International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1713779

1713779 Vol 2 · Issue 12 Download Paper

Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities

Oladapo Fadayomi Toyosi O Abolaji Joseph Edivri Jolly I. Ogbole Precious Osobhalenewie Okoruwa Bisola Akeju

Subject area: Science,Engineering and Technology  ·  Area of research: Risk-Based Cybersecurity Assurance

DOI: 10.64388/IREV2I12-1713779

Abstract

Ensuring cybersecurity assurance in complex digital environments increasingly requires a risk-based approach, where resource allocation, control implementation, and monitoring are guided by the potential impact of threats and system vulnerabilities rather than prescriptive compliance checklists. Risk-based cybersecurity assurance prioritizes the protection of critical assets, balances security investments against operational requirements, and incorporates probabilistic assessments of threat likelihood and severity. A key dimension of this approach is data availability, which directly influences decision-making, operational continuity, and the reliability of automated risk assessments. Despite advances in cybersecurity frameworks and monitoring technologies, organizations continue to face limitations in data completeness, timeliness, and quality. Inadequate or fragmented data can impede accurate risk modeling, delay detection of emerging threats, and reduce the effectiveness of control strategies, particularly in distributed, cloud-enabled, and high-velocity digital ecosystems. Recent advances address some of these challenges through the integration of real-time telemetry, behavioral analytics, and AI-driven anomaly detection. These technologies enable continuous assessment of system state and user activity, improving the granularity and predictive power of risk models. Additionally, the adoption of probabilistic and scenario-based methodologies allows organizations to quantify uncertainty, model cascading effects, and anticipate potential disruptions even under incomplete information. However, gaps remain in standardizing data collection, ensuring data integrity across multi-source environments, and integrating data-driven insights into actionable governance and policy frameworks. Future research opportunities include the development of autonomous, adaptive cybersecurity assurance systems that leverage AI-native risk assessment, cross-domain data integration, and continuous feedback loops. There is also a need for empirical validation of risk-based models in diverse operational contexts, exploration of data availability trade-offs, and methods for resilient decision-making under uncertainty. Advancing these areas will enhance the effectiveness of risk-based cybersecurity assurance, improve organizational resilience, and support sustained operational continuity in increasingly complex and interconnected digital systems.

Keywords

Risk-Based Cybersecurity, Data Availability, Assurance, Threat Modeling, Probabilistic Risk Assessment, Anomaly Detection, Operational Resilience, AI-Driven Security

References

[1] Ani, U.P.D., He, H. and Tiwari, A., 2017. Review of cybersecurity issues in industrial critical infrastructure: manufacturing in perspective. Journal of Cyber Security Technology, 1(1), pp.32-74.

[2] Bendre, M.R. and Thool, V.R., 2016. Analytics, challenges and applications in big data environment: a survey. Journal of Management Analytics, 3(3), pp.206-239.

[3] Bennett, J.C., Bettencourt, M.T., Clay, R.L., Edwards, H.C., Glass, M.W., Hollman, D.S., Kolla, H., Lifflander, J.J., Littlewood, D.J., Markosyan, A.H. and Moore, S.G., 2017. ASC ATDM Level 2 Milestone# 6015: Asynchronous Many-Task Software Stack Demonstration (No. SAND-2017-9980). Sandia National Lab.(SNL-CA), Livermore, CA (United States); Sandia National Lab.(SNL-NM), Albuquerque, NM (United States).

[4] Bhattacharjee, S., 2018. Practical Industrial Internet of Things security: A practitioner's guide to securing connected industries. Packt Publishing Ltd.

[5] Borky, J.M. and Bradley, T.H., 2018. Protecting information with cybersecurity. In Effective model-based systems engineering (pp. 345-404). Cham: Springer International Publishing.

[6] Boyd, R. and Holton, R.J., 2018. Technology, innovation, employment and power: Does robotics and artificial intelligence really mean social transformation?. Journal of Sociology, 54(3), pp.331-345.

[7] Bughin, J., Hazan, E., Sree Ramaswamy, P., DC, W. and Chu, M., 2017. Artificial intelligence the next digital frontier.

[8] Cantatore, F. and James, N.J., 2017. Heroism science offers a new framework for cultivating civic virtue within clinical law programs. Australian Journal of Clinical Education, 2(1), pp.1-19.

[9] Carr, M., 2016. Public–private partnerships in national cyber-security strategies. International Affairs, 92(1), pp.43-62.

[10] Chen, Z., Xu, G., Mahalingam, V., Ge, L., Nguyen, J., Yu, W. and Lu, C., 2016. A cloud computing based network monitoring and threat detection system for critical infrastructures. Big Data Research, 3, pp.10-23.

[11] Ciapessoni, E., Cirio, D., Kjølle, G., Massucco, S., Pitto, A. and Sforna, M., 2016. Probabilistic risk-based security assessment of power systems considering incumbent threats and uncertainties. IEEE Transactions on Smart Grid, 7(6), pp.2890-2903.

[12] Cram, W.A., Proudfoot, J.G. and D’arcy, J., 2017. Organizational information security policies: a review and research framework. European Journal of Information Systems, 26(6), pp.605-641.

[13] Eker, S., Rovenskaya, E., Obersteiner, M. and Langan, S., 2018. Practice and perspectives in the validation of resource management models. Nature communications, 9(1), p.5359.

[14] Falconi, S.M. and Palmer, R.N., 2017. An interdisciplinary framework for participatory modeling design and evaluation—What makes models effective participatory decision tools?. Water Resources Research, 53(2), pp.1625-1645.

[15] Fini, A.A.F., 2017. Optimizing Crew Performance through Integration of Human Resource Strategies into Planning of Construction Activities.

[16] Force, J.T., 2018. Risk management framework for information systems and organizations. NIST Special Publication, 800, p.37.

[17] Fraga-Lamas, P., Fernández-Caramés, T.M., Suárez-Albela, M., Castedo, L. and González-López, M., 2016. A review on internet of things for defense and public safety. Sensors, 16(10), p.1644.

[18] Heald, D., 2018. Transparency‐generated trust: The problematic theorization of public audit. Financial Accountability & Management, 34(4), pp.317-335.

[19] Hibshi, H. and Breaux, T.D., 2018. Risk management and information assurance decision support. Acquisition Research Program.

[20] Houser, B.M., 2016. A model for real-time data reputation via cyber telemetry.

[21] Ibitoye, J.S., 2018. Securing smart grid and critical infrastructure through AI-enhanced cloud networking. International Journal of Computer Applications Technology and Research, 7(12), pp.517-529.

[22] Jarvis, A., Morales, L. and Jose, J., 2018. Quality Experience Telemetry. Quality Press..

[23] Jow, J., Xiao, Y. and Han, W., 2017. A survey of intrusion detection systems in smart grid. International Journal of Sensor Networks, 23(3), pp.170-186.

[24] Katina, P.F. and Keating, C.B., 2018. Cyber-physical systems governance: a framework for (meta) cybersecurity design. In Security by design: innovative perspectives on complex problems (pp. 137-169). Cham: Springer International Publishing.

[25] Kure, H.I., Islam, S. and Razzaque, M.A., 2018. An integrated cyber security risk management approach for a cyber-physical system. Applied Sciences, 8(6), p.898.

[26] Lamba, A., Singh, S., Balvinder, S., Dutta, N. and Rela, S., 2018. Embedding machine & deep learning for mitigating security & privacy issues in iot enabled devices & networks. International Journal For Technological Research In Engineering.

[27] Laszewski, T., Arora, K., Farr, E. and Zonooz, P., 2018. Cloud Native Architectures: Design high-availability and cost-effective applications for the cloud. Packt Publishing Ltd.

[28] Layton, T.P., 2016. Information Security: Design, implementation, measurement, and compliance. Auerbach Publications.

[29] Levi, M., Doig, A., Gundur, R., Wall, D. and Williams, M., 2017. Cyberfraud and the implications for effective risk-based responses: themes from UK research. Crime, Law and Social Change, 67(1), pp.77-96.

[30] Luciano, M.M., Mathieu, J.E., Park, S. and Tannenbaum, S.I., 2018. A fitting approach to construct and measurement alignment: The role of big data in advancing dynamic theories. Organizational Research Methods, 21(3), pp.592-632.

[31] McAdam, R., Bititci, U. and Galbraith, B., 2017. Technology alignment and business strategy: A performance measurement and dynamic capability perspective. International Journal of Production Research, 55(23), pp.7168-7186.

[32] Mehan, J., 2016. Insider threat: A guide to understanding, detecting, and defending against the enemy from within. IT Governance Ltd.

[33] Moore, D. and Rid, T., 2016. Cryptopolitik and the Darknet. Survival, 58(1), pp.7-38.

[34] Nandigama, N.C., 2016. Teradata-driven big data analytics for suspicious activity detection with real-time Tableau dashboards. International Journal For Innovative Engineering and Management Research, 5(1), pp.73-78.

[35] Nespoli, P., Papamartzivanos, D., Mármol, F.G. and Kambourakis, G., 2017. Optimal countermeasures selection against cyber attacks: A comprehensive survey on reaction frameworks. IEEE Communications Surveys & Tutorials, 20(2), pp.1361-1396.

[36] NETTO, M.A., TOOSI, A.N., RODRIGUEZ, M.A., LLORENTE, I.M., DI VIMERCATI, S.D.C., SAMARATI, P., MILOJICIC, D., VARELA, C., BAHSOON, R., DE ASSUNCAO, M.D. and RANA, O., 2018. A Manifesto for Future Generation Cloud Computing: Research Directions for the Next Decade.

[37] Nicho, M., 2018. A process model for implementing information systems security governance. Information & Computer Security, 26(1), pp.10-38.

[38] Nikolakis, W., John, L. and Krishnan, H., 2018. How blockchain can shape sustainable global value chains: An evidence, verifiability, and enforceability (EVE) framework. Sustainability, 10(11), p.3926.

[39] Nissen, C., Gronager, J.E., Metzger, R.S. and Rishikof, H., 2018. Deliver uncompromised: A strategy for supply chain security and resilience in response to the changing character of war.

[40] No, W.G. and Vasarhelyi, M.A., 2017. Cybersecurity and continuous assurance. Journal of Emerging Technologies in Accounting, 14(1), pp.1-12.

[41] Nwankwo, C.O. and Ihueze, C.C., 2018. Corrosion rate models for oil and gas pipeline systems a numerical approach. International Journal of Engineering Research and Technology.

[42] Onovo, A.A., Nta, I.E., Onah, A.A., Okolo, C.A., Aliyu, A., Dakum, P., Atobatele, A.O. and Gado, P., 2015. Partner HIV serostatus disclosure and determinants of serodiscordance among prevention of mother to child transmission clients in Nigeria. BMC public health, 15(1), p.827.

[43] Palomino, J., Muellerklein, O.C. and Kelly, M., 2017. A review of the emergent ecosystem of collaborative geospatial tools for addressing environmental challenges. Computers, Environment and Urban Systems, 65, pp.79-92.

[44] Pappas, I.O., Mikalef, P., Giannakos, M.N., Krogstie, J. and Lekakos, G., 2018. Big data and business analytics ecosystems: paving the way towards digital transformation and sustainable societies. Information systems and e-business management, 16(3), pp.479-491.

[45] Paté‐Cornell, M.E., Kuypers, M., Smith, M. and Keller, P., 2018. Cyber risk management for critical infrastructure: a risk analysis model and three case studies. Risk Analysis, 38(2), pp.226-241.

[46] Rahmani, A.M., Gia, T.N., Negash, B., Anzanpour, A., Azimi, I., Jiang, M. and Liljeberg, P., 2018. Exploiting smart e-Health gateways at the edge of healthcare Internet-of-Things: A fog computing approach. Future Generation Computer Systems, 78, pp.641-658.

[47] Reetz, M.A., Prunty, L.B., Mantych, G.S. and Hommel, D.J., 2017. Cyber risks: Evolving threats, emerging coverages, and ensuing case law. Penn St. L. Rev., 122, p.727.

[48] Rezaee, Z., 2017. Business sustainability: Performance, compliance, accountability and integrated reporting. Routledge.

[49] Romanosky, S., 2016. Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), pp.121-135.

[50] Sans, V. and Cronin, L., 2016. Towards dial-a-molecule by integrating continuous flow, analytics and self-optimisation. Chemical Society Reviews, 45(8), pp.2032-2043.

[51] Scholz, R.W., Bartelsman, E.J., Diefenbach, S., Franke, L., Grunwald, A., Helbing, D., Hill, R., Hilty, L., Höjer, M., Klauser, S. and Montag, C., 2018. Unintended side effects of the digital transition: European scientists’ messages from a proposition-based expert round table. Sustainability, 10(6), p.2001.

[52] Sun, N., Zhang, J., Rimba, P., Gao, S., Zhang, L.Y. and Xiang, Y., 2018. Data-driven cybersecurity incident prediction: A survey. IEEE communications surveys & tutorials, 21(2), pp.1744-1772.

[53] Thompson, M.P., MacGregor, D.G. and Calkin, D., 2016. Risk management: core principles and practices, and their relevance to wildland fire. Gen. Tech. Rep. RMRS-GTR-350. Fort Collins, CO: US Department of Agriculture, Forest Service, Rocky Mountain Research Station. 29 p., 350.

[54] Tsakalidis, G., Vergidis, K., Madas, M. and Vlachopoulou, M., 2018. Cybersecurity threats: a proposed system for assessing threat severity. In Proceedings of the the forth international conference on decision support system technology–ICDSST 2018.

[55] Tupa, J., Simota, J. and Steiner, F., 2017. Aspects of risk management implementation for Industry 4.0. Procedia manufacturing, 11, pp.1223-1230.

[56] Ugwu-Oju, U. M., Okeke, O. T., & Nwankwo, C. O. (2018). Advances in cybersecurity protection for sensitive business digital infrastructure. IRE Journals, 1(11), 127–135.

[57] Ugwu-Oju, U. M., Okeke, O. T., & Nwankwo, C. O. (2018). Conceptual model improving encryption strategies for organizational information protection. IRE Journals, 2(2), 139–147.

[58] Ugwu-Oju, U. M., Okeke, O. T., & Nwankwo, C. O. (2018). Conceptual model improving digital workflows within organizational information

[59] Ugwu-Oju, U. M., Okeke, O. T., & Nwankwo, C. O. (2018). Review of network protocol stability techniques for enterprise information systems. IRE Journals, 1(8), 196–204.

[60] Vaidya, J. and Li, J. eds., 2018. Algorithms and Architectures for Parallel Processing: 18th International Conference, ICA3PP 2018, Guangzhou, China, November 15-17, 2018, Proceedings, Part IV (Vol. 11337). Springer.

How to cite this paper

Oladapo Fadayomi, Toyosi O Abolaji, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa; Bisola Akeju "Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities" Iconic Research And Engineering Journals Volume 2 Issue 12 2019 Page 602-617 https://doi.org/10.64388/IREV2I12-1713779
Oladapo Fadayomi, Toyosi O Abolaji, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa; Bisola Akeju "Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities" Iconic Research And Engineering Journals, vol. 2, no. 12, Jun. 2019, doi: https://doi.org/10.64388/IREV2I12-1713779
Oladapo Fadayomi, Toyosi O Abolaji, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa; Bisola Akeju (2019). Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities. Iconic Research And Engineering Journals, 2(12). doi: https://doi.org/10.64388/IREV2I12-1713779
Oladapo Fadayomi, Toyosi O Abolaji, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa; Bisola Akeju "Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities" Iconic Research And Engineering Journals, vol. 2, no. 12, Jun. 2019. Crossref, https://doi.org/10.64388/IREV2I12-1713779
@article{1713779,
      author = {Oladapo Fadayomi, Toyosi O Abolaji, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa; Bisola Akeju},
      title = {Risk-Based Cybersecurity Assurance and Data Availability Limitations, Advances and Future Research Opportunities},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {2},
      number = {12},
      pages = {602-617},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1713779.pdf},
      abstract = {Ensuring cybersecurity assurance in complex digital environments increasingly requires a risk-based approach, where resource allocation, control implementation, and monitoring are guided by the potential impact of threats and system vulnerabilities rather than prescriptive compliance checklists. Risk-based cybersecurity assurance prioritizes the protection of critical assets, balances security investments against operational requirements, and incorporates probabilistic assessments of threat likelihood and severity. A key dimension of this approach is data availability, which directly influences decision-making, operational continuity, and the reliability of automated risk assessments. Despite advances in cybersecurity frameworks and monitoring technologies, organizations continue to face limitations in data completeness, timeliness, and quality. Inadequate or fragmented data can impede accurate risk modeling, delay detection of emerging threats, and reduce the effectiveness of control strategies, particularly in distributed, cloud-enabled, and high-velocity digital ecosystems. Recent advances address some of these challenges through the integration of real-time telemetry, behavioral analytics, and AI-driven anomaly detection. These technologies enable continuous assessment of system state and user activity, improving the granularity and predictive power of risk models. Additionally, the adoption of probabilistic and scenario-based methodologies allows organizations to quantify uncertainty, model cascading effects, and anticipate potential disruptions even under incomplete information. However, gaps remain in standardizing data collection, ensuring data integrity across multi-source environments, and integrating data-driven insights into actionable governance and policy frameworks. Future research opportunities include the development of autonomous, adaptive cybersecurity assurance systems that leverage AI-native risk assessment, cross-domain data integration, and continuous feedback loops. There is also a need for empirical validation of risk-based models in diverse operational contexts, exploration of data availability trade-offs, and methods for resilient decision-making under uncertainty. Advancing these areas will enhance the effectiveness of risk-based cybersecurity assurance, improve organizational resilience, and support sustained operational continuity in increasingly complex and interconnected digital systems.},
      keywords = {Risk-Based Cybersecurity, Data Availability, Assurance, Threat Modeling, Probabilistic Risk Assessment, Anomaly Detection, Operational Resilience, AI-Driven Security},
      month = {June},
      doi = {https://doi.org/10.64388/IREV2I12-1713779}
  }