Note on Cyber Risk and Cyber Security

By Tuncer Ören, Professor Emeritus of Computer Science, University of Ottawa

As the Achilles heel of the digital era, the importance of cyber risk is increasing for industrialized countries [1]. A recent publication [2] at Forbes was titled, “If You Don’t Know Much about Cybersecurity, You’re Not Alone.” Amazingly, even some of the conferences on complex systems also do not consider cyber security as part of their themes [3, 4]. A situation, which will hopefully be changed soon. On the other hand, October is declared Cyber Security Awareness Month, in Canada [5] and in the USA [6].

Simulation-based approaches are gaining momentum for several disciplines [7] as well as in cyber security studies. Even cyber security modeling and simulation engineer jobs are already in demand [8].

At SIMULTECH’17 (The seventh International Conference on Simulation and Modeling Methodologies, Technologies and Applications) [9] two events were worth noting from cyber security point of view:

Dr. Jerry Couretas, the Editor-in-chief of JDMS (The Journal of Defense Modeling and Simulation: Applications, Methodology, Technology of SCS) was one of the invited speakers and his speech was titled: “Cyber Systems Risk – an Opportunity for Model Based Engineering & Design.”

His excellent presentation is available at the conference site [10]. (You may also be interested to the Special Issue of JDMS on “Cyber Modeling and Simulation (vol. 14, July 2017 issue, pp. 197-324) [11].)

The traditional opening panel of SIMULTECH’17 organized by Prof. Mohammad Obaidat was very pertinent to cyber security and was titled, “Challenges and Directions in Modeling and Simulation of Computer Networks and Systems.”

One of the good sources of books (both printed and pdf versions) is NAP (National Academic Press) [12]. Most of the publications of NAP on cyber security can be accessed from [13].

To assure high level of reliability of simulation studies of cyber security issues, in addition to traditional V&V and QA, one can also consider Failure Avoidance (FA) [14].

