How cyber insurance influences the ransomware payment decision: theory and evidence

被引:5
|
作者
Cartwright, Anna [1 ]
Cartwright, Edward [2 ]
MacColl, Jamie [3 ]
Mott, Gareth [4 ]
Turner, Sarah [5 ]
Sullivan, James [3 ]
Nurse, Jason R. C. [5 ]
机构
[1] Oxford Brookes Univ, Oxford Brookes Business Sch, Oxford, England
[2] De Montfort Univ, Dept Accounting Finance & Econ, Leicester, England
[3] Royal United Serv Inst, London, England
[4] Univ Kent, Sch Polit & Int Relat, Canterbury, England
[5] Univ Kent, Sch Comp, Canterbury, England
关键词
Ransomware; Insurance; Cybersecurity; Double extortion; Moral hazard; Negotiation;
D O I
10.1057/s41288-023-00288-8
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
In this paper, we analyse how cyber insurance influences the cost-benefit decision-making process of a ransomware victim. Specifically, we ask whether organisations with cyber insurance are more likely to pay a ransom than non-insureds. We propose a game-theoretic framework with which to categorise and distinguish different channels through which insurance may influence victim decision making. This allows us to identify ways in which insurance may incentivise or disincentivise payment of the ransom. Our framework is informed by data from semi-structured interviews with 65 professionals with expertise in cyber insurance, cybersecurity and/or ransomware, as well as data from the U.K. Cyber Security Breaches Survey. We find that perceptions are divided on whether victims with insurance are more (or less) likely to pay a ransom. Our model can reconcile these views once we take into account context specifics, such as the severity of the attack as measured by business interruption and restoration and/or the exfiltration of sensitive data.
引用
收藏
页码:300 / 331
页数:32
相关论文
共 50 条
  • [21] Externalities in Payment Card Networks: Theory and Evidence
    Chakravorti, Sujit
    REVIEW OF NETWORK ECONOMICS, 2010, 9 (02):
  • [22] Towards a Managerial Decision Framework for Utilization of Cyber Insurance Instruments in IT security
    Bandyopadhyay, Tridib
    Shidore, Snehal
    AMCIS 2011 PROCEEDINGS, 2011,
  • [23] How crop insurance influences agricultural green total factor productivity: Evidence from Chinese farmers
    Fang, Lan
    Hu, Rong
    Mao, Hui
    Chen, Shaojian
    JOURNAL OF CLEANER PRODUCTION, 2021, 321
  • [24] Data Breach, Privacy, and Cyber Insurance: How Insurance Companies Act as "Compliance Managers" for Businesses
    Talesh, Shauhin A.
    LAW AND SOCIAL INQUIRY-JOURNAL OF THE AMERICAN BAR FOUNDATION, 2018, 43 (02): : 417 - 440
  • [25] Ransomware: How attacker's effort, victim characteristics and context influence ransom requested, payment and financial loss
    Meurs, Tom
    Junger, Marianne
    Tews, Erik
    Abhishta, Abhishta
    2022 APWG SYMPOSIUM ON ELECTRONIC CRIME RESEARCH, ECRIME, 2022,
  • [26] Partnerships as insurance devices: Theory and evidence
    Lang, K
    Gordon, PJ
    RAND JOURNAL OF ECONOMICS, 1995, 26 (04): : 614 - 629
  • [27] EVIDENCE THEORY FOR CYBER-PHYSICAL SYSTEMS
    Santini, Riccardo
    Foglietta, Chiara
    Panzieri, Stefano
    CRITICAL INFRASTRUCTURE PROTECTION VIII, 2014, 441 : 95 - 109
  • [28] Evidence theory for cyber-physical systems
    Santini, Riccardo
    Foglietta, Chiara
    Panzieri, Stefano
    IFIP Advances in Information and Communication Technology, 2014, 441 : 95 - 109
  • [29] How cyber insurance can still leave you vulnerable to risks
    Stephens S.
    Computer Fraud and Security, 2020, 2020 (02): : 12 - 14
  • [30] How Expert Advice Influences Decision Making
    Meshi, Dar
    Biele, Guido
    Korn, Christoph W.
    Heekeren, Hauke R.
    PLOS ONE, 2012, 7 (11):