1 1
Colorado State University Yashwant K Malaiya CS559 L23
Quantitative Cyber-Security
CSU Cybersecurity Center Computer Science Dept
Quantitative Cyber-Security Colorado State University Yashwant K - - PowerPoint PPT Presentation
Quantitative Cyber-Security Colorado State University Yashwant K Malaiya CS559 L23 CSU Cybersecurity Center Computer Science Dept 1 1 Presentations/Final Report Slides should be ready by Wed 11/18/20, but .. Post 24 hours in advance of
1 1
CSU Cybersecurity Center Computer Science Dept
2
3
4
5
Malaiya 2015
6
Over the next two years, involving minimum of 10,000 and maximum of 100,000 records.
Cost of a Data Breach Report 2019, IBM Security, study conducted by Ponemon Institute.
5 10 15 20 25 30 35 20,000 40,000 60,000 80,000 100,000 120,000
Probability %
Exponential form
7
8 8
CSU Cybersecurity Center Computer Science Dept
9
* Post data breach response # Measured by the stock-market?
10
11
12
The Flaw of Averages, Sam Savage, Harvard Business Review, Nov. 2002
13
Verizon 2015 data, the claim amount vs. breach size (ranges from single digits to 108 million records)
14
15
16
software vulnerabilities and data breaches, CSU
= 𝑏 ∗ 𝑡𝑗𝑨𝑓 !"# 𝑔𝑝𝑠 𝑔𝑏𝑑𝑢𝑝𝑠𝑡 4,5,6 ∗ 𝐺𝑐𝑠𝑓𝑏𝑑ℎ_𝑑𝑏𝑣𝑡𝑓 ∗ 𝐺𝑓𝑜𝑑𝑠𝑧𝑞𝑢𝑗𝑝𝑜 ∗ 𝐺𝑞𝑠𝑗𝑤𝑏𝑑𝑧
= [𝑏 ∗ (𝑡𝑗𝑨𝑓) ^ (𝑐 − 1) 𝑔𝑝𝑠 𝑔𝑏𝑑𝑢𝑝𝑠 11] ∗ 𝐺𝐶𝐷𝑁
= 𝑏 ∗ (𝑡𝑗𝑨𝑓) ^ (𝑐 − 1) 𝑔𝑝𝑠 𝑔𝑏𝑑𝑢𝑝𝑠 14
= 𝑏 ∗ (𝑡𝑗𝑨𝑓) ^ (𝑐 − 1) 𝑔𝑝𝑠 𝑔𝑏𝑑𝑢𝑝𝑠 15 𝑏𝑜𝑒 16
17
18
Per record cost: US$, Total cost measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020, 3,400-99,730 records. Excludes mega-breaches)
3.4 3.5 3.6 3.7 3.8 3.9 4 4.1 140 142 144 146 148 150 152 154 156 158 160 2013 2014 2015 2016 2017 2018 2019 2020 2021
Average cost/per record cost of a data breach
Av /rec cost $ Av Cost Mill$
19
1 2 3 4 5 6 5000 10000 15000 20000 25000 30000
Average total cost of a data breach by organizational size
2019 Cost 2020 Cost
20
(Ponemon Global Cost of Data Breach Study 2020, 3,400-99,730 records. Excludes mega-breaches)
Types of records compromised Percent Cost/rec Cost/rec in malacious attack Customer PII 80 150 175 Intellectual property 32 149 171 Anonymized customer data 24 147 163 Other corporate data 23 143 151 Employee PII 21 141 150
21
Cost in $million in category
Category Percent 2015 2016 2017 2018 2019 2020 Lost business 39.4 1.57 1.63 1.51 1.45 1.42 1.52 Ex-post response 28.8 1.07 1.1 0.93 1.02 1.07 0.99 Notification 6.2 0.17 0.18 0.19 0.16 0.21 0.24 Detection and escalation 25.6 0.98 1.09 0.99 1.23 1.22 1.11
Detection and escalation: Activities that enable a company to reasonably detect the breach of personal data either at risk (in storage) or in motion and to report the breach of protected information to appropriate personnel within a specified time period. Notification: Activities that enable the company to notify individuals who had data compromised in the breach (data subjects) as regulatory activities and communications. Also included are costs that relate to communication with data protection regulators and other related parties. Post data breach response: Processes set up to help individuals or customers affected by the breach to communicate with the company, as well as costs associated with redress activities and reparation with data subjects and regulators. Lost business: Activities associated with cost of lost business including customer churn, business disruption, and system downtime. Also included in this category are the costs of acquiring new customers and costs related to revenue loss.
22
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020)
23
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020)
24
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020)
25
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020)
26
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020) Root cause Frequency Av total cost $ mill Malicious attack 52% 4.27 System glitch 25% 3.38 Human error 23% 3.33
30 35 40 45 50 55 2013 2014 2015 2016 2017 2018 2019 2020 2021
Percent of all breaches caused by a malacious attack
27
Measured in US$ millions (Ponemon Global Cost of Data Breach Study 2020)
28
29
Trends % Cost of a breach (mill$) Automation level 2018 2019 2020 2018 2019 2020 Fully deployed 15 16 21 2.88 2.65 2.45 Partially deployed 34 36 38 3.39 3.86 4.11 Not deployed 51 48 41 4.43 5.16 6.03
intelligence, machine learning, analytics and automated orchestration.
30
31
32
Measured in US$ millions (Ponemon Global Cost of Data Breach 2020)
Actor type Fraction % Cost Nation state 13 $4.43 Unknown 21 $4.29 Hacktivist 13 $4.28 Financially motivated 53 $4.23 Average malicious attack $4.27
33
50 100 150 200 250 300 350 400 450 10 20 30 40 50 60
Million records
Av Total Cost (m$)
2018 2019 2020
34
35
National Component Illustrative cost
37 37
CSU Cybersecurity Center Computer Science Dept
38
39
40
Authors Sample size Period Result Garg et al. (2003) 22 1999–2002 Found that on average the loss to a company was $17–28 million as compared to
some other reported estimates of between $50,000 to $2 million per incident.
Kannan et
72 1997–2003 No significant impact on the firms was detected on the analysis of both short- and long-term reactions. Gatzlaff and McCullough (2010) 77 2004–2006 The overall effect of a data breach on shareholder is negative and statistically
ratios experience greater negative abnormal returns.
Yayla and Hu (2011) 58 1994–2006 Pure e-commerce firms experienced higher negative market reactions than traditional bricks-and-mortar firms. Also
found that DoS attacks had higher negative impact than other types of security breaches.
The Effect of Data Theft on a Firm’s Short-Term and Long-Term Market Value 2020
41
The impact of information security events to the stock market: A systematic literature review, 2015
42
Much Ado about Nothing: The (Lack of) Economic Impact of Data Privacy Breaches, 2019
43
44
45
The Effect of Data Theft on a Firm’s Short-Term and Long-Term Market Value 2020
46
47
– When the event company declared that it suffered a confidential information breach, the event led to an average stock price fell of −0.23%. – The abnormal return for trading day after the event was −0.41% .
48
after the event. Supported.
49
50
Microsoft)