If You Can’t Measure it You Can’t Manage it - Quantitative Analysis of Cyber Risk Prediction and Mitigation

Sun, Meng (2023) If You Can’t Measure it You Can’t Manage it - Quantitative Analysis of Cyber Risk Prediction and Mitigation. In: Current Topics on Business, Economics and Finance Vol. 5. B P International, pp. 150-180. ISBN Dr. Fang Xiang Current Topics on Business, Economics and Finance Vol. 5 04 29 2023 04 29 2023 9788119217502 B P International (a part of SCIENCEDOMAIN International) 10.9734/bpi/ctbef/v5 https://stm.bookpi.org/CTBEF-V5/issue/view/1044

Full text not available from this repository.

Abstract

Cyber breach incidents have increased dramatically during COVID-19 pandemic and keep a cyclical trend there after. Data breach incidents result in severe financial loss and reputational damage to business, government, healthcare and educational institutions. Compared to sufficient amount of cyber risk investigation in economic and IT system domain, seldom investigations of cyber risk have been made in quantitative perspective, In order to fill this gap, we propose a Bayesian generalized linear mixed model to analyze data breach incidents chronology since 2001. Our model captures the dependency between frequency and severity of cyber losses, and the behavior of cyber attacks on entities across time. Risk characteristics such as types of breach, types of organization, entity locations in chronology, as well as time trend effects are taken into consideration when investigating breach frequencies. A statistical predictive model is generated under actuarial mathematics frame, with flexible input available such as location and organization types. Predictions and implications of the proposed model in enterprise risk management and cyber insurance rate filing are discussed and illustrated. Our results show that both geological location and business type play significant roles in measuring cyber risks. The outcomes of our predictive analytics provide numerical currency loss level that can be utilized by various kinds of organizations and design their risk mitigation strategies.

Item Type: Book Section
Subjects: European Scholar > Social Sciences and Humanities
Depositing User: Managing Editor
Date Deposited: 29 Sep 2023 12:47
Last Modified: 29 Sep 2023 12:47
URI: http://article.publish4promo.com/id/eprint/2312

Actions (login required)

View Item
View Item