Machine learning-based validation of an integrated cybersecurity risk framework for supply chain auditing
摘要
The rapid digitalization and interconnectivity of global supply chains have significantly increased exposure to cybersecurity risks, particularly through third-party dependencies, IoT integration, remote access, and shared digital infrastructures. Traditional supply chain auditing approaches, which rely heavily on periodic compliance checks and retrospective assessments, are increasingly insufficient for identifying dynamic and systemic cyber risks. This study proposes an integrated machine learning-based cybersecurity risk framework for supply chain auditing and examines how ML models capture multidimensional and time-related cybersecurity risk indicators. A quantitative experimental design was adopted using a hybrid dataset that combines empirically grounded cybersecurity indicators with simulated supply chain cyber risk scenarios. The synthetic data were generated through controlled attack scenarios using AttackIQ and Cymulate simulation platforms and were conceptually aligned with the NIST Cybersecurity Framework, ENISA guidelines, and the Verizon DBIR. IBM Watsonx was used to develop and evaluate supervised and time-series models, including Random Forest and ARIMA. The integrated risk flag was constructed as a composite cybersecurity risk representation derived from standardized audit-relevant indicators. The findings show that the integrated ML-based risk framework achieved strong classification performance, with accuracy = 98.5% and F1 > 0.98. The results primarily reflect the internal consistency of the constructed cybersecurity risk framework rather than direct prediction of real-world cyber incidents. Sensitivity analyses confirmed the robustness of the framework under different synthetic data conditions. Random Forest effectively captured complex nonlinear risk patterns, while ARIMA modeled temporally persistent risk indicators. In contrast, compliance metrics showed limited ability to reflect actual cybersecurity risk exposure.