Cybersecurity investments in supply chains with two-stage risk propagation

被引:0
作者
Dash, Aishwarya [1 ]
Sarmah, S. P. [1 ]
Tiwari, M. K. [1 ]
Jena, Sarat Kumar [2 ]
Glock, Christoph H. [3 ]
机构
[1] Indian Inst Technol Kharagpur, Ind & Syst Engn, Kharagpur, West Bengal, India
[2] XIM Univ, Xavier Inst Management, Operat Management, Bhubaneswar, India
[3] Tech Univ Darmstadt, Inst Prod & Supply Chain Management, Darmstadt, Germany
关键词
Supply chain management; Cyber-attacks; Cybersecurity investment; Cybersecurity insurance; Indirect risk propagation; Direct and indirect attacks; INFORMATION SECURITY INVESTMENT; GAME; IMPACT; INTERDEPENDENCY;
D O I
10.1016/j.cie.2024.110519
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cyber-attacks present a significant threat to supply chains as their nodes are directly or indirectly vulnerable to risk propagation at various stages. The risk level varies depending on the type of attack. A cybersecurity insurance offers a practical method to mitigate this risk, and it is crucial to determine optimal cybersecurity investments for all supply chain nodes. Previous studies have overlooked the joint impact of the attack type, two- stage risk propagation, and cybersecurity insurance in optimizing cybersecurity investments. This paper addresses this research gap by examining optimal investments under targeted and opportunistic attacks in a two- stage supply chain using game theory. The findings indicate that optimal investments differ based on the type of attack. For instance, retailers should invest more in cybersecurity under opportunistic attacks, while suppliers need to spend more under targeted attacks. Additionally, the results show that under opportunistic attacks, members should reduce their investments. Conversely, under targeted attacks, investments should initially increase and then stabilize. In the case of opportunistic attacks, suppliers and retailers should prioritize reconfiguring their systems over investing heavily in cybersecurity. The model presented in this paper demonstrates that not all cyber risks are worth defending against and that cybersecurity insurance for the entire supply chain can be more cost-effective than addressing cybersecurity risks individually. The paper also explores the impact of joint decisions on cybersecurity insurance when firms are unwilling to invest individually. The insights obtained enable supply chains to identify their optimal cybersecurity investment strategies effectively.
引用
收藏
页数:19
相关论文
共 50 条
  • [41] Coordination of a socially responsible two-stage supply chain under random yield and demand
    Zhao, Xia
    Dou, Jianping
    RAIRO-OPERATIONS RESEARCH, 2024, 58 (06) : 4971 - 4995
  • [42] Investigation of Impact of Revenue Sharing Contract on Performance of Two-Stage Supply Chain System
    Ryu, Chungsuk
    JOURNAL OF DISTRIBUTION SCIENCE, 2022, 20 (06): : 125 - 135
  • [43] A Two-Stage Sustainable Supplier Selection Model Considering Disruption Risk
    Lu, Jie
    Li, Feng
    Wu, Desheng
    SUSTAINABILITY, 2024, 16 (09)
  • [44] Circular economy-driven two-stage supply chain management for nullifying waste
    Sarkar, Biswajit
    Debnath, Abhijit
    Chiu, Anthony S. F.
    Ahmed, Waqas
    JOURNAL OF CLEANER PRODUCTION, 2022, 339
  • [45] Integrating production and transportation scheduling in a two-stage supply chain considering order assignment
    Seyed Hessameddin Zegordi
    Mohammad Ali Beheshti Nia
    The International Journal of Advanced Manufacturing Technology, 2009, 44 : 928 - 939
  • [46] Two-stage grey cloud clustering model for drought risk assessment
    Luo, Dang
    Zhang, Manman
    Zhang, Huihui
    GREY SYSTEMS-THEORY AND APPLICATION, 2019, 10 (01) : 68 - 84
  • [47] Water risk assessment in supply chains
    Schaefer, Torben
    Udenio, Maximiliano
    Quinn, Shannon
    Fransoo, Jan C.
    JOURNAL OF CLEANER PRODUCTION, 2019, 208 (636-648) : 636 - 648
  • [48] On risk management of a two-stage stochastic mixed 0-1 model for the closed-loop supply chain design problem
    Baptista, Susana
    Barbosa-Povoa, Ana Paula
    Escudero, Laureano E.
    Gomes, Maria Isabel
    Pizarro, Celeste
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2019, 274 (01) : 91 - 107
  • [49] Lot-Rolling - Supply Chain Negotiation in a Two-Stage Multi-echelon System
    Filzmoser, Michael
    OUTLOOKS AND INSIGHTS ON GROUP DECISION AND NEGOTIATION, GDN 2015, 2015, 218 : 395 - 401
  • [50] Two-stage supply chain study of deteriorating items considering the double effect for multimedia systems
    Liu, Min
    Zuo, Xiaode
    Lan, Xian-Gang
    Xu, Minghui
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (04) : 4655 - 4672