Analysing cyber-insurance claims to design harm-propagation trees

被引:0
|
作者
Axon, Louise [1 ]
Erola, Arnau [1 ]
Agrafiotis, Ioannis [1 ]
Goldsmith, Michael [1 ]
Creese, Sadie [1 ]
机构
[1] Univ Oxford, Dept Comp Sci, Oxford, England
关键词
cyber-insurance; harm trees; cyber threats;
D O I
10.1109/cybersa.2019.8899641
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With a continuously changing threat landscape, companies must be prepared for the most unforeseen cyber events. Harm originating from cyberspace varies in magnitude and type, with potential for systemic consequences. While the adoption of security controls may partially mitigate the impact of cyber-attacks, a nuanced understanding of how events unfold during and after an incident will help organisations to better estimate the risk they face and implement advanced incident response strategies. A better estimation of risk is of particular importance to the insurance community because the costs from claims due to cyber-events vary significantly. Towards this end, we collected and analysed more than 70 claims against an insurance company, extracting different types of harm and their characteristics. We then reconstructed the claims based on these types of harm in order to obtain patterns of how cyber-harm propagates. The result is a graph indicating the most common paths that harm follows on multiple events. The findings can help policy-makers and insurance companies to understand how harm propagates, estimate more accurately the value-at-risk and adopt the necessary controls to mitigate these harms.
引用
收藏
页数:4
相关论文
共 3 条
  • [1] A Coalitional Cyber-Insurance Design Considering Power System Reliability and Cyber Vulnerability
    Lau, Pikkin
    Wang, Lingfeng
    Liu, Zhaoxi
    Wei, Wei
    Ten, Chee-Wooi
    [J]. IEEE TRANSACTIONS ON POWER SYSTEMS, 2021, 36 (06) : 5512 - 5524
  • [2] Optimal model design for the cyber-insurance contract with asymmetric information
    Yang, Yunxue
    Yang, Qin
    Yang, Zhenqi
    Xue, Shengjun
    [J]. 2019 INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2019, : 513 - 518
  • [3] Optimal Cyber-Insurance Contract Design for Dynamic Risk Management and Mitigation
    Zhang, Rui
    Zhu, Quanyan
    [J]. IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2022, 9 (04): : 1087 - 1100