Toward enhancing the information base on costs of cyber incidents: implications from literature and a large-scale survey conducted in Germany

Bennet Simon von Skarczinski, Arne Dreißigacker, Frank Teuteberg
{"title":"Toward enhancing the information base on costs of cyber incidents: implications from literature and a large-scale survey conducted in Germany","authors":"Bennet Simon von Skarczinski, Arne Dreißigacker, Frank Teuteberg","doi":"10.1108/ocj-08-2021-0020","DOIUrl":null,"url":null,"abstract":"PurposeLiterature repeatedly complains about the lack of empirical data on the costs of cyber incidents within organizations. Simultaneously, managers urgently require transparent and reliable data in order to make well-informed and cost-benefit optimized decisions. The purpose of this paper is to (1) provide managers with differentiated empirical data on costs, and (2) derive an activity plan for organizations, the government and academia to improve the information base on the costs of cyber incidents.Design/methodology/approachThe authors analyze the benchmark potential of costs within existing literature and conduct a large-scale interview survey with 5,000 German organizations. These costs are directly assignable to the most severe incident within the last 12 months, further categorized into attack types, cost items, employee classes and industry types. Based on previous literature, expert interviews and the empirical results, the authors draft an activity plan containing further research questions and action items.FindingsThe findings indicate that the majority of organizations suffer little to no costs, whereas only a small proportion suffers high costs. However, organizations are not affected equally since prevalence rates and costs according to attack types, employee classes, and other variables tend to vary. Moreover, the findings indicate that board members and IS/IT-managers show partly different response behaviors.Originality/valueThe authors present differentiated insights into the direct costs of cyber incidents, based on the authors' knowledge, this is the largest empirical survey in continental Europe and one of the first surveys providing in-depth cost information on German organizations.","PeriodicalId":107089,"journal":{"name":"Organizational Cybersecurity Journal: Practice, Process and People","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Organizational Cybersecurity Journal: Practice, Process and People","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1108/ocj-08-2021-0020","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

PurposeLiterature repeatedly complains about the lack of empirical data on the costs of cyber incidents within organizations. Simultaneously, managers urgently require transparent and reliable data in order to make well-informed and cost-benefit optimized decisions. The purpose of this paper is to (1) provide managers with differentiated empirical data on costs, and (2) derive an activity plan for organizations, the government and academia to improve the information base on the costs of cyber incidents.Design/methodology/approachThe authors analyze the benchmark potential of costs within existing literature and conduct a large-scale interview survey with 5,000 German organizations. These costs are directly assignable to the most severe incident within the last 12 months, further categorized into attack types, cost items, employee classes and industry types. Based on previous literature, expert interviews and the empirical results, the authors draft an activity plan containing further research questions and action items.FindingsThe findings indicate that the majority of organizations suffer little to no costs, whereas only a small proportion suffers high costs. However, organizations are not affected equally since prevalence rates and costs according to attack types, employee classes, and other variables tend to vary. Moreover, the findings indicate that board members and IS/IT-managers show partly different response behaviors.Originality/valueThe authors present differentiated insights into the direct costs of cyber incidents, based on the authors' knowledge, this is the largest empirical survey in continental Europe and one of the first surveys providing in-depth cost information on German organizations.
加强网络事件成本的信息库:来自文献和在德国进行的大规模调查的启示
文献一再抱怨缺乏组织内部网络事件成本的经验数据。同时,管理者迫切需要透明和可靠的数据,以便做出明智和成本效益优化的决策。本文的目的是(1)为管理者提供差异化的成本经验数据,(2)为组织、政府和学术界提供活动计划,以改善网络事件成本的信息库。设计/方法/方法作者分析了现有文献中成本的基准潜力,并对5000个德国组织进行了大规模的访谈调查。这些成本直接分配给过去12个月内最严重的事件,并进一步分类为攻击类型、成本项目、员工类别和行业类型。基于以往文献、专家访谈和实证结果,作者起草了一份包含进一步研究问题和行动项目的活动计划。调查结果调查结果表明,大多数组织几乎没有成本,而只有一小部分遭受高成本。然而,组织受到的影响并不相同,因为根据攻击类型、员工类别和其他变量的流行率和成本往往会有所不同。此外,研究结果表明,董事会成员和信息技术/ it经理表现出部分不同的反应行为。原创性/价值基于作者的知识,作者对网络事件的直接成本提出了不同的见解,这是欧洲大陆最大的实证调查,也是第一批提供德国组织深度成本信息的调查之一。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信