Abstract
We present a method for developing executable algorithms for quantitative cyber-risk assessment. Exploiting techniques from security risk modeling and actuarial approaches,
the method pragmatically combines use of available empirical
data and expert judgments. The input to the algorithms are
indicators providing information about the target of analysis, such as suspicious events observed in the network. Automated execution of the algorithms facilitates continuous assessment.
the method pragmatically combines use of available empirical
data and expert judgments. The input to the algorithms are
indicators providing information about the target of analysis, such as suspicious events observed in the network. Automated execution of the algorithms facilitates continuous assessment.