Document Type
Article
Publication Date
5-2019
Abstract
Collaboration between the DHS Cybersecurity and Infrastructure Security Agency (CISA) and public-sector partners has revealed that a dearth of cyber-incident data combined with the unpredictability of cyber attacks have contributed to a shortfall in first-party cyber insurance protection in the critical infrastructure community. This research explores the foundations of insurance theory and adopts behavioral manipulation methods to incentivize cyber-security investment. We validate the model by applying power industry performance data from 2013-2015 to assess risk facing the industry. Results show that the model can successfully discriminate between individual power companies as well as geographic regions on the basis of risk and can recommend cyber risk- management strategies tailored to individual risk profiles. The adoption of this framework could invite more market participation, which will create a more robust cyber-incident reporting environment, contributing directly to the DHS goal of creating a national cyber-incident data repository.
Source Publication
Homeland Security Affairs
Recommended Citation
Rosson, J. P., Rice, M., Lopez Jr., J., & Fass, R. D. (2019). Incentivizing Cyber Security Investment in the Power Sector Using An Extended Cyber Insurance Framework. Homeland Security Affairs, 15, Article 2. https://www.hsaj.org/articles/15082
Comments
Copyright © 2019 by the authors.
Homeland Security Affairs is the online journal of the Naval Postgraduate School Center for Homeland Defense and Security (CHDS).
Shared on AFIT Scholar in accordance with the terms of the journal.