Diana Yudina

Work place: Faculty of Computer Science and Technology, State University ―Kyiv Aviation Institute‖, Kyiv, Ukraine

E-mail: diana.yudina22@gmail.com

Website:

Research Interests:

Biography

Diana Yudina received a master's degree in computer science in 2021. The topic of her master's thesis is devoted to researching methods for assessing cybersecurity risks to critical information infrastructure. She is currently pursuing a PhD at the State University ―Kyiv Aviation Institute‖. Her research topics include calculating the level of cyber protection for critical information infrastructure objects, assessing the state of cyber protection for critical infrastructure, and researching the hierarchy of cybersecurity maturity models.

Author Articles
Model for calculating the level of Cybersecurity of Critical Infrastructure Facilities

By Sergiy Gnatyuk Diana Yudina

DOI: https://doi.org/10.5815/ijcnis.2026.05.02, Pub. Date: 8 Oct. 2026

The article examines the problem of ensuring the cyber resilience of critical information infrastructure in the context of the global transformation of cyberattack methods and the growing role of foreign state actors in destabilizing critical systems. Given the unprecedented increase in the number of incidents and the emergence of new threat vectors associated with the use of artificial intelligence, traditional approaches to security assessment are becoming insufficient. This creates a critical need to develop tools for quantitatively calculating the level of critical information infrastructure cybersecurity in order to respond quickly to challenges and objectively predict risks. Based on a systematic analysis of international standards and frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework, the article justifies the need for a formalized mathematical apparatus for the transition from a qualitative description of security measures to their quantitative measurement. The authors propose a hierarchical Multi-Criteria Decision Making model for calculating an integral indicator of the level of cybersecurity. This model is based on a synthesis of the theoretical-multiple approach, the Analytic Hierarchy Process, and non-compensatory gating thresholds. The mathematical apparatus allows for the inequality of different groups of cybersecurity measures to be taken into account by applying a system of weighting coefficients calculated on the basis of expert assessments using the Saaty scale. The development process includes eight distinct stages, from determining criteria sets to integrating non-compensatory gating mechanisms to prevent technical deficiencies from being masked by administrative achievements. Experimental testing of the model was conducted using a representative critical infrastructure facility grounded in anonymized real-world audit data from the energy sector. The results confirmed the model's effectiveness, yielding an integral indicator of 0.56, while specifically identifying the detection domain as a vulnerable segment with a score of 0.36. This confirms the practical significance of the model for supporting management decisions on priority resource allocation.

[...] Read more.
Other Articles