<?xml version="1.0" encoding="UTF-8"?>
<record>
  <title>Impact of Cybersecurity Controls on Attack Success, Financial Loss, and Incident Response: An Empirical Analysis Using Synthetic Enterprise Incident Data</title>
  <journal>Journal of Information Security Research</journal>
  <author>K. Kiruthika</author>
  <volume>17</volume>
  <issue>3</issue>
  <year>2026</year>
  <doi>https://doi.org/10.6025/jisr/2026/17/3/113-137</doi>
  <url>https://www.dline.info/jisr/fulltext/v17n3/jisrv17n3_1.pdf</url>
  <abstract>The rapid digital transformation of enterprises has expanded the cyber threat landscape, necessitating
robust security strategies and predictive analytics to strengthen organizational resilience. This study presents
an empirical analysis of enterprise cybersecurity incident data to evaluate the effectiveness of major technical,
organizational, and governance controls in reducing cyber risk and improving operational response
performance. Using the Cyber Attack Detection &amp; Risk Prediction Dataset (AI Explorer, 2026) a synthetic
dataset comprising over 100,000 enterprise level incidents with 50+ features we develop a multi task
machine learning pipeline employing XGBoost, Random Forest, SVM, and statistical baselines across three
core tasks: binary attack success classification, multi-class risk level prioritization (Low, Medium, High,
Critical), and financial loss regression.
Our results reveal a hierarchical efficacy among security controls. Multi-Factor Authentication (MFA)
emerges as the most impactful preventive control, reducing attack success rates by approximately 28%
(37.4% ï‚® 26.8%) with a medium to large effect size (Cohenâ€™s d = 0.68). Endpoint Detection and Response
(EDR) demonstrates large operational effects (d &gt;0.8), cutting detection time by ~46 minutes and response
time by ~27 minutes. Security awareness training halves successful phishing click rates (40.95% ï‚® 20.91%),
while weak password policies significantly elevate attack success (34.70%) and financial losses ($82,395).
Firewall deployment shows modest but statistically significant benefits in reducing financial loss and cyber
risk scores. Organizations aligned with ISO 27001 exhibit the lowest attack success rates (26.74%) and
incident costs ($64,672).
The XGBoost model achieves superior performance across all tasks: AUC-ROC of 0.961 for attack success
prediction, 82.1% accuracy for risk categorization, and RÂ² of 0.867 with MAE of $14,892 for financial loss
forecasting. These findings provide a data driven blueprint for strategic cybersecurity investments,
demonstrating that identity centric controls, rapid detection and response capabilities, and governance
frameworks collectively form the foundation of resilient enterprise security architectures. The study confirms
the practical value of integrating multiple control features and machine learning analytics for proactive
cyber defense, risk quantification, and evidence based security decision making.</abstract>
</record>
