资本管理的网络风险评估

IF 2.1 3区 经济学 Q2 BUSINESS, FINANCE
Wing Fung Chong, Runhuan Feng, Hins Hu, Linfeng Zhang
{"title":"资本管理的网络风险评估","authors":"Wing Fung Chong,&nbsp;Runhuan Feng,&nbsp;Hins Hu,&nbsp;Linfeng Zhang","doi":"10.1111/jori.12504","DOIUrl":null,"url":null,"abstract":"<p>This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cybersecurity cascade models to capture the unique nature of cyber risk. The second pillar, cyber capital management, facilitates informed allocation of capital for a balanced cyber risk management strategy, including cybersecurity investments, insurance coverage, and reserves. A case study, based on historical cyber incident data and realistic assumptions, demonstrates the necessity of comprehensive cost–benefit analysis for budget-constrained companies with competing objectives in cyber risk management. In addition, sensitivity analysis highlights the dependence of the optimal strategy on factors such as the price of cybersecurity controls and their effectiveness. The framework's implementation across a diverse range of companies yields general insights on cyber risk management.</p>","PeriodicalId":51440,"journal":{"name":"Journal of Risk and Insurance","volume":"92 2","pages":"424-471"},"PeriodicalIF":2.1000,"publicationDate":"2025-04-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Cyber risk assessment for capital management\",\"authors\":\"Wing Fung Chong,&nbsp;Runhuan Feng,&nbsp;Hins Hu,&nbsp;Linfeng Zhang\",\"doi\":\"10.1111/jori.12504\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cybersecurity cascade models to capture the unique nature of cyber risk. The second pillar, cyber capital management, facilitates informed allocation of capital for a balanced cyber risk management strategy, including cybersecurity investments, insurance coverage, and reserves. A case study, based on historical cyber incident data and realistic assumptions, demonstrates the necessity of comprehensive cost–benefit analysis for budget-constrained companies with competing objectives in cyber risk management. In addition, sensitivity analysis highlights the dependence of the optimal strategy on factors such as the price of cybersecurity controls and their effectiveness. The framework's implementation across a diverse range of companies yields general insights on cyber risk management.</p>\",\"PeriodicalId\":51440,\"journal\":{\"name\":\"Journal of Risk and Insurance\",\"volume\":\"92 2\",\"pages\":\"424-471\"},\"PeriodicalIF\":2.1000,\"publicationDate\":\"2025-04-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Risk and Insurance\",\"FirstCategoryId\":\"96\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1111/jori.12504\",\"RegionNum\":3,\"RegionCategory\":\"经济学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"BUSINESS, FINANCE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Risk and Insurance","FirstCategoryId":"96","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1111/jori.12504","RegionNum":3,"RegionCategory":"经济学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"BUSINESS, FINANCE","Score":null,"Total":0}
引用次数: 0

摘要

本文介绍了一个双支柱网络风险管理框架,以解决管理网络风险的普遍挑战。第一个支柱是网络风险评估,将保险频率-严重性模型与网络安全级联模型相结合,以捕捉网络风险的独特性。第二个支柱是网络资本管理,旨在促进明智的资本配置,以实现平衡的网络风险管理战略,包括网络安全投资、保险覆盖和储备。基于历史网络事件数据和现实假设的案例研究表明,对于预算有限、在网络风险管理方面有竞争目标的公司来说,进行全面的成本效益分析是必要的。此外,敏感性分析强调了最优策略对网络安全控制的价格及其有效性等因素的依赖性。该框架在多家公司的实施,产生了对网络风险管理的总体见解。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cyber risk assessment for capital management

This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cybersecurity cascade models to capture the unique nature of cyber risk. The second pillar, cyber capital management, facilitates informed allocation of capital for a balanced cyber risk management strategy, including cybersecurity investments, insurance coverage, and reserves. A case study, based on historical cyber incident data and realistic assumptions, demonstrates the necessity of comprehensive cost–benefit analysis for budget-constrained companies with competing objectives in cyber risk management. In addition, sensitivity analysis highlights the dependence of the optimal strategy on factors such as the price of cybersecurity controls and their effectiveness. The framework's implementation across a diverse range of companies yields general insights on cyber risk management.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
3.50
自引率
15.80%
发文量
43
期刊介绍: The Journal of Risk and Insurance (JRI) is the premier outlet for theoretical and empirical research on the topics of insurance economics and risk management. Research in the JRI informs practice, policy-making, and regulation in insurance markets as well as corporate and household risk management. JRI is the flagship journal for the American Risk and Insurance Association, and is currently indexed by the American Economic Association’s Economic Literature Index, RePEc, the Social Sciences Citation Index, and others. Issues of the Journal of Risk and Insurance, from volume one to volume 82 (2015), are available online through JSTOR . Recent issues of JRI are available through Wiley Online Library. In addition to the research areas of traditional strength for the JRI, the editorial team highlights below specific areas for special focus in the near term, due to their current relevance for the field.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信