课题基金 / 基金详情

PhD Proposal on Financial Stability, Critical Infrastructure and Cyber Security.

PhD Proposal on Financial Stability, Critical Infrastructure and Cyber Security.
关于金融稳定、关键基础设施和网络安全的博士提案。
批准号:
2888135
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2023
资助国家:
英国
项目状态:
未结题
起止时间:
2023 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
能源电网、电信网络和道路运输基础设施等关键国家基础设施资产(CNI)的信息安全对英国及其合作伙伴的经济安全具有重要意义。在大多数情况下,私营组织(通常是公司)以某种形式的许可证签约或分包经营这些资产。这些组织需要对其安全进行战略投资,并在发生攻击时调整其安全态势。这种紧张关系和研究对象是因为观察到,可能对社会造成的损害程度可能远远超过基础设施提供商所遭受的损失(例如,交易资产的价值远远超过伦敦证交所或纽约商品交易所等典型金融交易所的价值,长期停电造成的经济产出损失通常远远高于基础设施提供商的价值)。在这些情况下,需要立法补救措施来激励适当的网络安全姿态,以反映整个社会的风险偏好。这并不是什么新鲜事,对于存储个人信息的公司来说,一般数据保护条例就是一个众所周知的例子。然而,目前的安全监管设计大多针对隐私,而不是基础设施资产的安全运行。在这篇论文中,我将重点设计必要的监管机制,以激励CNI运营商在网络安全风险管理方面进行适当和良好的定向投资,利用经济学理论和对公司和运营层面的数据进行实证分析。
英文摘要
The information security of critical national infrastructure assets (CNI) such as energy grids, telecommunications networks and road transport infrastructure is of significant import to the economic security of the UK and its partners. In most cases private organizations (usually firms) are either contracted or sub-contracted to operate those assets under some form of licence. Those organizations need to make strategic investments in their security and adjust their security posture when an attack occurs. The tension and object of research is driven by the observation that the level of damage that could be inflicted on society may far exceed the losses incurred by the infrastructure provider (e.g, the value of traded assets far exceeds the value of a typical financial exchange like the LSE or NYMEX and the economic output lost to a prolonged power cut is normally significantly higher than the value of the infrastructure provider). In these cases, there is a need for legislative remedies to incentivize appropriate cyber security postures to reflect the risk preferences of society at large. This is not new, the General Data Protection Regulation is a well-known example for firms storing individual information. However, the current design of security regulation is mostly directed at privacy, rather than the secure operation of the infrastructure assets. In this thesis I will focus on the design of regulatory mechanisms needed to incentivize appropriate and well directed investment in cyber security risk management for CNI operators using economic theory and empirical analysis on firm and operational level data.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金