Date of Award

2026

Keywords

cyber security, quantitative risk management, cyber insurance, critical infrastructures

Document Type

Thesis - ECU Access Only

Publisher

Edith Cowan University

Degree Name

Doctor of Philosophy (Integrated)

School

School of Science

First Supervisor

Leslie Sikos ORCID iD 0000-0003-3368-2215

Second Supervisor

Mohiuddin Ahmed ORCID iD 0000-0002-4559-4768

Third Supervisor

Bazlur Rashid ORCID iD 0000-0002-8672-5023

Fourth Supervisor

Oliver Guidetti ORCID iD 0000-0002-4235-4259

Abstract

Critical infrastructure underpins essential services and economic activity, yet its cyber risk profile is changing rapidly as operational technology environments become more connected, supply chains more interdependent, and attacks more disruptive. Incidents such as ransomware campaigns and fast-moving worms have demonstrated that cyber-events can propagate beyond an initial target and generate cascading operational and economic consequences. These characteristics make critical infrastructure cyber-risk difficult to assess using approaches that are largely static, qualitative, or detached from live evidence of threat activity and organisational security posture.

This thesis develops a dynamic approach to cyber risk assessment for critical infrastructure that supports decision-making across both technical risk treatment and financial risk transfer. The research begins with a systematic review of critical infrastructure cyber risk assessment methodologies, identifying persistent gaps relating to dynamism, operational deployability, and the limited integration of economic mechanisms such as cyber insurance. Building on these findings, the thesis develops DCRAM (Dynamic Cyber Risk Assessment Model) that represents risk as a time-varying quantity and introduces a Risk Mitigation Coefficient to capture the effect of security maturity and control effectiveness on breach likelihood and expected loss. The model is designed to support continuous updates from operational security evidence and to produce risk metrics that are meaningful for both infrastructure opera tors and insurers.

Beyond the conceptual model, the thesis shows how DCRAM can be engineered as a live risk engine and evaluated using critical infrastructure-style experiments. The evaluation draws on controlled scenarios that emulate evolving defensive posture and simulated adversarial activity, alongside structured case study reasoning using well-documented incidents. A further contribution is a curated dataset derived from these experiments to support reproducible evaluation of dynamic risk dynamics and to lower the barrier to comparative assessment in future work. The resulting body of work advances the state of practice for critical infrastructure cyber risk management by providing a defensible bridge between continuously updated technical risk signals and the economic decisions that infrastructure operators and insurers are required to make.

Access Note

Access to this thesis is embargoed until 9th October 2029

Available for download on Tuesday, October 09, 2029

Share

 
COinS
 

Link to publisher version (DOI)

10.25958/1fq5-cz88