Pricing cyber-insurance for systems via maturity models

02/09/2023
by   Henry Skeoch, et al.
0

Risks associated with information technology systems present a complex modelling challenge, combining the disciplines of operations management, security, and economics. The challenge is to establish a representation of an organization's operational and systems architecture that allows an assessment of the security postures of its various components able to support an assessment of its insurance risk. This work proposes a socioeconomic model for cyber-insurance decisions compromised of entity relationship diagrams, security maturity models, and economic models, thereby linking systems-type and economic approaches to cyber-security assessments. The concept of a cyber-loss-adjuster is introduced, who reconciles cyber-incidents with economic losses. The work aims to bridge a number of disciplines to partly address a longstanding research challenge of accounting for organizational structure in the design and pricing of cyber-insurance. It is important to note the following: insurance companies have long experience of the magnitude and frequency of losses that arise in organizations based on their size, industry sector, and location. Consequently, their calculations of premia will start from a baseline determined by these considerations. The contribution of the methodology proposed here is to provide a framework for calculating the effects of cyber-based risk on the frequency and magnitude of losses. This is achieved through a security analysis of the relationship between the operational structure of an organization and its information systems. It also provides a consistent means for those seeking insurance to describe and understand their security posture and for an insurance company to price its offer of coverage.

READ FULL TEXT

page 12

page 15

page 20

page 22

research
03/08/2022

Guidelines for cyber risk management in shipboard operational technology systems

Over the past few years, we have seen several cyber incidents being repo...
research
05/15/2022

Mod2Dash: A Framework for Model-Driven Dashboards Generation

The construction of an interactive dashboard involves deciding on what i...
research
04/20/2019

Economic Analyses of Security Investments on Cryptocurrency Exchanges

Cryptocurrency exchanges are frequently targeted and compromised by cybe...
research
06/29/2020

Pricing cyber insurance for a large-scale network

Facing the lack of cyber insurance loss data, we propose an innovative a...
research
06/23/2022

MAGIC: A Method for Assessing Cyber Incidents Occurrence

The assessment of cyber risk plays a crucial role for cybersecurity mana...
research
01/14/2019

Statistical Models for the Number of Successful Cyber Intrusions

We propose several generalized linear models (GLMs) to predict the numbe...
research
07/08/2021

Cyber Crossroads: A Global Research Collaborative on Cyber Risk Governance

Spending on cybersecurity products and services is expected to top 123 b...

Please sign up or login with your details

Forgot password? Click here to reset