Optimal Cyber Security Investment in a Mixed Risk Management Framework: Examining the Role of Cyber Insurance and Expenditure Analysis

被引:2
作者
Mazzoccoli, Alessandro [1 ]
机构
[1] Roma Tre Univ, Dept Econ, Via Silvio DAmico 77, I-00146 Rome, Italy
关键词
cyber insurance; breach probability function; cyber security; risk management; MODEL; MARKET; COSTS;
D O I
10.3390/risks11090154
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
Cyber security importance has escalated globally, driven by its pivotal role in shaping daily life, encompassing both personal and non-personal aspects. Cyber security breach probability functions play a crucial role in comprehending how cyber security investments affect vulnerability to cyber attacks. These functions employ mathematical models to guide decision making in cyber risk management. Thus, studying and improving them is useful in this context. In particular, using these models, this article explores the effectiveness of an integrated risk management strategy that merges insurance and security investments, aiming to minimize overall security expenses. Within this strategy, security investments contribute to reducing the insurance premium. This research investigates the optimal investment for this blended approach under total insurance coverage. When the integrated risk management strategy combining insurance and security investments is deemed the optimal choice, this paper reveals that the insurance premium tends to be the dominant component in the overall security expense in the majority of cases. This implies that the cost of insurance outweighs the cost of security investments.
引用
收藏
页数:14
相关论文
共 50 条
[21]   FlipIn: A Game-Theoretic Cyber Insurance Framework for Incentive-Compatible Cyber Risk Management of Internet of Things [J].
Zhang, Rui ;
Zhu, Quanyan .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 :2026-2041
[22]   An integrated cyber security risk management framework and risk predication for the critical infrastructure protection [J].
Kure, Halima Ibrahim ;
Islam, Shareeful ;
Mouratidis, Haralambos .
NEURAL COMPUTING & APPLICATIONS, 2022, 34 (18) :15241-15271
[23]   Information Chaos, Risk Management and Cyber Security [J].
Capek, Jan .
PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON STRATEGIC MANAGEMENT AND ITS SUPPORT BY INFORMATION SYSTEMS, 2015, :36-45
[24]   Risk Management Using Cyber-Threat Information Sharing and Cyber-Insurance [J].
Tosh, Deepak K. ;
Shetty, Sachin ;
Sengupta, Shamik ;
Kesan, Jay P. ;
Kamhoua, Charles A. .
GAME THEORY FOR NETWORKS (GAMENETS 2017), 2017, 212 :154-164
[25]   An integrated framework for innovation management in cyber security and privacy [J].
Security and Cloud Lab, Hewlett-Packard Laboratories, Long Down Avenue, Bristol ;
BS34 8QZ, United Kingdom .
Kapletia, Dharm (dharmendra.kapletia@hp.com), 1600, Springer Verlag (470) :135-147
[26]   Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance [J].
Mukhopadhyay, Arunabha ;
Chatterjee, Samir ;
Bagchi, Kallol K. ;
Kirs, Peteer J. ;
Shukla, Girja K. .
INFORMATION SYSTEMS FRONTIERS, 2019, 21 (05) :997-1018
[27]   Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance [J].
Arunabha Mukhopadhyay ;
Samir Chatterjee ;
Kallol K. Bagchi ;
Peteer J. Kirs ;
Girja K. Shukla .
Information Systems Frontiers, 2019, 21 :997-1018
[28]   ANALYSIS OF MATHEMATICAL MODELS OF INVESTMENT STRATEGIES IN THE UNIVERSITY ON CYBER SECURITY SYSTEMS [J].
Akhmetov, B. B. ;
Lakhno, V. A. ;
Adranova, A. B. ;
Kydyralina, L. M. ;
Pliska, L. D. .
BULLETIN OF THE NATIONAL ACADEMY OF SCIENCES OF THE REPUBLIC OF KAZAKHSTAN, 2020, (01) :128-139
[29]   Cyber Security Risk Management in the SCADA Critical Infrastructure Environment [J].
Henrie, Morgan .
ENGINEERING MANAGEMENT JOURNAL, 2013, 25 (02) :38-45
[30]   Designing Cyber Insurance Policies: The Role of Pre-Screening and Security Interdependence [J].
Khalili, Mohammad Mahdi ;
Naghizadeh, Parinaz ;
Liu, Mingyan .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (09) :2226-2239