Distributed Denial of Service (DDoS) attacks on critical information infrastructures (CII) cause operational disruptions and result in financial and reputational damage to organisations. Our study provides an integrated framework to assess, quantify and mitigate the cyber-risk of DDoS attacks on CII organisations in the energy and power sectors. Our model adopts a socio-technological perspective and draws on protection motivation theory (PMT) and rational choice theory (RCT).
Our study adopts a mixed-method approach. In the quantitative section, we estimate the likelihood of misdetection of different DDoS attacks by using observable attackers’ strategy. These observations influence how CISOs implement the organisation’s cybersecurity posture and IT governance. Next, we compute the expected loss. Lastly, the study recommends CISO for various mitigation strategies based on the NIST Cybersecurity Framework by creating a 2×2 risk-impact heat matrix. Subsequently, Linear Programming is used to determine the priority of optimal allocation of investment across different mitigation strategies. In qualitative section, in-depth interviews with cybersecurity executives corroborate findings.
The likelihood of the misdetection of DDoS attacks by the CISO of an organisation is low. Most DDoS attacks result in small financial losses, but rare, severe incidents can cause disproportionately serious damage. The study further finds that organisations must invest in technological interventions, complemented by financial tools, to mitigate DDoS attacks.
The study uses a mixed-methods approach, combining quantitative analysis with executive interviews to assess the CISO's misdetection rate for DDoS attacks, compute the expected financial loss, and recommend a mitigation and investment strategy based on the NIST framework for CII organisations.
