CYBECO: “Supporting Cyberinsurance from a Behavioural Choice Perspective”
Lorentz Cyberinsurance Open Day March 27, 2019
CYBECO: Supporting Cyberinsurance from a Behavioural Choice - - PowerPoint PPT Presentation
CYBECO: Supporting Cyberinsurance from a Behavioural Choice Perspective Lorentz Cyberinsurance Open Day March 27, 2019 Objective Research and develop a framework for managing cybersecurity risks, focused on cyberinsurance as key risk
Lorentz Cyberinsurance Open Day March 27, 2019
➢ Research and develop a framework for managing cybersecurity risks, focused on cyberinsurance as key risk management treatment ➢ How? ✓ By transferring risk of the insured companies to the insurance provides ✓ By providing incentives for improving security
➢ Lack of data => incomplete overall risk picture => inability of insurance companies to design their offerings ➢ Companies deciding on whether to buy cyberinsurance or not
➢ Develop a cybersecurity risk management model ✓ Intentionality of adversaries ✓ Cyberinsurance in the risk management portfolio ✓ Structured expert judgement methodologies for little data ✓ Cyber security behavioural and psychological findings ➢ Develop a decision support tool, the CYBECO Toolbox implementing the modelling framework ➢ Conduct behavioural experiments to validate the models and tool ➢ Provide policy recommendations to cover policy gaps
Kate Labunets & Wolter Pieters TU Delft
Company Expert
Cover losses due to cyber risk Collect necessary data Provide results
Security provider Threat Reinsurance provider Sector regulator
Provide security services Compliance with regulations Pay premiums Damage or steal company's assets Request for a specific expertise
Insurance regulator
Compliance with regulations Invest in security controls
Policymaker
Interests of insurers (e.g., insurance federation)
Consumer
Provide product/service P
i c y c h a n g e s
Research
Policy recommendations Provide product/service
Vendor
Interests of companies (e.g., SME association)
Insurer
Research results Cover part of insurer's clients losses Interests of consumers (e.g., consumer rights supervisory authority)
Insurance broker
Advice on cyber insurance offerings Negoti at e po l i c y co n d itio ns S e c ur ity s e r v i ces f
i n surer and it s c li e n t s
– Get advice on security investments – Cover possible losses related to cyber risk – Help with incident response
– Provide high quality advice about cyber risks – Make profit
– Increase market share – Have better actuarial data – Profitable business
– Increase overall level of security – Resilient ecosystem
1 Woods, D. and Simpson, A., 2017. Policy measures and cyber insurance: a
amount of insurance sold
Vassilis Chatzigiannakis (Intrasoft International) Aitor Couce Vieira (CSIC-ICMAT)
Complexity Pre-simulated results Semi-simulated results Fully simulated results Computation speed
Devstat (José Vila) & Northumbria University (Pam Briggs)
➢ Psychological theories can help explain behaviour and decision making around cybersecurity, and identify factors influencing insurance uptake ➢ Combined with behavioural economic experiments, this provides a strong scientific method to study how participants make security decisions
Technical Component Human Behavioural Component
Traditional approach Assumes humans are always conscious, logical decision makers BUT… human behaviour (including decision making) is not always logical!
VULNERABILITY: My online data/accounts are at risk of being compromised SEVERITY: If my online data/accounts were hacked, it would be severe RESPONSE EFFICACY: Insurance is an effective method to protect against loss SELF-EFFICACY: Taking the necessary security measures is entirely under my control REWARDS OF NOT HAVING INSURANCE / COSTS OF INSURANCE: Insurance is financially costly for me Insurance is not worth it Setting up insurance would require too much from me
CYBECO economic experiments address this in three ways:
Experiment 2: Testing the toolbox
protection & cyberinsurance Experiment 1: Testing the model
design of cyberinsurance products
‘behavioural version’ of the CYBECO model Experiment 3: Belief formation
adversarial cyberinsurance models
CYBECO economic experiments address this in three ways:
Experiment 2: Testing the toolbox
protection & cyberinsurance Experiment 1: Testing the model
design of cyberinsurance products
‘behavioural version’ of the CYBECO model Experiment 3: Belief formation
adversarial cyberinsurance models
Factors Context of the cyberattack The attack is random (virus) / intentional (cyber-criminal). Price dependence Insurance price does / does not depend on protection level Features of the product Base price (expected utility) Proportional price increment Non-proportion
Protection level Insurance level Online behaviour PMT variables Risk Attitude
Behavioural measures Treatments
are complementary
affect online behaviour