Journal of Cybersecurity in AI and Quantum Computing

ISSN: Pending Request (Online)Peer ReviewedOpen AccessOpen Access
open accessOpen Access

research

👁️22views

A Comprehensive Cyber Risk Measurement Framework Using Key Risk Indicators (KRIs) for Enterprise Risk Governance

Volume 2026, Issue 1ISSN: Pending Request (Online)Journal: Journal of Cybersecurity in AI and Quantum Computing
by 

Sopheaktra Huy ORCID profile ;

Mony Ho ORCID profile ;

Sokroeurn Ang ORCID profile ;

Midhunchakkaravarthy Janarthanan ORCID profile

Sopheaktra Huy: School of AI Computing and Multimedia, Lincoln University College, Selangor, Malaysia, MYS

Mony Ho: School of AI Computing and Multimedia, Lincoln University College, Selangor, Malaysia, MYS

Sokroeurn Ang: School of AI Computing and Multimedia, Lincoln University College, Selangor, Malaysia, MYS

Midhunchakkaravarthy Janarthanan: School of AI Computing and Multimedia, Lincoln University College, Selangor, Malaysia, MYS

PDF logoPDF

Published: 2026/09/05

Pages: 117135

Abstract

Organizations across all industries continue to face challenges in quantifying and monitoring cyber risk in a consistent, actionable, and predictive manner. Although cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, and COBIT provide guidance for establishing controls, they offer limited support for operationalizing cyber risk measurement. Traditional qualitative assessments often rely on subjective scoring and static evaluations that fail to reflect the dynamic nature of cyber threats. This research addresses these limitations by proposing a comprehensive cyber risk measurement framework grounded in Key Risk Indicators (KRIs). The framework introduces a multi-domain taxonomy encompassing technology, human behavior, governance processes, and external threat conditions, supported by a quantitative scoring and threshold model that enables objective and comparable measurement. It further provides an integration approach for embedding KRIs into governance reporting and a five-level maturity model that guides organizations in developing their KRI capabilities. Drawing on design science research principles, the framework synthesizes cybersecurity standards, academic literature, and industry practices to deliver a practical and sector-agnostic method for transforming fragmented security metrics into data-driven cyber risk intelligence. The proposed framework enhances predictive risk management, strengthens decision-making, and supports continuous improvement in organizational cyber resilience. Practically, the framework supports risk managers, auditors, and boards in transitioning from fragmented security metrics to governance-ready cyber risk intelligence that enables timely prioritization and accountable decision-making.

Keywords

Quantum computingCritical infrastructure protectionPost-quantum cryptographyArtificial intelligenceCybersecurity risk mitigation.

References

  1. National Institute of Standards and Technology. (2023). NIST cybersecurity framework (CSF) 2.0. https://www.nist.gov/cyberframework
  2. Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise risk management—Integrating with strategy and performance.
  3. Melaku, H. M. (2023). A dynamic and adaptive cybersecurity governance framework. Journal of Cybersecurity and Privacy, 3(3), 327-350.
  4. ISACA. (2019). COBIT 2019 framework: Governance and management objectives.
  5. Bernardo, L., Malta, S., & Magalhães, J. (2025). An evaluation framework for cybersecurity maturity aligned with the NIST CSF. Electronics, 14(7), 1364.
  6. Hubbard, D. W., & Seiersen, R. (2016). How to measure anything in cybersecurity risk. Wiley. https://doi.org/10.1002/9781119085294
  7. Gartner. (2023). Top cybersecurity trends and challenges for 2023. Gartner Research.
  8. Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135. https://doi.org/10.1093/cybsec/tyw001
  9. Ludvigson, S. C., & Ng, S. (2007). The empirical risk–return relation: A factor analysis approach. Journal of financial economics, 83(1), 171-222.
  10. Basel Committee on Banking Supervision. (2011). Principles for the sound management of operational risk. Bank for International Settlements.
  11. PwC. (2022). Global digital trust insights survey 2022. PwC Global.
  12. Verizon. (2023). Data breach investigations report 2023. Verizon Enterprise.
  13. Böhme, M., & Kataria, G. (2020). Models of cyber risk. Workshop on the Economics of Information Security. https://doi.org/10.48550/arXiv.2005.08168
  14. Center for Internet Security. (2021). CIS critical security controls v8.
  15. International Organization for Standardization, & International Electrotechnical Commission. (2022). ISO/IEC 27001:2022—Information security management systems—Requirements. International Organization for Standardization.
  16. International Organization for Standardization, & International Electrotechnical Commission. (2016). ISO/IEC 27004:2016—Information security management—Monitoring, measurement, analysis and evaluation. International Organization for Standardization.
  17. Microsoft. (2023). Microsoft digital defense report 2023. Microsoft Security.
  18. Calvo, M., & Beltrán, M. (2024). Applying the Goal, Question, Metric method to derive tailored dynamic cyber risk metrics. Information & Computer Security, 32(2), 133-158.
  19. Accenture. (2023). State of cybersecurity resilience 2023. Accenture Security.
  20. IBM Security, & Ponemon Institute. (2023). Cost of a data breach report 2023. IBM.
  21. Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105. https://doi.org/10.25300/MISQ/2004/28.1.05
  22. Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302
  23. Software Engineering Institute. (2018). Capability maturity model integration (CMMI) v2.0. Carnegie Mellon University.
  24. Ionescu, Ș., Dumitrescu, G., Ioanăș, C., & Delcea, C. (2024). Mapping the landscape of key performance and key risk indicators in business: A comprehensive bibliometric analysis. Risks, 12(8), 125.
  25. Cernisevs, O., Popova, Y., & Cernisevs, D. (2023, June). Risk-based approach for selecting company key performance indicator in an example of financial services. In Informatics (Vol. 10, No. 2, p. 54). MDPI.
  26. Cernisevs, O., Popova, Y., & Cernisevs, D. (2023). Business KPIs based on compliance risk estimation. Journal of Tourism and Services, 14(27), 222-248.
  27. Biener, C., Eling, M., & Wirfs, J. (2015). Insurability of cyber risk: An empirical analysis. The Geneva Papers on Risk and Insurance—Issues and Practice, 40(1), 131–158. https://doi.org/10.1057/gpp.2014.19
  28. Eling, M., & Schnell, W. (2016). What do we know about cyber risk and cyber risk insurance? Journal of Risk Finance, 17(5), 474–491. https://doi.org/10.1108/JRF-09-2016-0122
  29. Marotta, A., Martinelli, F., Nanni, S., Orlando, A., & Yautsiukhin, A. (2017). Cyber-insurance survey. Computer Science Review, 24, 35–61. https://doi.org/10.1016/j.cosrev.2017.01.001
  30. Crelinsten, R. D. (1989). Terrorism, counter‐terrorism and democracy: The assessment of national security threats. Terrorism and Political Violence, 1(2), 242-269.
  31. Ruan, K. (2017). Introducing cybernomics: A unifying economic framework for measuring cyber risk. Computers & Security, 65, 77-89.
  32. Aven, T. (2016). Risk assessment and risk management: Review of recent advances. European Journal of Operational Research, 253(1), 1–13. https://doi.org/10.1016/j.ejor.2015.12.023
  33. Organisation for Economic Co-operation and Development. (2020). Digital security risk management for economic and social prosperity. OECD Publishing. https://doi.org/10.1787/ecd2ec57-en
  34. Slapničar, S., Axelsen, M., & Eulerich, M. (2025). Cyber risk management: an illusion of a risk-based approach. Journal of Management Control, 1-36.
  35. Awan, M. S. K., Burnap, P., & Rana, O. (2016). Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk. computers & security, 57, 31-46.
  36. Paulk, M. C., Curtis, B., Chrissis, M. B., & Weber, C. V. (1993). Capability maturity model for software. IEEE Software, 10(4), 18–27. https://doi.org/10.1109/52.219617
  37. Le, N. T., & Hoang, D. B. (2016, December). Can maturity models support cyber security?. In 2016 IEEE 35th international performance computing and communications conference (IPCCC) (pp. 1-7). IEEE.
  38. Kott, A., & Arnold, C. (Eds.). (2013). Cyber situational awareness: Issues and research. Springer. https://doi.org/10.1007/978-3-319-04117-4
  39. Sabottke, C., Suciu, O., & Dumitraş, T. (2015). Vulnerability disclosure and patching behavior. In Proceedings of the 24th USENIX Security Symposium.