Journal of Cyber Security and Risk Auditing

Journal of Cyber Security and Risk Auditing

ISSN: 3079-5354 (Online)

Publishing model:

: Open access
open accessOpen Access

Article

👁️80views

A Quantitative Framework for Dynamic Cyber Risk Assessment in Hybrid Enterprise Networks

by 

Udit Mamodiya Orcid link ;

Indra Kishor ;

Pellakuri Vidyullatha ;

Rami Shehab ;

Amer Alqatish ;

Ghada Alradwan

PDF logoPDF

Published: 2026/06/30

Abstract

Cyber risk estimation in hybrid enterprise networks, which integrate cloud-native services with legacy on-premises infrastructure, is increasingly challenging due to their distributed architecture and complex interdependencies. Traditional risk assessment approaches often fail to capture real-time exposure dynamics arising from service-level interactions and context-dependent infrastructure relationships. To address this limitation, this study proposes the Dynamic Enterprise Cyber Risk Estimation with Service Topology (DECRE-ST) framework, an adaptive and quantitative approach for real-time cyber risk estimation in hybrid enterprise environments. The proposed framework models enterprise infrastructure as a weighted interaction graph and incorporates contextual exposure factors to compute dynamic asset risk scores. Experimental validation was performed using enterprise telemetry datasets comprising 120 interconnected assets deployed within simulated hybrid cloud environments. Results demonstrate that the DECRE-ST framework improves risk prediction consistency by 17.6% and reduces estimation variance by 21.3% compared with Bayesian-based dynamic risk estimation models. Furthermore, the framework decreases mean risk estimation latency by 14.2% under fluctuating threat conditions. Ablation analysis further confirms the effectiveness of contextual service dependency modeling, contributing nearly 11% to overall estimation stability. These findings indicate that the DECRE-ST framework provides a more accurate, adaptive, and context-aware approach to cyber risk estimation. By enabling continuous assessment of evolving enterprise environments, the framework supports adaptive security governance and enhances decision-making for organizations operating hybrid cloud infrastructures.

Keywords

Hybrid enterprise networksDynamic cyber risk assessmentContext-aware risk modelingService dependency analysisQuantitative risk estimation

How to Cite the Article

Mamodiya, U., Kishor, I., Vidyullatha, P., Shehab, R., Alqatish, A., & Alradwan, G. (2026). A Quantitative Framework for Dynamic Cyber Risk Assessment in Hybrid Enterprise Networks. Journal of Cyber Security and Risk Auditing, 2026(2), 148–182. https://doi.org/10.63180/jcsra.thestap.2026.2.2

References

  1. Deaver-Vazquez, C., Taylor, E., Rowley, D., & Langis, B. (2024). A quantitative approach to assessing and managing cybersecurity risks. EDPACS. Advance online publication. https://doi.org/10.1080/07366981.2024.2340849
  2. Behbehani, D., Komninos, N., Al-Begain, K., & Rajarajan, M. (2023). Cloud enterprise dynamic risk assessment (CEDRA): A dynamic risk assessment using dynamic Bayesian networks for cloud environment. Journal of Cloud Computing, 12(1). https://doi.org/10.1186/s13677-023-00454-2
  3. Šijan, A., Viduka, D., Ilić, L., Predić, B., & Karabašević, D. (2024). Modeling cybersecurity risk: The integration of decision theory and pivot pairwise relative criteria importance assessment with scale for cybersecurity threat evaluation. Electronics, 13(21), Article 4209. https://doi.org/10.3390/electronics13214209
  4. Natsheh, E., & Tabook, F. B. (2025). AI-enhanced Cybersecurity Risk Assessment with Multi-Fuzzy Inference. Journal of ICT Research & Applications, 19(1). https://doi.org/10.5614/itbj.ict.res.appl.2025.19.1.1
  5. Cano, J. J. (2024). RAFA model: Rethinking cyber risk management in organizations. In Artificial Intelligence and Cybersecurity (pp. 231–243). Springer. https://doi.org/10.1007/978-3-031-47594-8_12
  6. Burnap, P., Anthi, E., Reineckea, P., Williams, L., Cao, F., Aldmoura, R., & Jones, K. (2024). Mapping automated cyber attack intelligence to context-based impact on system-level goals. Journal of Cybersecurity and Privacy, 4(2), 340-356. https://doi.org/10.3390/jcp4020017
  7. Mamodiya, U., Kishor, I., Vidyullatha, P., Alqutaesh, A., Alradwan, G., & Obedat, M. (2026). A hybrid fuzzy–deep learning framework for real-time cyber-attack detection in smart energy grids. International Journal of Data and Network Science, 10. https://doi.org/10.5267/j.ijdns.2026.2.007
  8. Xie, J., Zhang, S., Wang, H., & Chen, L. (2023). Multiobjective network security dynamic assessment method based on Bayesian network attack graph. International Journal of Intelligent Computing and Cybernetics, 17, 38–60. https://doi.org/10.1108/IJICC-05-2023-0121
  9. Figueredo Franco, M., Künzler, F., von der Assen, J., Feng, C., & Stiller, B. (2024). RCVaR: An economic approach to estimate cyberattack costs using data from industry reports. Computers & Security, 139, Article 103737. https://doi.org/10.1016/j.cose.2024.103737
  10. Mishra, A., Sarat, P., & Afza, R. (2024). A factual study on hybrid multi-cloud cybersecurity threats and proposed methodologies to enable cyber resilience. In Proceedings of the IEEE International Conference on Electronics, Computing and Communication Technologies (CONECCT) (pp. 1–6). IEEE. https://doi.org/10.1109/CONECCT62155.2024.10677052
  11. Safarzadehvahed, M., Abazari, F., & Shabani, F. (2023). QR-SACP: Quantitative risk-based situational awareness calculation and projection through threat information sharing. In Cyber Security and Digital Transformation (pp. 170–193). Springer. https://doi.org/10.1007/978-981-99-7032-2_11
  12. Khosravi-Farmad, M., & Ghaemi-Bafghi, A. Dynamic Security Risk Management Considering Systems Structural and Probabilistic Attributes. Methods, 4, 5. https://doi.org/10.22067/cke.2023.83744.1102
  13. Song, Y., Jiang, S., Shan, Q., Yang, Y., Yu, Y., Shen, W., & Guo, Q. (2024). Hierarchical-Based Dynamic Scenario-Adaptive Risk Assessment for Power Data Lifecycle. Electronics, 13(3), 631. https://doi.org/10.3390/electronics13030631
  14. Kuo, C. T., Chen, H. Y., & Lin, T. N. (2023). RAIN: risk assessment framework based on an interdependent-input propagation network for a 5G network. IEEE Access, 11, 54881-54896. https://doi.org/10.1109/ACCESS.2023.3281560
  15. Pal, R., Sequeira, R. X., Yin, X., Zeijlemaker, S., & Kotala, V. (2023). How should enterprises quantify and analyze (multi-party) apt cyber-risk exposure in their industrial IoT network?. ACM Transactions on Management Information Systems. https://doi.org/10.1145/3605949
  16. Bhatta, U. (2024). How to integrate cloud service, data analytic and machine learning technique to reduce cyber risks associated with the modern cloud based infrastructure. arXiv preprint arXiv:2405.11601. arXiv. https://doi.org/10.48550/arXiv.2405.11601
  17. Unal, N. M., & Celiktas, B. (2025, August). A Metric-Driven IT Risk Scoring Framework: Incorporating Contextual and Organizational Factors. In 2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA) (pp. 1-7). IEEE. https://doi.org/10.1109/ACDSA65407.2025.11166074
  18. Kodela, V. (2025). Real-time threat detection in enterprise networks: Integrating Cisco Umbrella, Stealthwatch, and SIEM platforms. Journal of Informatics Education and Research, 2(2). https://doi.org/10.52783/jier.v1i2.3301
  19. AlHidaifi, S. M., Asghar, M. R., & Ansari, I. S. (2024). Towards a cyber resilience quantification framework (CRQF) for IT infrastructure. Computer Networks. https://doi.org/10.1016/j.comnet.2024.110446
  20. Zadeh, A., Lavine, B., Zolbanin, H. M., & Hopkins, D. (2023). A cybersecurity risk quantification and classification framework for informed risk mitigation decisions. Decision Analytics Journal. https://doi.org/10.1016/j.dajour.2023.100328
  21. Lin, X., Yao, Y., Hu, B., Yang, W., Zhou, X., & Zhang, W. (2024). Enhancing power communication network security: A comprehensive cyber risk visual analytics framework with real-time risk assessment. Sustainable Energy, Grids and Networks, 38, 101325. https://doi.org/10.1016/j.segan.2024.101325
  22. Luo, M., Tao, C., Liu, Y., Chen, S., & Chen, P. (2025). An Endogenous Security-Oriented Framework for Cyber Resilience Assessment in Critical Infrastructures. Applied Sciences, 15(15), 8342. https://doi.org/10.3390/app15158342
  23. Wang, C., Dong, J., Guo, G., & Ren, T. (2024). Dynamic real-time analysis of network attacks based on dynamic risk probability algorithm. Journal of Advanced Computational Intelligence and Intelligent Informatics. https://doi.org/10.20965/jaciii.2024.p0141
  24. Mamodiya, U., Kishor, I., Almaiah, M., Alqutaish, A., Shehab, R., & Obeidat, M. (2026). Behavior-aware cybersecurity using artificial intelligence and cryptographic intelligence. International Journal of Data and Network Science, 10. https://doi.org/10.5267/j.ijdns.2026.1.001
  25. Boudermine, A., Khatoun, R., & Choyer, J.-H. (2023). Dynamic logic-based attack graph for risk assessment in complex computer systems. Computer Networks, 228, Article 109730. https://doi.org/10.1016/j.comnet.2023.109730
  26. Abdi, A., Bennouri, H., & Keane, A. (2024, June). Cyber resilience, risk management, and security challenges in enterprise-scale cloud systems: Comprehensive review. In 2024 13th Mediterranean Conference on Embedded Computing (MECO) (pp. 1-8). IEEE. https://doi.org/10.1109/MECO62516.2024.10577956
  27. Vajpayee, P., & Hossain, G. (2024, May). Risk assessment of cybersecurity IoT anomalies through cyber value at risk (CVaR). In 2024 IEEE World AI IoT Congress (AIIoT) (pp. 77-83). IEEE. https://doi.org/10.1109/AIIOT61789.2024.10578956
  28. Dong, C., Feng, Y., & Shang, W. (2024). A new method of dynamic network security analysis based on dynamic uncertain causality graph. Journal of Cloud Computing, 13(1), 24. https://doi.org/10.1186/s13677-023-00568-7
  29. Kim, A. (2023). Endpoint device risk-scoring algorithm proposal for zero trust. Electronics, 12(8), Article 1906. https://doi.org/10.3390/electronics12081906
  30. Zhylin, A. (2024). Methodology of quantitative assessment of network cyber threats using a risk-based approach. Applied Cybersecurity & Internet Governance, 3(1), 227-260. https://doi.org/10.60097/acig/190345
  31. Soylu, M., & Daş, R. (2025). A hybrid graph neural network model for predicting cyber attacks from heterogeneous and dynamic network data. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3603403
  32. Cue, H. A. A., Bourlai, T., & Lupo, M. (2025). Proactive cyber resilience: A unified assessment methodology for incident forecasting with cyber threat intelligence integration. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3596252
  33. Ali, S., Razzaque, A., Abbas, H., Yousaf, M., & Ali, S. (2025). A novel AI-based integrated cybersecurity risk assessment framework and resilience of national critical infrastructure. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2024.3524884
  34. López, A. D., Amor, M., & Carvajal Mora, H. (2025). A novel risk-based methodology for enhancing industrial control systems security: A systematic review and case study. IEEE Access. Advance online publication. https://doi.org/10.1109/ACCESS.2025.3609252
  35. Masukawa, R., Yun, S., Jeong, S., Bastian, N. D., & Imani, M. (2025). TriageHD: A hyper-dimensional learning-to-rank framework for dynamic micro-segmentation in zero-trust network security. IEEE Access, 13, 136806–136815. https://doi.org/10.1109/ACCESS.2025.3592877
  36. Ting, T., & Li, M. (2025). Enhanced secure storage and data privacy management system for big data based on multilayer model. Scientific Reports, 15(1), 32285. https://doi.org/10.1038/s41598-025-16624-y
  37. Islam, S., Basheer, N., Papastergiou, S., Ciampi, M., & Silvestri, S. (2025). Intelligent dynamic cybersecurity risk management framework with explainability and interpretability of AI models for enhancing security and resilience of digital infrastructure. Journal of Reliable Intelligent Environments, 11(3), 12. https://doi.org/10.1007/s40860-025-00253-3
  38. Rana, A., Gupta, S., & Gupta, B. (2024). A comprehensive framework for quantitative risk assessment of organizational networks using FAIR-modified attack trees. Frontiers in Computer Science, 6, 1304288. https://doi.org/10.3389/fcomp.2024.1304288
  39. Cheimonidis, P., & Rantos, K. (2023). Dynamic risk assessment in cybersecurity: A systematic literature review. Future Internet, 15(10), Article 324. https://doi.org/10.3390/fi15100324
  40. Sharma, A., Rani, S., & Shabaz, M. (2025). A comprehensive review of explainable AI in cybersecurity: Decoding the black box. ICT Express. https://doi.org/10.1016/j.icte.2025.10.004
  41. Radanliev, P., De Roure, D., Maple, C., Nurse, J. R., Nicolescu, R., & Ani, U. (2024). AI security and cyber risk in IoT systems. Frontiers in big data, 7, 1402745. https://doi.org/10.3389/fdata.2024.1402745
SCImago Journal & Country Rank