Ricardo Ochoa, Diego Ticse, Emilio Herrera, Jose Vargas
{"title":"Ransomware scenario oriented financial quantification model for the financial sector","authors":"Ricardo Ochoa, Diego Ticse, Emilio Herrera, Jose Vargas","doi":"10.1109/SHIRCON53068.2021.9652252","DOIUrl":null,"url":null,"abstract":"More and more companies are becoming victims of cyber-attacks and most of these attacks are the result of a ransomware infection. Currently, there are few organizations that perform a quantitative analysis of cyber risks, allowing them to calculate their impact in monetary terms. In this paper, we propose a model with a quantitative approach, so that organizations can express in financial terms the potential impact of a ransomware attack. The proposed model was implemented in a process of a Peruvian company in the financial sector, with which an optimization of 32.2% in cybersecurity investment was achieved.","PeriodicalId":420900,"journal":{"name":"2021 IEEE Sciences and Humanities International Research Conference (SHIRCON)","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE Sciences and Humanities International Research Conference (SHIRCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SHIRCON53068.2021.9652252","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
More and more companies are becoming victims of cyber-attacks and most of these attacks are the result of a ransomware infection. Currently, there are few organizations that perform a quantitative analysis of cyber risks, allowing them to calculate their impact in monetary terms. In this paper, we propose a model with a quantitative approach, so that organizations can express in financial terms the potential impact of a ransomware attack. The proposed model was implemented in a process of a Peruvian company in the financial sector, with which an optimization of 32.2% in cybersecurity investment was achieved.