Two simple models of business interruption accumulation risk in cyber insurance
At a glance
- Citations
- 1
- References
- 13
- Comments
- 0
Abstract
As modern society becomes ever more dependent on IT services, risk management of cyber incidents becomes more important. Cyber insurance is one tool, among others, for such risk management that has received much attention in the past few years. One obstacle to well-functioning cyber insurance, however, is the fact that cyber accumulation risk remains poorly understood, despite efforts from practitioners and scientists. In this article, we address the accumulation risk of business interruption incidents, an area that has received less attention than the accumulation risk of data breach incidents. Two simple models are introduced: First, a model that takes the insurer's perspective and explores the impact on aggregated claims cost from incidents that unintentionally propagate between firms. Second, a model that takes the insured's perspective, considering the impacts of limited incident management capacity and showing that there is sometimes an economic case for collectively funding additional incident managers. The paper is concluded with some reflections on the models and an outlook.
Publication details
- DOI
- 10.1109/cybersa.2019.8899678
- OpenAlex
- W2983037960
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.