Abstract
As the construction industry adopts digital technologies, cybersecurity risks are rising. However, the absence of a standardized incident reporting framework has resulted in limited disclosure of cybersecurity incidents and a lack of a centralized database. This prevents construction companies from learning from past events and developing effective cyber risk management strategies. To address this issue, this study applies the Cybersecurity Incident Severity Scale (CISS) model to assess the severity of cyber incidents within the construction sector. The CISS model uses a structured, semi-quantifiable approach to generate an integrated score, evaluating dimensions such as safety and financial impacts to provide a comprehensive understanding of an incident’s consequences. A real-world construction cyber incident serves as a case study to demonstrate the model’s applicability. By promoting standardized reporting, the CISS model can improve data collection, ensure consistent reporting across organizations, and enable meaningful comparisons over time and across regions.
Author supplied keywords
Cite
CITATION STYLE
Yao, D., Mantha, B. R. K., & de Soto, B. G. (2025). Implementation of the Cybersecurity Incident Severity Scale (CISS) to Assess Cyber Incidents in the Construction Sector. In Proceedings of the International Symposium on Automation and Robotics in Construction (pp. 657–664). International Association for Automation and Robotics in Construction (IAARC). https://doi.org/10.22260/ISARC2025/0086
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.