Model for calculating the level of Cybersecurity of Critical Infrastructure Facilities

PDF (916KB), PP.17-29

Views: 0 Downloads: 0

Author(s)

Sergiy Gnatyuk 1,2,* Diana Yudina 1

1. Faculty of Computer Science and Technology, State University ―Kyiv Aviation Institute‖, Kyiv, Ukraine

2. State Scientific and Research Institute of Cybersecurity Technologies and Information Protection, Kyiv, Ukraine

* Corresponding author.

DOI: https://doi.org/10.5815/ijcnis.2026.05.02

Received: 3 Mar. 2026 / Revised: 2 Apr. 2026 / Accepted: 9 Jul. 2026 / Published: 8 Oct. 2026

Index Terms

Cybersecurity, Cybersecurity Level, Critical Information Infrastructure Facility, Model, Criteria System.

Abstract

The article examines the problem of ensuring the cyber resilience of critical information infrastructure in the context of the global transformation of cyberattack methods and the growing role of foreign state actors in destabilizing critical systems. Given the unprecedented increase in the number of incidents and the emergence of new threat vectors associated with the use of artificial intelligence, traditional approaches to security assessment are becoming insufficient. This creates a critical need to develop tools for quantitatively calculating the level of critical information infrastructure cybersecurity in order to respond quickly to challenges and objectively predict risks. Based on a systematic analysis of international standards and frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework, the article justifies the need for a formalized mathematical apparatus for the transition from a qualitative description of security measures to their quantitative measurement. The authors propose a hierarchical Multi-Criteria Decision Making model for calculating an integral indicator of the level of cybersecurity. This model is based on a synthesis of the theoretical-multiple approach, the Analytic Hierarchy Process, and non-compensatory gating thresholds. The mathematical apparatus allows for the inequality of different groups of cybersecurity measures to be taken into account by applying a system of weighting coefficients calculated on the basis of expert assessments using the Saaty scale. The development process includes eight distinct stages, from determining criteria sets to integrating non-compensatory gating mechanisms to prevent technical deficiencies from being masked by administrative achievements. Experimental testing of the model was conducted using a representative critical infrastructure facility grounded in anonymized real-world audit data from the energy sector. The results confirmed the model's effectiveness, yielding an integral indicator of 0.56, while specifically identifying the detection domain as a vulnerable segment with a score of 0.36. This confirms the practical significance of the model for supporting management decisions on priority resource allocation.

Cite This Paper

Sergiy Gnatyuk, Diana Yudina, "Model for calculating the level of Cybersecurity of Critical Infrastructure Facilities", International Journal of Computer Network and Information Security(IJCNIS), Vol.18, No.5, pp. 17-29, 2026. DOI:10.5815/ijcnis.2026.05.02

Reference

[1]European Union Agency for Cybersecurity, "ENISA Threat Landscape 2025," ENISA, Oct. 2025. [Online]. Available: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025
[2]Microsoft Corporation, "Microsoft Digital Defense Report 2025," Microsoft Digital Security & Threat Intelligence, 2025. [Online]. Available: https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1
[3]IBM Corporation, "IBM X-Force 2025 Threat Intelligence Index," IBM Institute for Business Value, 2025. [Online]. Available: https://www.ibm.com/thought-leadership/institute-business-value/report/2025-threat-intelligence-index
[4]Verizon Business, "2025 Data Breach Investigations Report (DBIR)," Verizon Business Resources, 2025. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/
[5]State Service of Special Communications and Information Protection of Ukraine, "Russian Cyber Operations: H1 ’2025," 2025. [Online]. Available: https://cip.gov.ua/services/cm/api/attachment/download?id=71278
[6]State Service of Special Communications and Information Protection of Ukraine, "Russian Cyber Operations: H2 ’2024," 2024. [Online]. Available: https://cip.gov.ua/services/cm/api/attachment/download?id=68769
[7]Information technology — Security techniques — Information security management systems — Requirements, ISO/IEC 27001:2022, International Organization for Standardization, 2022.
[8]National Institute of Standards and Technology (NIST), "NIST Cybersecurity Framework Version 2.0," U.S. Department of Commerce, 2024. [Online]. Available: https://www.nist.gov/cyberframework
[9]T. A. Ivanochko and S. A. Semenyuk, "Cybersecurity risk management using NIST CSF 2.0," Modern Information Protection, vol. 63, no. 3, pp. 75–82, 2025, doi: 10.31673/2409-7292.2025.030936.
[10]CMMI Institute, "Capability Maturity Model Integration (CMMI) for Development, Version 3.0," 2023. [Online]. Available: https://cmmiinstitute.com/cmmi
[11]U.S. Department of Energy, "Cybersecurity Capability Maturity Model (C2M2), Version 2.1," Jun. 2022. [Online]. Available: https://www.energy.gov/sites/default/files/2022-06/C2M2%20Version%202.1%20June%202022.pdf
[12]Carnegie Mellon University Software Engineering Institute (SEI), "Smart Grid Maturity Model, Version 1.2," SEI Technical Report, 2012. [Online]. Available: https://www.sei.cmu.edu/library/smart-grid-maturity-model-assets-collection-version-12/
[13]Cybersecurity and Infrastructure Security Agency (CISA), "CISA Cybersecurity Performance Goals (CPGs)," 2023. [Online]. Available: https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf
[14]G. Kotzamani et al., "A Systematic Review of Voluntary Cybersecurity Standards and Frameworks," Springer Nature, 2025, doi: 10.1007/s10207-025-01121-0.
[15]S. M. Shevchenko, Y. D. Zhdanova, and O. S. Kiy, "Semi-automated tool for multi-standard assessment of an organization's cyber maturity based on NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019, and CIS Controls V8," Cybersecurity: Education, Science, Technology, vol. 31, no. 3, pp. 43–60, 2025.
[16]O. Mikhailova, A. Petrov, and J. Smith, "Recent Trends in Information and Cyber Security Maturity Assessment: A Systematic Review," Systems, vol. 13, no. 1, p. 52, 2025, doi: 10.3390/systems13010052.
[17]G. Büyüközkan and M. Güler, "Cybersecurity maturity model: Systematic literature review and a proposed model," Technological Forecasting and Social Change, vol. 213, 2025.
[18]Y. Zakharova and A. Partika, "Evolyutsiya upravlinnya kiber-ryzykamy kriz prismu NIST Cybersecurity Framework," Cybersecurity: Education, Science, Technology, vol. 30, no. 2, pp. 333–347, 2025, doi: 10.28925/2663-4023.2025.30.980.
[19]D. Yudina, "Modification of the Model for Calculating the Level of Cyber Security of Critical Infrastructure Facilities," Cybersecurity: Education, Science, Technology, vol. 29, no. 1, pp. 818–836, 2025, doi: 10.28925/2663-4023.2025.29.943.
[20]L. G. Vargas and T. L. Saaty, Models, Methods, Concepts & Applications of the Analytic Hierarchy Process. Kluwer Academic Publishers, 2001. doi: 10.1007/978-1-4615-1665-1.
[21]Norman Dalkey and Olaf Helmer, “An Experimental Application of the Delphi Method to the Use of Experts,” Management Science, vol. 9, no. 3, pp. 458–467, 1963, doi: 10.1287/mnsc.9.3.458.
[22]C. Hsu and B. A. Sandford, “The Delphi Technique: Making Sense of Consensus,” Practical Assessment, Research, and Evaluation, vol. 12, no. 1, art. 10, 2007, doi: 10.7275/pdz9-th90
[23]Roy, B. The outranking approach and the foundations of electre methods. Theor Decis 31, 49–73 (1991). https://doi.org/10.1007/BF00134132