Open this publication in new window or tab >>2025 (English)In: Critical Information Infrastructures Security: 19th International Conference, CRITIS 2024, Rome, Italy, September 18–20, 2024, Revised Selected Papers / [ed] Gabriele Oliva, Stefano Panzieri, Bernhard Hämmerli, Federica Pascucci, Luca Faramondi, Springer Nature , 2025, p. 269-288Conference paper, Published paper (Refereed)
Abstract [en]
The financial sector is experiencing an increase in cyber incidents, prompting numerous firms to outsource IT infrastructure management. A primary factor contributing to these breaches is that the impacted systems are socio-technical systems (STSs), which include not only technical components such as software and hardware but also physical elements (e.g., robotics, mobility) and social components (e.g., human actors, business processes, and organizational units). Evaluating STS security breaches requires a holistic approach, considering human, organizational, software, and infrastructural elements. The study involves combining strategic factors, including social and organizational dynamics, with technical components such as software and physical infrastructure.
In our previous work, we developed a security attack-monitoring system to tackle these challenges. This framework was developed to monitor, analyze, and model security incidents across the social, cyber, and physical dimensions of cyber-physical systems (CPS). This paper employs the framework to conduct threat-led penetration testing in accordance with the Digital Operational Resilience Act (DORA), thus improving the financial sector’s capacity to address information and communication crises. This study provides important insights into cyberattacks and their impact on the financial sector by examining security breaches reported to the Swedish Civil Contingencies Agency (MSB) by critical service providers. The experiment was performed in collaboration with a prominent Swedish financial institution.
Place, publisher, year, edition, pages
Springer Nature, 2025
Series
Lecture Notes in Computer Science (LNCS), ISSN 0302-9743, E-ISSN 1611-3349
Keywords
Incident Reporting, DORA, Cybersecurity, Cyber-Resilience, Risk Management, Penetration Testing
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-240585 (URN)10.1007/978-3-031-84260-3_16 (DOI)2-s2.0-105000827523 (Scopus ID)978-3-031-84260-3 (ISBN)978-3-031-84259-7 (ISBN)
Conference
The 19th International Conference on Critical Information Infrastructures Security (CRITIS 2024), September 18–20, 2024, Rome, Italy.
2025-03-102025-03-102025-08-22Bibliographically approved