Industry sector matters: mapping industry-specific cyber vulnerabilities through rational choice theory analysis

Sandeep Suntwal et al.

Information and Computer Security2026https://doi.org/10.1108/ics-06-2025-0204article
AJG 1ABDC B
Weight
0.50

Abstract

Purpose This study applies rational choice theory (RCT) to understand how cyber attackers strategically select targets and attack vectors for data breaches. The purpose of the study is to demonstrate how complex, contextual risk-reward calculations influence attackers’ decisions, providing a foundation for aligning cybersecurity measures with sector-specific risks in an increasingly digital landscape. Design/methodology/approach The authors analyzed 631 global breach incidents from 2010 to 2023 across various industry sectors using logistic regression. The authors found sector-specific vulnerabilities and highlight the nonuniform nature of cyber risk. Findings The study analysis reveals that financial sector organizations face heightened risks from misconfiguration attacks despite sophisticated defenses, while operational technology sectors show elevated phishing attacks at the sector level. These findings indicate that cyber risks are not uniform across industry sectors and require tailored defensive strategies. The findings map directly to MITRE ATT&CK techniques, providing actionable defensive strategies aligned with industry-standard frameworks. The results inform RCT-based theoretical implications and offer practical insights aligned with the MITRE ATT&CK frameworks. Originality/value The findings suggest that more nuanced vulnerability patterns may require sector-specific cybersecurity strategies. The results inform RCT-based theoretical implications and offer practical insights aligned with the MITRE ATT&CK frameworks. By demonstrating how complex, contextual risk-reward calculations influence attackers’ decisions, this research provides a foundation for aligning cybersecurity measures with sector-specific risks in an increasingly digital landscape.

Open via your library →

Cite this paper

https://doi.org/https://doi.org/10.1108/ics-06-2025-0204

Or copy a formatted citation

@article{sandeep2026,
  title        = {{Industry sector matters: mapping industry-specific cyber vulnerabilities through rational choice theory analysis}},
  author       = {Sandeep Suntwal et al.},
  journal      = {Information and Computer Security},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1108/ics-06-2025-0204},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Industry sector matters: mapping industry-specific cyber vulnerabilities through rational choice theory analysis

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.