{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T13:47:36Z","timestamp":1783432056954,"version":"3.54.6"},"reference-count":49,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2021,5,9]],"date-time":"2021-05-09T00:00:00Z","timestamp":1620518400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100010676","name":"H2020 Societal Challenges","doi-asserted-by":"publisher","award":["832907"],"award-info":[{"award-number":["832907"]}],"id":[{"id":"10.13039\/100010676","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The MITRE ATT&amp;CK (Adversarial Tactics, Techniques, and Common Knowledge) Framework provides a rich and actionable repository of adversarial tactics, techniques, and procedures. Its innovative approach has been broadly welcomed by both vendors and enterprise customers in the industry. Its usage extends from adversary emulation, red teaming, behavioral analytics development to a defensive gap and SOC (Security Operations Center) maturity assessment. While extensive research has been done on analyzing specific attacks or specific organizational culture and human behavior factors leading to such attacks, a holistic view on the association of both is currently missing. In this paper, we present our research results on associating a comprehensive set of organizational and individual culture factors (as described on our developed cyber-security culture framework) with security vulnerabilities mapped to specific adversary behavior and patterns utilizing the MITRE ATT&amp;CK framework. Thus, exploiting MITRE ATT&amp;CK\u2019s possibilities towards a scientific direction that has not yet been explored: security assessment and defensive design, a step prior to its current application domain. The suggested cyber-security culture framework was originally designed to aim at critical infrastructures and, more specifically, the energy sector. Organizations of these domains exhibit a co-existence and strong interaction of the IT (Information Technology) and OT (Operational Technology) networks. As a result, we emphasize our scientific effort on the hybrid MITRE ATT&amp;CK for Enterprise and ICS (Industrial Control Systems) model as a broader and more holistic approach. The results of our research can be utilized in an extensive set of applications, including the efficient organization of security procedures as well as enhancing security readiness evaluation results by providing more insights into imminent threats and security risks.<\/jats:p>","DOI":"10.3390\/s21093267","type":"journal-article","created":{"date-parts":[[2021,5,10]],"date-time":"2021-05-10T02:54:58Z","timestamp":1620615298000},"page":"3267","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":93,"title":["Assessing MITRE ATT&amp;CK Risk Using a Cyber-Security Culture Framework"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0078-6969","authenticated-orcid":false,"given":"Anna","family":"Georgiadou","sequence":"first","affiliation":[{"name":"Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Spiros","family":"Mouzakitis","sequence":"additional","affiliation":[{"name":"Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dimitris","family":"Askounis","sequence":"additional","affiliation":[{"name":"Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,5,9]]},"reference":[{"key":"ref_1","unstructured":"Cybersecurity Ventures (2019). 2019 Official Annual Cybercrime Report, Herjavec Group."},{"key":"ref_2","unstructured":"Europol (2020). Internet Organised Crime Threat Assessment 2020."},{"key":"ref_3","unstructured":"INTERPOL (2021, January 07). INTERPOL Report Shows Alarming Rate of Cyberattacks during COVID-19, Available online: https:\/\/www.interpol.int\/en\/News-and-Events\/News\/2020\/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19."},{"key":"ref_4","unstructured":"(2020, April 16). Coronavirus-Related Fraud Reports Increase by 400% in March. Available online: https:\/\/www.actionfraud.police.uk\/alert\/coronavirus-related-fraud-reports-increase-by-400-in-march."},{"key":"ref_5","unstructured":"(2020, April 16). Coronavirus Scam Costs Victims over \u00a3800k in One Month. Available online: https:\/\/www.actionfraud.police.uk\/alert\/coronavirus-scam-costs-victims-over-800k-in-one-month."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"431","DOI":"10.3233\/JCS-2003-11308","article-title":"The economic cost of publicly announced information security breaches: Empirical evidence from the stock market","volume":"11","author":"Campbell","year":"2003","journal-title":"J. Comput. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1108\/09685220310468646","article-title":"Quantifying the financial impact of IT security breaches","volume":"11","author":"Garg","year":"2003","journal-title":"Inf. Manag. Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"33","DOI":"10.3233\/JCS-2009-0398","article-title":"The impact of information security breaches: Has there been a downward shift in costs?","volume":"19","author":"Lawrence","year":"2011","journal-title":"J. Comput. Secur."},{"key":"ref_9","unstructured":"UNIT 42 (2020). 2020 Unit 42 IoT Threat Report, Palo Alto Networks."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Kwon, R., Ashley, T., Castleberry, J., Mckenzie, P., and Gourisetti, S.N.G. (2020, January 19\u201323). Cyber Threat Dictionary Using MITRE ATT&CK Matrix and NIST Cybersecurity Framework Mapping. Proceedings of the 2020 Resilience Week (RWS), Salt Lake City, UT, USA.","DOI":"10.1109\/RWS50334.2020.9241271"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Al-Shaer, R., Spring, J.M., and Christou, E. (July, January 29). Learning the Associations of MITRE ATT&CK Adversarial Techniques. Proceedings of the 2020 IEEE Conference on Communications and Network Security (CNS), Avignon, France.","DOI":"10.1109\/CNS48642.2020.9162207"},{"key":"ref_12","unstructured":"(2020, January 6\u20138). Modeling Attack, Defense and Threat Trees and the Cyber Kill Chain, ATT&CK and STRIDE Frameworks as Blackboard Architecture Networks. Proceedings of the 2020 IEEE International Conference on Smart Cloud (SmartCloud), Washington, DC, USA."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Khan, M.S., Siddiqui, S., and Ferens, K. (2018). A Cognitive and Concurrent Cyber Kill Chain Model. Computer and Network Security Essentials, Springer.","DOI":"10.1007\/978-3-319-58424-9_34"},{"key":"ref_14","unstructured":"Basra, J., and Kaushik, T. (2020). MITRE ATT&CK\u00ae as a Framework for Cloud Threat Investigation, Center for Long-Term Cybersecurity (CLTC)."},{"key":"ref_15","unstructured":"AIT News Desk (2020). MITRE ATT&CK Improves Cloud Security, Yet Many Enterprises Struggle to Implement It, AiThority. Available online: https:\/\/aithority.com\/it-and-devops\/cloud\/study-mitre-attck-improves-cloud-security-yet-many-enterprises-struggle-to-implement-it\/."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Cho, S., Han, I., Jeong, H., Kim, J., Koo, S., Oh, H., and Park, M. (2018, January 11\u201312). Cyber Kill Chain based Threat Taxonomy and its Application on Cyber Common Operational Picture. Proceedings of the 2018 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA), Glasgow, UK.","DOI":"10.1109\/CyberSA.2018.8551383"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Mavroeidis, V., and Bromander, S. (2017, January 11\u201313). Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence. Proceedings of the 2017 European Intelligence and Security Informatics Conference (EISIC), Athens, Greece.","DOI":"10.1109\/EISIC.2017.20"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Subrahmanian, V., Swarup, V., and Wang, C. (2016). Integrating Cyber-D&D into Adversary Modeling for Active Cyber Defense. Cyber Deception, Springer.","DOI":"10.1007\/978-3-319-32699-3"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Maym\u00ed, F., Bixler, R., Jones, R., and Lathrop, S. (2017, January 11\u201314). Towards a definition of cyberspace tactics, techniques and procedures. Proceedings of the 2017 IEEE International Conference on Big Data (Big Data), Boston, MA, USA.","DOI":"10.1109\/BigData.2017.8258514"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Farooq, H.M., and Otaibi, N.M. (2018, January 27\u201329). Optimal Machine Learning Algorithms for Cyber Threat Detection. Proceedings of the 2018 UKSim-AMSS 20th International Conference on Computer Modelling and Simulation (UKSim), Cambridge, UK.","DOI":"10.1109\/UKSim.2018.00018"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Hasan, K., Shetty, S., and Ullah, S. (2019, January 12\u201314). Artificial Intelligence Empowered Cyber Threat Detection and Protection for Power Utilities. Proceedings of the 2019 IEEE 5th International Conference on Collaboration and Internet Computing (CIC), Los Angeles, CA, USA.","DOI":"10.1109\/CIC48465.2019.00049"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Parmar, M., and Domingo, A. (2019, January 12\u201314). On the Use of Cyber Threat Intelligence (CTI) in Support of Developing the Commander\u2019s Understanding of the Adversary. Proceedings of the MILCOM 2019 IEEE Military Communications Conference (MILCOM), Norfolk, VA, USA.","DOI":"10.1109\/MILCOM47813.2019.9020852"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Husari, G., Al-Shaer, E., Chu, B., and Rahman, R.F. (2019). Learning APT chains from cyber threat intelligence. HotSoS \u201919: Proceedings of the 6th Annual Symposium on Hot Topics in the Science of Security, Association for Computing Machinery.","DOI":"10.1145\/3314058.3317728"},{"key":"ref_24","first-page":"1","article-title":"The Triangle Model for Cyber Threat Attribution","volume":"2021","author":"Warikoo","year":"2021","journal-title":"J. Cyber Secur. Technol."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1016\/j.future.2019.02.013","article-title":"A machine learning-based FinTech cyber threat attribution framework using high-level indicators of compromise","volume":"96","author":"Noor","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_26","first-page":"71","article-title":"Automated Cyber Threat Emulation Based on ATT&CK for Cyber Security Training","volume":"25","author":"Kim","year":"2020","journal-title":"J. Korea Soc. Comput. Inf."},{"key":"ref_27","first-page":"797","article-title":"The Design and Implementation of Simulated Threat Generator based on MITRE ATT&CK for Cyber Warfare Training","volume":"22","author":"Hong","year":"2019","journal-title":"J. Korea Inst. Mil. Sci. Technol."},{"key":"ref_28","first-page":"31","article-title":"Research on System Architecture and Methodology based on MITRE ATT&CK for Experiment Analysis on Cyber Warfare Simulation","volume":"25","author":"Ahn","year":"2020","journal-title":"J. Korea Soc. Comput. Inf."},{"key":"ref_29","unstructured":"Xiong, W., and Hacks, S. (2020, January 19\u201322). Threat Modeling and Attack Simulations for Enterprise and ICS. Proceedings of the CS3STHLM, Stockholm, Sweden."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Georgiadou, A., Mouzakitis, S., and Askounis, D. (2021). Detecting Insider Threat via a Cyber-Security Culture Framework. J. Comput. Inf. Syst.","DOI":"10.1080\/08874417.2021.1903367"},{"key":"ref_31","unstructured":"Strom, B. (2021, January 03). \u201cATT&CK 101\u201d, Medium. Available online: https:\/\/medium.com\/mitre-attack\/att-ck-101-17074d3bc62."},{"key":"ref_32","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., and Thomas, C.B. (2018). MITRE ATT&CK\u00ae: Design and Philosophy, The MITRE Corporation."},{"key":"ref_33","unstructured":"Strom, B.E., Battaglia, J.A., Kemmerer, M.S., Kupersanin, W., Miller, D.P., Wampler, C., Whitley, S.M., and Wolf, R.D. (2017). Finding Cyber Threats with ATT&CK\u2122-Based Analytics, The MITRE Corporation."},{"key":"ref_34","unstructured":"The MITRE Corporation (2021, January 03). \u201cMITRE ATT&CK\u00ae\u201d, The MITRE Corporation. Available online: https:\/\/attack.mitre.org\/."},{"key":"ref_35","unstructured":"Caimi, S. (2020). MITRE ATT&CK: The Magic of Mitigations, Cisco. Available online: https:\/\/cscoblogs-prod-17bj.appspot.com\/security\/mitre-attck-the-magic-of-mitigations."},{"key":"ref_36","unstructured":"Esbeck, K., and Strom, B. (2013). Integrating PRE-ATT&CK Techniques into ATT&CK, The MITRE Corporation. Available online: https:\/\/www.mitre.org\/capabilities\/cybersecurity\/overview\/cybersecurity-blog\/integrating-pre-attck-techniques-into-attck."},{"key":"ref_37","unstructured":"The MITRE Corporation (2021, January 03). ATT&CK\u00ae for Industrial Control Systems. Available online: https:\/\/collaborate.mitre.org\/attackics\/index.php\/Main_Page."},{"key":"ref_38","unstructured":"Alexander, O., Belisle, M., and Steele, J. (2020). MITRE ATT&CK\u00ae for Industrial Control Systems: Design and Philosophy, The MITRE Corporation."},{"key":"ref_39","unstructured":"Claroty (2020). The Global State of Industrial Cybersecurity, Claroty."},{"key":"ref_40","unstructured":"Zafra, D.K., Lunden, K., Alexander, O., Brubaker, N., and Agboruche, G. (2020). In Pursuit of a Gestalt Visualization: Merging MITRE ATT&CK\u00ae for Enterprise and ICS to Communicate Adversary Behaviors, FireEye, Inc.. Available online: https:\/\/www.fireeye.com\/blog\/executive-perspective\/2020\/09\/merging-mitre-attack-for-enterprise-and-ics-to-communicate-adversary-behaviors.html."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Georgiadou, A., Mouzakitis, S., Bounas, K., and Askounis, D. (2020). A Cyber-Security Culture Framework for Assessing Organization Readiness. J. Comput. Inf. Syst.","DOI":"10.1080\/08874417.2020.1845583"},{"key":"ref_42","first-page":"33","article-title":"Designing a Cyber-security Culture Assessment Survey Targeting Critical Infrastructures during Covid-19 Crisis","volume":"13","author":"Georgiadou","year":"2020","journal-title":"Int. J. Netw. Secur. Appl."},{"key":"ref_43","unstructured":"Georgiadou, A., Mouzakitis, S., and Askounis, D. (2021, May 09). Working from Home during COVID-19 Crisis: A Cyber-Security Culture Assessment Survey. Mendeley Data, V1. Available online: https:\/\/data.mendeley.com\/datasets\/59tp8sdgr8\/1."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Georgiadou, A., Mouzakitis, S., and Askounis, D. (2021). Working from home during COVID 19 crisis: A cyber security culture assessment survey. Secur. J.","DOI":"10.1057\/s41284-021-00286-2"},{"key":"ref_45","unstructured":"(2020, March 25). Energy Shield. Available online: https:\/\/energy-shield.eu\/."},{"key":"ref_46","unstructured":"Greenfield, D. (2020). Cybersecurity Survey Reveals IT\/OT Bridges and Disconnects, AutomationWorld. Available online: https:\/\/www.automationworld.com\/cybersecurity\/article\/21130642\/cybersecurity-survey-reveals-itot-bridges-and-disconnects."},{"key":"ref_47","unstructured":"MITRE Corporation (2020). Mitigations Enterprise|MITRE ATT&CK, MITRE Corporation. Available online: https:\/\/attack.mitre.org\/mitigations\/enterprise\/."},{"key":"ref_48","unstructured":"MITRE Corporation (2020). Mitigations Attackics, MITRE Corporation. Available online: https:\/\/collaborate.mitre.org\/attackics\/index.php\/Mitigations."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1361-3723(19)30063-6","article-title":"Cybercrime has evolved: It\u2019s time cyber security did too","volume":"2019","author":"Lee","year":"2019","journal-title":"Comput. Fraud Secur."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/9\/3267\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T05:58:26Z","timestamp":1760162306000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/9\/3267"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,9]]},"references-count":49,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2021,5]]}},"alternative-id":["s21093267"],"URL":"https:\/\/doi.org\/10.3390\/s21093267","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,9]]}}}