Journal of Information Technology and Cyber Security
Vol. 4 No. 1 (2026): January

A Data Driven Approach for Information Technology Risk Modelling and Visualization: Integrating ISO 31000 and Monte Carlo Simulation

Kumalasari, Rahmania (Unknown)
Setia, Lutfiyah Dwi (Unknown)
Septianto, Tri (Unknown)



Article Info

Publish Date
04 Feb 2026

Abstract

Information technology (IT) plays a critical role in enhancing organizational efficiency, accelerating decision-making, and strengthening competitiveness. However, as a core infrastructure, IT also introduces various risks that must be managed effectively to ensure business continuity. This study examines IT risk management at Company XYZ by integrating the ISO 31000 framework with the Monte Carlo Simulation method to quantify potential losses from 18 identified risk categories, including system failure, human error, cyberattacks, and natural disasters. To improve the interpretation and communication of risk outcomes, the research employs interactive data visualization using the Shiny dashboard (R). The simulation results show an average expected annual loss of IDR 478 million, with major risks originating from data corruption, backup failures, and cybercrime, while external factors such as earthquakes and fires also have significant impacts. This integrative approach demonstrates how ISO 31000, Monte Carlo Simulation, and interactive visualization can strengthen data-driven and transparent IT risk management for informed organizational decision-making. However, this study is limited to a single organizational case and simulated data assumptions, which may affect the generalizability of the findings.

Copyrights © 2026






Journal Info

Abbrev

jitsc

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management Electrical & Electronics Engineering

Description

Journal of Information Technology and Cyber Security (JITCS) is a refereed international journal whose focus is on exchanging information relating to Information Technology and Cyber Security in industry, government, and universities worldwide. The thrust of the journal is to publish papers dealing ...