CyberICT : a hybrid evaluation framework for products and supply chain services
CyberICT : υβριδικό πλαίσιο αξιολόγησης κυβερνοασφάλειας προϊόντων και υπηρεσιών εφοδιαστικών αλυσίδων ΤΠΕ
Doctoral Thesis
Author
Kalogeraki, Eleni Maria
Καλογεράκη, Ελένη Μαρία
Date
2026-07Advisor
Polemi, DespinaΠολέμη, Δέσποινα
View/ Open
Keywords
CyberICT hybrid evaluation framework ; Cybersecurity risk management of ICT products and supply chain services ; Risk and conformity assessment of composite ICT products ; ICT Protection Profile ; Attack Simulation and Evidence Chain Generation model ; Cybersecurity standards ontology ; Maritime and logistics supply chain ; Risk ontology ; Yβριδικό πλαίσιο αξιολόγησης κυβερνοασφάλειας ; Διαχείριση κινδύνων προϊόντων και υπηρεσιών εφοδιαστικών αλυσίδων ΤΠΕ ; Αξιολόγηση κινδύνων και συμμόρφωσης σύνθετων προϊόντων ΤΠΕ ; Προφίλ Προστασίας ΤΠΕ ; Μοντέλο Προσομοίωσης Επίθεσης και Δημιουργίας Αλυσίδας Πειστηρίων ; Οντολογία προτύπων τυποποίησης κυβερνοασφάλειας ; Ναυτιλιακή και εφοδιαστική αλυσίδα μεταφορών ; Οντολογία κινδύνουAbstract
The growing digitalisation has made ICT product and supply chain security a regulatory priority, yet the EU's Cyber Resilience Act, Cybersecurity Act, and NIS 2 Directive lack harmonised risk and conformity assessment guidance, which is compounded by fragmented standards, complex composite products, and shallow risk methods for large-scale supply chains.
This dissertation proposes the CyberICT hybrid evaluation framework integrating cybersecurity risk management and conformity assessment into a unified framework for composite ICT products and their supply chains. Built via Design Science Research, the hybrid evaluation framework comprises a risk management methodology and a relevant risk ontology; a Protection Profile preparatory framework with an accompanying taxonomy; and a cybersecurity standards ontology.
The CyberICT Risk Management Methodology estimates vulnerabilities, threats, and risks and their impact and explores corresponding cascading effects across complex, heterogeneous environments of composite ICT products (software, firmware, and hardware) and their supply chain services.
It supports diverse evaluation perspectives for supply chain environments of business, holistic-technical, and sectoral, using techniques such as process modelling, cyberdependency mapping, criticality identification of products and supply chain services, and estimates vulnerability and impact through a weighted exploitability scoring model. Moreover, it provides an Attack Simulation and Evidence Chain Generation (ASECG) model
that delivers credible attack paths based on real evidence that illustrate the attacker’s course inside the ICT network.
The CyberICT Protection Profile provides a stepwise method and a corresponding taxonomy for preparing Protection Profiles of composite ICT products and assessing their security claims under the Common Criteria-based EUCC scheme. The taxonomy maps threat categories with security objectives, requirements, and controls for measurable assurance.
Together, these artefacts support certification readiness under the Cybersecurity Act, compliance pathways under the Cyber Resilience Act, and supply chain resilience under the NIS 2 Directive. Two developed ontologies related to risks and cybersecurity standards further support organisational learning and knowledge sharing through machine-readable representations using a widely known knowledge management framework and Semantic Web techniques.
The CyberICT hybrid evaluation framework was validated against real Maritime and Logistics Supply Chain real-life scenarios and implemented across various digital security management and certification platforms within the context of European projects. The developed ontologies were verified via reasoning mechanisms. The evaluation outcomes confirm the framework’s applicability, consistency, and utility for securing composite ICT products and supply chains under the existing EU legal framework.


