A DATA-DRIVEN MULTI-CRITERIA DECISION FRAMEWORK FOR CYBERSECURITY INVESTMENT AND PROJECT PRIORITIZATION IN BANKING
DOI:
https://doi.org/10.48047/xe7af830Keywords:
Multi-criteria decision-making, cybersecurity investment, AHP, TOPSIS, VIKOR, deep learning, banking, CVE, EPSSAbstract
Investments in cybersecurity prioritization by banks are usually determined based on expert judgement, which is hard to audit, reproduce and defend from regulators and boards of directors. We propose a hybrid, data-driven multi-criteria decision framework where two of the eight prioritization criteria (risk reduction and threat-likelihood coverage) are based on actual threat-intelligence data rather than opinion while keeping the other six transparent and analyst-editable. The data layer consists of a combination of 337,705 CVE records, Exploit Prediction Scoring System (EPSS) exploit-probability scores, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities flags, and 893 banking-sector incidents identified over the use of VERIS Community Database (NAICS code 52).This data-driven severity ordering is held in a consistent feature-ordered sense across seven attack-type categories using a GPU-trained feed-forward deep neural network and is subsequently reweighted toward the specific banking threat landscape observable from the incident data. Next, twelve candidate security investments are ranked using five different independent methods such as Analytic Hierarchy Process (AHP), Shannon entropy weighting, TOPSIS, Fuzzy-TOPSIS and VIKOR. Pairwise Spearman correlation from 0.90 to 0.97 and strong cross-method agreement (Kendall's W=0.944), with the highest-ranked solution–vulnerability management platform–is stable across 232 weight-perturbation trials (rank-reversal rate=zero; mean full-ranking Spearman correlation against baseline≥0.997). We present the framework, its validation method and limitations, including a data quality artifact in the KO given in the KEV field and that criteria derived from configurations are illustrative.
Downloads
References
L. A. Gordon and M. P. Loeb, "The economics of information security investment," ACM Transactions on Information and System Security, vol. 5, no. 4, pp. 438-457, 2002.
Fielder, E. Panaousis, P. Malacaria, C. Hankin, and F. Smeraldi, "Decision support approaches for cyber security investment," Decision Support Systems, vol. 86, pp. 13-23, 2016.
L. P. Rees, J. K. Deane, T. R. Rakes, and W. H. Baker, "Decision support for cybersecurity risk planning," Decision Support Systems, vol. 51, no. 3, pp. 493-505, 2011.
A. Ganin, P. Quach, M. Panwar, Z. A. Collier, J. M. Keisler, D. Marchese, and I. Linkov, "Multicriteria decision framework for cybersecurity risk assessment and management," Risk Analysis, vol. 40, no. 1, pp. 183-199, 2020.
R. Goel, A. Kumar, and J. Haddow, "PRISM: a strategic decision framework for cybersecurity risk assessment," Information and Computer Security, vol. 28, no. 4, pp. 591-625, 2020.
T. L. Saaty, The Analytic Hierarchy Process. New York, NY: McGraw-Hill, 1980.
T. L. Saaty, "How to make a decision: the analytic hierarchy process," European Journal of Operational Research, vol. 48, no. 1, pp. 9-26, 1990.
C. L. Hwang and K. Yoon, Multiple Attribute Decision Making: Methods and Applications. Berlin, Germany: Springer-Verlag, 1981.
C. T. Chen, "Extensions of the TOPSIS for group decision-making under fuzzy environment," Fuzzy Sets and Systems, vol. 114, no. 1, pp. 1-9, 2000.
S. Opricovic and G. H. Tzeng, "Compromise solution by MCDM methods: a comparative analysis of VIKOR and TOPSIS," European Journal of Operational Research, vol. 156, no. 2, pp. 445-455, 2004.
C. E. Shannon, "A mathematical theory of communication," Bell System Technical Journal, vol. 27, no. 3, pp. 379-423, 1948.
M. Zeleny, Multiple Criteria Decision Making. New York, NY: McGraw-Hill, 1982.
D. Diakoulaki, G. Mavrotas, and L. Papayannakis, "Determining objective weights in multiple criteria problems: the CRITIC method," Computers and Operations Research, vol. 22, no. 7, pp. 763-770, 1995.
P. Mell, K. Scarfone, and S. Romanosky, "Common Vulnerability Scoring System," IEEE Security and Privacy, vol. 4, no. 6, pp. 85-89, 2006.
J. Jacobs, S. Romanosky, I. Adjerid, and W. Baker, "Improving vulnerability remediation through better exploit prediction," Journal of Cybersecurity, vol. 6, no. 1, tyaa015, 2020.
J. Jacobs, S. Romanosky, B. Edwards, I. Adjerid, and M. Roytman, "Exploit Prediction Scoring System (EPSS)," Digital Threats: Research and Practice, vol. 2, no. 3, article 20, 2021.
G. Spanos and L. Angelis, "A multi-target approach to estimate software vulnerability characteristics and severity scores," Journal of Systems and Software, vol. 146, pp. 152-166, 2018.
Z. Han, X. Li, Z. Xing, H. Liu, and Z. Feng, "Learning to predict severity of software vulnerability using only vulnerability description," in Proc. IEEE International Conference on Software Maintenance and Evolution (ICSME), 2017, pp. 125-136.
Verizon, "2021 Data Breach Investigations Report," Verizon Business, 2021.
Hossain, I., Lindon, A. R., Rahman, M., Khan, H. A., Tohfa, N. A., Shagar, M. T. M., ... & Nasif, M. R. I. (2026). Hybrid ensemble learning for robust DDoS detection and attack classification with a web-based analytical tool for cybersecurity analysts. Journal of Electrical Engineering, 11(5).
Chy, M. S. K., Abdullah, S. M., Nabil, M. A., Alam, A., Himeluzzaman, M., Onik, T. A., ... & Khan, H. A. (2022). QShield-NS: A variational quantum machine learning model for zero-day cyber threat detection in national security systems. International Journal of Future Innovative Science and Technology (IJFIST), 5(5), 9283.
Hossain, M. S., Biswas, B., & Rahaman, M. M. (2023). THE ROLE OF ARTIFICIAL INTELLIGENCE IN ENHANCING CYBERSECURITY DEFENSE MECHANISMS. International Journal Of Engineering Technology Research & Management (IJETRM), 7(07), 157-166.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
You are free to:
- Share — copy and redistribute the material in any medium or format for any purpose, even commercially.
- Adapt — remix, transform, and build upon the material for any purpose, even commercially.
- The licensor cannot revoke these freedoms as long as you follow the license terms.
Under the following terms:
- Attribution — You must give appropriate credit , provide a link to the license, and indicate if changes were made . You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
- No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.
Notices:
You do not have to comply with the license for elements of the material in the public domain or where your use is permitted by an applicable exception or limitation .
No warranties are given. The license may not give you all of the permissions necessary for your intended use. For example, other rights such as publicity, privacy, or moral rights may limit how you use the material.
