Modelling maximum cyber incident losses of German organisations: an empirical study and modified extreme value distribution approach

Author:

von Skarczinski BennetORCID,Raschke MathiasORCID,Teuteberg FrankORCID

Abstract

AbstractCyber incidents are among the most critical business risks for organisations and can lead to large financial losses. However, previous research on loss modelling is based on unassured data sources because the representativeness and completeness of op-risk databases cannot be assured. Moreover, there is a lack of modelling approaches that focus on the tail behaviour and adequately account for extreme losses. In this paper, we introduce a novel ‘tempered’ generalised extreme value (GEV) approach. Based on a stratified random sample of 5000 interviewed German organisations, we model different loss distributions and compare them to our empirical data using graphical analysis and goodness-of-fit tests. We differentiate various subsamples (industry, size, attack type, loss type) and find our modified GEV outperforms other distributions, such as the lognormal and Weibull distributions. Finally, we calculate losses for the German economy, present application examples, derive implications as well as discuss the comparison of loss estimates in the literature.

Funder

Bundesministerium für Wirtschaft und Energie

Universität Osnabrück

Publisher

Springer Science and Business Media LLC

Subject

Economics and Econometrics,Finance,General Business, Management and Accounting,Accounting

Reference79 articles.

1. Abrams, L. 2021. Coop supermarket closes 500 stores after Kaseya Ransomware Attack. https://www.bleepingcomputer.com/news/security/coop-supermarket-closes-500-stores-after-kaseya-ransomware-attack/. Accessed 22 Jan 2023.

2. Ahlander, J. and J. Menn. 2021. Major Ransomware Attack against U.S. tech provider forces swedish store closures. https://www.reuters.com/technology/cyber-attack-against-us-it-provider-forces-swedish-chain-close-800-stores-2021-07-03/. Accessed 28 Aug 2021.

3. Albrecher, H., J.C. Araujo-Acuna, and J. Beirlant. 2021. Tempered Pareto-type modelling using Weibull distributions. ASTIN Bulletin 51 (2): 509–538. https://doi.org/10.1017/asb.2020.43.

4. Allianz. Allianz risk barometer 2022: the most important business risks for the next 12 months and beyond, based on the insight of 2,650 risk management experts from 89 countries and territories. 2022. https://www.agcs.allianz.com/content/dam/onemarketing/agcs/agcs/reports/Allianz-Risk-Barometer-2020.pdf. Accessed 5 Apr 2022

5. Anderson, R., C. Barton, R. Böhme, R. Clayton, C. Ganan, T. Grasso, M. Levi, T. Moore, and M. Vasek. 2019. Measuring the changing cost of cybercrime. The 18th annual workshop on the economics of information security. https://doi.org/10.17863/CAM.41598.

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3