• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Cybersecurity risk assessment in OT systems using attack graphs
 
  • Details
  • Full
Options
January 22, 2026
Journal Article
Title

Cybersecurity risk assessment in OT systems using attack graphs

Abstract
Cybersecurity risk assessment is essential for ensuring the security and resilience of Operational Technology (OT) systems, which are increasingly targeted by cyber threats. Traditional assessment frameworks often struggle with complexity, inefficiency, and the inability to adapt dynamically to evolving attack scenarios. In this work, we propose a novel approach that utilizes Attack Graphs to systematically model and assess cybersecurity risks in OT environments. Attack Graphs provide a structured representation of attack paths, enabling a comprehensive analysis of vulnerabilities and potential adversary actions. We extend conventional Attack Graphs by integrating countermeasures and impact assessment, allowing for a more complete cybersecurity risk evaluation process. Our framework facilitates adaptive assessments by efficiently incorporating system or environmental changes and identifying the most critical security threats. We validate our approach through a case study, demonstrating its effectiveness in enhancing OT risk assessment and aligning it with established cybersecurity standards. By bridging the gap between theoretical cybersecurity risk assessment models and practical security challenges, our work contributes to a more proactive and structured defense strategy for OT systems.
Author(s)
Unger, Simon
Arzoglou, Ektor
Heinrich, Markus
Scheuermann, Dirk  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Katzenbeisser, Stefan
Journal
International journal of information security  
Open Access
File(s)
Download (3.3 MB)
Rights
CC BY 4.0: Creative Commons Attribution
DOI
10.1007/s10207-025-01198-7
10.24406/publica-8019
Additional link
Full text
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • Attack Graphs

  • CLC/TS 50701

  • Cybersecurity Risk Assessment

  • ISO/SAE 21434

  • Security Evaluation

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024