Reducing Informational Disadvantages to Improve

0 downloads 0 Views 9KB Size Report
Reducing Informational Disadvantages to Improve Cyber Risk Management. Sachin Shetty ... Abstract: Effective cyber risk management should include the use of insurance not only to transfer ... Author contact: E-mail: [email protected].
Reducing Informational Disadvantages to Improve Cyber Risk Management Sachin Shetty, Michael McShane, Linfeng Zhang, Jay P. Kesan, Charles A. Kamhoua, Kevin Kwiat and Laurent L. Njilla

Abstract: Effective cyber risk management should include the use of insurance not only to transfer cyber risk but also to provide incentives for insured enterprises to invest in cyber self-protection. Research indicates that asymmetric information, correlated loss, and interdependent security issues make this difficult if insurers cannot monitor the cybersecurity efforts of the insured enterprises. To address this problem, this paper proposes the Cyber Risk Scoring and Mitigation (CRISM) tool, which estimates cyberattack probabilities by directly monitoring and scoring cyber risk based on assets at risk and continuously updated software vulnerabilities. CRISM also produces risk scores that allow organisations to optimally choose mitigation policies that can potentially reduce insurance premiums. Keywords: cyber risk management; cyber insurance; vulnerability assessment; security risk scores; Bayesian belief networks; attack graphs To view the full paper, click on http://rdcu.be/GriI Forthcoming: The Geneva Papers on Risk and Insurance The Geneva Papers (2018). https://doi.org/10.1057/s41288-018-0078-3 © 2018 The Geneva Association 1018-5895/18 www.genevaassociation.org Author contact: E-mail: [email protected]