Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes
Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes
复制标题
灾难性网络风险聚合会在物联网时代蓬勃发展吗?
DOI:
10.1145/3446635
复制
发表时间:
2021
影响因子:
2.5
通讯作者:
Nag, Bodhibrata
中科院分区:
文献类型:
--
作者:
Pal, Ranjan;Huang, Ziyuan;Lototsky, Sergey;Yin, Xinlong;Liu, Mingyan;Crowcroft, Jon;Sastry, Nishanth;De, Swades;Nag, Bodhibrata
Service liability interconnections among networked IT and IoT-driven service organizations create potential channels for cascading service disruptions due to modern cybercrimes such as DDoS, APT, and ransomware attacks. These attacks are known to inflict cascading catastrophic service disruptions worth billions of dollars across organizations and critical infrastructure around the globe. Cyber-insurance is a risk management mechanism that is gaining increasing industry popularity to cover client (organization) risks after a cyber-attack. However, there is a certain likelihood that the nature of a successful attack is of such magnitude that an organizational client’s insurance provider is not able to cover the multi-party aggregate losses incurred upon itself by its clients and their descendants in the supply chain, thereby needing to re-insure itself via other cyber-insurance firms. To this end, one question worth investigating in the first place iswhether an ecosystem comprising a set of profit-minded cyber-insurance companies, each capable of providing re-insurance services for a service-networked IT environment, is economically feasible to cover the aggregate cyber-losses arising due to a cyber-attack.Our study focuses on an empirically interesting case ofextreme heavy tailed cyber-risk distributionsthat might be presenting themselves to cyber-insurance firms in the modern Internet age in the form of catastrophic service disruptions, and could be a possible standard risk distribution to deal with in the near IoT age. Surprisingly, as a negative result for society in the event of such catastrophes,we prove via a game-theoretic analysisthat itmay not be economically incentive compatible,even under i.i.d. statistical conditionsoncatastrophiccyber-risk distributions, for limited liability-taking risk-averse cyber-insurance companies to offer cyber re-insurance solutionsdespite the existence of large enough market capacity to achieve full cyber-risk sharing.However, our analysistheoretically endorsesthe popular opinion thatspreading i.i.d. cyber-risksthat arenot catastrophicis an effective practice for aggregate cyber-risk managers, a result established theoretically and empirically in the past. A failure to achieve a working re-insurance market in critically demanding situations after catastrophic cyber-risk events strongly calls for centralized government regulatory action/intervention to promote risk sharing through re-insurance activities for the benefit of service-networked societies in the IoT age.
登录
查看更多内容
DOI:
--
发表时间:
2020
期刊:
Online World Conference on Soft Computing in Industrial Applications
影响因子:
--
作者:
Ranjan Pal;Ziyuan Huang;Xinlong Yin;Mingyan Liu;S. Lototsky;Jon Crowcroft
通讯作者:
Jon Crowcroft
DOI:
--
发表时间:
2014
期刊:
影响因子:
--
作者:
Parinaz Naghizadeh;M. Liu
通讯作者:
M. Liu
DOI:
--
发表时间:
2011
期刊:
Decision and Game Theory for Security
影响因子:
--
作者:
R. Pal;L. Golubchik;K. Psounis
通讯作者:
K. Psounis
DOI:
--
发表时间:
2010
期刊:
影响因子:
--
作者:
Véronique Bruggeman;M. Faure;Karine Fiore
通讯作者:
Karine Fiore
影响因子:
3.8
作者:
Jonathan W. Welburn;Aaron Strong
通讯作者:
Aaron Strong