Cybersecurity investments in supply chains with two-stage risk propagation

被引:0
|
作者
Dash, Aishwarya [1 ]
Sarmah, S. P. [1 ]
Tiwari, M. K. [1 ]
Jena, Sarat Kumar [2 ]
Glock, Christoph H. [3 ]
机构
[1] Indian Inst Technol Kharagpur, Ind & Syst Engn, Kharagpur, West Bengal, India
[2] XIM Univ, Xavier Inst Management, Operat Management, Bhubaneswar, India
[3] Tech Univ Darmstadt, Inst Prod & Supply Chain Management, Darmstadt, Germany
关键词
Supply chain management; Cyber-attacks; Cybersecurity investment; Cybersecurity insurance; Indirect risk propagation; Direct and indirect attacks; INFORMATION SECURITY INVESTMENT; GAME; IMPACT; INTERDEPENDENCY;
D O I
10.1016/j.cie.2024.110519
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cyber-attacks present a significant threat to supply chains as their nodes are directly or indirectly vulnerable to risk propagation at various stages. The risk level varies depending on the type of attack. A cybersecurity insurance offers a practical method to mitigate this risk, and it is crucial to determine optimal cybersecurity investments for all supply chain nodes. Previous studies have overlooked the joint impact of the attack type, two- stage risk propagation, and cybersecurity insurance in optimizing cybersecurity investments. This paper addresses this research gap by examining optimal investments under targeted and opportunistic attacks in a two- stage supply chain using game theory. The findings indicate that optimal investments differ based on the type of attack. For instance, retailers should invest more in cybersecurity under opportunistic attacks, while suppliers need to spend more under targeted attacks. Additionally, the results show that under opportunistic attacks, members should reduce their investments. Conversely, under targeted attacks, investments should initially increase and then stabilize. In the case of opportunistic attacks, suppliers and retailers should prioritize reconfiguring their systems over investing heavily in cybersecurity. The model presented in this paper demonstrates that not all cyber risks are worth defending against and that cybersecurity insurance for the entire supply chain can be more cost-effective than addressing cybersecurity risks individually. The paper also explores the impact of joint decisions on cybersecurity insurance when firms are unwilling to invest individually. The insights obtained enable supply chains to identify their optimal cybersecurity investment strategies effectively.
引用
收藏
页数:19
相关论文
共 50 条
  • [21] Evaluating sustainability of supply chains by two-stage range directional measure in the presence of negative data
    Izadikhah, Mohammad
    Saen, Reza Farzipoor
    TRANSPORTATION RESEARCH PART D-TRANSPORT AND ENVIRONMENT, 2016, 49 : 110 - 126
  • [22] Speculation in a two-stage retail supply chain
    Feng, Tianke
    Geunes, Joseph
    IIE TRANSACTIONS, 2014, 46 (12) : 1315 - 1328
  • [23] Risk propagation through payment distortion in supply chains
    Serrano, Alejandro
    Oliva, Rogelio
    Kraiselburd, Santiago
    JOURNAL OF OPERATIONS MANAGEMENT, 2018, 58-59 : 1 - 14
  • [24] Cybersecurity investments in the supply chain: Coordination and a strategic attacker
    Simon, Jay
    Omar, Ayman
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2020, 282 (01) : 161 - 171
  • [25] A two-stage stochastic programming approach for identifying optimal postponement strategies in supply chains with uncertain demand
    Weskamp, Christoph
    Koberstein, Achim
    Schwartz, Frank
    Suhl, Leena
    Voss, Stefan
    OMEGA-INTERNATIONAL JOURNAL OF MANAGEMENT SCIENCE, 2019, 83 : 123 - 138
  • [26] A two-stage data envelopment analysis model for measuring performance in three-level supply chains
    Tavana, Madjid
    Kaviani, Mohamad Amin
    Di Caprio, Debora
    Rahpeyma, Bentolhoda
    MEASUREMENT, 2016, 78 : 322 - 333
  • [27] Risk performance of two-stage dynamic supply chain under multi-uncertainty
    Ma, Jian-Hua
    Ai, Xing-Zheng
    Tang, Xiao-Wo
    Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2012, 32 (06): : 1222 - 1231
  • [28] A New Two-Stage Fuzzy Decision Making Model in Supply Chain Risk Management
    Berenji, Hossein Rikhtehgar
    Anantharaman, R. N.
    Karegar, Mojtaba
    INNOVATION, MANAGEMENT AND SERVICE, ICMS 2011, 2011, 14 : 44 - 49
  • [29] Risk-Averse Suppliers' Optimal Pricing Strategies in a Two-Stage Supply Chain
    Shen, Rui
    Meng, Zhiqing
    Xu, Xinsheng
    Jiang, Min
    DISCRETE DYNAMICS IN NATURE AND SOCIETY, 2013, 2013
  • [30] Report: Supply Chains Present Cybersecurity Risks
    Koenig, Bill
    MANUFACTURING ENGINEERING, 2020, 165 (12): : 15 - 16