SoK: Cyber Insurance - Technical Challenges and a System Security Roadmap
Savino Dambra, Leyla Bilge, Davide Balzarotti
摘要
Cyber attacks have increased in number and complexity in recent years, and companies and organizations have accordingly raised their investments in more robust infrastructure to preserve their data, assets and reputation. However, the full protection against these countless and constantly evolving threats is unattainable by the sole use of preventive measures. Therefore, to handle residual risks and contain business losses in case of an incident, firms are increasingly adopting a cyber insurance as part of their corporate risk management strategy.As a result, the cyber insurance sector – which offers to transfer the financial risks related to network and computer incidents to a third party – is rapidly growing, with recent claims that already reached a $100M dollars. However, while other insurance sectors rely on consolidated methodologies to accurately predict risks, the many peculiarities of the cyber domain resulted in carriers to often resort to qualitative approaches based on experts opinions.This paper looks at past research conducted in the area of cyber insurance and classifies previous studies in four different areas, focused respectively on studying the economical aspects, the mathematical models, the risk management methodologies, and the predictions of cyber events. We then identify, for each insurance phase, a group of practical research problems where security experts can help develop new data-driven methodologies and automated tools to replace the existing qualitative approaches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
- A First Look at Governments' Enterprise Security GuidanceKimberly Ruth, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li 等USENIX Security 2025
- Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach AttorneysDaniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel SchwarczUSENIX Security 2023
它引用的顶会 Paper3
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- RiskTeller: Predicting the Risk of Cyber IncidentsLeyla Bilge, Yufei Han, Matteo Dell'AmicoCCS 2017 · 被引用 92 次
- Predicting Impending Exposure to Malicious Content from User BehaviorMahmood Sharif, Jumpei Urakawa, Nicolas Christin, Ayumu Kubota 等CCS 2018 · 被引用 71 次
相关 Paper
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- Dynalogue: A Transformer-Based Dialogue System with Dynamic AttentionRongjunchen Zhang, Tingmin Wu, Xiao Chen, Sheng Wen 等WWW 2023 · 被引用 4 次
- "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber InsuranceRachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins 等S&P 2025
- SoK: Quantifying Cyber RiskDaniel W. Woods, Rainer BöhmeS&P 2021 · 被引用 54 次
- Batten the Hatches: Cybersecurity with Military MarinersRyan Von Brock, Anna Raymaker, Animesh Chhotaray, Frank Li 等CCS 2026
