A taxonomy of cyber risk taxonomies

Giovanni Rabitti*, Amir Khorrami Chokami, Patrick Coyle, Ruben D. Cohen

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

3 Citations (Scopus)
52 Downloads (Pure)

Abstract

The field of cyber risks is rapidly expanding, yet significant research remains to be conducted. Numerous taxonomy‐based systems have been proposed in both the academic literature and industrial practice to classify cyber risk threats. However, the fragmentation of various approaches has resulted in a plethora of taxonomies, often incongruent with one another. In this study, we undertake a comprehensive review of these alternative taxonomies and offer a common framework for their classification based on their scope. Furthermore, we introduce desirable properties of a taxonomy, which enable comparisons of different taxonomies with the same scope. Finally, we discuss the managerial implications stemming from the utilization of each taxonomy class to support decision‐making processes.
Original languageEnglish
Pages (from-to)376-386
Number of pages11
JournalRisk Analysis
Volume45
Issue number2
Early online date2 Aug 2024
DOIs
Publication statusPublished - 2 Feb 2025

Keywords

  • cyber risks
  • risk classification
  • industrial taxonomy

Fingerprint

Dive into the research topics of 'A taxonomy of cyber risk taxonomies'. Together they form a unique fingerprint.

Cite this