SoK: Cyber Insurance - Technical Challenges and a System Security Roadmap
Savino Dambra, Leyla Bilge, Davide Balzarotti
Abstract
Cyber attacks have increased in number and complexity in recent years, and companies and organizations have accordingly raised their investments in more robust infrastructure to preserve their data, assets and reputation. However, the full protection against these countless and constantly evolving threats is unattainable by the sole use of preventive measures. Therefore, to handle residual risks and contain business losses in case of an incident, firms are increasingly adopting a cyber insurance as part of their corporate risk management strategy.As a result, the cyber insurance sector – which offers to transfer the financial risks related to network and computer incidents to a third party – is rapidly growing, with recent claims that already reached a $100M dollars. However, while other insurance sectors rely on consolidated methodologies to accurately predict risks, the many peculiarities of the cyber domain resulted in carriers to often resort to qualitative approaches based on experts opinions.This paper looks at past research conducted in the area of cyber insurance and classifies previous studies in four different areas, focused respectively on studying the economical aspects, the mathematical models, the risk management methodologies, and the predictions of cyber events. We then identify, for each insurance phase, a group of practical research problems where security experts can help develop new data-driven methodologies and automated tools to replace the existing qualitative approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b46134ca-cd57-484d-8923-77b2350e815cCited by top-tier papers3
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- A First Look at Governments' Enterprise Security GuidanceKimberly Ruth, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li et al.USENIX Security 2025
- Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach AttorneysDaniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel SchwarczUSENIX Security 2023
Builds on3
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- RiskTeller: Predicting the Risk of Cyber IncidentsLeyla Bilge, Yufei Han, Matteo Dell'AmicoCCS 2017 · 92 citations
- Predicting Impending Exposure to Malicious Content from User BehaviorMahmood Sharif, Jumpei Urakawa, Nicolas Christin, Ayumu Kubota et al.CCS 2018 · 71 citations
Related papers
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- Dynalogue: A Transformer-Based Dialogue System with Dynamic AttentionRongjunchen Zhang, Tingmin Wu, Xiao Chen, Sheng Wen et al.WWW 2023 · 4 citations
- "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber InsuranceRachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins et al.S&P 2025
- SoK: Quantifying Cyber RiskDaniel W. Woods, Rainer BöhmeS&P 2021 · 54 citations
- Batten the Hatches: Cybersecurity with Military MarinersRyan Von Brock, Anna Raymaker, Animesh Chhotaray, Frank Li et al.CCS 2026
