To main content

When to Treat Security Risks with Cyber Insurance

Abstract

Transferring security risk to a third party through cyber insurance is an unfamiliar playing field for a lot of organisations, and therefore many hesitate to make such investments. Indeed, there is a general need for affordable and practical ways of performing risk quantification when determining risk treatment options. To address this concern, we propose a lightweight, data-driven approach for organisations to evaluate their own need for cyber insurance. A generic risk model, populated with available industry averages, is used as a starting point. Individual organisations can instantiate this model to obtain a risk profile for themselves related to relevant cyber threats. The risk profile is then used together with a cyber insurance profile to estimate the benefit and as a basis for comparing offers from different insurance providers.
Read the publication

Category

Academic chapter

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies
  • SINTEF Digital / Software Engineering, Safety and Security
  • Norwegian University of Science and Technology

Year

2018

Publisher

IEEE (Institute of Electrical and Electronics Engineers)

Book

2018 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA), Glasgow UK, 11-12 June 2018

ISBN

9781538645659

View this publication at Norwegian Research Information Repository