VLDB 2026 Research / reviewers in the wild / expert
Sergeja Slapnicar
dblp:315/6479
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0002-7228-7560ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The FABRICS framework: A Bayesian approach to financial quantification of cyber riskabstract• The study introduces a novel framework FABRICS - Fault tree And Bayesian Risk & Impact analysis for Cyber Security - that combines Bayesian fault tree models with business impact analysis to quantify cyber risk both in terms of likelihood and financial impact. • The framework employs a structured elicitation process to gather expert judgments from both cybersecurity and business experts. • The framework was applied in a real insurance company, involving over 20 experts across cybersecurity and business domains analyzing a data breach and operational downtime. • The framework supports executive-level reporting, return on investment calculation, cyber insurance negotiations, and capital adequacy assessments. This study presents a model for financially quantifying an organization's cyber risk by analysing scenarios in which critical business processes are compromised. Financial impact and likelihood of a cyber incident remain difficult to quantify due to several challenges: scarcity of reliable data, limited methods for effectively incorporating expert judgment in lieu of objective data, threat landscape uncertainty, and the inherently interrelated cyber risks that lead to incidents. To be meaningful and actionable, any cyber risk analysis must be tailored to the organization's specific characteristics. This includes identifying relevant threats, assessing the effectiveness of existing controls, and evaluating the financial value of affected processes. Our proposed framework addresses these requirements by evaluating threats and control failure probabilities, and financial impact of cyber scenarios, with particular emphasis on reputational costs—an aspect frequently overlooked in prior research. The novelty of our approach lies in the integration of several methods: a) Business Impact Analysis to identify the most relevant cyber scenarios and their associated losses, b) expert elicitation techniques to capture collective uncertainty regarding the likelihood and financial consequences of cyber incidents, and c) Bayesian Fault Tree Analysis combined with Monte Carlo simulations to estimate scenario probabilities. We refer to this integrated framework as FABRICS, Fault tree And Bayesian Risk & Impact analysis for Cyber Security, a novel framework that synthesizes structured risk modeling with expert-driven uncertainty assessment. We demonstrate its practical application through a real-world case study involving an insurance company. Sergeja Slapnicar, Chaitanya Joshi |
Comput. Secur. | 1 |
| 2025 | Contrasting the optimal resource allocation to cybersecurity controls and cyber insurance using prospect theory versus expected utility theoryabstractProtecting against cyber-threats is essential for every organization and can be achieved by investing in cybersecurity controls and purchasing cyber insurance. These two alternatives are interlinked, as insurance premiums can be reduced by investing more in cybersecurity controls. However, cyber insurance remains under-utilized, a puzzle that Expected Utility Theory (EUT) cannot explain. In this paper, we analyze how decision-makers allocate resources between cybersecurity controls and cyber insurance, comparing optimal allocation under Prospect Theory (PT) to that under EUT. We propose a new functional form of risk curves to model the relationship between investment in cybersecurity controls and cyber risk , demonstrating how a bespoke risk curve can be fitted for an organization. We derive the optimal allocation strategy of resources to cybersecurity controls and cyber insurance under EUT and PT paradigms. Using mathematical results and numerical examples, we identify specific behavioral considerations in PT that lead to different resource allocations compared to EUT. We show that decision-makers aligned with EUT are generally indifferent to purchasing insurance, whereas those aligned with PT favor full insurance coverage; otherwise, they invest more in self-protection. Our results indicate that, in addition to a challenging cybersecurity environment and the nature of insurance coverage, behavioral aspects (diminished sensitivity to losses and probability weights) play a key role in determining the optimal level of investment in cybersecurity. Chaitanya Joshi, Sergeja Slapnicar, Ryan Kok Leong Ko |
Comput. Secur. | 2 |
| 2022 | Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead
Megan Gale, Ivano Bongiovanni, Sergeja Slapnicar |
Comput. Secur. | 3 |