Skip to content

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

Aug 2026 · International Conference on Cyber Security And Protection Of Digital Services · 0 citations

TL;DR

The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios.

Abstract

The rapid digitisation of critical infrastructure has made traditional fragmented risk assessment practices increasingly challenging to scale. For global industrial leaders managing hundreds of diverse projects, there is a real need for a unified methodology that ensures technical rigour, cross-project reproducibility, and scalability. This paper introduces the Advanced Risk Assessment Methodology for Industrial Systems (ARAMIS), an innovative framework developed through a strategic partnership between Airbus Protect and Alstom. ARAMIS merges the structured, requirement-driven security levels of ISA/IEC 62443 with the scenario-based approach of Expression des Besoins et Identification des Objectifs de Sécurité Risk Manager (EBIOS RM). The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T). Finally, it discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

View source

Similar papers

Aug 2026

Cyber-risk assessment and mitigation framework for critical information infrastructure: mixed-methods approach

Distributed Denial of Service (DDoS) attacks on critical information infrastructures (CII) cause operational disruptions and result in financial and reputational damage to organisations. Our study provides an integrated framework to assess, quantify and mitigate the cyber-risk of DDoS attacks on CII organisations i...

Priyanka Srivastava, Arunabha Mukhopadhyay · 0 citations
Review Open access Aug 2026

Bridging the gaps in cyber risk assessment: a comprehensive systematic review of standards, frameworks and quantification methods

The increasing frequency of cyber threats poses substantial challenges for organizations in both the private and public sectors. This systematic literature review evaluates and categorizes current cyber risk assessment methodologies and frameworks, supporting the selection of suitable approaches for practical and a...

Phillip Sampson, Barry Sheehan, D. Shannon et al. · 0 citations
Conference Open access 2026

A Hierarchical Evaluation Framework for LLM-driven Threat Modelling Tools

A systematic evaluation framework for LLM-driven threat modelling tools to support tool selection, observing the general LLM-integration, governance risks, and allowing for comparison of tool output is introduced.

Josephine Bakka, A. Brandhøj, T. Bøgedal et al. · 0 citations
Review Open access Aug 2026

MODÉLISATION INTÉGRÉE DES RISQUES CYBER-PHYSIQUES POUR LES INSTALLATIONS NUCLÉAIRES : VERS UNE ÉVALUATION DYNAMIQUE ET FONDÉE SUR LES DONNÉES

The digital transformation of nuclear facilities increases the interdependence of information technologies, operational systems, physical devices, and human actors, while existing risk-assessment approaches often remain domain-specific. This study aims to design an integrated framework for dynamic cyber-physical risk a...

Hervé T. A. Buanga, Nathanael Kasoro, S. Kasereka · 0 citations
Review Aug 2026

Demystifying cyber threat intelligence: A first-principles approach to capability development and vendor evaluation

The case is made for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit are offered.

Aaron Aubrey Ng · 0 citations
Review Aug 2026

Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure and explains why periodic assessment loses completeness when asset states change between review cycles.

Kolchin Rustam · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.