https://doi.org/10.1109/ACCESS.2023.3281560
- Pal, R., Sequeira, R. X., Yin, X., Zeijlemaker, S., & Kotala, V. (2023). How should enterprises quantify and analyze (multi-party) apt cyber-risk exposure in their industrial IoT network?. ACM Transactions on Management Information Systems. https://doi.org/10.1145/3605949
- Bhatta, U. (2024). How to integrate cloud service, data analytic and machine learning technique to reduce cyber risks associated with the modern cloud based infrastructure. arXiv preprint arXiv:2405.11601. arXiv. https://doi.org/10.48550/arXiv.2405.11601
- Unal, N. M., & Celiktas, B. (2025, August). A Metric-Driven IT Risk Scoring Framework: Incorporating Contextual and Organizational Factors. In 2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA) (pp. 1-7). IEEE. https://doi.org/10.1109/ACDSA65407.2025.11166074
- Kodela, V. (2025). Real-time threat detection in enterprise networks: Integrating Cisco Umbrella, Stealthwatch, and SIEM platforms. Journal of Informatics Education and Research, 2(2). https://doi.org/10.52783/jier.v1i2.3301
- AlHidaifi, S. M., Asghar, M. R., & Ansari, I. S. (2024). Towards a cyber resilience quantification framework (CRQF) for IT infrastructure. Computer Networks. https://doi.org/10.1016/j.comnet.2024.110446
- Zadeh, A., Lavine, B., Zolbanin, H. M., & Hopkins, D. (2023). A cybersecurity risk quantification and classification framework for informed risk mitigation decisions. Decision Analytics Journal. https://doi.org/10.1016/j.dajour.2023.100328
- Lin, X., Yao, Y., Hu, B., Yang, W., Zhou, X., & Zhang, W. (2024). Enhancing power communication network security: A comprehensive cyber risk visual analytics framework with real-time risk assessment. Sustainable Energy, Grids and Networks, 38, 101325. https://doi.org/10.1016/j.segan.2024.101325
- Luo, M., Tao, C., Liu, Y., Chen, S., & Chen, P. (2025). An Endogenous Security-Oriented Framework for Cyber Resilience Assessment in Critical Infrastructures. Applied Sciences, 15(15), 8342. https://doi.org/10.3390/app15158342
- Wang, C., Dong, J., Guo, G., & Ren, T. (2024). Dynamic real-time analysis of network attacks based on dynamic risk probability algorithm. Journal of Advanced Computational Intelligence and Intelligent Informatics. https://doi.org/10.20965/jaciii.2024.p0141
- Mamodiya, U., Kishor, I., Almaiah, M., Alqutaish, A., Shehab, R., & Obeidat, M. (2026). Behavior-aware cybersecurity using artificial intelligence and cryptographic intelligence. International Journal of Data and Network Science, 10. https://doi.org/10.5267/j.ijdns.2026.1.001
- Boudermine, A., Khatoun, R., & Choyer, J.-H. (2023). Dynamic logic-based attack graph for risk assessment in complex computer systems. Computer Networks, 228, Article 109730. https://doi.org/10.1016/j.comnet.2023.109730
- Abdi, A., Bennouri, H., & Keane, A. (2024, June). Cyber resilience, risk management, and security challenges in enterprise-scale cloud systems: Comprehensive review. In 2024 13th Mediterranean Conference on Embedded Computing (MECO) (pp. 1-8). IEEE. https://doi.org/10.1109/MECO62516.2024.10577956
- Vajpayee, P., & Hossain, G. (2024, May). Risk assessment of cybersecurity IoT anomalies through cyber value at risk (CVaR). In 2024 IEEE World AI IoT Congress (AIIoT) (pp. 77-83). IEEE. https://doi.org/10.1109/AIIOT61789.2024.10578956
- Dong, C., Feng, Y., & Shang, W. (2024). A new method of dynamic network security analysis based on dynamic uncertain causality graph. Journal of Cloud Computing, 13(1), 24. https://doi.org/10.1186/s13677-023-00568-7
- Kim, A. (2023). Endpoint device risk-scoring algorithm proposal for zero trust. Electronics, 12(8), Article 1906. https://doi.org/10.3390/electronics12081906
- Zhylin, A. (2024). Methodology of quantitative assessment of network cyber threats using a risk-based approach. Applied Cybersecurity & Internet Governance, 3(1), 227-260. https://doi.org/10.60097/acig/190345
- Soylu, M., & Daş, R. (2025). A hybrid graph neural network model for predicting cyber attacks from heterogeneous and dynamic network data. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3603403
- Cue, H. A. A., Bourlai, T., & Lupo, M. (2025). Proactive cyber resilience: A unified assessment methodology for incident forecasting with cyber threat intelligence integration. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3596252
- Ali, S., Razzaque, A., Abbas, H., Yousaf, M., & Ali, S. (2025). A novel AI-based integrated cybersecurity risk assessment framework and resilience of national critical infrastructure. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2024.3524884
- López, A. D., Amor, M., & Carvajal Mora, H. (2025). A novel risk-based methodology for enhancing industrial control systems security: A systematic review and case study. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3609252
- Masukawa, R., Yun, S., Jeong, S., Bastian, N. D., & Imani, M. (2025). TriageHD: A hyper-dimensional learning-to-rank framework for dynamic micro-segmentation in zero-trust network security. IEEE Access, 13, 136806–136815. https://doi.org/10.1109/ACCESS.2025.3592877
- Ting, T., & Li, M. (2025). Enhanced secure storage and data privacy management system for big data based on multilayer model. Scientific Reports, 15(1), 32285. https://doi.org/10.1038/s41598-025-16624-y
- Islam, S., Basheer, N., Papastergiou, S., Ciampi, M., & Silvestri, S. (2025). Intelligent dynamic cybersecurity risk management framework with explainability and interpretability of AI models for enhancing security and resilience of digital infrastructure. Journal of Reliable Intelligent Environments, 11(3), 12. https://doi.org/10.1007/s40860-025-00253-3
- Rana, A., Gupta, S., & Gupta, B. (2024). A comprehensive framework for quantitative risk assessment of organizational networks using FAIR-modified attack trees. Frontiers in Computer Science, 6, 1304288. https://doi.org/10.3389/fcomp.2024.1304288
- Cheimonidis, P., & Rantos, K. (2023). Dynamic risk assessment in cybersecurity: A systematic literature review. Future Internet, 15(10), Article 324. https://doi.org/10.3390/fi15100324
- Sharma, A., Rani, S., & Shabaz, M. (2025). A comprehensive review of explainable AI in cybersecurity: Decoding the black box. ICT Express. https://doi.org/10.1016/j.icte.2025.10.004
- Radanliev, P., De Roure, D., Maple, C., Nurse, J. R., Nicolescu, R., & Ani, U. (2024). AI security and cyber risk in IoT systems. Frontiers in big data, 7, 1402745. https://doi.org/10.3389/fdata.2024.1402745
