<p>For financial institutions, safeguarding against cyber attack is now about more than just protection – increasingly it means managing cyber risk effectively across the organization. In modern, diffuse networks, such as those in most large banks, allocating risk across multiple network nodes (defined here as IT infrastructure, assets, and points of access) is vital to developing comprehensive strategies for managing cyber risk. Central to this is quantifying the risk. We believe that current scoring and statistically oriented models for cyber risk quantification are based on flawed assumptions, and fail to answer several key questions.</p>
<p>We propose a methodology for quantifying cyber risk that incorporates the physical network in the organization, and the behavior and characteristics of individuals and processes in that network – including the actions they take to mitigate cyber risks. In addition, as allocating and attributing risk are central to modifying the behavior of institutions and individuals, enabling organizations to easily attribute and allocate risk to specific nodes and edges of the network is central to our method. This paper provides a high-level summary of the approach, and highlights how it differs from, and improves on, existing models of cyber risk quantification.</p>
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@chartis-research.com to find out more.
You are currently unable to copy this content. Please contact info@chartis-research.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@chartis-research.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@chartis-research.com