Author Identifier
Date of Award
2026
Keywords
cyber security, quantitative risk management, cyber insurance, critical infrastructures
Document Type
Thesis - ECU Access Only
Publisher
Edith Cowan University
Degree Name
Doctor of Philosophy (Integrated)
School
School of Science
First Supervisor
Leslie Sikos
0000-0003-3368-2215
Second Supervisor
Mohiuddin Ahmed
0000-0002-4559-4768
Third Supervisor
Bazlur Rashid
0000-0002-8672-5023
Fourth Supervisor
Oliver Guidetti
0000-0002-4235-4259
Abstract
Critical infrastructure underpins essential services and economic activity, yet its cyber risk profile is changing rapidly as operational technology environments become more connected, supply chains more interdependent, and attacks more disruptive. Incidents such as ransomware campaigns and fast-moving worms have demonstrated that cyber-events can propagate beyond an initial target and generate cascading operational and economic consequences. These characteristics make critical infrastructure cyber-risk difficult to assess using approaches that are largely static, qualitative, or detached from live evidence of threat activity and organisational security posture.
This thesis develops a dynamic approach to cyber risk assessment for critical infrastructure that supports decision-making across both technical risk treatment and financial risk transfer. The research begins with a systematic review of critical infrastructure cyber risk assessment methodologies, identifying persistent gaps relating to dynamism, operational deployability, and the limited integration of economic mechanisms such as cyber insurance. Building on these findings, the thesis develops DCRAM (Dynamic Cyber Risk Assessment Model) that represents risk as a time-varying quantity and introduces a Risk Mitigation Coefficient to capture the effect of security maturity and control effectiveness on breach likelihood and expected loss. The model is designed to support continuous updates from operational security evidence and to produce risk metrics that are meaningful for both infrastructure opera tors and insurers.
Beyond the conceptual model, the thesis shows how DCRAM can be engineered as a live risk engine and evaluated using critical infrastructure-style experiments. The evaluation draws on controlled scenarios that emulate evolving defensive posture and simulated adversarial activity, alongside structured case study reasoning using well-documented incidents. A further contribution is a curated dataset derived from these experiments to support reproducible evaluation of dynamic risk dynamics and to lower the barrier to comparative assessment in future work. The resulting body of work advances the state of practice for critical infrastructure cyber risk management by providing a defensible bridge between continuously updated technical risk signals and the economic decisions that infrastructure operators and insurers are required to make.
Access Note
Access to this thesis is embargoed until 9th October 2029
Recommended Citation
Moonsamy, A. (2026). Dynamic cyber risk assessment for critical infrastructure contexts: A telemetry-informed, posture-sensitive model for governance and insurance-relevant decision support. Edith Cowan University. https://doi.org/10.25958/1fq5-cz88