This paper presents a novel framework for assessing the cyber security of Small and Medium-sized Enterprises (SMEs) and identifying the specific problematic security controls. The combination of dimensionality reduction and clustering techniques with logistic regression results in a data-driven, non-linear scoring system that provides more information about the current state and possible improvements, including “the best way of improvements.” The state of the art in the context of assessments is a linear scoring system, which is most often subjective due to manually determined weights in the corresponding linear combination. Our unsupervised methodology addresses not only this issue through the application of unsupervised algorithms, but also the unique challenges faced by SMEs in terms of limited resources, lack of expertise and inadequate cyber security measures. To validate our approach, we acquired a variety of data sets from SMEs across different industries and geographies. These data sets include organisational characteristics, cyber security controls and incident response measures. Our analysis shows that the proposed framework accurately provides actionable recommendations for improvement, while remaining highly configurable and extensible.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Data-Driven Approach for Cyber Security Assessments of SMEs

  • Nico Mexis,
  • Stefan Katzenbeisser

摘要

This paper presents a novel framework for assessing the cyber security of Small and Medium-sized Enterprises (SMEs) and identifying the specific problematic security controls. The combination of dimensionality reduction and clustering techniques with logistic regression results in a data-driven, non-linear scoring system that provides more information about the current state and possible improvements, including “the best way of improvements.” The state of the art in the context of assessments is a linear scoring system, which is most often subjective due to manually determined weights in the corresponding linear combination. Our unsupervised methodology addresses not only this issue through the application of unsupervised algorithms, but also the unique challenges faced by SMEs in terms of limited resources, lack of expertise and inadequate cyber security measures. To validate our approach, we acquired a variety of data sets from SMEs across different industries and geographies. These data sets include organisational characteristics, cyber security controls and incident response measures. Our analysis shows that the proposed framework accurately provides actionable recommendations for improvement, while remaining highly configurable and extensible.