Submitted:
26 November 2025
Posted:
27 November 2025
You are already at the latest version
Abstract

Keywords:
1. Introduction
2. Background and Related Works
2.1. Approaches, Methods and Limits
2.2. Advanced Assessment Methods
2.3. Machine and Deep Learning
3. Materials and Methods
- We will perform the clean for a standard month according to the formula (1):
- In a similar way, we perform cleaning on working days according to the formula (2):
- Hardware. The area of hardware includes not only computer devices and their accessories, but also other computer components that ensure the functions of the information system. We can apply these approach of valuation option for all types of hardware (Warren et al., 2023).
- ➢
- Valuation at acquisition costs, this method is applied in the case of assets that are acquired for consideration (the price includes related costs such as installation and transportation, patents and licenses or exploration, geological and other works). Costs re-lated to the purchase price may also include interest on the loan.
- ➢
- Repurchase valuation costs represents the price for which the asset was acquired at the time of its entry into accounting, i.e. a deposit of tangible assets, tangible assets as a gift or tangible assets acquired free of charge on the basis of financial leasing (in the case when the actual costs of creating the asset cannot be ascertained).
- ➢
- Actual costs are tangible assets that have been created by the business itself. These are direct or indirect costs that were incurred in the course of production or other activities (Warren et al., 2023).
- Software. For the purposes of this paper, the amount of costs that would have to be incurred to reinstall the software in the event of a breach will be used. Since the organization owns a license to operate the software tools, this is not necessary repurchase the software at a new price. There may also be a situation where the software is acquired and tied to the hardware it was purchased with, however, this possibility is not very likely in the case of small and medium enterprises. If were necessary to reinstall the software due to a cyber threat, the price of the software could be set based on the demand for the product. Pricing of software is also can be stated on the base of competitive price determination on the market. (Lehmann and Buxmann, 2009).
-
Fees associated to the occurrence of a cyber threat can be applied in various situations. If the organization primarily focuses on production, it may face sanctions for failing to comply with the production plan. This situation can occur in the event of a disruption in the function of the organization's information system, whose main task is to ensure the operation of production machines. If the required number of products were not fulfilled within the time schedule, the organization would also incur large financial losses. Another entity that can impose sanctions on a given organization is the competent supervisory authority. This policy is governed by the General Data Protection Regulation (GDPR).No predefined formula can be used to represent this category financially. The amount of the fine is always an individual matter and depends on supplier-customer relation-ships. In the case of the general GDPR regulation, the amount of fines is set between 10 000 000,- Euro and 20 000 000,- Euro or 4 % of the company's total turnover (Pavlík, 2019).
- Lost turnover. This mathematical formula can be utilized when an organization is unable to produce certain products or services. Originally designed for the production of tangible goods, the formula can also be adapted for organizations that produce digital products or services. For the digital sector, the formula will require adjustments to account for the duration when services cannot be provided to customers or other entities. This calculation should include the financial losses incurred during the period when digital products and services are unavailable.
- Data reconstruction and recovery costs. The cost of data reconstruction and recovery can be defined as the costs incurred for the recovery of data resources, which can be represented by hardware and software resources. In the event of a breach of these data resources, stored or backed-up data may be irretrievably lost or damaged. It is also possible to determine the average cost of lost or stolen data from available statistical sources. This average cost is reported to be 141,- USD per person (Ponemon Institute, 2017). The following formula can be used (7):
- Damage to reputation. To financially quantify an organization's reputation, it is essential to define what this term encompasses. In the context of insurance against cyber threats, “damage to reputation” refers to the future financial losses that could result from a cyber threat affecting specific areas of the organization. These areas include suppliers, customers, and sponsors. The financial resources potentially lost by the organization over a certain period due to such an adverse event represent this damage. The organization’s reputation, also known as goodwill in economics, can be expressed in financial terms using a mathematical framework. In this case, it is mainly about advertising and the image of the organization. In the area of advertising and image, the organization is evaluated as a whole, not only based on certain areas. To express the financial amount that reflects the area of advertising and image, it is necessary to measure the profitability of investments in this category. Furthermore, it is necessary to take into account the synergy that the company creates in order to reach the market (8).
- Costs of reporting data loss or leakage to supervisory authorities. When insuring against cyber threats, the costs of reporting data loss or leakage to supervisory authorities must also be considered. According to the General Data Protection Regulation (GDPR), personal data breaches must be reported to the relevant supervisory authority within 72 hours. This category also includes notifications and communications with other parties affected by the data or information breach. This issue is also closely related to maintaining the reputation of the organization (Ponemon Institute, 2017). For the purpose of expressing this parameter, the following formula may be used (10):
- First phase: economic part (appreciation of endangered elements of the organization's information environment). In this phase, with the help of the proposed mathematical formulas, it is appreciated that the endangered elements in the information environment of the selected organization are defined.
- Second phase: IT security part (assigning a significance value to individual endangerered elements and selected cyber threats).
- The third phase: interaction (expressing the interaction between cyber threats and endangered elements). This phase is aimed at identifying the most serious cyber threats in relation to the possible financial impacts on defined endangered elements.
- The fourth phase: prediction (predicting the development of the identified most serious cyber threats over time). In this phase, the possible development of identified cyber threats is predicted using the application of time series, from the point of view of the time dimension. The goal of this prediction should be a more accurate estimate of the development and impacts of selected cyber threats.
- Fifth phase: financial impacts (expressing the financial impacts of selected cyber threats on the organization's information environment).
4. Application
| Endagered Element | Price of endangered element |
|---|---|
| Hardware | 213 832 487, - € |
| Software | 1 480 541, - € |
| Fees | 198 687 € |
| Reputation | 225 185 237, - € |
| Data reconstruction and recovery costs | 31 630 118, - € |
| Costs of reporting data loss or leakage | 544 162, - € |
| The endangered elements of the university are valued at a total amount | 472 871 232, - € |






5. Results
- in the graph of level of cyber threat risk, the threat that was identified in the Saaty method analysis as the most serious is selected,
- for this threat, the sum of all values that appear in the given matrix is performed (i.e. the interaction of the endangered element and the threat),
- the total is divided by the number of interactions,
- the value obtained by this mathematical operation is assigned a range of values in the table with the appropriate percentage,
- this percentage is calculated from the amount that was determined at the beginning of the whole process, i.e. the valuation of the organization,
- the resulting amount should cover the costs and financial damages that may be caused by this cyber threat.
6. Discussion
6.1. Contribution of the Paper
6.2. Implication for Practice
6.3. Implications for Research
6.4. Limitations of the Research
7. Conclusions
Acknowledgements
References
- Zeller, G.; Scherer, M. A Comprehensive Model for Cyber Risk Based on Marked Point Processes and Its Application to Insurance. Eur. Actuar. J. 2021, 12, 33–85. [Google Scholar] [CrossRef]
- Siegel, C.A.; et al. Cyber-Risk Management: Technical and Insurance Controls for Enterprise – Level Security. In Information Security. In Information Security Management Handbook; Auerbach Publications: Boca Raton, FL, USA, 2002; Volume 4, pp. 433–449. [Google Scholar]
- Majuca, R.P.; et al. The Evolution of Cyberinsurance. Preprint 2006. [Google Scholar]
- Bradford, J. Insight Cyber Insurance Market Update. Advisen 2015. [Google Scholar]
- Biener, C.; Eling, M.; Wirfs, J.H. Insurability of Cyber Risk: An Empirical Analysis. Geneva Pap. Risk Insur. Issues Pract. 2015, 40, 131–158. [Google Scholar] [CrossRef]
- Romanosky, S. Examining the Costs and Causes of Cyber Incidents. J. Cybersecurity 2016, 2, 121–135. [Google Scholar] [CrossRef]
- Woods, D.; Simpson, A. Policy Measures and Cyber Insurance: A Framework. J. Cyber Policy 2017, 2, 209–226. [Google Scholar] [CrossRef]
- Dacorogna, M.; Kratz, M. Managing Cyber Risk, a Science in the Making. ESSEC Bus. Sch. Res. Pap. 2302. [Google Scholar]
- Franke, U. The Cyber Insurance Market in Sweden. Comput. Secur. 2017, 68, 130–144. [Google Scholar] [CrossRef]
- Schwartz, J.; Mathew, R. Ransomware: Average Ransom Payout Increases to $41,000. Data Breach Today 2019. [Google Scholar]
- Zhaoxin, L.; et al. Pricing Cyber Security Insurance. J. Math. Financ. 2022, 12, 46–70. [Google Scholar] [CrossRef]
- Marotta, A.; Martinelli, F.; Nanni, S.; Orlando, A.; Yautsiukhin, A. Cyber-Insurance Survey. Comput. Sci. Rev. 2017, 24, 35–61. [Google Scholar] [CrossRef]
- Young, D.; Lopez, J.; Rice, M.; McElroy, S.; Dandurand, L.; Serrano, O. A Framework for Incorporating Insurance in Critical Infrastructure Cyber Risk Strategies. Int. J. Crit. Infrastruct. Prot. 2016, 14, 43–57. [Google Scholar] [CrossRef]
- Tunggal, A. 22 Types of Malware and How to Recognize Them in 2023. UpGuard 2023. [Google Scholar]
- Millaire, P.; et al. Latest Industry Trends in Cyber Security and Cyber Insurance. Report 2018. [Google Scholar]
- Palson, K.; et al. Analysis of the Impact of Cyber Events for Cyber Insurance. Geneva Pap. Risk Insur. Issues Pract. 2020, 45, 564–579. [Google Scholar] [CrossRef]
- Erola, A.; et al. A System to Calculate Cyber Value-at-Risk. Report 2022. [Google Scholar] [CrossRef]
- Pavlík, L. Modeling the Impact of Cyber Threats on an Organization's Information System in the Framework of Cyber-Risk Insurance. Int. J. Math. Model. Methods Appl. Sci. 2019. [Google Scholar]
- Ponemon Institute. 2017 Cost of Data Breach Study – Global Overview; Ponemon Institute: Traverse City, MI, USA, 2017. [Google Scholar]
- Eling, M. Cyber Risk Research in Business and Actuarial Science. Eur. Actuar. J. 2020, 10, 303–333. [Google Scholar] [CrossRef]
- European Union. EU Cyber-Resilience Act. Preprint.
- Subroto, A.; Apriyana, A. Cyber Risk Prediction Through Social Media Big Data Analytics and Statistical Machine Learning. J. Big Data 2019, 6, 1–19. [Google Scholar] [CrossRef]
- Gulati, P.; et al. Artificial Intelligence In Cyber Security: Rescue Or Challenge. Rev. Artif. Intell. Educ. 2023. [Google Scholar] [CrossRef]
- The Lawyer. Incentives and Barriers of the Cyber Insurance Market in Europe. Report 2010. [Google Scholar]
- Zahn, N.; Toregas, C. Insurance for Cyber Attacks: The Issue of Setting Premiums in Context. Report 2014. [Google Scholar]
- Woods, D.; Simpson, A. Policy Measures and Cyber Insurance: A Framework. J. Cyber Policy 2017, 2, 209–226. [Google Scholar] [CrossRef]
- Awiszus, K.; et al. Modeling and Pricing Cyber Insurance: Idiosyncratic, Systematic, and Systemic Risk. Eur. Actuar. J. 2023, 13, 1–53. [Google Scholar] [CrossRef]
- Montgomery, D.C.; Runger, G.C. Introduction to Time Series Analysis and Forecasting; John Wiley & Sons: Hoboken, NJ, USA, 2024. [Google Scholar]
- Warren, C.; et al. Survey of Accounting; Cengage Learning: Boston, MA, USA, 2023. [Google Scholar]
- Lehman, S.; Buxmann, P. Pricing Strategies of Software Vendors. Bus. Inf. Syst. Eng. 2009, 1, 452–462. [Google Scholar] [CrossRef]
- Bank of Scotland. The Impacts of a Cyber Attack – What Cyber Means for Your Environmental, Social & Governance Strategy. Report.
- Tao, F.; et al. The Future of Artificial Intelligence in Cybersecurity: A Comprehensive Survey. EAI Endorsed Trans. Creat. Technol. 2021, 8, e28. [Google Scholar] [CrossRef]
- Cremer, F.; Sheehan, B.; Fortmann, M.; Kia, A.N.; Mullins, M.; Murphy, F.; Materne, S. Cyber Risk and Cybersecurity: A Systematic Review of Data Availability. Geneva Pap. Risk Insur. Issues Pract. 2022, 47, 698–736. [Google Scholar] [CrossRef] [PubMed]
- Bredt, S. Artificial Intelligence (AI) in the Financial Sector—Potential and Public Strategies. Front. Artif. Intell. 2019, 2, 1–5. [Google Scholar] [CrossRef]
- Bentley, M.; Stephenson, A.; Toscas, P.; Zhu, Z.A. A Multivariate Model to Quantify and Mitigate Cybersecurity Risk. Risks 2020, 8, 61. [Google Scholar] [CrossRef]
- Eling, M.; Schnell, W. What Do We Know about Cyber Risk and Cyber Risk Insurance? J. Risk Financ. 2016, 17, 474–491. [Google Scholar] [CrossRef]
- Aldasoro, I.; Gambacorta, L.; Giudici, P.; Leach, T. Operational and Cyber Risks in the Financial Sector. BIS Work. Pap. 2020, No. 840, 39. [Google Scholar]
- Orlando, A. Cyber Risk Quantification: Investigating the Role of Cyber Value at Risk. Risks 2021, 9, 184. [Google Scholar] [CrossRef]
- Cavusoglu, H.; Mishra, B.; Raghunathan, S. The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers. Int. J. Electron. Commer. 2004, 9, 70–104. [Google Scholar] [CrossRef]
- Portela, D.; Nogueira-Leite, D.; Almeida, R.; Cruz-Correia, R. Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study. JMIR Form. Res. 2023, 7, e41738. [Google Scholar] [CrossRef]
- Assen von der, J.; Franco, M.F.; Dong, M.; Stiller, B. QuantTM: Business-Centric Threat Quantification for Risk Management and Cyber Resilience. Report 2024. [Google Scholar]
- Eling, M.; Elvedi, M.; Falco, G. The Economic Impact of Extreme Cyber Risk Scenarios. N. Am. Actuar. J. 2023, 27, 429–443. [Google Scholar] [CrossRef]
- Franco, M.F.; Künzler, F.; Von Der Assen, J.; Feng, C.; Stiller, B. RCVaR: An Economic Approach to Estimate Cyberattacks Costs Using Data from Industry Reports. Comput. Secur. 2024, 139, 103737. [Google Scholar] [CrossRef]
- Ahmadi-Assalemi, G.; Al-Khateeb, H.; Epiphaniou, G.; Aggoun, A. Super Learner Ensemble for Anomaly Detection and Cyber-Risk Quantification in Industrial Control Systems. IEEE Internet Things J. 2022, 9, 13279–13297. [Google Scholar] [CrossRef]
- Ali, S.M.; Razzaque, A.; Yousaf, M.; Ali, S.S. A Novel AI-Based Integrated Cybersecurity Risk Assessment Framework and Resilience of National Critical Infrastructure. IEEE Access 2025, 13, 12427–12446. [Google Scholar] [CrossRef]
- Huang, T.; Zhang, Q.; Tang, X.; Zhao, S.; Lu, X. A Novel Fault Diagnosis Method Based on CNN and LSTM and Its Application in Fault Diagnosis for Complex Systems. Artif. Intell. Rev. 2022, 55, 1289–1315. [Google Scholar] [CrossRef]
- Eling, M.; Wirfs, J. What Are the Actual Costs of Cyber Risk Events? Eur. J. Oper. Res. 2019, 272, 1109–1119. [Google Scholar] [CrossRef]

| Endangered elements | Identified element | Value of endangered element |
|---|---|---|
| Hardware | Servers | 5 |
| Computer systems | 4 | |
| Printers | 2 | |
| Lost turnover | Lost turnover | 5 |
| Fees | Fees by supervisory authorities | 5 |
| Software | Database systems | 5 |
| Special software | 4 | |
| Operating systems | 4 | |
| Data reconstruction and recovery costs | Data reconstruction costs | 5 |
| Data recovery costs | 5 | |
| Damage to reputation | Damage to relationships with current students | 5 |
| Damage to relationships with potential future students | 5 | |
| Costs of reporting data loss or leakage to supervisory authorities | Help-desk costs | 3 |
| Special investigative activity of a cyber incident | 4 | |
| Corrective measures | 5 |
| Probability of Threat | Decimal Expression |
|---|---|
| 1 | 0 - 0,25 |
| 2 | 0,26 - 0,45 |
| 3 | 0,46 - 0,65 |
| 4 | 0,66 – 0,85 |
| 5 | 0,86 - 1 |
| Cyber threat | Probability of threat | Example of vulnerability |
|---|---|---|
| Ransomware | 5 | Insufficient antivirus protection of the information system, insufficiently educated employee |
| Intentional crime committed by a hacker | 4 | Insufficient antivirus protection of the information system, insufficiently educated employee |
| Unauthorized access | 3 | Insufficient security of the information system (irregular updating of passwords, easy access to the information system) |
| Malware | 3 | Insufficient antivirus protection of the information system, poor quality security software, insufficient e-mail security, insufficiently educated employee |
| Data leakage due to employee negligence | 3 | Failure to comply with security policies regarding the handling of internal and sensitive data of the organization |
| DDoS attack | 4 | Insufficient capacity and resilience of the computer network, insufficient network protection |
| Physical loss of data carrier (loss of laptop) | 2 | Insufficient security of the object in which the data carrier is located, risky behavior of the employee |
| Loss of data or disruption of the information system due to a lightning strike | 1 | Insufficient protection against lightning strikes (absence of lightning conductors, lightning arresters, etc.) |
| Failure system | 1 | Insufficient technical maintenance of equipment, human factor failure |
| Risk | Value range | Colour |
|---|---|---|
| Low risk | 1 - 30 | |
| Moderate risk | 34 - 65 | |
| High risk | 66 - 125 |
| Cyber threat | January | February | March | April |
|---|---|---|---|---|
| Ransomware | 42,3904 | 42,6148 | 42,586 | 42,304 |
| Intentional Crime Committed by a hacker | 36,2442 | 39,9426 | 44,071 | 48,6294 |
| DDoS attack | 22,6544 | 26,1712 | 30,137 | 34,5518 |
| Number of points | Descriptor |
|---|---|
| 1 | The criteria are equally reciprocal |
| 3 | The first criterion is slightly more important than the second |
| 5 | The first criterion is quite important than the second |
| 7 | The first criterion is demonstrably more important than the second |
| 9 | The first criterion is absolutely more important than the second |
| Cyber threat | Ransom ware | Intentional Crime Committed by a hacker | DDoS attack | Geometric mean |
|---|---|---|---|---|
| Ransomware | 3 | 5 | 3,87 | |
| Intentional Crime Committed by a hacker | 3 | 5 | ||
| DDoS attack |
| The degree of severity of the threat | Percentage of total |
|---|---|
| 66 - 70 | 10 |
| 71 - 66 | 20 |
| 77 - 82 | 30 |
| 83 - 88 | 40 |
| 89 - 94 | 50 |
| 95 - 100 | 60 |
| 101 - 106 | 70 |
| 107 - 112 | 80 |
| 113 - 118 | 90 |
| 119 - 125 | 100 |
| Cyber Threat | Resulting value |
|---|---|
| The sum of value for cyber threats "ransomware“ | 1176 |
| Number of interactions (endangered element x threat) | 14 |
| The average threat value | 1176/14 = 84 |
| Finacial impacts | 871 232 * 0.40 = 189 148 493 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).