脆弱性(计算)
业务
投资(军事)
计算机安全
宏
宏观层面
资产(计算机安全)
风险分析(工程)
精算学
计算机科学
经济
政治
政治学
法学
经济体制
程序设计语言
标识
DOI:10.1016/j.pacfin.2019.101173
摘要
This paper presents analytical models for optimizing firm's cybersecurity spending and cyber insurance based on the effectiveness of spending in reducing cyber threats, vulnerability and impact, respectively. At the macro-level, the paper shows how private-sector contribution toward countering cybercrimes can reduce the overall cyber loss and create economic value. At the micro level, a firm's effectiveness of security spending in addressing specific cyber threats can be reduced when other co-dependent security measures are not put in place. The paper derives an optimal mix of cybersecurity investments in "knowledge and expertise" versus "deploying mitigation measures". The paper proposes customizing cyber insurance for firms with itemized threat-specific coverage with a portion of the premium used to help clients with risk knowledge and nudge clients in implementing risk mitigation measures. Small and Mid-sized Enterprises can stand benefit the most from such innovative cyber insurance.
科研通智能强力驱动
Strongly Powered by AbleSci AI