Systemic Cyber Risk and Aggregate Impacts

Systemic Cyber Risk and Aggregate Impacts
复制标题

系统性网络风险和总体影响

DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
3.8
通讯作者:
Aaron Strong
Aaron Strong
中科院分区:
医学3区
文献类型:
--
作者:
Jonathan W. Welburn;Aaron Strong

文献摘要

被引文献

相似文献

随着近年来发生的一些最大的网络攻击-从2010年到2019年-我们才刚刚开始了解网络风险的全部程度。随着企业努力应对网络事件的风险及其不完善的预防能力,注意力已经转向风险管理和保险。虽然人们一直在努力了解网络攻击的成本,但与网络攻击相关的系统性风险(风险在相互依赖的系统中传播的结果)仍然是一个关键问题,需要进一步研究。我们贡献了一个理论框架,描述了网络事件后级联,共同原因或独立故障的结果系统性网络风险。我们构建了一个量化模型的级联故障,以估计潜在的经济损失与给定的网络事件。我们提出了一种跨学科的方法,将标准的部门级投入产出分析扩展到网络领域,这还没有完成。我们估计与公司级事件相关的总损失,这有助于风险分析和计算经济建模。我们使用该模型来估计潜在网络事件的影响,并将模型结果与已知损害的案例进行比较。最后,我们使用系统性网络故障模型来考虑对不断增长的网络保险市场的影响以及更广泛的网络政策的必要性。当我们讨论系统性网络风险的话题时,我们使用I/O分析来估计公司级事件的总损失的贡献适用于从环境到健康的各种风险分析应用。
With some of the largest cyber attacks occurring in recent years—from 2010 to 2019—we are only beginning to understand the full extent of cyber risk. As businesses grapple with the risks of cyber‐incidents and their imperfect ability to prevent them, attention has shifted toward risk management and insurance. While there have been efforts to understand the costs of cyber attacks, the systemic risk—a result of risks spreading across interdependent systems—associated with cyber attacks remains a critical and problem in need of further study. We contribute a theoretical framework that describes systemic cyber risk as the result of cascading, common cause, or independent failures following a cyber incident. We construct a quantitative model of cascading failures to estimate the potential economic damage associated with a given cyber incident. We present an interdisciplinary approach for extending standard sector‐level input–output analyses to the cyber domain, which has not been done. We estimate the aggregate losses associated with firm‐level incidents, a contribution to risk analysis and computational economic modeling. We use this model to estimate the impact of potential cyber incidents and compare model results to a case with known damages. Finally, we use the model of systemic cyber failure to consider the implications on the growing cyber insurance market and the need for broader cyber policy. While we discuss the topic of systemic cyber risk, our contribution of using I/O analysis to estimate the aggregate losses from firm‐level incidents is applicable across a variety of risk analysis applications from environment to health.