谷歌浏览器插件
订阅小程序
在清言上使用

Between a rock and a hard(ening) place: Cyber insurance in the ransomware era

Comput. Secur.(2023)

引用 4|浏览9
暂无评分
摘要
Cyber insurance and ransomware are two of the most studied areas within security research and prac-tice to date, and their interplay continues to raise concerns in industry and government. This article offers substantial new insights and analysis into the complex question of whether cyber insurance can help organisations in mitigating the threat of ransomware, particularly its impacts. Having conducted an interview or workshop with 96 industry professionals spanning the cyber insurance, cyber security, ran-somware negotiations, policy, and law enforcement sectors, we identify that ransomware has been a key cause of the 'hardening' of the cyber insurance market, which is exhibited at almost all levels of the mar-ket. Such hardening has been beneficial in raising the security standards required prior to purchase, but has also created a situation where some organisations may not be able to acquire viable cyber insurance at all. In presenting the outcomes of our thematic analysis of the interview and workshop outputs, the paper provides significant new empirical evidence to support the theory that cyber insurance can act as a form of governance for improving cyber security amongst organisations. Nonetheless, the hardening market does nothing to increase the penetration of cyber insurance. Questions were also raised as to the likelihood of unintended unethical - and potentially illegal - outcomes given the professionalisation of a remediation process that has to determine the most cost-effective solution to an organisation being held ransom. We conclude that insurance, at best, can help to mitigate the ransomware threat for those that can access it, as part of a wider basket of actions that must also come from different stakeholders.(c) 2023 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )
更多
查看译文
关键词
Cyber security,Ransomware,Cyber insurance,Security incidents,Harms,Cyber policy,Resilience,Critical national infrastructure,Malware
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要