0% found this document useful (0 votes)
25 views13 pages

Cyber Risk Management Framework

Uploaded by

stzmilad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views13 pages

Cyber Risk Management Framework

Uploaded by

stzmilad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Business Horizons (2021) 64, 659e671

Available online at [Link]

ScienceDirect
w w w. j o u r n a l s . e l s e v i e r. c o m / b u s i n e s s - h o r i z o n s

Cybersecurity: Risk management


framework and investment cost analysis
In Lee

School of Computer Sciences, College of Business & Technology, Western Illinois


University, Macomb, IL 61455, U.S.A.

KEYWORDS Abstract As organizations accelerate digital transformation with mobile devices,


Cybersecurity; cloud services, social media, and Internet of Things services, cybersecurity has
Cyberthreats; become a key priority in enterprise risk management. While improving cybersecur-
Risk management; ity leads to higher levels of customer trust and increased revenue opportunities,
Risk assessment; rapidly evolving data protection and privacy regulations have complicated cyberse-
Cyberinvestment; curity management. Against the backdrop of rapidly rising cyberbreaches and the
Data security; emergence of novel cybersecurity technologies such as machine learning and arti-
Cybercrime; ficial intelligence, this article introduces a cyber risk management framework, dis-
Cyberattack; cusses a cyber risk assessment process, and illustrates a continuous improvement of
Cybersecurity breach cybersecurity performance and cyberinvestment cost analysis with a real-world cy-
bersecurity example.
ª 2021 Kelley School of Business, Indiana University. Published by Elsevier Inc. All
rights reserved.

1. A multilayer approach to new threat methods and techniques aiming to


cybersecurity take advantage of IT and human vulnerabilities.
Currently, cybersecurity is considered one of
According to ISO/IEC 27032:2012, cybersecurity is the critical components in enterprise risk
defined as preservation of the confidentiality, management, as the ever-growing number of
integrity, and availability of information in com- cyberbreaches causes a wide range of critical costs
plex environments resulting from the interaction to organizations and people. These costs include
of people, software, and services on the internet penalties, reputational harm, decrease in stock
using technology devices and connected networks value, compliance breaches, privacy breaches,
(ISO/IEC, 2012). Along with the advances of IT, the and disruption of operations.
domains of cybersecurity have constantly faced The average number of security breaches grew
by 11% from 130 in 2017 to 145 in 2018 per orga-
nization. The average cost of cybercrime for an
organization increased from $1.4 million to $13
E-mail address: i-lee@[Link]

[Link]
0007-6813/ª 2021 Kelley School of Business, Indiana University. Published by Elsevier Inc. All rights reserved.
660 I. Lee

million (Accenture, 2019). The exponential growth major goals of the Health Insurance Portability and
of smartphones, cloud services, social media, and Accountability Act of 1996 (HIPAA) is to protect the
Internet of Things (IoT) applications has motivated privacy and security of healthcare information by
cybercriminals to innovate penetration tools and creating national standards and improving the ef-
techniques and increase cyberattacks. Cybercri- ficiency and effectiveness of the nation’s health-
minals not only steal data, but they also disrupt care system (U.S. Department of Health and
operations and services. Improving cyberdefense Human Services, 1996). The Health Information
leads to higher levels of customer trust and Technology for Economic and Clinical Health Act
increased revenue opportunities. (HITECH) of 2009 expanded the scope of privacy
The annual cybersecurity spending worldwide and security protections available under HIPAA by
grew by 64% from $75.6 billion in 2015 to $124 increasing the potential legal liability for
billion in 2020 (Statista, 2020). Worldwide spending noncompliance and providing for more stringent
on security solutions will achieve a compound enforcement (U.S. Department of Health and
annual growth rate (CAGR) of 9.2% over the Human Services, 2009). The General Data Protec-
2018e2022 period and reach $133.8 billion in 2022. tion Regulation (GDPR), considered to be the
The fastest-growing technology categories include toughest privacy and security law in the world,
managed security services (14.2% CAGR), security established minimum levels of organizational
analytics, intelligence, response, and orchestration cybersecurity requirements for the collection and
software (10.6% CAGR), and network security soft- use of personal data as well as the rights of data
ware (9.3% CAGR; Business Wire, 2019). The “Top 7 owners. GDPR enforcement began in 2016 after
security and risk trends for 2020” include creating the regulation passed European Parliament and all
pragmatic risk appetite statements, implementing organizations were required to be compliant in the
security operations centers (SOCs), establishing a European Union and the European Economic Area
data security governance framework to prioritize (GDPR, 2018). While government regulations are
data security investments, and investing in their instrumental in safeguarding personal data and
cloud security competency (Gartner, 2020). computer resources, they have significantly
Installing firewalls, antivirus software, and increased compliance burden and cyberinvestment
encryption technologies serves a basic security costs for organizations.
function in safeguarding organizations’ computing Against the backdrop of the current cyberse-
resources from cyberattacks and intrusions, but it curity issues and existing cybersecurity frame-
is not sufficient in meeting current cybersecurity works, this article discusses the trends of
needs. As a growing number of organizations use cyberattacks and breaches before presenting a
public cloud and mobile services, the scope of four-layer cyber risk management framework. An
cybersecurity management goes beyond organiza- illustration-based discussion with a real-world
tional boundaries, as in the Capital One data breach scenario follows the cyber risk assessment and
case in which a former Amazon cloud service investment cost analysis.
employee gained access to more than 100 million
Capital One customers’ accounts and credit card
applications early in 2019 (Berthelsen et al., 2019). 2. Cybersecurity trends
With more and more enterprises adopting cloud
services to accelerate their business and promote Cybersecurity gained wide public attention with the
collaboration, the importance of securing apps and introduction of microcomputers in the late 1970s,
data managed by public cloud services is growing. creating a shift from highly centralized mainframe-
While cloud services are economical, cloud users based computing to end-user-based decentralized
must assess security risks and the degree to which computing where end users started to develop their
new human behaviors are required (Cusack & own applications with various office tools. However,
Ghazizadeh, 2016). Forrester’s 2019 report esti- compared to mainframe computers which were
mated that by 2023 the global market for cloud tightly controlled and protected by professional
security technologies will reach $12.7 billion, up developers, end-user-developed applications on
from $5.6 billion in 2018, and a demand for the microcomputers became a fertile ground for
public cloud is driving the overall market for cloud numerous security attacks such as the Brain virus,
security (Kerner, 2019). Michelangelo virus, and Morris worm.
Various cybersecurity regulations have been The invention of WWW in 1989 led to the
enacted to safeguard computer systems and pro- explosive growth of web applications and created
tect data in organizations with the primary pur- new opportunities for cybercriminals. Most cyber-
pose of protecting the public interest. One of the attacks came through web systems as well as the
Cybersecurity 661

internet and other networks. A host of cyber- 3-3 (99.03.03)-2013). The NIST Cybersecurity
threats developed to take advantage of WWW, Framework is voluntary guidance created through
including spyware, adware, spam, spim, phishing, collaboration between industry and government
denial-of-service attack (DoS Attack), ransom- for organizations to better manage and reduce
ware, and eavesdropping. Cybercriminals started cybersecurity risk (NIST, 2018). However, risk
to apply a variety of social engineering techniques management issues are tangentially addressed in
for cybercrime victims to perform certain actions the NIST Cybersecurity Framework where risk
or divulge confidential or personal information. management specifically relevant to the supply
Cybercriminals often exploited security flaws of chain with external parties was discussed.
internet-connected computers to steal millions of The seven stages/chains Cyber Kill Chain
credit card data and the personal data of millions framework is also a widely used framework in
of customers from major corporations such as TJX, cybersecurity. The model identifies what the
Target, Marshalls, and Adobe. cyberattacker must complete to achieve their
Recently, mobile devices and the IoT became objective and helps the defender break the chain
popular targets of cybercriminals. Bring-your-own- at an early stage as well as each stage to stop the
device (BYOD) policies related to the rapid diffu- cyberattacker’s malicious actions (Hutchins et al.,
sion of mobile devices have introduced mobility 2011). The framework focuses mainly on the
security risks to organizations. Employees bring technological side of cybersecurity involving at-
their personal smartphones, tablets, and laptop tackers and defenders, informing stage-by-stage
computers to routinely access corporate computer activities defenders can take against organized
systems via wireless public/private networks. cybersecurity attacks. However, it did not fully
Many of these devices are fraught with security reflect human aspects of cyber risks such as human
risks as users are less concerned about authenti- mistakes and internal threats as witnessed in the
cation and data encryption for most mobile de- case of Capital One - Amazon cloud data breach
vices and less concerned about protecting their (Berthelsen et al., 2019).
devices from cyberattacks. Fake public Wi-Fi net- While these well-known frameworks provide
works and text message phishing scams are some high-level qualitative guidelines for managers,
other growing mobile security threats. none of these frameworks presents a balanced
The IoT has brought about a new paradigm in view of cyber risk management. They do not
which a global network of machines and devices explicitly address the cybersecurity ecosystem and
capable of interacting with each other is driving its impacts on risk management. Furthermore, the
digital innovation in enterprises (Lee, 2019). As the frameworks do not provide any guidance on how
growing number and variety of connected devices risk is measured quantitatively and how cyberse-
are introduced into IoT networks, the potential curity investment can be justified. Therefore,
cyberthreats grow exponentially. A lack of security managers are left to develop cybersecurity pro-
in IoT systems opens up opportunities for cyber- jects without understanding macro-level cyberse-
criminals to access sensitive customer data related curity issues occurring in the cyberecosystem and
to privacy and business transactions. For example, without quantitative risk assessment methods for
when medical IoT devices such as remote patient adequate financial investment analysis.
monitoring systems are left unprotected, the This article proposed a cyber risk management
entire network can be exposed and patients framework with a focus on the cyberecosystem
become extremely vulnerable to potential attacks and cyber risk quantification to complement
(Abraham et al., 2019). Wearable devices are also existing frameworks such as the NIST Cybersecurity
susceptible to cyberattacks that can not only Framework and Cyber Kill Chain framework. The
compromise data but also harm the wearer physi- proposed framework categorizes factors affecting
cally (Mills et al., 2016). cyber risk into four layers, each of which is dedi-
cated to specific functions and responsibilities
related to cyber risk management. Figure 1 shows
3. A cyber risk management framework the proposed framework, which consists of the
cyberecosystem layer, the cyberinfrastructure
Cyber risk management needs to address both layer, the cyber risk assessment layer, and the
technical and human aspects holistically. cyberperformance layer.
Currently, there are a plethora of cybersecurity The cyberecosystem layer focuses on under-
frameworks (e.g., NIST Cybersecurity Framework, standing its stakeholders in the organizational
ISO/IEC 27001, Control Objectives for Information environment. The cyberinfrastructure layer fo-
and Related Technology (COBIT), ANSI/ISA-62443- cuses on an understanding of the
662 I. Lee

Figure 1. The proposed cyber risk management framework

intraorganizational elements such as organization, 3.1. Cyberecosystem layer


employees/internal users, and cybertechnologies
that interact with elements of both the cyber- The cyberecosystem layer is the top layer of the
ecosystem and the cyber risk assessment. At the cyber risk management framework. Cybersecurity
cyber risk assessment layer, cyber risks are iden- involves largely independent or interdependent
tified, quantified, and investment/spending de- stakeholders whose interests and goals may not be
cisions are made to mitigate cyber risks. At the compatible with each other. Understanding how
cyberperformance layer, investment plans are specific stakeholders of the cyberecosystem interact
executed, prioritized cyberthreats are monitored, with IT assets and services such as applications,
and continuous improvements are made. The ele- networks, and data is a prerequisite for an organi-
ments of the cyberecosystem are exogenous vari- zation to be able to develop defense strategies and
ables in that the values of the elements in the protect the IT assets from cyberattacks. An organi-
layer are determined outside the organization. zation’s cyberecosystem also helps them work
The elements of the cyberinfrastructure layer, the cooperatively and competitively with stakeholders
cyber risk assessment layer, and the cyberper- to support cybersecurity activities. An organization
formance layer are endogenous variables whose needs to continuously monitor and evaluate the
values are determined by the organization. Each cyberecosystem and communicate any changes
layer is detailed in Figure 1. detected from the ecosystem to the other layers.
Cybersecurity 663

Major players in the cyberecosystem include compliance strengthen and reinforce the security
supply chain partners, customers, intruders/ practices.
hackers, regulatory agencies, technology de- The employees/internal users, also called the
velopers, and integrators/consultants. It is crucial people element, focuses on awareness, motiva-
to understand how and why supply chain partners tion, and behavior about cybersecurity risk. The
and customers interact with the IT systems of an employees/internal users interact with the
organization to conduct business transactions. It is cyberecosystem and presumably support organi-
essential to identify technology developers and zational goals. According to a study conducted by
integrators/consultants and to understand how Shred-it (2018), more than 85% of senior execu-
they help organizations develop cybersecurity tives and 515 small business owners admit
policies and technologies. It should be noted that employee negligence is one of their most serious
the cyberecosystem also includes adversaries such information security risks. In many organizations,
as intruders and hackers who commit cyberattacks the people aspect of cybersecurity is one of the
for economic gains or other nefarious purposes. It weakest links (Esteves et al., 2017). Raising
is important to identify those intruders/hackers cybersecurity awareness and training are critical
and analyze how they penetrate the organization’s to promoting cybersecurity best practices and
IT systems, steal data, install malware, and/or integrating them into daily tasks. It is also neces-
intercept communications. Regulatory agencies sary to develop people-centric security workplaces
are responsible for establishing cybersecurity where desirable security behaviors are dissemi-
laws, rules, and guidelines, and overseeing nated amongst the employees (Dang-Pham et al.,
compliance. Once the cyberecosystem is evalu- 2016).
ated, the cyberinfrastructure layer is analyzed to The cybertechnologies are used to protect three
understand the state of the internal infrastructure broad categories of IT assets and services from
needed to support cyber risk management. cyberthreats: applications, networks, and data.
Cybertechnologies are critical for protecting or-
3.2. Cyberinfrastructure layer ganizations from threats due to the use of wireless
communication technologies used in various sys-
The cyberinfrastructure layer is the middle layer tems, unknown security holes of IT assets and
of the cyber risk management framework, which services, and connectivity to the internet. For
plays an active role in safeguarding the current IT successful cybersecurity management, organiza-
assets and services of an organization. Organiza- tions need to continuously assess cyberthreats to-
tions, employees/internal users, and cybertech- wards the IT assets and services to commission and
nologies are the three key elements of the decommission various cybertechnologies.
cyberinfrastructure layer. The cyberinfrastructure To deploy cybertechnologies for applications
layer focuses on both the technological and human and networks, an organization needs to analyze
aspects of cybersecurity management and reflects how the technologies are used and what the
the current cybersecurity capability of an organi- threats are to vulnerabilities of the applications
zation. The organization element defines roles, and networks. Data is another important consid-
responsibilities, policies, and processes for cyber- eration in cybertechnology deployment. The
security management. The employee/internal explosive growth of unstructured distributed data
users element focuses on employee awareness, increases cybervulnerability threats to organiza-
morale, job satisfaction, and cybertraining. The tions. Understanding what data are generated,
cybertechnologies are deployed to detect and how the data are used, and what data are targets
counter cyberattacks, mitigate the risk of threats, of cyberattacks is important to the adoption of
and ensure data confidentiality and user specific cybertechnologies for data security.
authentication. Recently, machine-learning technologies have
The organization element plays the central role been receiving growing attention, as they showed
in defining their strategies for cyberdefense and better results in some scenarios than traditional
mitigation. A large-scale survey shows that posi- cybersecurity technologies (Lezzi et al., 2019).
tive attitudes toward cybersecurity policies are
related to more secure behaviors (Choong & 3.3. Cyber risk assessment layer
Theofanos, 2015). Sustained support from senior
management is crucial to ensure that action plans The cyber risk assessment layer plays a central role in
are in place to mitigate the risk of cyberattacks the cyber risk management framework. Abraham
(Esteves et al., 2017). Establishing the best- et al. (2019) present a three-stage approach to un-
practice cybersecurity policy and overseeing derstanding, valuing, and mitigating cybersecurity
664 I. Lee

risks. Similarly, the cyber risk assessment layer in- arising from external hackers and cybervulner-
volves three steps: abilities and threats related to laptop/desktop
mishandling arising from internal users.
1. Risk identification, which pinpoints potential
cybersecurity threats, vulnerabilities, and 3.3.2. Risk quantification
attacks; Most industry sectors are increasingly adopting risk
quantification (Allodi & Massacci, 2017) as it is a
2. Risk quantification, which quantifies the critical step toward a more efficient allocation of
magnitude and frequencies of cyberattacks resources and a more secure environment overall
and prioritizes attack types; and (Chen et al., 2011). Risk quantification requires
measuring frequencies of cyberattack types,
3. Cyberinvestment analysis, which examines the calculating the magnitude of consequences of
cyberinvestment cost-benefit and making in- cyberbreaches arising from the attacks, and
vestment decisions in the cyberinfrastructure. prioritizing cyberattacks using a risk matrix.
Keeping track of the frequencies of cyberbreaches
and the number of individuals affected/financial
3.3.1. Risk identification losses helps an organization quantify the risk in the
Identifying cyber risks requires understanding the future.
preferred approaches intruders and hackers take. Cyberattacks arrive in certain probability dis-
Taxonomies of cyber risk represent the prior tributions. For example, cyberattacks can be
knowledge that the organization has regarding the modeled as a random process of arrival with a
types of assets to be protected as well as the type Poisson probability density function, which is
of vulnerabilities and threats (Rea-Guaman et al., commonly used for a variety of arrival applications
2020). The taxonomies corresponding to assets, (Kuypers & Maillart, 2018). Hence, the expected
cybersecurity vulnerabilities, and cybersecurity arrival rate of cyberattacks per period is an
threats need to be established and updated by the essential parameter in quantifying the frequency
organization over time to facilitate risk identifi- of a certain cyberattack type. An organization may
cation (Rea-Guaman et al., 2020). The organiza- also identify how the frequency of cyberattacks
tion must be aware of the importance of changes over time from their cybersecurity moni-
establishing and maintaining updated taxonomies toring system and use the trend data to continu-
to address the ever-changing cybersecurity envi- ously adjust their cybersecurity action plans.
ronment and ongoing or periodic cyber risk Risk quantification involves estimating the cost
identification. associated with different attack types and breach
Esteves et al. (2017) suggested two stages scenarios. The cost of a cyberbreach for the indi-
typical hackers take: exploration and exploitation. vidual or organization responsible is dependent
During the initial stage of an attack, hackers upon three things: (1) statutory fines, (2) cost of
typically take on an exploration that combines experts or lawyers needed to resolve the breach,
deliberate and intuitive thinking and relies on and (3) value of the data released (Draper &
intensive experimentation. Once access to a sys- Raymond, 2020). For a healthcare organization,
tem is gained, hackers depend on exploitation to negative consequences include ransomware pay-
achieve their goals. On the other hand, the Cyber ment, sending patients/customers to alternative
Kill Chain framework classified cyberattacks into sites for care services, reputation damage, gov-
seven stages (Lockheed Martin, 2009). Each of the ernment penalties and sanctions, and the costs of
seven stagesdfrom ‘reconnaissance’ to ‘act on recovering data, replacing equipment, and imple-
objective’dpresents unique threats and vulnera- menting various security measures (Abraham
bilities. Every intruder and hacker exploits vul- et al., 2019). Risk quantification would require
nerabilities of an applicable asset type and launch sophisticated and comprehensive analyses to
attacks. For the cyber risk assessment, risk iden- determine frequencies of the different cyber-
tification requires two major actions: (1) identify attack types and the breach costs.
the types of assets to be protected and the type of The construction of a cyber risk matrix facili-
vulnerabilities and threats from external actors, tates risk quantification. The use of a cyber risk
and (2) identify the types of assets to be protected matrix helps assessment team members facilitate
and the type of vulnerabilities and threats from the quantification process. The cyber risk matrix
internal actors. For example, an organization may has two dimensions. One dimension is the fre-
identify major cybervulnerabilities and threats quency of cyberattack types per period and the
regarding network servers and email systems other dimension is the expected financial loss per
Cybersecurity 665

cyberbreach. A cyberbreach refers to a penetrated defense probability of 1.0. The expected financial
cyberattack as not all cyberattacks lead to loss of cyberattack type i at varying degree of
cyberbreaches. Through the analysis of the risk defense probability, r, is given as:
matrix, the risk priority of attack-breach can be
FLi Z ðfi  li Þð1  rÞ ð1Þ
determined. In general, an attack-type with a
higher expected financial loss and more frequent where fi is an estimate of the frequency of
cyberattacks and/or frequently penetrated cyberattack type, i, which is a constant, li is an
cyberattacks will have a higher priority. With estimate of the financial loss of each breach of
modified real-world data, Figure 2 shows a cyber cyberattack type, i, which is also a constant, and r
risk matrix of the three attack types. In this sce- is a defense probability. r depends on cyberse-
nario and subsequent discussion, we assume that curity investment. It is assumed that the decision
the decision horizon under consideration is 1 year. horizon is one year. Note that the estimate of the
Depending on the decision horizon an organization frequency of cyberattacks is a constant and is in-
chooses, a proper numeric adjustment may be dependent of the defense probability since the
needed for a shorter or longer decision horizon cyberattacks come from adversaries and are not
than one year. The dotted lines are drawn to divide under the organization’s control. It is assumed that
a high, medium, and low-risk area. The network the organization achieves the target defense
server attack is in the high-risk area with 250 at- probability with certain cyberinvestment to
tacks per year and $20,000 of expected financial reduce the number of penetrated attacks (i.e.,
loss/per breach. Email is in the medium risk area realized cyberbreaches). The cyberinvestment will
with 100 attacks per year and $20,000 expected be discussed in the next section. The number of
financial loss/per breach. Finally, laptop/desktop penetrated cyberattacks is affected by the de-
is on the border of the medium and low-risk area fense probability, r, and is fi )ð1  rÞ. The total
with 100 attacks per year and $10,000 of expected expected financial loss of all cyberattacks at a
financial loss/per breach. defense probability, r, is given as:
The second step in the risk quantification is to Xn
derive an expected financial loss function for each TFL Z iZ1
ðfi ) li Þð1  rÞ ð2Þ
cyberattack type and the entire cyberattack. The
highest expected financial loss comes from the Continuing from the previous scenario, Figure 3
defense probability of zero from cyberattacks shows the linear relationship between the ex-
(i.e., all cyberattacks results in cyberbreaches) pected financial loss from cyberattack types and the
and the lowest expected financial loss from the defense probability. According to Eqn. (1), the
network server’s expected financial loss is $5 million
per year when the defense probability is zero. i.e.,
Figure 2. A cyber risk matrix for three cyberattack (250)$20,000))(1-0.0). The network server’s ex-
types pected financial loss is $2.5 million per year when the
defense probability is 0.5. i.e., (250)$20,000))(1-
0.5). The total expected financial loss of all three
cyberattack types is $8 million per year when the
defense probability is zero. i.e., $1 million þ $2
million þ $5 million. The total expected financial loss
of all three cyberattack types is $4 million per year
when the defense probability is 0.5.

3.3.3. Cyberinvestment analysis


Financial losses due to cyberattacks and other in-
formation system failures in an organization can be
prevented with investment in different security
measures and the purchase of data protection
systems (Bojanc & Jerman-Blazic, 2008). A cyber-
investment cost analysis needs to take into ac-
count two opposing forces of the cybersecurity
equation: cyberattackers and cyberdefenders. In
general, the stronger the cyberdefense is, the
more deflected the cyberattacks are, and vice
versa. A cyberdefense plan involves cost-benefit
666 I. Lee

Figure 3. Relationship between financial loss from cyberattack types and defense probability

analyses of various defense options. In this article, The objective function given as Eqn. (3) is to
cyberinvestment cost is defined as any money minimize the total cybercost, TC. Cyberinvest-
spent to enhance cybersecurity within a given ment cost, D, is a function of the defense proba-
period with the expectation of certain benefits. bility, r.
The cyberinvestment cost analysis uses a simple Xn
but methodically sound technique for practi- Min TC Z DðrÞ þ ð1  rÞ iZ1 ðfi ) li Þ ð3Þ
tioners. The output of the risk quantificationdthe
quantified relationship between financial loss from The investment of cyberdefenders influences
cyberattack types and defense proba- the defense probability. The probability of the
bilitydbecomes an input for the cyberinvestment cyberdefense is modeled as a binomial probability
cost analysis. distribution (i.e., either success or no success).
As in many other new IT projects, one of the The number of successful cyberdefense against
barriers to the investment in cyber risk manage- attacks in a given period is fi )r. The financial loss
ment is the difficulty in justifying the investment due to unsuccessful cyberdefense at a given de-
benefits due to a lack of proper analysis models fense probability is the second term in Eqn. (3).
and techniques. Without a good justification for The achievement of a successful defense proba-
investment, organizations may overlook opportu- bility requires a certain investment cost, D, which
nities to achieve significant benefits obtainable trades off the decrease of the financial loss.
from cybersecurity investment. The cyberinvest- Continuing the previous scenario, Figure 4
ment cost analysis aims to provide convincing shows the tradeoff between the decrease of
financial justification to managers with quantifi- financial loss and the increase of cyberinvestment
cation of tradeoffs between financial loss from cost (and the increase of the defense probability).
cyberbreaches and cyberinvestment cost. The goal The horizontal axis represents the defense proba-
of the cyberinvestment cost analysis is to minimize bility against cyberattacks from 0.0 to 1.0 and the
the total cost of both financial loss from vertical axis represents the financial loss and
cyberbreaches (i.e., penetrated cyberattacks) and cyberinvestment cost over the varying defense
cyberinvestment cost for target cyberdefense. The probability. The linear financial loss curve repre-
cyberinvestment analysis needs to take into ac- sents the financial loss from cyberbreaches due to
count all three elements of the cyberinfras- unsuccessful defense. The total cost minimization
tructure layerdorganization, employees/internal is achieved at the point where the marginal in-
users, and cybertechnologiesdin order to maxi- crease of the cyberinvestment cost is equal to the
mize the benefits of the investment. Traditional marginal decrease of the financial loss. Therefore,
financial methods such as NPV, ROI, and payback the point of the minimum total cost depends on
methods can be easily integrated into the cyber- both the shape of the cyberinvestment cost curve
investment cost analysis. and the shape of the financial loss curve.
Cybersecurity 667

Figure 4. Cyberinvestment cost analysis

Figure 4 shows that when the defense proba- own situation. The IT asset owners (e.g., managers
bility is 0.0, the expected financial loss is of network servers) should have a primary re-
$8,000,000 from cyberbreaches. Assume that an sponsibility to estimate financial loss and the in-
organization is likely to receive 400 cyberattacks vestment cost curve. Well-known expert judgment
per year and each breach (which is not defended techniques such as three-point cost estimates
successfully) costs $20,000. A defense probability (e.g., pessimistic, optimistic, most likely) and the
of 0.5 is equivalent to 200 breaches out of the 400 Delphi method may be used to facilitate the esti-
cyberattacks. The potential financial loss at a de- mation process and derive more reliable and effi-
fense probability of 0.5 is $4 million per year (i.e., cient estimates.
0.5)400)$20,000). There is a wide range of posi- First, the IT asset owners need to identify
tive net benefits between the defense probability different types of attacks on the asset and their
of 0.28 and 0.99 in which the cyberinvestment is potential financial losses such as penalties, com-
beneficial to the organization due to the greater pensations, replacement, upgrade, and reputation
decrease of financial loss compared to the cyber- damages. When internal data about financial los-
investment cost. ses from cyberbreaches do not exist, they may
In this cybersecurity scenario, the cyberinvest- look for data from the industry or similar organi-
ment curve is assumed to be s-shaped, which is a zations. Estimates of potential financial losses of
typical investment cost curve widely used for cost different types of attacks on the asset are summed
estimation of technology projects. The s-shaped and the estimate of the average of the financial
function suggests that a rapidly diminishing return loss per breach for the asset is calculated. For
occurs at the point of cyberinvestment cost example, a financial loss from cyberbreaches
beyond the defense probability of 0.99. While the arising from the attacks on the network servers
minimum total cost occurs at the defense proba- must take into account all different types of
bility of 0.9, senior management may want to cyberattacks.
choose a higher defense probability of over 0.9 up The average of the financial loss can be calcu-
to 0.99, if they are cyber risk-averse. lated by dividing the total financial loss of the
various types of attacks to the network servers by
3.3.4. Estimating costs for cyberinvestment the frequency of the attacks. For example, the
analysis sum of the expected financial loss from 10 attacks
Estimating costs is the basis of the cyberinvest- is $200,000. The average financial loss is $20,000,
ment analysis. The specific cost function may vary while different attack types may result in different
by industry and scale of business operations. This amounts of financial loss. While this kind of esti-
section discusses general starting points for a mation is rudimentary, it can reduce the problem
manager to plot a rudimentary cost curve for their space and simplify the cost function development.
668 I. Lee

A more precise approach could be taken with the into account the ease, usability, and usefulness of
use of occurrence probability of each attack type monitoring and control systems.
to derive the expected financial loss of a cyber-
breach to the network servers. This approach may 3.4.2. Monitoring and control
be useful when certain attack types occur more During the risk monitoring and control stage, the
frequently than other attack types. organization needs to monitor cyberattacks and
Next, they need to plot the cyberinvestment respond to them in a timely fashion. Prevention,
costs for varying degrees of countermeasures detection, and recovery are the core activities and
against the cyberthreats on the IT assets and ser- must be conducted concurrently. Detection activ-
vices. Cyberinvestment costs are identified in ities focus on the real-time tracking of external
various countermeasure activities such as policy cyberattacks, abnormal user activities, and illegal
development, tool development, training, moni- access to data and applications. Recovery activ-
toring, and control activities. For a theoretical ities deliver a solution in real time. Monitoring and
purpose, the previous section illustrated the control need to keep a log of types and sources of
continuous investment cost curve. However, in cyberattacks, frequencies, and magnitude of the
practice, the cyberinvestment cost curve may take attacks in terms of penalty, lost sales, ransom
a discrete cost curve and a specified defense paid, the amount of data stolen, and recovery for
probability range, not the entire range between future cyberinvestment cost analysis.
0 and 1. A good starting point for estimating
cyberinvestment costs is the current cybersecurity 3.4.3. Continuous improvement
expense level and defense performance for each Continuous improvement uses data collected over
IT asset and service. For example, the organization time to discover trends of attacks and long-term
may have operated at the 90% defense probability performance. Continuous improvement activities
with the cybersecurity expense of $200,000 for the need to establish measurable goals and generate
network server operations. For future cyber- periodic performance reports. It is also important
investments, the organization may consider de- to prioritize key performance metrics for these
fense probabilities of 96%, 97%, 98%, and 99% and activities. In order to establish performance goals
use those probabilities to estimate the corre- of various security dimensions, the best practices of
sponding investment costs. an industry and competitors can be benchmarked.
Continuous improvement allows organizations
3.4. Cyberperformance layer to improve and revise future cyberinvestment and
cyberstrategies according to changing patterns of
Once the investment decision is made at the cyberthreats and financial losses. The industry
cyberassessment layer, cyberperformance activ- data indicates this evolving nature of cyber-
ities follow. The cyberperformance layer focuses threats. During 2018, there was a 350% increase in
on the actual development and operation of the ransomware attacks, a 250% increase in spoofing or
cybersecurity systems based on the performance business email compromise attacks, and a 70% in-
goals set at the risk assessment layer. Three major crease in spear-phishing attacks in companies
activities at the cyberperformance layer are overall (Garrett, 2018). Identifying new cyber-
implementation, monitoring and control, and threat types and adversaries involved and updating
continuous improvement. the cyber risk matrix will shed light on the direc-
tion the cyberecosystem is taking. Timing of the
3.4.1. Implementation periodic performance evaluation depends on the
Implementation of cybersecurity includes cyber- types of organizations and IT systems. For
technology development, testing, deployment, example, a more frequent periodic performance
new policy development, training, and a user evaluation will be needed for organizations using
acceptance study. The new cyberinfrastructure complex high-connectivity systems (e.g., hospi-
should build on the existing infrastructure of or- tals, logistics services, transportation services,
ganizations, employees/internal users, and smart factories).
cybertechnologies. A variety of security tools
identified at the cyberecosystem layer should be
sourced for the implementation of the cybertech- 4. Illustration of continuous
nologies. Organizations also need to develop se- improvement
lection criteria to evaluate and choose among
commercially available cybertechnologies and As an illustration, Figure 5 shows the evolution of
vendors. The implementation activities must take the risk profile over 2-year periods with directed
Cybersecurity 669

Figure 5. Evolution of risk profile over a 2-year financial loss from cyberbreaches is $16 million.
period The financial loss curve is steeper than in Figure 4.
Figure 6 shows the maximum benefit shifted to the
defense probability of 0.94 from the defense
probability of 0.9, assuming the cyberinvestment
cost curve is the same. The range of positive net
benefit is between 0.1 and 0.998, which is wider
than in Figure 4. The change of risk profile is highly
likely across industries with frequent changes in
the IT field, and timely periodic cyber risk assess-
ment and continuous improvement will align the
cyberinvestment with the cybersecurity needs.

5. Summary and recommendations for


further application

With the increased cybersecurity risks posed by


cybercriminals and adversaries, it became imper-
ative for organizations to increase their awareness
of the change in the cybersecurity landscape and
respond to the change quickly. This article dis-
cussed cybersecurity trends coinciding with tech-
nological paradigm shifts. This article also
arrows. This risk matrix utilized real-world data developed the cyber risk management framework
with modification. For network server and email in which risk management activities are organized
system threats, both the frequency of attacks and and evaluated in four layers. As in many other IT
the expected financial loss per breach increase. projects, one of the barriers to the investment in
Email system moves from the medium-risk area to cyber risk management is difficulty in measuring
the high-risk area. Laptop/desktop moves to the the benefits and costs of cybersecurity risk man-
medium-risk area. However, the frequency of at- agement. The organization is responsible for
tacks decreases, and the expected financial loss identifying the need for cyberacquisition and the
per breach increases. best technology to meet that need. By prioritizing
Figure 6 shows the updated risk quantification. technologies that improve cybersecurity protec-
When the defense probability is 0%, the expected tion, organizations can reduce the consequences

Figure 6. Updated cyberinvestment cost analysis


670 I. Lee

of cybercrime and unlock future economic value as framework can be expanded to the qualitative risk
higher levels of trust encourage more business assessment (e.g., experts’ opinion on cyber risk,
from customers (Accenture, 2019). nonfinancial strategic decision-making, multi-
We must keep the basic tenet of the four-layer criteria decision-making) when quantitative his-
framework in mind. If we want to make a sound torical data are not readily available. While the
justifiable cyberinvestment to protect our IT assets cyberinvestment decision uses cost minimization
and services from threats, then we need to address as an objective, it is also possible to combine
each layer appropriately. We must: popular traditional financial methods for project
selection such as NPV, ROI, and payback methods
1. Understand our external environment in the process of a cyberinvestment decision. It
through the cyberecosystem layer; is also worth mentioning that while this article
focuses on cyber risk management, cyber risk
2. Evaluate the organization, employees/inter- management is part of large organization risk
nal users, and existing cybertechnologies management which involves noncybersecurity
through the cyberinfrastructure layer; organizational risk issues.

3. Assess cyber risks through the cyber risk


assessment layer; and Acknowledgment
4. Conduct cybersecurity activities at the I offer special thanks to Dr. Jan Kietzmann,
cyberperformance layer. Associate Editor, and reviewers for their valu-
able comments and suggestions regarding this
All the four layers are strongly intertwined and article.
referenced to the cyber risk management frame-
work so that holistic cyber risk management is
achieved.
The cyberecosystem layer is concerned with
References
identifying and understanding the roles of its
stakeholders under the organization’s idiosyn-
Abraham, C., Chatterjee, D., & Sims, R. R. (2019). Muddling
cratic cybersecurity environment. The cyberin- through cybersecurity: Insights from the U.S. healthcare
frastructure layer is concerned with safeguarding industry. Business Horizons, 62(4), 539e548.
IT assets and services of an organization. Organi- Accenture. (2019, March 6). Ninth annual cost of cybercrime
zation, employees/internal users, and cybertech- study. Available at [Link]
insights/security/cost-cybercrime-study
nologies are the three key elements of the
Allodi, L., & Massacci, F. (2017). Security events and vulnera-
cyberinfrastructure layer. The cyber risk assess- bility data for cybersecurity risk estimation. Risk Analysis,
ment layer focuses on the identification of IT as- 37(8), 1606e1627.
sets, cybervulnerabilities and cyberthreats, risk Berthelsen, C., Day, M., & Turton, W. (2019, July 29). Capital
quantification of cyberattack types, and invest- One says breach hit 100 million individuals in U.S. Bloom-
berg. Available at [Link]
ment analysis. Each cybersecurity breach can
articles/2019-07-29/capital-one-data-systems-breached-by-
cause financial loss and, conversely, the preven- seattle-woman-u-s-says
tion of it can reduce financial loss. Since an in- Bojanc, R., & Jerman-Blazic, B. (2008). An economic modelling
vestment in security technologies is a capital approach to information security risk management. Inter-
expenditure, the investment is likely to be under national Journal of Information Management, 28(5),
413e422.
the scrutiny of senior management for budget
Business Wire. (2019, March 20). Worldwide spending on secu-
approval. The optimal investment comes at the rity solutions forecast to reach $103.1 billion in 2019, ac-
point in which the marginal increase of the cording to a new IDC spending guide. Available at https://
cyberinvestment cost is equal to the marginal [Link]/news/home/20190320005114/en/
decrease of the financial loss. While it is not a Worldwide-Spending-on-Security-Solutions-Forecast-to-
Reach-103.1-Billion-in-2019-According-to-a-New-IDC-
trivial task, continuous improvement will help an
Spending-Guide
organization respond properly to the rapid devel- Chen, P., Kataria, G., & Krishnan, R. (2011). Correlated failures,
opment occurring in the cyberecosystem. diversification, and information security risk management.
To be better prepared for any emerging cyber- MIS Quarterly, 35(2), 397e422.
threats, organizations need to analyze not only Choong, Y. Y., & Theofanos, M. (2015). What 4,500þ people can
tell you e Employees’ attitudes toward organizational
their own organizational cybersecurity risks but
password policy do matter. In T. Tryfonas & I. Askoxylakis
also the industry-wide cybersecurity trends. While (Eds.), Human aspects of information security, privacy, and
our discussion is limited to risk quantification, our trust (pp. 299e310). Cham, Switzerland: Springer.
Cybersecurity 671

Cusack, B., & Ghazizadeh, E. (2016). Evaluating single sign-on Kuypers, M., & Maillart, T. (2018). Designing organizations for
security failure in cloud services. Business Horizons, 59(6), cyber security resilience. WEIS 2018. Available at https://
605e614. [Link]/wp-content/uploads/sites/5/
Dang-Pham, D., Pittayachawan, S., & Bruno, V. (2016). Impacts 2016/09/WEIS_2018_paper_50.pdf
of security climate on employees’ sharing of security advice Lee, I. (2019). The Internet of Things for enterprises: An
and troubleshooting: Empirical networks. Business Horizons, ecosystem, architecture, and IoT service business model.
59(6), 571e584. Internet of Things, 7, 100078.
Draper, C., & Raymond, A. H. (2020). Building a risk model for Lezzi, M., Lazoi, M., & Corallo, A. (2019). Cybersecurity for
data incidents: A guide to assist businesses in making ethical industry 4.0 in the current literature: A reference frame-
data decisions. Business Horizons, 63(1), 9e16. work. Computers in Industry, 103, 97e110.
Esteves, J., Ramalho, E., & De Haro, G. (2017). To improve Lockheed Martin. (2009). Cyber Kill Chain. Available at
cybersecurity, think like a hacker. MIT Sloan Management [Link]
Review, 58(3), 71e77. cyber/[Link]
Garrett, G. (2018, December 13). Cyberattacks skyrocketed in Mills, A. J., Watson, R. T., Pitt, L., & Kietzmann, J. (2016).
2018. Are you ready for 2019? IndustryWeek. Available at Wearing safe: Physical and informational security in the age
[Link] of the wearable device. Business Horizons, 59(6), 615e622.
article/22026828/cyberattacks-skyrocketed-in-2018-are- NIST. (2018). Framework documents. Available at [Link]
you-ready-for-2019 [Link]/cyberframework/framework
Gartner. (2020, September 17). Top 9 security and risk trends Rea-Guaman, A. M., Mejı́a, J., San Feliu, T., & Calvo-
for 2020. Available at [Link] Manzano, J. A. (2020). AVARCIBER: A framework for assess-
smarterwithgartner/gartner-top-9-security-and-risk-trends- ing cybersecurity risks. Cluster Computing. [Link]
for-2020/ 10.1007/s10586-019-03034-9
GDPR. (2018). What is GDPR, the EU’s new data protection law? Shred-it. (2018). Security tracker 2018. Available at https://
Available at [Link] [Link]/en-us/resource-center/original-
Hutchins, E. M., Cloppert, M. J., & Amin, R. M. (2011). Intelli- research/security-tracker-2018
gence-driven computer network defense informed by analysis Statista. (2020). Annual cyber security and cyber insurance
of adversary campaigns and intrusion kill chains. Lockheed spending worldwide from 2015 to 2020. Available at https://
Martin. Available at [Link] [Link]/statistics/387868/it-cyber-securiy-
content/dam/lockheed-martin/rms/documents/cyber/LM- budget/
[Link] U.S. Department of Health and Human Services. (1996). Health
ISO/IEC. (2012). ISO/IEC 27032:2012(en) Information technol- insurance portability and accountability act of 1996. Avail-
ogy - Security techniques -Guidelines for cybersecurity. able at [Link]
Available at [Link] portability-and-accountability-act-1996
27032:ed-1:v1:en U.S. Department of Health and Human Services. (2009).
Kerner, S. M. (2019, April 22). Cloud security spending set to HITECH act enforcement interim final rule. Available at
grow, Forrester forecasts. eWEEK. Available at https:// [Link]
[Link]/security/cloud-security-spending-set-to- topics/hitech-act-enforcement-interim-final-rule/index.
grow-forrester-forecasts html

Common questions

Powered by AI

The proposed cyber risk management framework is designed to address limitations of existing frameworks by introducing a structure that considers the cyber ecosystem and quantifies risks. It categorizes cyber risk into four layers: the cyberecosystem layer, the cyberinfrastructure layer, the cyber risk assessment layer, and the cyberperformance layer, each serving specific roles in a holistic approach to cybersecurity . Unlike previous frameworks, it offers a method for quantifying cyber risk and provides guidance for justifying cybersecurity investments through detailed financial analysis .

The financial loss from cyberattacks is inversely related to the defense probability in the cyber risk assessment layer. The higher the defense probability, the fewer the number of successful cyberattacks and thus lower the financial loss. The expected financial loss is calculated by considering the frequency and financial loss per breach of attack type, multiplied by the chance of the attack not being successfully defended (1 - defense probability). This establishes a quantifiable relationship, aiding the assessment of potential financial losses as defense investments vary .

Cyberinvestment cost analysis aids in achieving optimal cybersecurity investment by providing a methodology to weigh the financial losses from cyberbreaches against the costs of defensive investments. It aims to minimize total costs wherein the decrease in financial loss from increased defense spending matches the rise in investment cost. Managers can employ traditional financial methods like NPV, ROI, and payback to justify investment in cybersecurity . This approach helps identify the point of minimal total cost and aligns the cyberinvestment with strategic objectives .

The cyberinfrastructure layer is pivotal in a cyber risk management framework as it addresses both technological and human aspects of an organization's cybersecurity capability. It defines roles, responsibilities, policies, and processes critical for cyber defense, while also focusing on employee awareness and behavior. This layer helps in assessing the current cybersecurity capacity and guides deployment of cybertechnologies necessary for protecting IT assets such as applications, networks, and data, ensuring comprehensive protection from potential threats .

Employee behavior and training are critical in the cyberinfrastructure layer, which aims to safeguard an organization's IT assets. This layer emphasizes the importance of cybersecurity awareness, motivation, and the implementation of best practices among employees. Since employee negligence is a major security risk, enhanced training and awareness programs mitigate this threat by promoting secure behavior and reinforcing the organization's security posture . Cultivating a people-centric security culture is vital for effective cyber risk management .

Existing cybersecurity risk management frameworks, such as the NIST Cybersecurity Framework and Cyber Kill Chain framework, primarily focus on technological aspects and fail to offer a comprehensive view that includes human factors, such as human errors and internal threats . They are generally designed to provide high-level qualitative guidelines, but lack methodologies for quantifying risks and justifying cybersecurity investments. Furthermore, these frameworks do not consider the cybersecurity ecosystem and its broader impacts on risk management, leaving organizations without quantitative risk assessment tools needed for detailed financial investment analysis .

Stakeholder analysis is crucial because it allows the organization to understand the roles, interactions, and impacts of different parties, including supply chain partners, customers, intruders, and regulatory agencies, on the organization's IT assets. By evaluating these relationships, organizations can anticipate how they might affect cybersecurity activities, helping to craft effective defense strategies and ensuring compliance with laws and regulations . This analysis enables the organization to mitigate risks associated with the broader cyber environment .

The cyberecosystem layer, being the top layer of the proposed framework, focuses on understanding the interactions between stakeholders and the IT assets/services such as applications, networks, and data . It acts as a prerequisite for developing effective cyber defense strategies and mitigation measures. Key players like supply chain partners, customers, hackers, and regulatory agencies are analyzed to evaluate both cooperative and adversarial roles, supporting continuous monitoring and evaluation of the ecosystem .

Traditional financial methods like Net Present Value (NPV), Return on Investment (ROI), and payback periods are integrated into cyberinvestment cost analysis to offer a structured approach to evaluating the financial benefits and costs of cybersecurity investments. These methods help quantify potential returns on cybersecurity expenditures by analyzing the trade-offs between the cost of investments and the expected reduction in financial losses from cyber attacks. This integration facilitates informed decision-making and prioritization among potential cybersecurity projects .

Organizations often struggle to justify cybersecurity investments due to the absence of robust analytical models to correlate investment benefits with financial losses prevented, leading to potential oversight of investment opportunities. The proposed framework addresses these challenges by integrating quantitative risk assessment with financial metrics and justifications, offering a structured methodology to evaluate the trade-offs between financial loss and cyberinvestment cost. This allows managers to clearly demonstrate the value of cybersecurity projects and their financial impact .

You might also like