A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments
Abstract
1. Introduction
2. Related Works
2.1. Existing Approaches to Cyber Resilience Frameworks
2.2. The Bank of Korea Cyber Resilience Assessment Guidelines
2.3. Research on MITRE ATT&CK and D3FEND Frameworks
2.4. The D3FEND Framework for Technology-Centric Defense
3. Proposed Method
3.1. Research Design
3.2. Mapping Guideline Items to D3FEND Technologies
3.3. Formal Definition of the Normalized Resilience Index
- (i)
- Rate-type indicators (e.g., true positive rate, hardening coverage) are already in [0, 1] and pass through unchanged: ni,j = xi,j.
- (ii)
- Time-type indicators (e.g., MTTD, MTTR) use exponential normalization with a domain-specific target T*: ni,j = exp(−xi,j/T*) so that ni,j → 1 as xi,j → 0 and ni,j → 0 as xi,j → ∞.
- (iii)
- Maturity-type indicators (1–5 ordinal scale) use linear rescaling: ni,j = (xi,j − 1)/4.
| Algorithm 1: NRI Computation |
| Input: X = {x_{i,j}} // raw indicator measurements type(i,j) ∈ {rate, time, maturity} dim(i,j) ∈ {C, M, A, T} T*_{i,j} // target for time-type indicators w = (w_C, w_M, w_A, w_T) // AHP-elicited weights ω = {ω_i} // domain importance weights Output: NRI_inst ∈ [0, 1], DataCompletenessFlag 1: for each domain d_i: 2: for each indicator (i,j) with observed x_{i,j}: 3: if type(i,j) == rate: n_{i,j} ← x_{i,j} 4: else if type(i,j) == time: n_{i,j} ← exp(−x_{i,j}/T*_{i,j}) 5: else if type(i,j) == maturity: n_{i,j} ← (x_{i,j} − 1)/4 6: for each dimension φ ∈ {C, M, A, T}: 7: S_{i,φ} ← {n_{i,j}: dim(i,j) = φ, observed} 8: if |S_{i,φ}| > 0: ñ_{i,φ} ← mean(S_{i,φ}) 9: else: ñ_{i,φ} ← n_min = 0.10; flag i 10: NRI(d_i) ← ∏_{φ} (ñ_{i,φ})^{w_φ} 11: NRI_inst ← ∑_i ω_i · NRI(d_i) 12: DataCompletenessFlag ← (any domain flagged?) 13: return (NRI_inst, DataCompletenessFlag) |
3.4. Reconfiguring Evaluation Items
3.5. ATT&CK–CVE Threat Anchoring
4. Verification of Research Results
4.1. Logical and Conceptual Validation
4.2. Expert Validation via the Delphi Method
4.2.1. Panel Composition
4.2.2. Procedure
4.2.3. Results
4.2.4. Threats to Validity
4.3. Experimental Setup and Methodology
4.4. Experimental Results and Comparative Analysis
4.5. NRI–Breach Impact Proxy Validation
5. Extended Comparison with Recent Quantitative Cyber-Resilience and SOC-Maturity Frameworks
6. Operational Trade-Offs and the Mechanism of Performance-Based Assessment
6.1. Operational Trade-Offs
6.2. Mechanism of Performance-Based Assessment
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2022; ENISA: Athens, Greece, 2022. Available online: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2022 (accessed on 13 April 2026).
- Craigen, D.; Diakun-Thibault, N.; Purse, R. Defining Cybersecurity. Technol. Innov. Manag. Rev. 2014, 4, 13–21. [Google Scholar] [CrossRef] [PubMed]
- World Economic Forum. Global Cybersecurity Outlook 2023; World Economic Forum: Geneva, Switzerland, 2023; Available online: https://www.weforum.org/publications/global-cybersecurity-outlook-2023 (accessed on 13 April 2026).
- Bank of Korea. Cyber Resilience Assessment Methodology for Korean Financial Market Infrastructures; Bank of Korea: Seoul, Republic of Korea, 2018. Available online: https://www.bok.or.kr/portal/bbs/B0000232/view.do?nttId=234703&menuNo=200725 (accessed on 11 April 2026).
- Ahn, G.H.; Shin, D.K. Research on Cyber Resilience Assessment Metrics Through the Integrated Implementation of Zero Trust and MITRE ATT&CK. J. Internet Comput. Serv. 2024, 25, 107–129. [Google Scholar]
- MITRE Corporation. MITRE ATT&CK®. Available online: https://attack.mitre.org (accessed on 20 January 2026).
- Cho, H.; Lee, J.; Kim, S. Quantifying Cyber Resilience: A Framework Based on Availability Metrics and AUC-Based Normalization. Electronics 2025, 14, 2465. [Google Scholar] [CrossRef]
- Hasan, K.F.; Iqbal, S.; Islam, M.R.; Liyanage, M.; Roy, P.P.; Hassan, M.M. ISADM: An Integrated STRIDE, ATT&CK, and D3FEND Model for Threat Modeling Against Real-World Adversaries. arXiv 2025, arXiv:2512.18751. [Google Scholar]
- Ahn, G.H.; Shin, D.K. Research on a Technology-Centric Evaluation Framework for Cyber Resilience Based on MITRE D3FEND: Supplementing the Practical Application of Assessment Guidelines for Financial Institutions. J. Internet Comput. Serv. 2025, 26, 161–177. [Google Scholar]
- Ross, R.; Pillitteri, V.; Graubart, R.; Bodeau, D.; McQuaid, R. Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (NIST SP 800-160 Vol. 2 Rev. 1); NIST: Gaithersburg, MD, USA, 2021. Available online: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf (accessed on 18 January 2026).
- National Institute of Standards and Technology. Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1; NIST: Gaithersburg, MD, USA, 2018. Available online: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf (accessed on 15 January 2026).
- European Union Agency for Cybersecurity (ENISA). Cyber Resilience for the Financial Sector; ENISA: Athens, Greece, 2022. Available online: https://finance.ec.europa.eu/digital-finance/cyber-resilience_en (accessed on 15 January 2026).
- National Institute of Standards and Technology. Implementing a Zero Trust Architecture (NIST SP 1800-35); NIST: Gaithersburg, MD, USA, 2024. Available online: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-35.pdf (accessed on 18 January 2026).
- Alhidaifi, S.M.; Asghar, M.R.; Ansari, I.S. Cyber Resilience Quantification: A Probabilistic Estimation Model. Reliab. Eng. Syst. Saf. 2026, 265, 111473. [Google Scholar] [CrossRef]
- Mushtaq, S.; Kausar, F.; Khan, F.A. A Systematic Literature Review on the Implementation and Evaluation of Zero Trust Architecture. Sensors 2025, 25, 6118. [Google Scholar]
- MITRE Corporation. MITRE D3FEND®. Available online: https://d3fend.mitre.org (accessed on 20 January 2026).
- Podlesnik, L.; Bencic, F.M.; Sokolović, A.; Lukan, J. Integrating Cyber Threat Intelligence and Threat Modeling for Cyber Resilience: An AHP Assessment. PLoS ONE 2025, 20, e0335154. [Google Scholar]
- Moreira, F.R.; Filho, D.S.; da Silva Junior, F.J. Cybersecurity Risk Assessment Through Analytic Hierarchy Process: Integrating Multicriteria and Sensitivity Analysis. In Proceedings of the 27th International Conference on Enterprise Information Systems (ICEIS), Porto, Portugal, 4–6 April 2025; Volume 2, pp. 117–128. [Google Scholar]
- Almazroi, A.A.; Ayub, N. Prioritizing Cybersecurity Controls for SDG 3: An AHP-Based Impact–Feasibility Assessment Framework. Appl. Sci. 2025, 15, 10669. [Google Scholar]
- Roy, S.; Panaousis, E.; Noakes, C.; Laszka, A.; Panda, S.; Loukas, G. SoK: The MITRE ATT&CK Framework in Research and Practice. arXiv 2023, arXiv:2304.07411. [Google Scholar]
- Hussey, I.; Hughes, S. An Aberrant Abundance of Cronbach’s Alpha Values at 0.70. Adv. Methods Pract. Psychol. Sci. 2025, 8, 25152459241287123. [Google Scholar]
- Bolton, J.; Elluri, L.; Joshi, K.P. An Overview of Cybersecurity Knowledge Graphs Mapped to the MITRE ATT&CK Framework Domains. In Proceedings of the 2023 IEEE International Conference on Intelligence and Security Informatics (ISI), Charlotte, NC, USA, 2–3 October 2023; pp. 1–6. [Google Scholar]
- Sledjeski, C.; Donovan, S.; Tannehill, B.; Stevens, R. Stronger Together: Critical Infrastructure Resilience Through a Shared Operational Environment (MITRE Report PR-24-0206); The MITRE Corporation: McLean, VA, USA, 2024; Available online: https://www.mitre.org/sites/default/files/2024-02/PR-24-0206-critical-infrastructure-resilience-through-shared-operationa-environment.pdf (accessed on 18 January 2026).
- Hong, G.; Kim, S.; Lee, J. Establishment of a Benchmarking Tool for Evaluating the Operation of Biorepositories Using a Modified Delphi Method. Biosaf. Health 2024, 6, 199–205. [Google Scholar] [CrossRef] [PubMed]
- Jeldres, M.; Costa, S.; Salgado, V. A Review of Lawshe’s Method for Calculating Content Validity in the Social Sciences. Front. Educ. 2023, 8, 1271335. [Google Scholar]
- Zimmerman, C. Ten Strategies of a World-Class Cybersecurity Operations Center; The MITRE Corporation: McLean, VA, USA, 2022; Available online: https://www.mitre.org/sites/default/files/2022-04/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf (accessed on 18 January 2026).












| Aspect | NIST CSF [11] | ENISA Financial [12] | BoK Guideline [4] | D3-CREF |
|---|---|---|---|---|
| Governance coverage | High | High | High | High (inherited) |
| Quantitative metrics | Limited | Limited | Absent | Native (NRI, MTTD, MTTR, etc.) |
| Threat-informed (ATT&CK linkage) | Optional | Partial | Absent | Mandatory |
| Defensive ontology (D3FEND) | Absent | Absent | Absent | Native |
| Regulatory directness | Voluntary | EU-binding | KR-binding | Supplements KR-binding |
| Evaluation Item | Key Security Objective | D3FEND | Proposed Quantitative Metric | Measurement Method |
|---|---|---|---|---|
| Governance | Establish organization-level security responsibilities and management systems. | - | Documentation Update Rate; D3FEND Investment Ratio | Audit log of policy revisions; ratio of D3FEND-aligned security spending. |
| Identification | Systematically identify information assets and related risks. | - | Asset Identification/Classification Accuracy; Risk Assessment Cycle Compliance Rate | CMDB-vs-network-scan delta; on-time completion of vulnerability assessments. |
| Protection | Reduce attack surface. | Hardening | System Hardening Coverage; Patch Automation Rate | % of assets meeting CIS-style hardening; SLA-conformant patch propagation. |
| Protection | Early identification of anomalies and breaches. | Detection, Analytics | Breach Detection Accuracy (TPR); Mean Time To Detect (MTTD) | Empirical success rate of SIEM/EDR detections; alert-to-event timestamp delta. |
| Response & Recovery | Respond to incidents and ensure service continuity. | Response & Recovery, Isolation | Mean Time To Recover (MTTR); Incident Response Playbook Automation Rate | Time from incident to recovery; SOAR Evict playbook success rate. |
| Situational Awareness | Real-time understanding of threats and security posture. | Analytics | Threat Intelligence Integration Level; Security Dashboard Real-Time Performance | Utilization of external threat feeds; accuracy of real-time monitoring via Analytics. |
| Learning & Evolving | Adapt defenses post-incident. | All | Lesson-Learned Closure Rate | % of post-incident actions verified as deployed within 90 days. |
| Category | Existing Evaluation Items (Financial Sector) | D3FEND Group | Reconfigured Evaluation Items |
|---|---|---|---|
| Protection | Presence of information security policy and procedure documents | Hardening | Security hardening level of servers and network equipment; application of configuration-management automation tools. |
| Detection | Adoption and operation of an intrusion detection system | Detection, Analytics | Application rate and update status of SIEM/EDR detection rules; achievement of MTTD goals. |
| Response | Presence of an incident response team and emergency contact list | Response, Isolation | Operational success rate of SOAR-based automated response playbooks; Mean Time to Acknowledge (MTTA) for critical threats. |
| Recovery | Periodic review of backup and disaster recovery plans | Recovery, Restore | Achievement rate of Recovery Time Objective (RTO) and Recovery Point Objective (RPO); success rate of periodic automated restoration tests. |
| Situational Awareness | Procedures for collecting external threat intelligence and sharing it internally | Analytics, Information Sharing | Automation level of integration between Threat Intelligence Platform and firewalls/SIEM; speed of automated IoC propagation. |
| Category | Existing Guideline for Financial Institutions | Proposed D3FEND-Based Evaluation Framework | Improvement Effect |
|---|---|---|---|
| Evaluation Focus | Status of policy establishment, documentation, and procedure existence (qualitative) | Actual technology implementation level, operational integration, and automation level (technology-centric quantitative) | Enables evaluation of practical defensive capabilities and technological maturity |
| Evaluation Criteria | Abstract; allows for subjective judgment | Measurable quantitative metrics (MTTD, detection-rule application rate, automation success rate) | Provides objective and consistent evaluation criteria suitable for longitudinal benchmarking |
| Latest Threat Linkage | Limited linkage with modern threat frameworks | Systematic linkage based on ATT&CK and D3FEND, with CVE annotations | Enables evaluation of defensive capabilities against real-world attack scenarios |
| Composition | Number of Members | Significance of Selection |
|---|---|---|
| Elite Technical Expert Group (Korea’s Best of the Best, BoB Program) | 30 | This group performs the core role of verifying the technical completeness and future suitability of the proposed framework, based on expertise in the latest attack/defense technologies and emerging threat trends |
| Professional Information Security Consultant Group | 10 | This group conducts an objective evaluation based on a broad understanding of diverse corporate environments, contributing to external validity by verifying universality, industry-specific applicability, and strategic value |
| Large Enterprise Security Practitioner Group | 10 | This group verifies whether the framework is practically applicable under realistic constraints—operational processes, budget, personnel structure—assessing operational practicality, indicator feasibility, and acceptability among industry professionals |
| Evaluation Domain | Question Code | Mean | Std. Dev. | CVR | Δ (R2 → R3) |
|---|---|---|---|---|---|
| Suitability | S1 | 4.68 | 0.47 | 0.92 | +0.06 |
| Suitability | S2 | 4.62 | 0.49 | 0.88 | +0.04 |
| Completeness | C1 | 4.48 | 0.58 | 0.84 | +0.10 |
| Completeness | C2 | 4.56 | 0.50 | 0.88 | +0.08 |
| Practicality | P1 | 4.12 | 0.65 | 0.68 | +0.14 |
| Practicality | P2 | 4.42 | 0.50 | 0.80 | +0.10 |
| Differentiation | D1 | 4.70 | 0.46 | 0.92 | +0.04 |
| Differentiation | D2 | 4.64 | 0.48 | 0.92 | +0.06 |
| Evaluation Domain | Mean | Std. Dev. |
|---|---|---|
| Differentiation | 4.67 | 0.47 |
| Suitability | 4.65 | 0.48 |
| Completeness | 4.52 | 0.54 |
| Practicality | 4.27 | 0.58 |
| Indicator (ATT&CK) | A (Mature) | B (Medium) | C (Nominal) |
|---|---|---|---|
| Phishing block rate (T1566) | 0.96 | 0.78 | 0.41 |
| RAT detection rate (T1059) | 0.91 | 0.65 | 0.30 |
| MTTD for C2 traffic (T1071), (minutes) | 8 | 47 | 210 |
| DLP/decoy alert rate (T1041) | 0.94 | 0.70 | 0.25 |
| MTTR (hour) | 2.1 | 9.6 | 38 |
| Baseline BoK score (existing) | 92/100 | 92/100 | 92/100 |
| Proposed NRI (this work) | 0.83 | 0.44 | 0.09 |
| Framework | Output | ATT&CK | D3FEND | Regulatory Link |
|---|---|---|---|---|
| Cho et al. (2025) [7] | Availability AUC | Indirect | No | None |
| Alhidaifi et al. (2026) [14] | Probabilistic estimate | Optional | No | None |
| SOC-CMM | Ordinal 1–5 | Optional | No | Voluntary |
| ISADM [8] | Descriptive map | Mandatory | Native | None |
| D3-CREF (this work) | Continuous NRI [0, 1] | Mandatory | Native | BoK guideline |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Ahn, G.; Shin, D. A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics 2026, 15, 2554. https://doi.org/10.3390/electronics15122554
Ahn G, Shin D. A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics. 2026; 15(12):2554. https://doi.org/10.3390/electronics15122554
Chicago/Turabian StyleAhn, GwangHyun, and Dongkyoo Shin. 2026. "A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments" Electronics 15, no. 12: 2554. https://doi.org/10.3390/electronics15122554
APA StyleAhn, G., & Shin, D. (2026). A Technology-Centric Cyber Resilience Evaluation Framework Using MITRE D3FEND for Bridging the Policy Technology Gap in Financial and Enterprise Environments. Electronics, 15(12), 2554. https://doi.org/10.3390/electronics15122554

