{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T22:07:02Z","timestamp":1778969222555,"version":"3.51.4"},"reference-count":38,"publisher":"National Library of Serbia","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ComSIS","COMPUT SCI INF SYST","COMPUT SCI INFORM SY","COMPUTER SCI INFORM","COMSIS J"],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:p>The accelerated pace of digital transformation has significantly reshaped the cybersecurity domain, fostering an interconnected ecosystem in which cyber threats have expanded in both their complexity and scope. Traditional cybersecurity methods are increasingly inadequate for addressing the rapidly evolving threat landscape, emphasizing the critical need for intelligent, adaptive, and proactive defensive strategies. This study introduces Dynamic Industrial Cyber Risk Modelling Based on Evidence (DICYME), a comprehensive system that integrates diverse analytical techniques to identify patterns and characteristics that reveal emerging threat trends, enabling organizations to proactively defend against potential future attacks. Beyond threat detection, DICYME operates as a pipeline that retrieves data from diverse cyber incident reports, specialized databases, and other relevant sources of cyber-related information, applies specialized techniques for victim identification, indicator computation, threat actor profiling, Common Vulnerability and Exposure (CVE) relationship mapping, and ultimately performs the Cyber Risk Quantification (CRQ). This final stage represents the system\u2019s most distinctive contribution, as it translates complex analytical outputs into actionable risk insights, empowering organizations to make informed strategic decisions in the face of evolving cyber threats. Alternatively, the system implements an automatic workflow that constructs new datasets of compromised entities, enabling these datasets to be used by all components of the system. Experiments on real cyber incident datasets demonstrate the system\u2019s ability to automatically construct high-quality victim profiles and estimate annualized financial risk, offering a scalable and data-driven approach for proactive cybersecurity management.<\/jats:p>","DOI":"10.2298\/csis251030011g","type":"journal-article","created":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T10:44:04Z","timestamp":1768905844000},"page":"343-368","source":"Crossref","is-referenced-by-count":0,"title":["DICYME: Dynamic industrial cyber risk modelling based on evidence"],"prefix":"10.2298","volume":"23","author":[{"given":"Javier","family":"Garc\u00eda-Ochoa","sequence":"first","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaime","family":"Rueda","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"R.","given":"Rub\u00e9n","family":"Fern\u00e1ndez","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alberto","family":"Fern\u00e1ndez-Isabel","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"Isaac","given":"Diego","family":"de","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"L.","given":"Emilio","family":"Cano","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University Department of Computing Science & Statistics, M\u00f3stoles, Madrid, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"R.","given":"Romy","family":"Ravines","sequence":"additional","affiliation":[{"name":"DeNexus Inc. Boston, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"L\u00f3pez","given":"Ovidio","family":"Espinosa","sequence":"additional","affiliation":[{"name":"DeNexus Inc. Boston, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"Puigb\u00f3","given":"Jaume","family":"Sanvisens","sequence":"additional","affiliation":[{"name":"DeNexus Inc. Boston, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1078","reference":[{"key":"ref1","unstructured":"Center for International and Security Studies at Maryland: Cyber Events Database (2024), https:\/\/cissm.umd.edu\/cyber-events-database"},{"key":"ref2","doi-asserted-by":"crossref","unstructured":"Chu, Z., Wan, Y., Li, Q., Wu, Y., Zhang, H., Sui, Y., Xu, G., Jin, H.: Graph neural networks for vulnerability detection: A counterfactual explanation. In: Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis. pp. 389-401 (2024)","DOI":"10.1145\/3650212.3652136"},{"key":"ref3","doi-asserted-by":"crossref","unstructured":"Cioppi, M., Curina, I., Forlani, F., Pencarelli, T.: Online presence, visibility and reputation: a systematic literature review in management studies. Journal of Research in Interactive Marketing 13(4), 547-577 (2019)","DOI":"10.1108\/JRIM-11-2018-0139"},{"key":"ref4","unstructured":"Electronic Transactions Development Agency: Threat Group Cards: A Threat Actor Encyclopedia (2025), https:\/\/apt.etda.or.th\/cgi-bin\/aptgroups.cgi"},{"key":"ref5","unstructured":"EuRepoC project: The European Repository of Cyber Incidents (2025), https:\/\/eurepoc.eu\/"},{"key":"ref6","doi-asserted-by":"crossref","unstructured":"Falowo, O.I., Popoola, S., Riep, J., Adewopo, V.A., Koch, J.: Threat actors\u2019 tenacity to disrupt: Examination of major cybersecurity incidents. IEEE access 10, 134038-134051 (2022)","DOI":"10.1109\/ACCESS.2022.3231847"},{"key":"ref7","doi-asserted-by":"crossref","unstructured":"Garc\u00eda-Ochoa, J., Fern\u00e1ndez-Isabel, A., Contreras, C., Fern\u00e1ndez, R.R., de Diego, I.M., Beltr\u00e1n, M.: Defining the attractiveness concept for cyber incidents forecasting. Computer Science and Information Systems (ComSIS) (2025)","DOI":"10.2298\/CSIS250131060G"},{"key":"ref8","unstructured":"Garc\u00eda-Ochoa, J., Fern\u00e1ndez-Isabel, A., Mart\u00edn de Diego, I., Contreras, C., R. Ravines, R., L\u00f3pez, O.: Defining the basal attractiveness concept for cybercriminals. In: Proceedings of the 10th Jornadas Nacionales de Investigaci\u00f3n en Ciberseguridad. pp. 513-517. Universidad de Zaragoza, Zaragoza, Spain (2025)"},{"key":"ref9","unstructured":"Industrial Safety and Security Source and Waterfall Security Solutions: ICSSTRIVE (2025), https:\/\/icsstrive.com\/"},{"key":"ref10","doi-asserted-by":"crossref","unstructured":"Kamruzzaman, M., Bhuyan, M.K., Hasan, R., Farabi, S.F., Nilima, S.I., Hossain, M.A.: Exploring the landscape: A systematic review of artificial intelligence techniques in cybersecurity. In: 2024 International Conference on Communications, Computing, Cybersecurity, and Informatics (CCCI). pp. 01-06. IEEE (2024)","DOI":"10.1109\/CCCI61916.2024.10736474"},{"key":"ref11","doi-asserted-by":"crossref","unstructured":"Knoth, N., Tolzin, A., Janson, A., Leimeister, J.M.: Ai literacy and its implications for prompt engineering strategies. Computers and Education: Artificial Intelligence 6, 100225 (2024)","DOI":"10.1016\/j.caeai.2024.100225"},{"key":"ref12","unstructured":"KonBriefing: Cyberattacks, Hacker attacks, Ransomware attacks (2025), https:\/\/konbriefing.com\/en-topics\/cyberattacks.html"},{"key":"ref13","doi-asserted-by":"crossref","unstructured":"Landauer, M., Skopik, F., Stojanovi\u0107, B., Flatscher, A., Ullrich, T.: A review of time-series analysis for cyber security analytics: from intrusion detection to attack prediction. International Journal of Information Security 24(1), 3 (2025)","DOI":"10.1007\/s10207-024-00921-0"},{"key":"ref14","unstructured":"Liu, A., Feng, B., Xue, B., Wang, B., Wu, B., Lu, C., Zhao, C., Deng, C., Zhang, C., Ruan, C., et al.: Deepseek-v3 technical report. arXiv preprint arXiv:2412.19437 (2024)"},{"key":"ref15","doi-asserted-by":"crossref","unstructured":"Liu, F., Kang, Z., Han, X.: Optimizing rag techniques for automotive industry pdf chatbots: A case study with locally deployed ollama modelsoptimizing rag techniques based on locally deployed ollama modelsa case study with locally deployed ollama models. In: Proceedings of the 2024 3rd International Conference on Artificial Intelligence and Intelligent Information Processing. pp. 152-159 (2024)","DOI":"10.1145\/3707292.3707358"},{"key":"ref16","doi-asserted-by":"crossref","unstructured":"Liu, R., Xie, Y., Dang, Z., Hao, J., Quan, X., Xiao, Y., Peng, C.: Dynamic vulnerability knowledge graph construction via multi-source data fusion and large language model reasoning. Electronics 14(12), 2334 (2025)","DOI":"10.3390\/electronics14122334"},{"key":"ref17","unstructured":"Mallick, M.A.I., Nath, R.: Navigating the cyber security landscape: A comprehensive review of cyber-attacks, emerging trends, and recent developments. World Scientific News 190(1), 1-69 (2024)"},{"key":"ref18","unstructured":"Meta: Introduction to the LLaMA 4 Models (2025), https:\/\/www.llama.com\/docs\/model-cardsand-prompt-formats\/llama4\/"},{"key":"ref19","doi-asserted-by":"crossref","unstructured":"M\u0131zrak, F.: Integrating cybersecurity risk management into strategic management: a comprehensive literature review. Research Journal of Business and Management 10(3), 98-108 (2023)","DOI":"10.17261\/Pressacademia.2023.1807"},{"key":"ref20","doi-asserted-by":"crossref","unstructured":"Okutan, A., Werner, G., Yang, S.J., McConky, K.: Forecasting cyberattacks with incomplete, imbalanced, and insignificant data. Cybersecurity 1, 1-16 (2018)","DOI":"10.1186\/s42400-018-0016-5"},{"key":"ref21","doi-asserted-by":"crossref","unstructured":"Okutan, A., Yang, S.J., McConky, K., Werner, G.: Capture: cyberattack forecasting using nonstationary features with time lags. In: 2019 IEEE Conference on Communications and Network Security (CNS). pp. 205-213. IEEE (2019)","DOI":"10.1109\/CNS.2019.8802639"},{"key":"ref22","doi-asserted-by":"crossref","unstructured":"Paolo Passeri: 2024 Cyber Attacks Statistics (03 2024), https:\/\/www.hackmageddon.com\/2024\/03\/26\/2024-cyber-attacks-statistics\/","DOI":"10.70470\/EDRAAK\/2024\/004"},{"key":"ref23","unstructured":"Paolo Passeri: Hackmageddon (2025), https:\/\/www.hackmageddon.com\/"},{"key":"ref24","doi-asserted-by":"crossref","unstructured":"Pat\u00e9-Cornell, M.E., Kuypers, M., Smith, M., Keller, P.: Cyber risk management for critical infrastructure: a risk analysis model and three case studies. Risk Analysis 38(2), 226-241 (2018)","DOI":"10.1111\/risa.12844"},{"key":"ref25","doi-asserted-by":"crossref","unstructured":"Phillips, S.C., Taylor, S., Boniface, M., Modafferi, S., Surridge, M.: Automated knowledgebased cybersecurity risk assessment of cyber-physical systems. IEEE Access 12, 82482-82505 (2024)","DOI":"10.1109\/ACCESS.2024.3404264"},{"key":"ref26","doi-asserted-by":"crossref","unstructured":"Pseftelis, T., Chondrokoukis, G.: Understanding cyber incident dynamics in the european union: A study of actor types and sector vulnerabilities. Preprints.org (04 2025)","DOI":"10.20944\/preprints202504.2169.v1"},{"key":"ref27","doi-asserted-by":"crossref","unstructured":"Qin, X., Jiang, F., Cen, M., Doss, R.: Hybrid cyber defense strategies using honey-x: A survey. Computer Networks 230, 109776 (2023)","DOI":"10.1016\/j.comnet.2023.109776"},{"key":"ref28","unstructured":"Qudus, L.: Advancing cybersecurity: strategies for mitigating threats in evolving digital and iot ecosystems. Int Res J Mod Eng Technol Sci 7(1), 3185 (2025)"},{"key":"ref29","doi-asserted-by":"crossref","unstructured":"Rajesh, P., Alam, M., Tahernezhadi, M., Monika, A., Chanakya, G.: Analysis of cyber threat detection and emulation using mitre attack framework. In: 2022 International Conference on Intelligent Data Science Technologies and Applications (IDSTA). pp. 4-12. IEEE (2022)","DOI":"10.1109\/IDSTA55301.2022.9923170"},{"key":"ref30","doi-asserted-by":"crossref","unstructured":"Rios Insua, D., Couce-Vieira, A., Rubio, J.A., Pieters, W., Labunets, K., G. Rasines, D.: An adversarial risk analysis framework for cybersecurity. Risk Analysis 41(1), 16-36 (2021)","DOI":"10.1111\/risa.13331"},{"key":"ref31","doi-asserted-by":"crossref","unstructured":"Sailio, M., Latvala, O.M., Szanto, A.: Cyber threat actors for the factory of the future. Applied Sciences 10(12), 4334 (2020)","DOI":"10.3390\/app10124334"},{"key":"ref32","doi-asserted-by":"crossref","unstructured":"Shi, Z., Matyunin, N., Graffi, K., Starobinski, D.: Uncovering cwe-cve-cpe relations with threat knowledge graphs. ACM Transactions on Privacy and Security 27(1), 1-26 (2024)","DOI":"10.1145\/3641819"},{"key":"ref33","doi-asserted-by":"crossref","unstructured":"Subroto, A., Apriyana, A.: Cyber risk prediction through social media big data analytics and statistical machine learning. Journal of Big Data 6(1), 50 (2019)","DOI":"10.1186\/s40537-019-0216-1"},{"key":"ref34","unstructured":"TI Safe: Incident Hub (2024), https:\/\/hub.tisafe.com\/"},{"key":"ref35","doi-asserted-by":"crossref","unstructured":"W\u00e5reus, E., Hell, M.: Automated cpe labeling of cve summaries with machine learning. In: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. pp. 3-22. Springer (2020)","DOI":"10.1007\/978-3-030-52683-2_1"},{"key":"ref36","doi-asserted-by":"crossref","unstructured":"Xie, Y., Jin, X., Xie, T., Lin, M., Chen, L., Yu, C., Cheng, L., Zhuo, C., Hu, B., Li, Z.: Decomposition for enhancing attention: Improving llm-based text-to-sql through workflow paradigm. arXiv preprint arXiv:2402.10671 (2024)","DOI":"10.18653\/v1\/2024.findings-acl.641"},{"key":"ref37","doi-asserted-by":"crossref","unstructured":"Yin, J., Hong, W., Wang, H., Cao, J., Miao, Y., Zhang, Y.: A compact vulnerability knowledge graph for risk assessment. ACM Transactions on Knowledge Discovery from Data 18(8), 1-17 (2024)","DOI":"10.1145\/3671005"},{"key":"ref38","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in neural information processing systems 32 (2019)"}],"container-title":["Computer Science and Information Systems"],"original-title":[],"language":"en","deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T21:34:47Z","timestamp":1778967287000},"score":1,"resource":{"primary":{"URL":"https:\/\/doiserbia.nb.rs\/Article.aspx?ID=1820-02142600011G"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026]]}},"URL":"https:\/\/doi.org\/10.2298\/csis251030011g","relation":{},"ISSN":["1820-0214","2406-1018"],"issn-type":[{"value":"1820-0214","type":"print"},{"value":"2406-1018","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}