An Organizational Decision-Support System for Cybersecurity Risk Management: Classifying Breach Types Using XGBoost and Real-World Incident Data
Financial institutions face an escalating volume of cybersecurity threats, yet existing decision frameworks rarely link predictive analytics to operational security priorities. Drawing on Task-Technology Fit theory, this study develops a machine learning-based decision-support framework to classify cybersecurity breach types in financial institutions and to identify the organizational risk factors that determine them. Analyzing 935 publicly disclosed incidents from the VERIS Community Database (VCDB, NAICS 52), we compare XGBoost against Random Forest, Logistic Regression, and Decision Tree. XGBoost achieves the most balanced performance (accuracy: 95.19%; weighted F1: 0.9519; 5-fold CV: 96.68% ± 0.21%). Feature importance analysis reveals ATM/kiosk infrastructure and breach pattern as the strongest predictors, translating into concrete SOC monitoring priorities. This framework supports UN/SDG 9 (Industry, Innovation and Infrastructure) and UN/SDG 16 (Peace, Justice and Strong Institutions) by strengthening the cyber resilience of financial institutions through open, replicable, data-driven methods. The open-data framework is replicable without commercial threat intelligence licenses.