SoK: Quantifying Cyber Risk
Daniel W. Woods, Rainer Böhme
Abstract
This paper introduces a causal model inspired by structural equation modeling that explains cyber risk outcomes in terms of latent factors measured using reflexive indicators. First, we use the model to classify empirical cyber harm studies. We discover cyber harms are not exceptional in terms of typical or extreme losses. The increasing frequency of data breaches is contested and stock market reactions to cyber incidents are becoming less damaging over time. Focusing on harms alone breeds fatalism; the causal model is most useful in evaluating the effectiveness of security interventions. We show how simple statistical relationships lead to spurious results in which more security spending or applying updates are associated with greater rates of compromise. When accounting for threat and exposure, indicators of security are shown to be important factors in explaining the variance in rates of compromise, especially when the studies use multiple indicators of the security level.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers3
- Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet CaseSvetlana Abramova, Rainer BöhmeUSENIX Security 2023
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
- Heimdall: Towards Risk-Aware Network Management OutsourcingYuejie Wang, Qiutong Men, Yongting Chen, Jiajin Liu et al.NDSS 2025
Related papers
- "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected ThemPeter Mayer, Yixin Zou, Florian Schaub, Adam J. AvivUSENIX Security 2021 · 65 citations
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern et al.USENIX Security 2018 · 51 citations
- Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach AttorneysDaniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel SchwarczUSENIX Security 2023
- Self-Efficacy and Security Behavior: Results from a Systematic Review of Research MethodsNele Borgert, Luisa Jansen, Imke Böse, Jennifer Friedauer et al.CHI 2024 · 19 citations
- "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber InsuranceRachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins et al.S&P 2025
