METHOD OF ASSESSING INFORMATION SECURITY RISK TAKING INTO ACCOUNT HYBRID IMPACT
DOI:
https://doi.org/10.31673/2409-7292.2026.027509Abstract
The article considers the problem of assessing information security risk in conditions of hybrid impact, which
combines technical, organizational and information-psychological factors. It is substantiated that the use of traditional
risk assessment without taking into account the specifics of the hybrid context may lead to insufficiently accurate
determination of threat priority, since different categories of assets have different sensitivity to individual channels of
influence. A method of assessing information security risk is proposed, in which the basic risk index is adjusted taking
into account the hybrid impact index. The hybrid impact index is formed on the basis of technical, organizational and
psychological components using modified weighted geometric aggregation. To determine the weight coefficients of the
components of hybrid impact, it is proposed to apply the method of hierarchy analysis taking into account the asset
category. Additionally, a scenario risk amplification coefficient is introduced, which allows assessing the change in risk
under conservative, basic and critical scenarios of hybrid pressure. An example of applying the proposed method for
typical asset categories and threat scenarios is given. The results obtained confirm that the proposed approach allows to
avoid simplified averaging of heterogeneous factors of hybrid impact, to take into account the specificity of assets and to
perform scenario ranking of information security risks. The practical value of the proposed method for preliminary
quantitative risk assessment, comparison of hybrid impact scenarios, prioritization of protective measures and justification
of management decisions to increase the resilience of the organization is proven.
Keywords: cybersecurity, information security; cyber risk, hybrid impact; hybrid threats; risk-oriented approach;
method of analysis of hierarchies.
References
1. Auzina I., Volkova T., Norena-Chavez D., Kadłubek M., Thalassinos E. Cyber Incident Response Managerial
Approaches for Enhancing Small–Medium-Size Enterprise’s Cyber Maturity. In: Digital Transformation, Strategic
Resilience, Cyber Security and Risk Management. Vol. 111A. Bingley: Emerald Publishing Limited, 2023. P. 175–190.
DOI: http://dx.doi.org/10.1108/s1569-37592023000111a012.
2. Берко А. Ю., Висоцька В. А., Рішняк І. В. Методи та засоби оцінювання ризиків безпеки інформації в
системах електронної комерції. Інформаційні системи та мережі. 2008. № 610(1). С. 20–33. URL:
https://lnk.ua/Y7HCO2OWQ.
3. Барченко Н. Л., Любчак В. О., Лаврик Т. В. Модель індикаторів оцінки національного рівня
цифровізації та кібербезпеки держав світу. Кібербезпека: освіта, наука, техніка. 2022. № 2(18). С. 73–85. DOI:
https://doi.org/10.28925/2663-4023.2022.18.7385
4. Дзюба Л. Ф., Чмир О. Ю. Оцінювання ризиків інформаційної безпеки з використанням методів
математичної статистики. Вісник Львівського державного університету безпеки життєдіяльності. 2022. № 26. С.
47–54. URL: https://lnk.ua/6jeUP9iLX
5. Khakzad N., Khan F., Amyotte P. Safety analysis in process facilities: Comparison of fault tree and Bayesian
network approaches. Reliability Engineering & System Safety. 2013. Vol. 111. P. 81–92. DOI:
http://dx.doi.org/10.1016/j.ress.2011.03.012
6. Гловацький В. В. Методи оцінювання стану безпеки та загроз інформаційних ресурсів. Зв’язок. 2016.
№ 5. С. 13–16. URL: https://con.dut.edu.ua/index.php/communication/article/view/1324/1257
7. OECD. Economic Security in a Changing World: Building Stronger Defences for a Digital Future – The Role
of Cybersecurity. Paris: OECD Publishing, 2025. URL: https://www.oecd.org/en/publications/2025/09/economicsecurity-in-a-changing-world_78f3b129/full-report/building-stronger-defences-for-a-digital-future-the-role-ofcybersecurity_484bcb90.html
8. PwC. Building Cybersecurity through Top Management Collaboration. Findings from the 2025 Global Digital
Trust Insights Survey. 2025. URL: https://www.pwc.com/ua/uk/survey/2025/cee-findings-from-the-2025-global-digitaltrust-insights-survey.html
9. Savelieva T., Panasko O., Prigodyuk O. Analysis of Methods and Means to Implement a Risk-Oriented
Approach in the Context of Providing Enterprise Information Security. Bulletin of Cherkasy State Technological
University. 2018. Vol. 23, No. 1. P. 81–89. DOI: http://dx.doi.org/10.24025/2306-4412.1.2018.153279
10. Memon M., Hameed S. Information Security Risk Plans within Enterprise Architecture Framework.
International Journal of Advanced Computer Science and Technology. 2019. Vol. 8, № 10. P. 82-88.
https://doi.org/10.30534/ijacst/2019/018102019.