Adaptive cybersecurity management model for information and communication systems based on a risk-oriented approach

Authors

  • Rzaieva S.L. https://orcid.org/0000-0002-7589-2045 , Borys Grinchenko Kyiv Metropolitan University image/svg+xml
  • Lytvyn O.S. https://orcid.org/0000-0002-5118-1003 , Borys Grinchenko Kyiv Metropolitan University image/svg+xml
  • Skladannyi P.M. https://orcid.org/0000-0002-7775-6039 , Borys Grinchenko Kyiv Metropolitan University image/svg+xml , Institute of Mathematical Machines and Systems Problems image/svg+xml
  • Kostiuk Yu.V. https://orcid.org/0000-0001-5423-0985 , Borys Grinchenko Kyiv Metropolitan University image/svg+xml
  • Rzaiev D.O. https://orcid.org/0000-0002-7149-4971 , Kyiv National Economic University named after Vadym Hetman image/svg+xml

DOI:

https://doi.org/10.34121/1028-9763-2026-2-92-109

Keywords:

adaptive management, cybersecurity, information and communication systems, risk-oriented approach, risk assessment, integral risk indicator, IDEF0 modeling

Abstract

The article addresses the problem of cybersecurity management of information and communication systems under conditions of continuously changing threat parameters, the emergence of new vulnerabilities, and the growing number of cyberattacks. It is substantiated that traditional static approaches based on fixed security policies and predefined countermeasures do not ensure an adequate level of protection during the operation of information and communication systems, as they fail to consider the dynamics of the threat environment, the transformation of asset criticality, and changes in the probability of threat realization, which leads to the gradual accumulation of risks. An adaptive cybersecurity management model based on a risk-oriented approach is proposed. The model integrates security event monitoring, local asset risk assessment, formation of an integral risk indicator, selection and adjustment of countermeasures, and feedback mechanisms into a unified cyclic management process. The formalization of the model is carried out using IDEF0 functional modeling and algorithmic description. Asset risk is defined as the sum of the products of the probability of relevant threat realization and potential damage, which is assessed using a multifactor scheme taking into account material, functional, and reputational losses. The integral risk indicator is formed as a weighted sum of local risks, considering asset criticality and established acceptability thresholds. The obtained results confirm a reduction in both local and integral risks and demonstrate improved system responsiveness to dynamic cyber threats compared to static security management models. Tabl.: 4. Figs.: 2. Refs.: 12 titles.

References

1. Melaku H.M. Context-based and adaptive cybersecurity risk management framework. Risks. 2023. Vol. 11 (6). Article 101. DOI: https://doi.org/10.3390/risks11060101.

2. Islam S., Basheer N., Papastergiou S., Ciampi M., Silvestri S. Intelligent dynamic cybersecurity risk management framework with explainability and interpretability of AI models for enhancing security and resilience of digital infrastructure. Journal of Reliable Intelligent Environments. 2025. Vol. 11. Article 12. DOI: https://doi.org/10.1007/s40860-025-00253-3.

3. Cheimonidis P. A dynamic risk assessment and mitigation model for cybersecurity. Applied Sciences. 2025. Vol. 15 (4). Article 2171. DOI: https://doi.org/10.3390/app15042171.

4. Minkevics V.A capability-driven automated cybersecurity monitoring and response system. Frontiers in Computer Science. 2025. Vol. 7. Article 1692263. DOI: https://doi.org/10.3389/fcomp.2025.1692263.

5. Salamah F.B., Palomino M.A., Craven M.J., Papadaki M., Furnell S. An adaptive cybersecurity training framework for the education of social media users at work. Applied Sciences. 2023. Vol. 13 (17). Article 9595. DOI: https://doi.org/10.3390/app13179595.

6. Tkach V., Shemendiuk O., Cherednychenko O. Research on issues of information security risks assessment and management in the security and defense sector and formation of security level indicators. Cybersecurity: Education, Science, Technique. 2024. Vol. 2 (26). P. 81–94. DOI: https://doi.org/10.28925/26634023.2024.26.636.

7. Symonov A., Klevtsov O., Trubchaninov S., Symonova A. Cybersecurity of NPP Instrumentation and Control Systems: Risks Assessment. Nuclear and Radiation Safety. 2022. Vol. 4 (96). P. 62–70. DOI: https://doi.org/10.32918/nrs.2022.4(96).08.

8. Kostiuk Y., Skladannyi P., Rzaieva S., Samoylenko Y., Korshun N. intelligent control and security systems in cyber-physical and cloud environments of smart grid. Cybersecurity: Education, Science, Technique. 2025. Vol. 2 (30). P. 125–156. DOI: https://doi.org/10.28925/2663-4023.2025.30.956.

9. Mashkina I., Rzaieva S., Kostiuk Y., Mazur N., Brzhevska Z. Cybersecurity in intelligent transport systems: Current challenges and solutions. Cybersecurity Providing in Information and Telecommunication Systems 2025. CEUR Workshop Proc. 2025. P. 1–13. URL: https://ceur-ws.org/Vol-3991/.

10. Rzaieva S.L., Skladannyi P.M., Kostiuk Y.V., Abramov V.O., Kravchenko V.H. Adaptive information security management in cloud-oriented intelligent transportation systems. Ukrainian Scientific Journal of Information Security. 2025. Vol. 31 (1). P. 23–36. DOI: https://doi.org/10.18372/2225-5036.31.20634.

11. Skladannyi P.M., Kostiuk Y.V., Rzaieva S.L., Samoylenko Y.O., Savchenko T.V. Development of modular neural networks for detecting different classes of network attacks. Cybersecurity: Education, Science, Technique. 2025. Vol. 3 (27). P. 534–548. DOI: https://doi.org/10.28925/2663-4023.2025.27.772.

12. Kostiuk Y.V., Bebeshko B.T., Skladannyi P.M., Rzaieva S.L., Khorolska K.V. Optimization of buffer and priorities for ensuring security in bluetooth networks. Information Systems and Technologies Security. 2024. Vol. 2 (8). P. 5–16. DOI: https://doi.org/10.17721/ISTS.2024.8.

Downloads

Views: 176
Downloads: 64

Published

2026-05-07

Issue

Section

SIMULATION AND MANAGEMENT

How to Cite

Adaptive cybersecurity management model for information and communication systems based on a risk-oriented approach. (2026). Mathematical Machines and Systems, 2, 92-109. https://doi.org/10.34121/1028-9763-2026-2-92-109