• The study introduces a novel framework FABRICS - Fault tree And Bayesian Risk & Impact analysis for Cyber Security - that combines Bayesian fault tree models with business impact analysis to quantify cyber risk both in terms of likelihood and financial impact. • The framework employs a structured elicitation process to gather expert judgments from both cybersecurity and business experts. • The framework was applied in a real insurance company, involving over 20 experts across cybersecurity and business domains analyzing a data breach and operational downtime. • The framework supports executive-level reporting, return on investment calculation, cyber insurance negotiations, and capital adequacy assessments. This study presents a model for financially quantifying an organization's cyber risk by analysing scenarios in which critical business processes are compromised. Financial impact and likelihood of a cyber incident remain difficult to quantify due to several challenges: scarcity of reliable data, limited methods for effectively incorporating expert judgment in lieu of objective data, threat landscape uncertainty, and the inherently interrelated cyber risks that lead to incidents. To be meaningful and actionable, any cyber risk analysis must be tailored to the organization's specific characteristics. This includes identifying relevant threats, assessing the effectiveness of existing controls, and evaluating the financial value of affected processes. Our proposed framework addresses these requirements by evaluating threats and control failure probabilities, and financial impact of cyber scenarios, with particular emphasis on reputational costs—an aspect frequently overlooked in prior research. The novelty of our approach lies in the integration of several methods: a) Business Impact Analysis to identify the most relevant cyber scenarios and their associated losses, b) expert elicitation techniques to capture collective uncertainty regarding the likelihood and financial consequences of cyber incidents, and c) Bayesian Fault Tree Analysis combined with Monte Carlo simulations to estimate scenario probabilities. We refer to this integrated framework as FABRICS, Fault tree And Bayesian Risk & Impact analysis for Cyber Security, a novel framework that synthesizes structured risk modeling with expert-driven uncertainty assessment. We demonstrate its practical application through a real-world case study involving an insurance company.
Slapničar et al. (Sun,) studied this question.