This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Open AccessArticle
A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments
by
GwangHyun Ahn
GwangHyun Ahn 1
and
Dongkyoo Shin
Dongkyoo Shin 1,2,3,*
1
Department of Computer Engineering, Sejong University, Seoul 05006, Republic of Korea
2
Department of Convergence Engineering for Intelligent Drones, Sejong University, Seoul 05006, Republic of Korea
3
Defense AI Cyber Convergence Research Institute, Sejong University, Seoul 05006, Republic of Korea
*
Author to whom correspondence should be addressed.
Electronics 2026, 15(12), 2554; https://doi.org/10.3390/electronics15122554 (registering DOI)
Submission received: 5 May 2026
/
Revised: 16 May 2026
/
Accepted: 1 June 2026
/
Published: 9 June 2026
Abstract
Existing Cyber Resilience Assessment Guidelines, including those of the Bank of Korea (BoK), focus on governance-oriented compliance and lack quantitative criteria for measuring the operational effectiveness of security technologies—a Policy–Technology Gap also common in general enterprise settings. To address this gap, this study proposes D3-CREF, a technology-centric cyber resilience evaluation framework that maps the MITRE D3FEND taxonomy to financial security domains and introduces a Normalized Resilience Index (NRI) aggregating four dimensions—Coverage, Maturity, Automation, and Timeliness—via a closed-form weighted geometric mean with AHP-elicited weights (consistency ratio CR = 0.04). All NRI indicators are anchored to MITRE ATT&CK techniques and exemplar CVE entries, enabling threat-informed measurement. The framework was validated through a three-round Delphi study with 50 experts (Kendall’s W = 0.78, p < 0.001; Cronbach’s α = 0.89; CVR 0.68–0.92) and a Cyber Range-based simulation. For three institutions with identical BoK scores (92/100), NRI yielded discriminative values of 0.83, 0.44, and 0.09 (CV = 0.68 vs. 0.00 for the baseline), confirming a shift from compliance-based to performance-driven assessment.
Share and Cite
MDPI and ACS Style
Ahn, G.; Shin, D.
A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics 2026, 15, 2554.
https://doi.org/10.3390/electronics15122554
AMA Style
Ahn G, Shin D.
A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics. 2026; 15(12):2554.
https://doi.org/10.3390/electronics15122554
Chicago/Turabian Style
Ahn, GwangHyun, and Dongkyoo Shin.
2026. "A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments" Electronics 15, no. 12: 2554.
https://doi.org/10.3390/electronics15122554
APA Style
Ahn, G., & Shin, D.
(2026). A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics, 15(12), 2554.
https://doi.org/10.3390/electronics15122554
Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details
here.
Article Metrics
Article Access Statistics
For more information on the journal statistics, click
here.
Multiple requests from the same IP address are counted as one view.