A Data-Driven Approach for Cyber Security Assessments of SMEs
摘要
This paper presents a novel framework for assessing the cyber security of Small and Medium-sized Enterprises (SMEs) and identifying the specific problematic security controls. The combination of dimensionality reduction and clustering techniques with logistic regression results in a data-driven, non-linear scoring system that provides more information about the current state and possible improvements, including “the best way of improvements.” The state of the art in the context of assessments is a linear scoring system, which is most often subjective due to manually determined weights in the corresponding linear combination. Our unsupervised methodology addresses not only this issue through the application of unsupervised algorithms, but also the unique challenges faced by SMEs in terms of limited resources, lack of expertise and inadequate cyber security measures. To validate our approach, we acquired a variety of data sets from SMEs across different industries and geographies. These data sets include organisational characteristics, cyber security controls and incident response measures. Our analysis shows that the proposed framework accurately provides actionable recommendations for improvement, while remaining highly configurable and extensible.