A Bounded Threat–Actor-Conditioned Cyber Risk Assessment Framework for Networked Systems Under Data-Scarce Conditions
Victor Zhora, Anatolii Antoniuk, Sergii Matvieiev, Volodymyr ArtemchukCyber risk assessment often combines likelihood and impact, but likelihood is difficult to justify when incident data are scarce and threat relevance depends on a specific actor. Existing attacker-aware methods improve context but frequently require attack graphs, vulnerability inventories, threat-intelligence feeds, exploit scores, telemetry, or calibrated probabilistic models. We propose a lightweight, auditable method that converts a multi-factor threat–actor profile into an actor–threat compatibility score and conditions a baseline likelihood through a bounded log-odds transformation. The model distinguishes uncertainty about which actor class is relevant from concurrent exposure to several active actor classes and propagates parameter uncertainty into decision-oriented rank robustness. Evaluation uses a reconstructed 35-scenario networked-system benchmark with 17 adversarial and 18 non-adversarial threats. Reproduction of the legacy calculation identifies three adjusted probability-like values above one, with a maximum of 1.54. The proposed formulation produces no boundedness or monotonicity violations in one million randomized stress tests. Compared with a static baseline, the resulting ranking remains globally stable (Spearman ρ=0.982; Kendall τb=0.911) while selectively reprioritizing actor-sensitive threats. A 20,000-run Monte Carlo analysis quantifies uncertainty intervals and top-five membership probabilities. At the reference κ=ln4, a transfer evaluation on an independent published video-conferencing case yields strong rank agreement with the source capability-based method (Spearman ρ=0.986; Kendall τb=0.966). These results establish mathematical and scenario-based robustness and portability, not calibration against observed incident frequencies. The method provides a transparent bridge between static ordinal risk matrices and data-intensive probabilistic cyber-risk models.