A Lightweight Cybersecurity Risk-Scoring Framework for Industrial Internet of Things Networks
Keywords:
Industrial Internet of Things, Cybersecurity Risk Assessment, Industrial Control Systems, Edge Security, Vulnerability Assessment, Explainable Security, Risk ScoringAbstract
Industrial Internet of Things (IIoT) networks join constrained field devices, legacy control protocols, edge gateways, and enterprise services while cyber incidents may produce physical and operational consequences. Security teams therefore need risk prioritization that is timely and intelligible, yet many assessment approaches require extensive modeling, complete evidence, or computationally demanding analytics. This conceptual paper proposes a lightweight, explainable framework that calculates bounded asset and network risk scores using simple arithmetic at an edge gateway or monitoring server. The framework combines asset criticality, vulnerability and configuration weakness, exposure, threat or anomaly evidence, control effectiveness, local propagation potential, and evidence confidence. It explicitly separates measured risk from confidence, applies conservative fallbacks when evidence is missing, and maps 0–100 scores to reviewable response priorities. Original equations define base, mitigation-adjusted, topology-aware, confidence-adjusted, aggregated, and temporally smoothed risk while preserving monotonicity and bounds. A gateway-centered architecture, operational workflow, linear-time scoring algorithm, and symbolic industrial scenario show how the design can support triage without imposing continuous analysis on constrained nodes. The contribution is a transparent synthesis intended for organizational calibration, not a validated standard or a substitute for safety, business-impact, or complete industrial risk assessment. No experiment, simulation, dataset, prototype, or field deployment is reported; expert elicitation and empirical validation remain future work.
References
L. L. Dhirani, E. Armstrong, and T. Newe, “Industrial IoT, cyber threats, and standards landscape: Evaluation and roadmap,” Sensors, vol. 21, no. 11, p. 3901, 2021.
T. Gebremichael, L. P. I. Ledwaba, M. H. Eldefrawy, G. P. Hancke, N. Pereira, M. Gidlund, and J. Åkerberg, “Security and privacy in the industrial internet of things: Current standards and future challenges,” IEEE Access, vol. 8, pp. 152351–152366, 2020.
K. Kandasamy, S. Srinivas, K. Achuthan, and V. P. Rangan, “IoT cyber risk: A holistic analysis of cyber risk assessment frameworks, risk vectors, and risk ranking process,” EURASIP Journal on Information Security, vol. 2020, no. 1, p. 8, 2020.
E. K. Parsons, E. Panaousis, G. Loukas, and G. Sakellari, “A survey on cyber risk management for the internet of things,” Applied Sciences, vol. 13, no. 15, p. 9032, 2023.
T. S. AlSalem, M. A. Almaiah, and A. Lutfi, “Cybersecurity risk analysis in the IoT: A systematic review,” Electronics, vol. 12, no. 18, p. 3958, 2023.
R. O. Andrade, S. G. Yoo, I. Ortiz-Garcés, and J. J. Barriga, “Security risk analysis in IoT systems through factor identification over IoT devices,” Applied Sciences, vol. 12, no. 6, p. 2976, 2022.
M. Beyrouti, A. Lounis, B. Lussier, A. Bouabdallah, and A. E. Samhat, “Vulnerability-oriented risk identification framework for IoT risk assessment,” Internet of Things, vol. 27, p. 101333, 2024.
M. Flores, D. Heredia, R. Andrade, and M. Ibrahim, “Smart home IoT network risk assessment using bayesian networks,” Entropy, vol. 24, no. 5, p. 668, 2022.
O. S. M. B. H. Almazrouei, P. Magalingam, M. K. Hasan, and M. Shanmugam, “A review on attack graph analysis for IoT vulnerability assessment: Challenges, open issues, and future directions,” IEEE Access, vol. 11, pp. 44350–44376, 2023.
G.-Y. Shin, S.-S. Hong, J.-S. Lee, I.-S. Han, H.-K. Kim, and H.-R. Oh, “Network security node-edge scoring system using attack graph based on vulnerability correlation,” Applied Sciences, vol. 12, no. 14, p. 6852, 2022.
F. Ö. Sönmez, C. Hankin, and P. Malacaria, “Attack dynamics: An automatic attack graph generation framework based on system topology, CAPEC, CWE, and CVE databases,” Computers & Security, vol. 123, p. 102938, 2022.
A. Akbarzadeh and S. K. Katsikas, “Dependency-based security risk assessment for cyber-physical systems,” International Journal of Information Security, vol. 22, no. 3, pp. 563–578, 2023.
S. C. Phillips, S. Taylor, M. Boniface, S. Modafferi, and M. Surridge, “Automated knowledge-based cybersecurity risk assessment of cyber-physical systems,” IEEE Access, vol. 12, pp. 82482–82505, 2024.
R. M. Czekster, P. Grace, C. Marcon, F. Hessel, and S. C. Cazella, “Challenges and opportunities for conducting dynamic risk assessments in medical IoT,” Applied Sciences, vol. 13, no. 13, p. 7406, 2023.
A. A. Ardebili, M. Lezzi, and M. Pourmadadkar, “Risk assessment for cyber resilience of critical infrastructures: Methods, governance, and standards,” Applied Sciences, vol. 14, no. 24, p. 11807, 2024.
T. Zhukabayeva, L. Zholshiyeva, N. Karabayev, S. Khan, and N. Alnazzawi, “Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions,” Sensors, vol. 25, no. 1, p. 213, 2025.
V. A. Thakor, M. A. Razzaque, and M. R. A. Khandaker, “Lightweight cryptography algorithms for resource-constrained IoT devices: A review, comparison and research opportunities,” IEEE Access, vol. 9, pp. 28177–28193, 2021.
K. Albulayhi, A. A. Smadi, F. T. Sheldon, and R. K. Abercrombie, “IoT intrusion detection taxonomy, reference architecture, and analyses,” Sensors, vol. 21, no. 19, p. 6432, 2021.
J. Yi and L. Guo, “AHP-based network security situation assessment for industrial internet of things,” Electronics, vol. 12, no. 16, p. 3458, 2023.
J. Jacobs, S. Romanosky, B. Edwards, I. Adjerid, and M. Roytman, “Exploit prediction scoring system (EPSS),” Digital Threats: Research and Practice, vol. 2, no. 3, pp. 1–17, 2021.
F. Cremer, B. Sheehan, M. Fortmann, A. N. Kia, M. Mullins, F. Murphy, and S. Materne, “Cyber risk and cybersecurity: A systematic review of data availability,” The Geneva Papers on Risk and Insurance–Issues and Practice, vol. 47, no. 3, pp. 698–736, 2022.
P. Cheimonidis and K. Rantos, “Dynamic risk assessment in cybersecurity: A systematic literature review,” Future Internet, vol. 15, no. 10, p. 324, 2023.
X. Lyu, Y. Ding, and S.-H. Yang, “Bayesian network based C2P risk assessment for cyber-physical systems,” IEEE Access, vol. 8, pp. 88506–88517, 2020.
A. Amro, V. Gkioulos, and S. K. Katsikas, “Assessing cyber risk in cyber-physical systems using the ATT&CK framework,” ACM Transactions on Privacy and Security, vol. 26, no. 2, pp. 1–33, 2023.
M. N. Nafees, N. Saxena, Á. A. Cárdenas, S. Grijalva, and P. Burnap, “Smart grid cyber-physical situational awareness of complex operational technology attacks: A review,” ACM Computing Surveys, vol. 55, no. 10, pp. 1–36, 2023.
X. Diao, Y. Zhao, C. Smidts, P. K. Vaddi, R. Li, H. Lei, Y. Chakhchoukh, B. K. Johnson, and K. L. Blanc, “Dynamic probabilistic risk assessment for electric grid cybersecurity,” Reliability Engineering & System Safety, vol. 241, p. 109699, 2024.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 The Author(s)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.