Towards a Reconceptualisation of Cyber Risk: An Empirical and Ontological Study

06/21/2018
by   Alessandro Oltramari, et al.
0

The prominence and use of the concept of cyber risk has been rising in recent years. This paper presents empirical investigations focused on two important and distinct groups within the broad community of cyber-defense professionals and researchers: (1) cyber practitioners and (2) developers of cyber ontologies. The key finding of this work is that the ways the concept of cyber risk is treated by practitioners of cybersecurity is largely inconsistent with definitions of cyber risk commonly offered in the literature. Contrary to commonly cited definitions of cyber risk, concepts such as the likelihood of an event and the extent of its impact are not used by cybersecurity practitioners. This is also the case for use of these concepts in the current generation of cybersecurity ontologies. Instead, terms and concepts reflective of the adversarial nature of cyber defense appear to take the most prominent roles. This research offers the first quantitative empirical evidence that rejection of traditional concepts of cyber risk by cybersecurity professionals is indeed observed in real-world practice.

READ FULL TEXT
research
08/11/2020

The Data that Drives Cyber Insurance: A Study into the Underwriting and Claims Processes

Cyber insurance is a key component in risk management, intended to trans...
research
05/15/2022

Mod2Dash: A Framework for Model-Driven Dashboards Generation

The construction of an interactive dashboard involves deciding on what i...
research
03/11/2019

Standardisation of cyber risk impact assessment for the Internet of Things (IoT)

In this research article, we explore the use of a design process for ada...
research
06/23/2022

MAGIC: A Method for Assessing Cyber Incidents Occurrence

The assessment of cyber risk plays a crucial role for cybersecurity mana...
research
10/04/2021

Realizing Forward Defense in the Cyber Domain

With the recognition of cyberspace as an operating domain, concerted eff...
research
10/27/2022

Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment

This paper provides the first large-scale data-driven analysis to evalua...

Please sign up or login with your details

Forgot password? Click here to reset