论文标题
资本管理的网络风险评估
Cyber Risk Assessment for Capital Management
论文作者
论文摘要
本文介绍了一个两柱网络风险管理框架,以应对管理网络风险的普遍挑战。第一个支柱网络风险评估将保险频率模型与网络安全级联模型相结合,以捕获网络风险的独特性质。第二个支柱网络资本管理促进了将资本分配的知情,以制定平衡的网络风险管理策略,包括网络安全投资,保险范围和储备。一项基于历史网络事件数据和现实假设的案例研究表明,对于在网络风险管理中具有竞争目标的预算受限公司,需要进行全面的成本效益分析。此外,灵敏度分析强调了最佳策略对诸如网络安全控制价格及其有效性等因素的依赖性。该框架在各种公司中的实施产生了对网络风险管理的一般见解。
This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cybersecurity cascade models to capture the unique nature of cyber risk. The second pillar, cyber capital management, facilitates informed allocation of capital for a balanced cyber risk management strategy, including cybersecurity investments, insurance coverage, and reserves. A case study, based on historical cyber incident data and realistic assumptions, demonstrates the necessity of comprehensive cost-benefit analysis for budget-constrained companies with competing objectives in cyber risk management. In addition, sensitivity analysis highlights the dependence of the optimal strategy on factors such as the price of cybersecurity controls and their effectiveness. The framework's implementation across a diverse range of companies yields general insights on cyber risk management.