Robustness of Optimal Investment Decisions in Mixed Insurance/Investment Cyber Risk Management

被引:25
作者
Mazzoccoli, Alessandro [1 ]
Naldi, Maurizio [1 ,2 ]
机构
[1] Univ Roma Tor Vergata, Dept Civil Engn & Comp Sci, Rome, Italy
[2] LUMSA Univ, Dept Law Econ Polit & Modern Languages, Via Marcantonio Colonna 19, I-00192 Rome, Italy
关键词
Cybersecurity; Gordon-Loeb model; risk management; security economics; security investments; SECURITY INVESTMENT; INSURANCE;
D O I
10.1111/risa.13416
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
An integrated risk management strategy, combining insurance and security investments, where the latter contribute to reduce the insurance premium, is investigated to assess whether it can lead to reduced overall security expenses. The optimal investment for this mixed strategy is derived under three insurance policies, covering, respectively, all the losses (total coverage), just those below the limit of maximum liability (partial coverage), and those above a threshold but below the maximum liability (partial coverage with deductibles). Under certain conditions (e.g., low potential loss, or either very low or very high vulnerability), the mixed strategy reverts however to insurance alone, because investments do not provide an additional benefit. When the mixed strategy is the best choice, the dominant component in the overall security expenses is the insurance premium in most cases. Optimal investment decisions require an accurate estimate of the vulnerability, whereas larger estimation errors may be tolerated for the investment-effectiveness coefficient.
引用
收藏
页码:550 / 564
页数:15
相关论文
共 50 条