The dissertation was be defended at the public meeting of the Dissertation Defence Council of the Scientific Field of Economics in the SRA-I Hall of Vilnius Gediminas Technical University at 9 a.m. on 31 May 2024.
Cyber security is becoming one of the most critical issues for companies willing to empower their growth and business success by using online technologies. The development of online services has completely changed the ways and processes of financial services. The scientific problem formulated in the dissertation is the necessity to properly evaluate cyber security levels in financial institutions arising due to various sector-specific vulnerabilities. The dissertation’s research object is the assessment of cyber security in a financial institution. The goal of this dissertation is to create a comprehensive tool that would allow financial institutions to evaluate the cyber security level individually within the organisation. The following main tasks are resolved within the dissertation: (1) to investigate cyber risks and cyber-security features and importance, identify the main areas of cyber security with indicators representing each area’s most significant features, based on scientific literature analyses, (2) to establish a methodology for a tool that allows the cyber security assessment in a financial institution, (3) to develop a unique questionnaire matrix to conduct an internal assessment of a financial institution’s cyber security level based on the provided cyber security indicators, (4) to create a tool for the cyber security evaluation in financial institutions by proposing a composite cyber security index as a final result, (5) to assess cyber security in selected financial institutions to practically verify the proposed composite cyber security index. The dissertation consists of the following parts: (1) a scientific literature analysis on cyber risks and cyber security, general features, legal requirements, and cyber risk assessment presumptions. This part of the research is a significant theoretical background for the following steps. (2) A methodology for creating a composite cyber security index. (3) Final development of a composite cyber security index that consists of these main parts: 4 major areas of cyber security; 22 specific indicators within the areas; specific weight for each indicator; model of questionaries for individual evaluation of each indicator within the organisation. The proposed tool for evaluating cyber security in financial institutions – the composite cyber security index – is considered a comprehensive and effective method to assess cyber security levels, indicate weaknesses and vulnerabilities, and initiate adjustments and improvements in the organisation.