Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
11012426 | European Journal of Operational Research | 2019 | 25 Pages |
Abstract
Cyber risks are high on the business agenda of every company, but they are difficult to assess due to the absence of reliable data and thorough analyses. This paper is the first to consider a broad range of cyber risk events and actual cost data. For this purpose, we identify cyber losses from an operational risk database and analyze these with methods from statistics and actuarial science. We use the peaks-over-threshold method from extreme value theory to identify “cyber risks of daily life” and “extreme cyber risks”. Human behavior is the main source of cyber risk and cyber risks are very different compared with other risk categories. Our models can be used to yield consistent risk estimates, depending on country, industry, size, and other variables. The findings of the paper are also useful for practitioners, policymakers and regulators in improving the understanding of this new type of risk.
Related Topics
Physical Sciences and Engineering
Computer Science
Computer Science (General)
Authors
Martin Eling, Jan Wirfs,