Cyber insurance risk analysis framework considerations

被引:0
|
作者
Rangu, Calin Mihail [1 ]
Badea, Leonardo [2 ]
Scheau, Mircea Constantin [3 ,4 ]
Gabudeanu, Larisa [5 ]
Panait, Iulian [6 ]
Radu, Valentin [7 ]
机构
[1] Danubius Univ, Business Adm & Econ Sci Fac, Galati, Romania
[2] Bucharest Univ Econ Studies, Bucharest, Romania
[3] Babes Bolyai Univ, European Res Inst, Cluj Napoca, Romania
[4] Univ Craiova, Fac Automat Comp & Elect, Craiova, Romania
[5] Babes Bolyai Univ, Fac Law, Cluj Napoca, Romania
[6] Hyper Univ, Bucharest, Romania
[7] Valahia Univ Targoviste, Fac Econ, Targoviste, Romania
关键词
Cyber security; Cyber insurance; Risk analysis; Information system; Insurance policy;
D O I
10.1108/JRF-10-2023-0245
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
PurposeIn recent years, the frequency and severity of cybersecurity incidents have prompted customers to seek out specialized insurance products. However, this has also presented insurers with operational challenges and increased costs. The assessment of risks for health systems and cyber-physical systems (CPS) necessitates a heightened degree of attention. The significant values of potential damages and claims request a solid insurance system, part of cyber-resilience. This research paper focuses on the emerging cyber insurance market that is currently in the process of standardizing and improving its risk analysis concerning the potential insured entity.Design/methodology/approachThe authors' approach involves a quantitative analysis utilizing a Likert-style questionnaire designed to survey cyber insurance professionals. The authors' aim is to identify the current methods used in gathering information from potential clients, as well as the manner in which this information is analyzed by the insurers. Additionally, the authors gather insights on potential improvements that could be made to this process.FindingsThe study the authors elaborated it has a particularly important cyber and risk components for insurance area, because it addresses a "niche" area not yet proper addressed in specialized literature - cyber insurance. Cyber risk management approaches are not uniform at the international level, nor at the insurer level. Also, not all insurers can perform solid assessments, especially since their companies should first prove that they are fully compliant with international cyber security standards.Research limitations/implicationsThis research has concentrated on analyzing the current practices in terms of gathering information about the insured entity before issuing the cyber insurance policy, level of details concerning the cyber security posture of the insured entity and way such information should be analyzed in a standardized and useful manner. The novelty of this research resides in the analysis performed as detailed above and the proposals in terms of information gathered, depth of analysis and standardization of approach made. Future work on the topic can focus on the standardization process for analyzing cyber risk for insurance clients, to improve the proposal based also on historical elements and trends in the market. Thus, future research can further refine the standardization process to analyze in more depth the way this can be implemented and included in relevant legislation at the EU level.Practical implicationsProposed improvements include proposals in terms of the level of detail and the usefulness of an independent centralized approach for information gathering and analysis, especially given the re-insurance and brokerage activities. The authors also propose a common practical procedural approach in risk management, with the involvement of insurance companies and certification institutions of cyber security auditors.Originality/valueThe study investigates the information gathered by insurers from potential clients of cyber insurance and the way this is analyzed and updated for issuance of the insurance policy.
引用
收藏
页码:224 / 252
页数:29
相关论文
共 50 条
  • [1] A framework for using insurance for cyber-risk management
    Gordon, LA
    Loeb, MP
    Sohail, T
    [J]. COMMUNICATIONS OF THE ACM, 2003, 46 (03) : 81 - 85
  • [3] A framework for incorporating insurance in critical infrastructure cyber risk strategies
    Young, Derek
    Lopez, Juan, Jr.
    Rice, Mason
    Ramsey, Benjamin
    McTasney, Robert
    [J]. INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2016, 14 : 43 - 57
  • [4] Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance
    Mukhopadhyay, Arunabha
    Chatterjee, Samir
    Bagchi, Kallol K.
    Kirs, Peteer J.
    Shukla, Girja K.
    [J]. INFORMATION SYSTEMS FRONTIERS, 2019, 21 (05) : 997 - 1018
  • [5] Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance
    Arunabha Mukhopadhyay
    Samir Chatterjee
    Kallol K. Bagchi
    Peteer J. Kirs
    Girja K. Shukla
    [J]. Information Systems Frontiers, 2019, 21 : 997 - 1018
  • [6] Some Risk Analysis Problems in Cyber Insurance Economics
    Rios Insua, David
    Couce-Vieira, Aitor
    Musaraj, Kreshnik
    [J]. ESTUDIOS DE ECONOMIA APLICADA, 2018, 36 (01): : 181 - 194
  • [7] New advances on cyber risk and cyber insurance
    Boyer, Martin
    Eling, Martin
    [J]. GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2023, 48 (02): : 267 - 274
  • [8] New advances on cyber risk and cyber insurance
    Martin Boyer
    Martin Eling
    [J]. The Geneva Papers on Risk and Insurance - Issues and Practice, 2023, 48 : 267 - 274
  • [9] Challenges in Cyber Risk Insurance
    Pirra, Marco
    [J]. MATHEMATICAL AND STATISTICAL METHODS FOR ACTUARIAL SCIENCES AND FINANCE, MAF2024, 2024, : 261 - 266
  • [10] A Bonus-Malus framework for cyber risk insurance and optimal cybersecurity provisioning
    Xiang, Qikun
    Neufeld, Ariel
    Peters, Gareth W.
    Nevat, Ido
    Datta, Anwitaman
    [J]. EUROPEAN ACTUARIAL JOURNAL, 2024, 14 (02) : 581 - 621