{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T10:34:11Z","timestamp":1781606051238,"version":"3.54.5"},"reference-count":73,"publisher":"MDPI AG","issue":"16","license":[{"start":{"date-parts":[[2021,8,15]],"date-time":"2021-08-15T00:00:00Z","timestamp":1628985600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["826404"],"award-info":[{"award-number":["826404"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Addressing cyber and privacy risks has never been more critical for organisations. While a number of risk assessment methodologies and software tools are available, it is most often the case that one must, at least, integrate them into a holistic approach that combines several appropriate risk sources as input to risk mitigation tools. In addition, cyber risk assessment primarily investigates cyber risks as the consequence of vulnerabilities and threats that threaten assets of the investigated infrastructure. In fact, cyber risk assessment is decoupled from privacy impact assessment, which aims to detect privacy-specific threats and assess the degree of compliance with data protection legislation. Furthermore, a Privacy Impact Assessment (PIA) is conducted in a proactive manner during the design phase of a system, combining processing activities and their inter-dependencies with assets, vulnerabilities, real-time threats and Personally Identifiable Information (PII) that may occur during the dynamic life-cycle of systems. In this paper, we propose a cyber and privacy risk management toolkit, called AMBIENT (Automated Cyber and Privacy Risk Management Toolkit) that addresses the above challenges by implementing and integrating three distinct software tools. AMBIENT not only assesses cyber and privacy risks in a thorough and automated manner but it also offers decision-support capabilities, to recommend optimal safeguards using the well-known repository of the Center for Internet Security (CIS) Controls. To the best of our knowledge, AMBIENT is the first toolkit in the academic literature that brings together the aforementioned capabilities. To demonstrate its use, we have created a case scenario based on information about cyber attacks we have received from a healthcare organisation, as a reference sector that faces critical cyber and privacy threats.<\/jats:p>","DOI":"10.3390\/s21165493","type":"journal-article","created":{"date-parts":[[2021,8,15]],"date-time":"2021-08-15T22:51:27Z","timestamp":1629067887000},"page":"5493","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Automated Cyber and Privacy Risk Management Toolkit"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2036-981X","authenticated-orcid":false,"given":"Gustavo","family":"Gonzalez-Granadillo","sequence":"first","affiliation":[{"name":"ATOS Spain, Atos Research & Innovation, Cybersecurity Unit, 08020 Barcelona, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2446-5470","authenticated-orcid":false,"given":"Sofia Anna","family":"Menesidou","sequence":"additional","affiliation":[{"name":"UBITECH Ltd., Thessalias 8 & Etolias 10, 152 31 Chalandri, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9471-5415","authenticated-orcid":false,"given":"Dimitrios","family":"Papamartzivanos","sequence":"additional","affiliation":[{"name":"UBITECH Ltd., Thessalias 8 & Etolias 10, 152 31 Chalandri, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ramon","family":"Romeu","sequence":"additional","affiliation":[{"name":"Fundaci\u00f3 Privada Hospital Asil de Granollers, 08402 Granollers, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0563-3937","authenticated-orcid":false,"given":"Diana","family":"Navarro-Llobet","sequence":"additional","affiliation":[{"name":"Fundaci\u00f3 Privada Hospital Asil de Granollers, 08402 Granollers, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Caxton","family":"Okoh","sequence":"additional","affiliation":[{"name":"School of Computing and Mathematical Sciences, University of Greenwich, London SE10 9LS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sokratis","family":"Nifakos","sequence":"additional","affiliation":[{"name":"Karolinska Institutet Department of Learning, Informatics, Management and Ethics, Tomtebodav\u00e4gen 18b, 171 77 Solna, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6718-122X","authenticated-orcid":false,"given":"Christos","family":"Xenakis","sequence":"additional","affiliation":[{"name":"Department of Digital Systems, University of Piraeus, Karaoli ke Dimitriou 80, 185 34 Pireas, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7306-4062","authenticated-orcid":false,"given":"Emmanouil","family":"Panaousis","sequence":"additional","affiliation":[{"name":"School of Computing and Mathematical Sciences, University of Greenwich, London SE10 9LS, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,8,15]]},"reference":[{"key":"ref_1","unstructured":"Whitman, M.E., and Mattord, H.J. (2011). Principles of Information Security, Cengage Learning."},{"key":"ref_2","unstructured":"Centre for Internet Security (2021, May 31). CIS Controls v7.1. Available online: https:\/\/www.cisecurity.org\/controls\/."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.3233\/THC-161263","article-title":"Cybersecurity in healthcare: A systematic review of modern threats and trends","volume":"25","author":"Kruse","year":"2017","journal-title":"Technol. Health Care"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Verizon (2021, March 30). 2020 Data Breach Investigations Report. Available online: https:\/\/enterprise.verizon.com\/resources\/reports\/2020-data-breach-investigations-report.pdf.","DOI":"10.1016\/S1361-3723(20)30059-2"},{"key":"ref_5","unstructured":"Bischoff, P. (2021, March 30). 172 Ransomware Attacks on US Healthcare Organizations Since 2016 (Costing Over $157 Million). Available online: https:\/\/www.comparitech.com\/blog\/information-security\/ransomware-attacks-hospitals-data\/."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Verizon (2021, April 12). 2019 Data Breach Investigations Report. Available online: https:\/\/enterprise.verizon.com\/resources\/reports\/2019-data-breach-investigations-report.pdf.","DOI":"10.1016\/S1361-3723(19)30060-0"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Martin, G., Ghafur, S., Kinross, J., Hankin, C., and Darzi, A. (2018). WannaCry\u2014A Year on, British Medical Journal Publishing Group.","DOI":"10.1136\/bmj.k2381"},{"key":"ref_8","unstructured":"Commission, E. (2021, June 08). General Data Protection Regulation (GDPR). Available online: https:\/\/gdpr-info.eu\/."},{"key":"ref_9","unstructured":"National Institute of Standards and Technology (2020). NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","article-title":"Optimal Countermeasures Selection Against Cyber Attacks: A Comprehensive Survey on Reaction Frameworks","volume":"20","author":"Nespoli","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1109\/MSECP.2003.1193216","article-title":"The weakest link revisited [information security]","volume":"1","author":"Arce","year":"2003","journal-title":"IEEE Secur. Priv."},{"key":"ref_12","unstructured":"Vavoulas, N., and Xenakis, C. (2010, January 23\u201324). A Quantitative Risk Analysis Approach for Deliberate Threats. Proceedings of the 5th International Workshop on Critical Information Infrastructures Security (CRITIS), Athens, Greece."},{"key":"ref_13","unstructured":"Vesely, W., Dugan, J., Fragola, J., Minarick, J., and Railsback, J. (2021, May 31). Fault Tree Handbook with Aerospace Applications (NASA Project). Available online: http:\/\/www.mwftr.com\/CS2\/Fault%20Tree%20Handbook_NASA.pdf."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1016\/j.cosrev.2015.03.001","article-title":"Fault tree analysis: A survey of the state-of-the-art in modeling, analysis and tools","volume":"15","author":"Ruijters","year":"2015","journal-title":"Comput. Sci. Rev."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/1471-2105-12-89","article-title":"Learning genetic epistasis using Bayesian network scoring criteria","volume":"12","author":"Jiang","year":"2011","journal-title":"BMC Bioinform."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Koumenides, C.L., and Shadbolt, N.R. (2012, January 16). Combining link and content-based information in a Bayesian inference model for entity search. Proceedings of the 1st Joint International Workshop on Entity-Oriented and Semantic Search, Portland, OR, USA.","DOI":"10.1145\/2379307.2379310"},{"key":"ref_17","unstructured":"Haugh, M. (2016). Monte-Carlo Methods for Risk Management. IEOR E4602: Quantitative Risk Management, Available online: https:\/\/martin-haugh.github.io\/files\/QRM\/MC_RiskManage.pdf."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Komorowski, M., and Raffa, J. (2016). Markov Models and Cost Effectiveness Analysis: Applications in Medical Research. Second. Anal. Electron. Health Rec., 351\u2013367.","DOI":"10.1007\/978-3-319-43742-2_24"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Yu-Ting, D., Hai-Peng, Q., and Xi-Long, T. (2014, January 7\u20139). Real-time risk assessment based on hidden Markov model and security configuration. Proceedings of the Conference on Information Science, Electronics & Electrical Engineering, Wuhan, China.","DOI":"10.1109\/InfoSEEE.2014.6946191"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Gonzalez Granadillo, G., Doynikova, E., Garcia-Alfaro, J., Kotenko, I., and Fedorchenko, A. (2020). Stateful RORI-based countermeasure selection using hypergraphs. J. Inf. Secur. Appl., 54.","DOI":"10.1016\/j.jisa.2020.102541"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"535","DOI":"10.1016\/j.future.2017.05.043","article-title":"Dynamic risk management response system to handle cyber threats","volume":"83","author":"Dubus","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Gonzalez-Granadillo, G., Alvarez, E., Motzek, A., Merialdo, M., Garcia-Alfaro, J., and Debar, H. (2016, January 2\u20134). Towards an Automated and Dynamic Risk Management Response System. Proceedings of the Nordic Conference on Secure IT Systems NordSec, Oulu, Finland.","DOI":"10.1007\/978-3-319-47560-8_3"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1111\/risa.12891","article-title":"Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management","volume":"40","author":"Ganin","year":"2017","journal-title":"Risk Anal. Int. J."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1016\/j.compind.2018.08.002","article-title":"Future developments in cyber risk assessment for the internet of things","volume":"102","author":"Radanliev","year":"2018","journal-title":"Comput. Ind."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"26448","DOI":"10.1109\/ACCESS.2019.2901408","article-title":"Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Model","volume":"7","author":"Parody","year":"2019","journal-title":"IEEE J. Access"},{"key":"ref_26","unstructured":"Bay Dynamics (2021, August 05). Cyber Value at Risk: Quantify the Financial Impact of Cyber Risk. Available online: https:\/\/www.ten-inc.com\/presentations\/2017_ISE_NE_BayDynamics_WP.pdf."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1016\/j.bjoms.2015.11.023","article-title":"Micromorts\u2014What is the risk?","volume":"54","author":"Fry","year":"2016","journal-title":"Br. J. Oral Maxillofac. Surg."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Biswas, B., Mukhopadhyay, A., Bhattacharjee, S., Kumar, A., and Delen, D. (2021). A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums. Decis. Support Syst., 113651.","DOI":"10.1016\/j.dss.2021.113651"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2725","DOI":"10.1016\/j.aej.2020.05.014","article-title":"Automatic cyber security risk assessment based on fuzzy fractional ordinary differential equations","volume":"59","author":"Wang","year":"2020","journal-title":"Alex. Eng. J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"102163","DOI":"10.1016\/j.cose.2020.102163","article-title":"\u201cTalking a different Language\u201d: Anticipating adversary attack cost for cyber risk assessment","volume":"103","author":"Derbyshire","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1016\/j.clsr.2009.02.002","article-title":"Privacy impact assessment: Its origins and development","volume":"25","author":"Clarke","year":"2009","journal-title":"Comput. Law Secur. Rev."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1057\/ejis.2013.18","article-title":"A systematic methodology for privacy impact assessments: A design science approach","volume":"23","author":"Oetzel","year":"2014","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Vemou, K., and Karyda, M. (2018, January 28\u201330). An Evaluation Framework for Privacy Impact Assessment Methods. Proceedings of the 12th Mediterranean Conference on Information Systems (MCIS), Corfu, Greece.","DOI":"10.1108\/ICS-04-2019-0047"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Papamartzivanos, D., Menesidou, S.A., Gouvas, P., and Giannetsos, T. (2021). A Perfect Match: Converging and Automating Privacy and Security Impact Assessment On-the-Fly. Future Internet, 13.","DOI":"10.3390\/fi13020030"},{"key":"ref_35","unstructured":"Institution, B.S. (2021, July 12). Data Protection\u2014Specification for a Personal Information Management System. Available online: https:\/\/www.bsigroup.com\/en-GB\/BS-10012-Personal-information-management\/."},{"key":"ref_36","unstructured":"ISO\/IEC-29151:2017 (2021, July 12). Information Technology\u2014Security techniques\u2014Code of Practice for Personally Identifiable Information Protection. Available online: https:\/\/www.iso.org\/standard\/62726.html."},{"key":"ref_37","unstructured":"ISO\/IEC-27018:2014 (2021, July 12). Information Technology\u2014Security Techniques\u2014Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds Acting as PII Processors. Available online: https:\/\/www.iso.org\/standard\/61498.html."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1468","DOI":"10.1007\/s11227-018-2371-0","article-title":"pISRA: Privacy considered information security risk assessment model","volume":"76","author":"Wei","year":"2020","journal-title":"J. Supercomput."},{"key":"ref_39","unstructured":"ISO\/IEC-29134:2017 (2021, July 12). Information Technology\u2014Security Techniques\u2014Guidelines for Privacy Impact Assessment. Available online: https:\/\/www.iso.org\/standard\/62289.html."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Wagner, I., and Eckhoff, D. (2018). Technical Privacy Metrics: A Systematic Survey. Assoc. Comput. Mach., 51.","DOI":"10.1145\/3168389"},{"key":"ref_41","unstructured":"National Institute of Standards and Technology (2021, March 29). NIST Privacy Risk Assessment Methodology (PRAM), Available online: https:\/\/www.nist.gov\/privacy-framework\/nist-pram."},{"key":"ref_42","unstructured":"Commission Nationale de l\u2019Informatique et des Libert\u00e9s (2020, November 08). Privacy Impact Assessment (PIA) 1: Methodology. Available online: https:\/\/www.cnil.fr\/sites\/default\/files\/atoms\/files\/cnil-pia-1-en-methodology.pdf."},{"key":"ref_43","unstructured":"Information Commissioner\u2019s Office (2020, November 08). Data Protection Impact Assessments (DPIAs). Available online: https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/accountability-and-governance\/data-protection-impact-assessments\/."},{"key":"ref_44","unstructured":"ENISA (2020, November 08). On-line Tool for the Security of Personal Data Processing. Available online: https:\/\/www.enisa.europa.eu\/risk-level-tool\/risk."},{"key":"ref_45","unstructured":"Arnell, S. (2020, November 08). GDPR Data Protection Impact Assessment Tool. Available online: https:\/\/github.com\/simonarnell\/GDPRDPIAT."},{"key":"ref_46","unstructured":"IITR (2020, November 08). Compliance Kit 2.0. Available online: https:\/\/www.iitr.us\/products-services\/compliance-kit.html."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1007\/978-981-13-8969-6_2","article-title":"A Quantitative Methodology for Business Process-Based Data Privacy Risk Computation","volume":"10","author":"Manna","year":"2020","journal-title":"Adv. Comput. Syst. Secur."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Henriksen-Bulmer, J., Faily, S., and Jeary, S. (2020). DPIA in Context: Applying DPIA to Assess Privacy Risks of Cyber Physical Systems. Future Internet, 12.","DOI":"10.3390\/fi12050093"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"438","DOI":"10.1145\/581271.581274","article-title":"The economics of information security investment","volume":"5","author":"Gordon","year":"2002","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/j.dss.2016.02.012","article-title":"Decision support approaches for cyber security investment","volume":"86","author":"Fielder","year":"2016","journal-title":"Decis. Support Syst."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Panda, S., Panaousis, E., Loukas, G., and Laoudias, C. (2020). Optimizing Investments in Cyber Hygiene for Protecting Healthcare Users. From Lambda Calculus to Cybersecurity Through Program Analysis, Springer.","DOI":"10.1007\/978-3-030-41103-9_11"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Rontidis, G., Panaousis, E., Laszka, A., Dagiuklas, T., Malacaria, P., and Alpcan, T. (2015, January 8\u201312). A game-theoretic approach for minimizing security risks in the internet-of-things. Proceedings of the 2015 IEEE International Conference on Communication Workshop (ICCW), London, UK.","DOI":"10.1109\/ICCW.2015.7247577"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1016\/j.adhoc.2016.11.008","article-title":"Game theoretic path selection to support security in device-to-device communications","volume":"56","author":"Panaousis","year":"2017","journal-title":"Ad Hoc Netw."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., and Smeraldi, F. (2014, January 2\u20134). Game theory meets information security management. Proceedings of the IFIP International Information Security Conference, Marrakech, Morocco.","DOI":"10.1007\/978-3-642-55415-5_2"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"101173","DOI":"10.1016\/j.pacfin.2019.101173","article-title":"Integrated framework for information security investment and cyber insurance","volume":"57","author":"Wang","year":"2019","journal-title":"Pac. Basin Financ. J."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"405","DOI":"10.1007\/s10479-016-2209-1","article-title":"A supply chain network game theory model of cybersecurity investments with nonlinear budget constraints","volume":"248","author":"Nagurney","year":"2017","journal-title":"Ann. Oper. Res."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"12175","DOI":"10.1109\/ACCESS.2017.2773366","article-title":"An options approach to cybersecurity investment","volume":"6","author":"Chronopoulos","year":"2017","journal-title":"IEEE Access"},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/j.dss.2018.10.001","article-title":"Decision support for the optimal allocation of security controls","volume":"115","author":"Zhang","year":"2018","journal-title":"Decis. Support Syst."},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Fielder, A., K\u00f6nig, S., Panaousis, E., Schauer, S., and Rass, S. (2018). Risk assessment uncertainties in cybersecurity investments. Games, 9.","DOI":"10.3390\/g9020034"},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"113069","DOI":"10.1016\/j.dss.2019.05.009","article-title":"Socially optimal IT investment for cybersecurity","volume":"122","author":"Paul","year":"2019","journal-title":"Decis. Support Syst."},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Dutta, A., and Al-Shaer, E. (2019, January 1\u20133). Cyber defense matrix: A new model for optimal composition of cybersecurity controls to construct resilient risk mitigation. Proceedings of the 6th Annual Symposium on Hot Topics in the Science of Security, Nashville, TN, USA.","DOI":"10.1145\/3314058.3317725"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Gonzalez-Granadillo, G., Gonzalez-Zarzosa, S., and Diaz, R. (2021). Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures. Sensors, 21.","DOI":"10.3390\/s21144759"},{"key":"ref_63","unstructured":"Marko Bohanec (2021, June 12). DEXi: Program for Multi-Attribute Decision Making User\u2019s Manual Version 5.05. Available online: https:\/\/kt.ijs.si\/MarkoBohanec\/pub\/DEXiManual505.pdf."},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Cleary, F., and Felici, M. (2015). Medusa: A Supply Chain Risk Assessment Methodology. Cyber Security and Privacy, Springer International Publishing.","DOI":"10.1007\/978-3-319-25360-2"},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Ahmadian, A.S., Str\u00fcber, D., Riediger, V., and J\u00fcrjens, J. (2018, January 9\u201313). Supporting Privacy Impact Assessment by Model-Based Privacy Analysis. Proceedings of the 33rd Annual ACM Symposium on Applied Computing, Pau, France.","DOI":"10.1145\/3167132.3167288"},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"793","DOI":"10.1142\/S0218488512400247","article-title":"Data privacy: Definitions and techniques","volume":"20","author":"Foresti","year":"2012","journal-title":"Int. J. Uncertain. Fuzziness Knowl. Based Syst."},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Makri, E.L., Georgiopoulou, Z., and Lambrinoudakis, C. (2020). A Proposed Privacy Impact Assessment Method Using Metrics Based on Organizational Characteristics. Computer Security, Springer International Publishing.","DOI":"10.1007\/978-3-030-42048-2_9"},{"key":"ref_68","unstructured":"QED Secure Solutions (2020, November 08). Risk Scoring System for Medical Devices (RSS-MD)-Technical Specification Guide. Available online: https:\/\/www.riskscoringsystem.com\/medical\/techspecmedical.pdf."},{"key":"ref_69","unstructured":"ENISA (2021, February 15). Procurement Guidelines for Cybersecurity in Hospitals. Available online: https:\/\/www.enisa.europa.eu\/publications\/good-practices-for-the-security-of-healthcare-services.pdf."},{"key":"ref_70","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1073\/pnas.36.1.48","article-title":"Equilibrium points in n-person games","volume":"36","author":"Nash","year":"1950","journal-title":"Proc. Natl. Acad. Sci. USA"},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Mohammadi, F., Panou, A., Ntantogian, C., Karapistoli, E., Panaousis, E., and Xenakis, C. (2019, January 14\u201317). CUREX: SeCUre and pRivate hEalth data eXchange. Proceedings of the IEEE\/WIC\/ACM International Conference on Web Intelligence, Thessaloniki, Greece.","DOI":"10.1145\/3358695.3361753"},{"key":"ref_72","doi-asserted-by":"crossref","unstructured":"Jofre, M., Navarro-Llobet, D., Agull\u00f3, R., Puig, J., Gonzalez-Granadillo, G., Mora Zamorano, J., and Romeu, R. (2021). Cybersecurity and Privacy Risk Assessment of Point-of-Care Systems in Healthcare\u2014A Use Case Approach. Appl. Sci., 11.","DOI":"10.3390\/app11156699"},{"key":"ref_73","unstructured":"Bray, T. (2021, May 10). The JavaScript Object Notation (JSON) Data Interchange Format. Available online: https:\/\/datatracker.ietf.org\/doc\/html\/rfc8259."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/16\/5493\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:46:28Z","timestamp":1760165188000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/16\/5493"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,15]]},"references-count":73,"journal-issue":{"issue":"16","published-online":{"date-parts":[[2021,8]]}},"alternative-id":["s21165493"],"URL":"https:\/\/doi.org\/10.3390\/s21165493","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,8,15]]}}}