MARATTO

article

Risk Assessment Model for IoT Security Governance

Abstract

The fast growth of the Internet of Things (IoT) has caused a huge rise in the number of connected devices, which creates major security issues because these devices are diverse and widely accessible. Standard risk assessment methods, which are mainly built for traditional IT systems, struggle to account for the changing and spread-out features of IoT environments.To address these problems, this paper introduces a new formula for analyzing IoT risks that takes into account five important parameters: device criticality, vulnerability, probability of occurrence, impact, and adaptability. Unlike conventional models, this approach contextualizes risk by considering not only technical factors but also the ability of devices to adapt and respond to threats in real time.Additionally, the article presents a comprehensive review of existing risk assessment methodologies and highlights the necessity for more flexible, adaptive framework to enhance cybersecurity governance in IoT environments. The proposed model aims to improve the precision and relevance of risk evaluation in complex, evolving IoT systems.

Research topics

  • IoT and Edge/Fog Computing
  • Information and Cyber Security
  • Smart Grid Security and Resilience

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/icoa66896.2025.11236842

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.