Skip to content
Review Open access

AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey

Aug 2026 · Journal of Cybersecurity and Privacy · Vol 6, pp. 131 · 0 citations · 32 references

TL;DR

Investigating stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework to help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats suggests that Information Technology and cybersecurity professionals had greater familiarity with CSA than did leaders and managers.

Abstract

Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (α = 0.868–0.926; ω = 0.870–0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (ρ = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.

Read PDF

Similar papers

Conference Aug 2026

Adapting NIST CSF 2.0 Framework to Enhance Cybersecurity Readiness Against Phishing in SMEs in Yemen

Small and medium-sized educational institutions in Yemen face significant challenges in building cybersecurity readiness, particularly against phishing attacks, which serve as a primary gateway to more sophisticated threats given the absence of formal policies and weak behavioral awareness. This study proposes a practi...

M. Abbas, Saleh Saleh Al-Amdi · 0 citations
Open access Jul 2026

Development of the Risk-Weighted Cybersecurity Maturity Index (RWCMI) Based on the NIST Cybersecurity Framework 2.0 for Multi-Entity Organizations

The RWCMI provides a more risk-sensitive cybersecurity maturity measurement framework that supports strategic decision-making, investment prioritization, and continuous improvement of cybersecurity governance in multi-entity organizations.

Ekky Cahya Dhitia, Ahmad Muklason · 0 citations
Open access Aug 2026

Cybersecurity Strategies in European SMEs: Navigating Digital Risks and Enhancing Cyber Resilience

Cybercrime rates have increased rapidly during the last decades, resulting in cybercrimes becoming common crimes and leading to the importance of companies’ attention to cybercrime experience. Therefore, this study examines cybercrime experience and provides insights into the companies’ concern, level of information...

Nessrine Omrani, Benedikt Wilke, Sascha Kraus et al. · 0 citations
Review Open access Sep 2026

Toward Dynamic and Risk-Aware Evaluation of Cybersecurity LLMs: A Survey and the RIRAG Framework

The rapid adoption of large language models (LLMs) in cybersecurity has created a growing need for evaluation methods that reflect operational risk rather than isolated language capability. Existing cybersecurity benchmarks assess useful dimensions such as factual knowledge, vulnerability analysis, secure coding, penet...

Ravi Prasad, Feroz Ahmed, Shohel Rana et al. · 0 citations
Open access Jul 2026

Identifying Critical Cybersecurity Threats Impacting Financial Stability in Investment Firms: A Qualitative Risk Management Perspective

Investment organizations now face greater cybersecurity risks as financial services become increasingly digitalized. Wherein the high-value transactions, sensitive client data, third-party platforms, and real-time operational systems are closely interconnected. The opinions of investment firm specialists on which speci...

Qamarsultana Alad, James C. Hyatt, Rahul Azmeera · 0 citations
Review Open access Aug 2026

Patching the Invisible Gap: A Comparative Analysis of Cyber Defense Strategies in Indonesian Digital Enterprises

Over the past five years, hacking incidents targeting Indonesia’s digital business ecosystem have increased significantly. The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara [BSSN]) recorded more than 1.6 billion cyberattacks throughout 2021, while 311 data breach incidents affecting 248 stakeholders we...

Aditya Akbar, Rafael Verdyansyah Pratama, Cahyo Purnomo et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.