An approach to scenario-based cybersecurity assessment of critical infrastructure facilities of the electric power sector of Ukraine

Authors

  • Lytvynov V.A. https://orcid.org/0000-0001-5568-7629 , Institute of Mathematical Machines and Systems Problems image/svg+xml
  • Hrybkov S.V. https://orcid.org/0000-0002-2552-2839 , National University of Food Technologies image/svg+xml
  • Chornobai K.Yu. https://orcid.org/0000-0002-5627-4444 , National University of Food Technologies image/svg+xml

DOI:

https://doi.org/10.34121/1028-9763-2026-3-21-30

Keywords:

energy infrastructure protection, scenario-based cybersecurity assessment, C2M2, MADS/MOSAR, GE/McKinsey Matrix

Abstract

Protecting energy infrastructure from cyber-physical threats is a pressing issue worldwide, especially given the current state of martial law in Ukraine. Currently, Ukraine employs the Methodology for Assessing the State and Practices of Cybersecurity in Critical Electrical Grid Infrastructure, which is based on the C2M2 cybersecurity capability maturity assessment model. This model evaluates general cybersecurity processes but does not address specific threat scenarios. An approach to potentially expanding the application of the C2M2 model by combining the assessment of an organization’s maturity with scenario-based threat analysis is proposed and examined. The approach involves integrating the C2M2, MADS/MOSAR, and GE/McKinsey Matrix models. Their integration is viewed as a two-stage process. At the first stage, a slightly generalized McKinsey matrix with scenario-dependent weighting coefficients is used for a rough scenario analysis. For this matrix, the «external» threats axis is determined through expert assessment, while for the  «internal» axis of the ability to counter threats, the MIL values of the C2M2 domains serve as the direct metric. This approach relies on data already collected in C2M2, provides rapid results for scenario prioritization, and establishes an architecture into which MOSAR can be integrated at the next stage. The standalone utility of the matrix lies in its ability to rapidly allocate defense resources in cases of critical need. At the second stage, MOSAR is integrated as a tool for in-depth, labor-intensive analysis of scenarios from the highest-priority zone of the matrix, with the possible subsequent integration of NIST SP 800-53 standards, which will provide resource-intensive and detailed technical specifications. The typical processes of the first and second stages, the shortcomings and limitations of the approach, and ways to potentially compensate for these shortcomings are justified and examined. For the practical implementation of the first stage, a corresponding pilot project should be carried out for several critical facilities; if the results are positive, the second stage can be initiated. Tabl.: 1. Fig.: 1. Refs.: 11 titles.

References

1. Maliarchuk T., Danyk Y., Briggs C. Hybrid Warfare and Cyber Effects in Energy Infrastructure. Connections: The Quarterly Journal. 2019. Vol. 18, N 1. P. 93–110. DOI: https://doi.org/10.11610/Connections. 18.1.0 (дата звернення: 19.05.2026).

2. Borychenko O., Cherniavskyi A., Muliarevych O., Shelekh Y., Sabat M. Cybersecurity in the energy industry of Ukraine: protection measures and challenges in the context of energy security. Revista Gestão & Tecnologia. 2024. Vol. 24 (4). P. 67–90. DOI: https://doi.org/10.20397/2177-6652/2024.v24i4.2876 (дата звернення: 19.05.2026).

3. Mehta U. Cybersecurity GRC in Energy & Utilities: Trends, Gaps, and Solutions. LinkedIn, 2025. URL: https://www.linkedin.com/pulse/blog-188-cybersecurity-grc-energy-utilities-trends-gaps-umang-mehtafyndf/ (дата звернення: 19.05.2026).

4. Єрмак С.О. Методологічні орієнтири аналізу критичної інфраструктури та критично важливих виробничих підприємств. Бізнес Інформ. 2025. № 12. C. 31–39. DOI: https://doi.org/10.32983/2222-4459-2025-12-31-39.

5. Кібербезпека. Міністерство енергетики України. URL: https://www.mev.gov.ua/storinka/kiberbezpeka (дата звернення: 19.06.2026).

6. U.S. Department of Energy. Cybersecurity Capability Maturity Model (C2M2) Version 2.0. July 2021. URL: https://www.energy.gov/sites/default/files/2021-07/C2M2%20Version%202.0%20July%202021_508.pdf (дата звернення: 19.05.2026).

7. U.S. Department of Energy. Cybersecurity Capability Maturity Model (C2M2) Version 2.1. June 2022. URL: https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2 (дата звернення: 19.05.2026).

8. Perrin L., Munoz-Giraldo F., Dufaud O., Laurent A. Normative barriers improvement through the MADS/MOSAR methodology. Safety Science. 2012. Vol. 50, N 7. P. 1502–1512. DOI: https://doi.org/10.1016/j.ssci.2012.02.002 (дата звернення: 19.05.2026).

9. Fošner A., Bertoncelj B., Poznič T., Fink L. Risk analysis of critical infrastructure with the MOSAR method. Heliyon. 2024. Vol. 10, N 4. P. e26439. DOI: https://doi.org/10.1016/j.heliyon.2024.e26439 (дата звернення: 19.05.2026).

10. Joint Task Force. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Revision 5. Gaithersburg, MD: National Institute of Standards and Technology, 2020. 495 p. DOI: https://doi.org/10.6028/NIST.SP.800-53r5 (дата звернення: 19.06.2026).

11. McKinsey GE Matrix: A Powerful Strategic Tool for Business Growth. The Strategy Institute. 2025. URL: https://www.thestrategyinstitute.org/insights/mckinsey-ge-matrix-a-powerful-strategic-tool-forbusiness-growth (дата звернення: 19.05.2026).

Downloads

Views: 17
Downloads: 12

Published

2026-09-14

Issue

Section

INFORMATION AND TELECOMMUNICATION TECHNOLOGY

How to Cite

An approach to scenario-based cybersecurity assessment of critical infrastructure facilities of the electric power sector of Ukraine. (2026). Mathematical Machines and Systems, 3, 21-30. https://doi.org/10.34121/1028-9763-2026-3-21-30