The threat assessment process in identifying cybersecurity risks
The article is devoted to the topical issue of analyzing and improving the methods and means of protecting a company's network infrastructure. A company's network contains all the important information that affects the continuity of the company's operations. That is why it is necessary to take a comprehensive approach to its protection. The focus is on building a technological chain for identifying network security risks. The study is based on a thorough analysis of modern literature and information resources, materials from leading companies providing network equipment and network configuration services. The main stages of the technological chain of risk identification are considered, including asset identification, threat assessment, vulnerability detection, consequence and probability assessment, development of risk minimization strategies, as well as monitoring, analysis, and improvement of security measures. The analysis made it possible to identify key aspects that affect the effectiveness of risk management and offer recommendations for improving network security. The process of assessing network security risks, which is critical to ensuring the security of the company's information systems, is also discussed in detail. The key stages of this process are described, starting with identifying assets and threats and ending with developing and implementing risk minimization strategies. The analysis demonstrated the importance of a systematic approach to risk management, including continuous monitoring, adaptation, and improvement of security measures. The findings are important for further developing strategies to protect and secure the company's network infrastructure and are the basis for further research in this area. Key words: cybersecurity; network security; technological chain for determining network security risks; threat assessment process; risk analysis methods; risk acceptance/avoidance table.