Cyber Risk Measurement And Management: An Introduction To Cybernomics

byKeyun Ruan

Paperback | June 1, 2018

Cyber Risk Measurement and Management: An Introduction to Cybernomicsexamines the indispensable role of economic modeling in the future of digitization to prepare industry for optimizing the management of financial risks associated with this mega trend. It addresses three problem areas: valuation of digital assets, quantification of risk exposures of digital valuables and economic modeling for the management of such risks. Employing a novel cyber risk measurement unit, the solution framework includes value, risk, control and cost and is considered from three views: entity, portfolio and global. The solution framework is built around cyber risk measurement units defined in this book.

  • Brings cutting-edge risk management practices to bear to the topic of cyber security risk mitigation
  • Focuses on topics such as insurance, ISO standards and supply chain vulnerabilities
  • Presents a model to convert domain-based control assessments to scenario-based control assessments
  • Estimates costs of improvements to strengthen control effectiveness against a given scenario
  • Applies classic risk management options (risk acceptance, risk avoidance, risk mitigation and risk transfer) to cyber risk
  • Provides detailed analyses of capital allocations
Keyun Ruan is a computer scientist, consultant and entrepreneur. She coined the term cloud forensics during her Ph.D. in cybercrime investigation. She pioneered the field with foundational publications, talks, and she edited the world's first academic reference book, making her one of the most cited scholar on the topic.
Table of Contents

1. Introduction

Section 1 Valuation of Digital Assets 2. Intrinsic, Market and Subjective Value of Digital Assets 3. Nature of Digital Infrastructure 4. Value Aggregation in the Digital Supply Chain

Section 2 Inherent Risks of Digital Valuables 5. A Data-centric View of Entity-level Inherent Cyber Risk Profiling 6. Nature of a Cyber Loss Event 7. Cyber Risk Accumulation in a Portfolio of Entities 8. Defining the Cyber Risk Unit GLMR

Section 3 Control Effectiveness for Cyber Risk 9. Measuring Cyber Risk Exposure: the Conversion from Qualitative Risk Assessments to Quantitative Measurements 10. Value of Benchmarking and the Influence of Peers 11. Measuring Return of Investment (ROI) for Cyber Transformation Programs

Section 4 Capital Modelling for Managing Residual Cyber Risk 12. Quantifying Residual Cyber Risk Using Structured Loss Scenario Analysis 13. Articulation of Cyber Risk Appetite 14. Transferring Residual Cyber Risk through Insurance 15. Point of Diminishing Returns for Cyber Resilience Investment