@article{4792, author = {K. Kiruthika}, title = {Impact of Cybersecurity Controls on Attack Success, Financial Loss, and Incident Response: An Empirical Analysis Using Synthetic Enterprise Incident Data}, journal = {Journal of Information Security Research}, year = {2026}, volume = {17}, number = {3}, doi = {https://doi.org/10.6025/jisr/2026/17/3/113-137}, url = {https://www.dline.info/jisr/fulltext/v17n3/jisrv17n3_1.pdf}, abstract = {The rapid digital transformation of enterprises has expanded the cyber threat landscape, necessitating robust security strategies and predictive analytics to strengthen organizational resilience. This study presents an empirical analysis of enterprise cybersecurity incident data to evaluate the effectiveness of major technical, organizational, and governance controls in reducing cyber risk and improving operational response performance. Using the Cyber Attack Detection & Risk Prediction Dataset (AI Explorer, 2026) a synthetic dataset comprising over 100,000 enterprise level incidents with 50+ features we develop a multi task machine learning pipeline employing XGBoost, Random Forest, SVM, and statistical baselines across three core tasks: binary attack success classification, multi-class risk level prioritization (Low, Medium, High, Critical), and financial loss regression. Our results reveal a hierarchical efficacy among security controls. Multi-Factor Authentication (MFA) emerges as the most impactful preventive control, reducing attack success rates by approximately 28% (37.4%  26.8%) with a medium to large effect size (Cohen’s d = 0.68). Endpoint Detection and Response (EDR) demonstrates large operational effects (d >0.8), cutting detection time by ~46 minutes and response time by ~27 minutes. Security awareness training halves successful phishing click rates (40.95%  20.91%), while weak password policies significantly elevate attack success (34.70%) and financial losses ($82,395). Firewall deployment shows modest but statistically significant benefits in reducing financial loss and cyber risk scores. Organizations aligned with ISO 27001 exhibit the lowest attack success rates (26.74%) and incident costs ($64,672). The XGBoost model achieves superior performance across all tasks: AUC-ROC of 0.961 for attack success prediction, 82.1% accuracy for risk categorization, and R² of 0.867 with MAE of $14,892 for financial loss forecasting. These findings provide a data driven blueprint for strategic cybersecurity investments, demonstrating that identity centric controls, rapid detection and response capabilities, and governance frameworks collectively form the foundation of resilient enterprise security architectures. The study confirms the practical value of integrating multiple control features and machine learning analytics for proactive cyber defense, risk quantification, and evidence based security decision making.}, }