A framework for incorporating insurance in critical infrastructure cyber risk strategies

被引:41
|
作者
Young, Derek [1 ]
Lopez, Juan, Jr. [2 ]
Rice, Mason [1 ]
Ramsey, Benjamin [1 ]
McTasney, Robert [3 ]
机构
[1] Air Force Inst Technol, Dept Elect & Comp Engn, Wright Patterson AFB, OH 45433 USA
[2] Appl Res Solut, 51 Plum St, Beavercreek, OH 45440 USA
[3] LGS Innovat, 15 Vreeland Rd, Florham Pk, NJ 07932 USA
关键词
Critical infrastructure; Cyber security insurance; Quantitative risk analysis; INFORMATION SECURITY; MANAGEMENT;
D O I
10.1016/j.ijcip.2016.04.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart critical infrastructure owners and operators are always looking for ways to minimize cyber risk while keeping a lid on cyber security expenditures. The insurance industry has been quantitatively assessing risk for hundreds of years to minimize risk and maximize profits. To achieve these goals, insurers continuously gather and analyze statistical data to improve their predictions, incentivize client investments in self-protection and periodically refine their models to improve the accuracy of risk estimates. This paper presents a framework that incorporates the operating principles of the insurance industry to provide quantitative estimates of cyber risk. The framework uses optimization techniques to suggest levels of investment in cyber security and insurance for critical infrastructure owners and operators. This analysis can be used to quantitatively formulate strategies to minimize cyber risk. Published by Elsevier B.V.
引用
下载
收藏
页码:43 / 57
页数:15
相关论文
共 50 条
  • [1] Cyber risk and insurance for transportation infrastructure
    Tonn, Gina
    Kesan, Jay P.
    Zhang, Linfeng
    Czajkowski, Jeffrey
    TRANSPORT POLICY, 2019, 79 : 103 - 114
  • [2] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Kure, Halima Ibrahim
    Islam, Shareeful
    Mouratidis, Haralambos
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (18): : 15241 - 15271
  • [3] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Halima Ibrahim Kure
    Shareeful Islam
    Haralambos Mouratidis
    Neural Computing and Applications, 2022, 34 : 15241 - 15271
  • [4] Protection of Critical Infrastructure in National Cyber Security Strategies
    Izycki, Eduardo
    Colli, Rodrigo
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 219 - 228
  • [5] Cyber insurance risk analysis framework considerations
    Rangu, Calin Mihail
    Badea, Leonardo
    Scheau, Mircea Constantin
    Gabudeanu, Larisa
    Panait, Iulian
    Radu, Valentin
    JOURNAL OF RISK FINANCE, 2024, 25 (02) : 224 - 252
  • [6] Need for a Cyber Resilience Framework for Critical Space Infrastructure
    Shahzad, Syed
    Qiao, Li
    Joiner, Keith
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 404 - 412
  • [7] A Risk Analysis Framework for Cyber Security and Critical Infrastructure Protection of the US Electric Power Grid
    Baggott, Sean S.
    Santos, Joost R.
    RISK ANALYSIS, 2020, 40 (09) : 1744 - 1761
  • [8] Risk Analysis Framework for Cyber Security and Critical Infrastructure Protection of the US Electric Power Grid
    Baggott, Sean
    Santos, Joost
    2019 SYSTEMS AND INFORMATION ENGINEERING DESIGN SYMPOSIUM (SIEDS), 2019, : 239 - 244
  • [9] Critical Infrastructure Cyber-Security Risk Management
    Spyridopoulos, Theodoros
    Maraslis, Konstantinos
    Tryfonas, Theo
    Oikonomou, George
    TERRORISTS' USE OF THE INTERNET: ASSESSMENT AND RESPONSE, 2017, 136 : 59 - 76
  • [10] A framework for using insurance for cyber-risk management
    Gordon, LA
    Loeb, MP
    Sohail, T
    COMMUNICATIONS OF THE ACM, 2003, 46 (03) : 81 - 85