On Gaps in Enterprise Cyber Attack Reporting

On Gaps in Enterprise Cyber Attack Reporting
复制标题

DOI:
10.1109/eurospw59978.2023.00030
复制
发表时间:
2023-07
期刊:
2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
影响因子:
--
通讯作者:
Abulfaz Hajizada;T. Moore
Abulfaz Hajizada;T. Moore
中科院分区:
其他
文献类型:
--
作者:
Abulfaz Hajizada;T. Moore

文献摘要

相似文献

长期以来,企业少报网络攻击事件一直令人惋惜。近年来,监管机构已开始要求某些组织在事件发生时必须公开报告。对这些要求的遵守情况是一个实证问题,到目前为止在很大程度上尚未得到检验。在本文中,我们研究了美国上市公司向美国证券交易委员会以及美国卫生与公众服务部提交的涉及网络攻击的监管文件。我们还将研究结果与媒体报道的网络事件众包报告进行了比较。我们发现报道存在很大差距,既存在登上新闻但未出现在监管文件中的攻击事件,反之亦然。最后,我们讨论了这对网络攻击与防御研究以及政策制定者的影响。
It has long been lamented that firms underreport cyber attacks. In recent years, regulators have begun mandating that certain organizations must publicly report when incidents occur. Adherence to these requirements is an empirical question that has been largely unexamined to date. In this paper, we study regulatory filings by U.S. public companies to the Securities Exchange Commission and to the Department Health and Human Services that discuss cyber attacks. We also compare the findings against crowdsourced reports of cyber incidents appearing in media outlets. We find substantial gaps in coverage, both in terms of attacks that make the news but do not appear in regulatory filings and vice versa. We conclude by discussing the implications for the study of cyber attack and defense as well as for policymakers.