H2020Индивидуална стипендия2020–2022

QCYRISK · Quantifying cyber risk: a computational insurance approach

„Хоризонт 2020“ — Действия „Мария Склодовска-Кюри“

Период
2020-05-01 → 2022-02-28
Финансиране от ЕС
159 653 €
Участници
1
Схема
MSCA-IF-EF-ST

Линиите свързват координатора с партньорите.

Накратко на български

Киберрисковете се изчисляват чрез анализ на застрахователните модели, за да се определи реалната цена на инциденти като атаките с вирус от типа „ransomware“. Това помага на фирмите да разпределят ресурсите си правилно и да намалят вредите за обществото.

Този кратък обзор е генериран от изкуствен интелект

Кратко обяснение, генерирано от езиков модел по текста на CORDIS. Оригиналът е по-долу.

Резултати накратко

Quantifying cyber risk: a computational insurance approach

Quantifying cyber risk is an important step in assigning resources to cybersecurity measures. Yet data limitations mean that current estimates ignore certain incidents (e.g. ransomware), rarely provide the financial cost, and rarely describe how risk varies based on the firm’s revenue or industry. This knowledge gap could lead organizations and policy-makers to either (a) under-estimate the problem and fail to assign enough resources to preventing adverse cybersecurity outcomes, or (b) possibly to become carried away by media attention surrounding cyber risk and to over-spend. The lack of firm-specific estimates likely means some organisations make the first type of errors and other organisations make the second type. The lack of data over certain incidents may mean the same organisation makes both errors regarding different aspects of cybersecurity. For example, a firm may over invest in measures intended to mitigate the risk of litigation over cybersecurity incidents and under invest in measures mitigating ransomware attacks. This problem affects society because the movement to integrate personal data into business models means we are all potentially exposed to privacy violations. Impacts can also be seen when ransomware attacks disrupt a firm’s operation, such as when the Colonial Pipeline attack caused soaring petrol prices in the USA. Thus, all of society can benefit from private firms making better risk decisions by incorporating fine-grained loss estimates. This project’s goal is to derive such risk estimates by inferring information from cyber insurance. Surprisingly insurers sell cyber insurance for the ignored incident types and vary the price based on firm-specific characteristics. Extracting insurers’ cyber loss models could help firms manage risk, regardless of whether they purchase insurance. Our contribution involved developing the underlying technique and also making practical estimates based on empirical data.

Текст от CORDIS, на английски · Данни: CORDIS, © Европейски съюз

Цел на проекта

Quantifying cyber risk is an important step in assigning resources to prevention. Yet data limitations mean that current estimates ignore certain incidents (e.g ransomware), rarely provide the financial cost, and cannot describe how risk varies based on the firm’s revenue or industry. Surprisingly insurers sell cyber insurance for the ignored incident types and vary the price based on firm-specific characteristics. Extracting insurers’ cyber loss models could help firms manage risk, regardless of whether they purchase insurance. The proposed action (QCYRISK) uses an iterative model fitting approach to infer loss distributions from insurance prices. The first research question develops the conceptual foundations by building an economic argument about how much information can be extracted from insurance markets. QCYRISK's second question seeks to infer full cyber loss distributions, including how they vary based on firm-specific characteristics. The final research question adopts an adversarial machine learning approach to probe the validity of the inferences, using both synthetic distributions and real cyber crime data. In terms of results and dissemination, QCYRISK will provide a set of loss distributions for multiple cyber incident types adjusted based on the firm’s revenue and industry. These will be made available as a spreadsheet for real-world risk managers. We will also run a continuing education seminar for insurance professionals to raise awareness about the method. The developed method represents a new computational insurance technique that could be applied to extract information from a global total of €4.7 trillion insurance premiums.

Оригинален текст от CORDIS (на английски).

Участници

  • UNIVERSITAET INNSBRUCK · InnsbruckКоординаторАвстрия

Връзки

Данни: CORDIS, © Европейски съюз