{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:40:44Z","timestamp":1760060444397,"version":"build-2065373602"},"reference-count":52,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Ransomware attacks pose a serious threat to global cybersecurity, inflicting severe financial and operational damage on organizations, individuals, and critical infrastructure. Despite their pervasive impact, proactive measures to mitigate ransomware threats remain underdeveloped, with most efforts focused on reactive responses. Moreover, prior literature reveals a significant gap in systematic approaches for predicting such incidents. This research seeks to address this gap by employing time-series analysis to forecast ransomware attacks. Using 1880 ransomware incidents, we decompose the dataset into trend, seasonal, and residual components, fit a time-series model, and forecast future attacks. The results indicate that time-series analysis is useful for uncovering broad, structural patterns in ransomware data. To gain further insight into these results, we perform sub-analyses based on attacks targeting the top five sectors. The findings reveal reasonable predictive performance for ransomware attacks against government facilities and the healthcare and public health sector, with the latter showing an upward trend in attacks. By providing a predictive lens, our model equips organizations with actionable intelligence, enabling preemptive measures and enhanced situational awareness. Finally, this research underscores the importance of integrating time-series forecasting into cybersecurity strategies and seeks to pave the way for future advancements in predictive analytics for cyber threats.<\/jats:p>","DOI":"10.3390\/jcp5030061","type":"journal-article","created":{"date-parts":[[2025,9,2]],"date-time":"2025-09-02T13:01:13Z","timestamp":1756818073000},"page":"61","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Predicting Ransomware Incidents with Time-Series Modeling"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7367-9152","authenticated-orcid":false,"given":"Yaman","family":"Roumani","sequence":"first","affiliation":[{"name":"Department of Information and Decision Sciences, Oakland University, Rochester, MI 48309, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yazan F.","family":"Roumani","sequence":"additional","affiliation":[{"name":"Department of Information and Decision Sciences, Oakland University, Rochester, MI 48309, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"e224873","DOI":"10.1001\/jamahealthforum.2022.4873","article-title":"Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations 2016\u20132021","volume":"3","author":"Neprash","year":"2022","journal-title":"JAMA Health Forum"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"tyaa023","DOI":"10.1093\/cybsec\/tyaa023","article-title":"An empirical study of ransomware attacks on organizations: An assessment of severity and salient factors affecting vulnerability","volume":"6","author":"Wall","year":"2020","journal-title":"J. Cybersecur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1016\/j.eij.2020.05.003","article-title":"Internet of things and ransomware: Evolution, mitigation and prevention","volume":"22","author":"Humayun","year":"2021","journal-title":"Egypt. Inform. J."},{"key":"ref_4","unstructured":"Fortinet (2025, January 12). The 2023 Global Ransomware Report. Available online: https:\/\/www.fortinet.com\/content\/dam\/fortinet\/assets\/reports\/report-2023-ransomware-global-research.pdf."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"103595","DOI":"10.1016\/j.cose.2023.103595","article-title":"A Survey of strategy-driven evasion methods for PE malware: Transformation, concealment, and attack","volume":"137","author":"Geng","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"40698","DOI":"10.1109\/ACCESS.2023.3268535","article-title":"The age of ransomware: A survey on the evolution, taxonomy, and research directions","volume":"11","author":"Razaulla","year":"2023","journal-title":"IEEE Access"},{"key":"ref_7","unstructured":"Quinkert, F., Holz, T., Hossain, K.S.M., Ferrara, E., and Lerman, K. (2018). Raptor: Ransomware attack predictor. arXiv."},{"key":"ref_8","first-page":"240","article-title":"Predictive analysis of ransomware attacks using context-aware AI in IoT systems","volume":"12","author":"Mathane","year":"2021","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Gazzan, M., and Sheldon, F.T. (2023). Opportunities for early detection and prediction of ransomware attacks against industrial control systems. Future Internet, 15.","DOI":"10.3390\/fi15040144"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"103349","DOI":"10.1016\/j.cose.2023.103349","article-title":"Cryptographic ransomware encryption detection: Survey","volume":"132","author":"Begovic","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"102490","DOI":"10.1016\/j.cose.2021.102490","article-title":"Ransomware: Recent advances, analysis, challenges and future research directions","volume":"111","author":"Beaman","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3479393","article-title":"Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions","volume":"54","author":"McIntosh","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Lanza, C., Lahmadi, A., and Fran\u00e7ois, J. (2024). Ransomware Analysis: Knowledge Extraction and Classification for Advanced Cyber Threat Intelligence, CRC Press.","DOI":"10.1201\/9781003528999"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s40163-019-0097-9","article-title":"Ransomware deployment methods and analysis: Views from a predictive model and human responses","volume":"8","author":"Hull","year":"2019","journal-title":"Crime Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Akcora, C.G., Li, Y., Gel, Y.R., and Kantarcioglu, M. (2019). Bitcoinheist: Topological data analysis for ransomware detection on the bitcoin blockchain. arXiv.","DOI":"10.24963\/ijcai.2020\/612"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xu, S. (2021, January 27\u201329). The application of machine learning in Bitcoin ransomware family prediction. Proceedings of the 2021 5th International Conference on Information System and Data Mining, New York, NY, USA.","DOI":"10.1145\/3471287.3471300"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2233716","DOI":"10.1080\/09540091.2023.2233716","article-title":"Early prediction of ransomware API calls behaviour based on GRU-TCN in healthcare IoT","volume":"35","author":"Jeon","year":"2023","journal-title":"Connect. Sci."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"578","DOI":"10.1016\/j.cose.2018.05.010","article-title":"Early-stage malware prediction using recurrent neural networks","volume":"77","author":"Rhode","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Albulayhi, K., and Al-Haija, Q.A. (2022, January 4\u20136). Early-stage malware and ransomware forecasting in the short-term future using regression-based neural network technique. Proceedings of the 2022 14th International Conference on Computational Intelligence and Communication Networks (CICN), Al-Khobar, Saudi Arabia.","DOI":"10.1109\/CICN56167.2022.10008270"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Li, S. (2024). Comparative Analysis of Predicting Malware Attack Trends in Cyber Supply Chain Using Multiple Classification Models. IEEE Access.","DOI":"10.1109\/ACCESS.2024.3471802"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Gogineni, K., Derasari, P., and Venkataramani, G. (2022, January 26\u201327). Foreseer: Efficiently forecasting malware event series with long short-term memory. Proceedings of the 2022 IEEE International Symposium on Secure and Private Execution Environment Design (SEED), Storrs, CT, USA.","DOI":"10.1109\/SEED55351.2022.00016"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1016\/j.cose.2015.03.003","article-title":"Time series modeling of vulnerabilities","volume":"51","author":"Roumani","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1109\/MIS.2018.111145153","article-title":"Predicting adversarial cyber-intrusion stages using autoregressive neural networks","volume":"33","author":"Rege","year":"2018","journal-title":"IEEE Intell. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"26759","DOI":"10.1109\/ACCESS.2024.3367240","article-title":"2019\u20132023 in Review: Projecting DDoS Threats with ARIMA and ETS Forecasting Techniques","volume":"12","author":"Falowo","year":"2024","journal-title":"IEEE Access"},{"key":"ref_25","unstructured":"Box, G.E., Jenkins, G.M., Reinsel, G.C., and Ljung, G.M. (2015). Time Series Analysis: Forecasting and Control, John Wiley & Sons."},{"key":"ref_26","unstructured":"Chatfield, C. (2013). The Analysis of Time Series: Theory and Practice, Springer."},{"key":"ref_27","unstructured":"Yaffee, R.A., and McGee, M. (2000). An Introduction to Time Series Analysis and Forecasting: With Applications of SAS\u00ae\u00ae and SPSS\u00ae\u00ae, Elsevier."},{"key":"ref_28","first-page":"3","article-title":"STL: A seasonal-trend decomposition","volume":"6","author":"Cleveland","year":"1990","journal-title":"J. off. Stat"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"596","DOI":"10.1080\/01621459.1988.10478639","article-title":"Locally weighted regression: An approach to regression analysis by local fitting","volume":"83","author":"Cleveland","year":"1988","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_30","unstructured":"Hyndman, R.J., and Athanasopoulos, G. (2018). Forecasting: Principles and Practice, Otexts."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1513","DOI":"10.1198\/jasa.2011.tm09771","article-title":"Forecasting time series with complex seasonal patterns using exponential smoothing","volume":"106","author":"Hyndman","year":"2011","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Hyndman, R., Koehler, A.B., Ord, J.K., and Snyder, R.D. (2008). Forecasting with Exponential Smoothing: The State Space Approach, Springer Science & Business Media.","DOI":"10.1007\/978-3-540-71918-2"},{"key":"ref_33","unstructured":"Rege, A. (2024, September 08). Critical Infrastructure Ransomware Attacks (CIRA) Dataset. Version 12.9. Temple University. Available online: https:\/\/sites.temple.edu\/care\/cira\/."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3558006","article-title":"The evolving menace of ransomware: A comparative analysis of pre-pandemic and mid-pandemic attacks","volume":"4","author":"Lng","year":"2023","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_35","first-page":"1","article-title":"Stationarity issues in time series models","volume":"30","author":"Dickey","year":"2015","journal-title":"SAS Users Group Int."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1093\/biomet\/65.2.297","article-title":"On a measure of lack of fit in time series models","volume":"65","author":"Ljung","year":"1978","journal-title":"Biometrika"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"79","DOI":"10.3354\/cr030079","article-title":"Advantages of the mean absolute error (MAE) over the root mean square error (RMSE) in assessing average model performance","volume":"30","author":"Willmott","year":"2005","journal-title":"Clim. Res."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3514229","article-title":"A survey on ransomware: Evolution, taxonomy, and defense solutions","volume":"54","author":"Oz","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"106771","DOI":"10.1016\/j.infsof.2021.106771","article-title":"Software security patch management-A systematic literature review of challenges, approaches, tools and practices","volume":"144","author":"Dissanayake","year":"2022","journal-title":"Inf. Softw. Technol."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"103364","DOI":"10.1016\/j.cose.2023.103364","article-title":"Evaluating organizational phishing awareness training on an enterprise scale","volume":"132","author":"Hillman","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_41","first-page":"802","article-title":"Simulated phishing attack and embedded training campaign","volume":"62","author":"Yeoh","year":"2022","journal-title":"J. Comput. Inf. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"103295","DOI":"10.1016\/j.cose.2023.103295","article-title":"Data flooding against ransomware: Concepts and implementations","volume":"131","author":"Brardi","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_43","unstructured":"Semperis (2025, February 05). 2024 Ransomware Holiday Risk Report. Available online: https:\/\/www.semperis.com\/ransomware-holiday-risk-report\/."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Keskin, O.F., Caramancion, K.M., Tatar, I., Raza, O., and Tatar, U. (2021). Cyber third-party risk management: A comparison of non-intrusive risk scoring reports. Electronics, 10.","DOI":"10.3390\/electronics10101168"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Argaw, S.T., Troncoso-Pastoriza, J.R., Lacey, D., Florin, M.V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J., O\u2019Leary, C., and Eshaya-Chauvin, B. (2020). Cybersecurity of Hospitals: Discussing the challenges and working towards mitigating the risks. BMC Med. Inform. Decis. Mak., 20.","DOI":"10.1186\/s12911-020-01161-7"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Hossain, S.T., Yigitcanlar, T., Nguyen, K., and Xu, Y. (2024). Local government cybersecurity landscape: A systematic review and conceptual framework. Appl. Sci., 14.","DOI":"10.3390\/app14135501"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Ulven, J.B., and Wangen, G. (2021). A systematic review of cybersecurity risks in higher education. Future Internet, 13.","DOI":"10.3390\/fi13020039"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"106946","DOI":"10.1016\/j.comnet.2019.106946","article-title":"Cybersecurity in industrial control systems: Issues, technologies, and challenges","volume":"165","author":"Asghar","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"109448","DOI":"10.1016\/j.ijpe.2024.109448","article-title":"The finance of cybersecurity: Quantitative modeling of investment decisions and net present value","volume":"279","author":"Brho","year":"2025","journal-title":"Int. J. Prod. Econ."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1016\/j.cose.2018.01.001","article-title":"Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions","volume":"74","author":"Maarof","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"NIST (2025, August 16). NIST Cybersecurity Framework, Available online: https:\/\/www.nist.gov\/cyberframework.","DOI":"10.6028\/NIST.SP.1299.jpn"},{"key":"ref_52","unstructured":"CISA (2025, March 28). Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), Available online: https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/information-sharing\/cyber-incident-reporting-critical-infrastructure-act-2022-circia."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/61\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:36:51Z","timestamp":1760035011000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/61"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,1]]},"references-count":52,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030061"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030061","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,9,1]]}}}