A people network detection unit (110) detects a people network indicating the connections between a target and a responsible persons group on the basis of public information about the target. A disclosure risk calculation unit (120) calculates the disclosure risk of the target on the basis of the public information about the target, and, on the basis of a public information group corresponding to the responsible persons group, calculates a disclosure risk group corresponding to said responsible persons group. On the basis of the disclosure risk group corresponding to the responsible persons group, a connection risk determination unit (130) determines a representative value of the disclosure risk group as the connection risk of the target. A security risk calculation unit (140) uses the disclosure risk of the target and the connection risk of the target to calculate a security risk of the target for cyber-attacks.
展开▼