Related Experiment Video
Updated: Nov 3, 2025

Author Spotlight: Innovations in iTUG Test for Enhanced Risk Assessment and Cognitive Insights
Published on: October 25, 2024
Assessing MITRE ATT&CK Risk Using a Cyber-Security Culture Framework
Anna Georgiadou1, Spiros Mouzakitis1, Dimitris Askounis1
1Decision Support Systems Laboratory, National Technical University of Athens, Iroon Polytechniou 9, 15780 Zografou, Greece.
This study links organizational culture factors to security vulnerabilities using the MITRE ATT&CK framework. It offers a novel approach for proactive cybersecurity assessment and defensive design, especially in critical infrastructure.
Area of Science:
- Cybersecurity
- Information Security
- Organizational Culture
Background:
- The MITRE ATT&CK framework is widely used for understanding adversary tactics and techniques.
- Existing research often analyzes attacks or culture separately, lacking a holistic view.
- A gap exists in understanding the association between organizational culture and security vulnerabilities.
Purpose of the Study:
- To associate organizational and individual culture factors with security vulnerabilities mapped to MITRE ATT&CK behaviors.
- To explore the application of the MITRE ATT&CK framework for scientific security assessment and defensive design.
- To develop a cybersecurity culture framework tailored for critical infrastructures, including IT/OT environments.
Main Methods:
- Developed a cybersecurity culture framework to identify relevant organizational and individual factors.
- Mapped these factors to security vulnerabilities using the MITRE ATT&CK framework.
- Utilized a hybrid MITRE ATT&CK for Enterprise and Industrial Control Systems (ICS) model.
Main Results:
- Demonstrated a method to link specific cultural factors to adversary behavior patterns.
- Showcased the potential of MITRE ATT&CK for proactive security assessment and design.
- Highlighted the importance of considering IT and OT network interactions in cybersecurity culture.
Conclusions:
- Associating culture with vulnerabilities provides a novel approach to cybersecurity.
- The research enables more scientific security assessment and defensive strategy development.
- Findings are applicable to enhancing security procedures and readiness evaluations in critical sectors.
More Related Videos
06:42Continuous Theta Burst Stimulation of the Posterior Medial Frontal Cortex to Experimentally Reduce Ideological Threat Responses
Published on: September 28, 2018
07:31Implementation of a Real-Time Psychosis Risk Detection and Alerting System Based on Electronic Health Records using CogStack
Published on: May 15, 2020
Related Concept Videos
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
The Role of Culture
Self-Esteem and Culture
Types of Reports II: Incident or Occurrence Report
Purposes:
In the healthcare industry, reports play a crucial role in documenting incidents within an agency. The primary objective of these reports is to ensure patient safety, uphold the...
Healthcare Associated Infections II: Preventive Measures
The best practices for preventing healthcare-associated infections include hand hygiene, patient risk...
Self-Evaluation Maintenance Model