Electronic Thesis/Dissertation
 

Enterprise Architecture Threat Modeling for Cybersecurity Risk Management

Open Access Deposited

Organizations rely heavily on and invest substantial resources in cybersecurity capabilities, yet enterprise architectures often exhibit gaps, redundancies, and misalignment with the threats they are intended to defend against. While threat modeling methodologies exist to characterize adversary behavior, they are rarely integrated into the decision-making process for cybersecurity capability investments. As a result, decision-makers often rely on regulatory and industry compliance requirements, vendor-driven signals, and peer adoption patterns rather than empirically observed adversary behavior. This research examines how threat-modeled cybersecurity capability coverage aligns with real-world deployments and practitioners' perceptions of that coverage. A threat-informed baseline was established using the Cybersecurity Architecture Review threat modeling methodology, aligned with the MITRE ATT&CK framework. Protect, detect, and respond coverage for 12 commonly deployed cybersecurity capability categories was quantified, normalized, and aggregated into a tactic-level baseline. The modeled baselines were compared with survey-based assessments of deployed capabilities, perceived coverage, and decision-making drivers collected from cybersecurity professionals across roles, sectors, and organizational contexts. The results show a persistent, statistically significant divergence between perceived and threat-modeled coverage, with practitioners systematically overestimating defensive effectiveness across all adversary tactics. This optimism bias persists across experience levels, professional roles, and industry sectors. Additional findings indicate limited reliance on formal threat modeling during capability selection and substantial overlap in deployed capability portfolios, suggesting inefficient allocation of defensive resources. By integrating threat-informed architectural analysis with empirical perception data, this research offers a repeatable method for assessing the alignment of enterprise cybersecurity capabilities and underscores the need to more explicitly incorporate adversary behavior into cybersecurity governance and investment decision-making.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Bokan_gwu_0075A_17765.pdf File 2026-06-24 Embargo