A quantitative bow-tie cyber risk classification and assessment framework
نویسندگان
چکیده
Cyber-attacks pose a growing threat to global commerce that is increasingly reliant on digital technology conduct business. Traditional risk assessment and underwriting practices face serious shortcomings when encountered with cyber threats. Conventional frameworks rate based historical frequency severity of losses incurred, this method effective for known risks; however, due the absence data, prove ineffective assessing risk. This paper proposes conceptual classification framework, designed demonstrate significance proactive reactive barriers in reducing companies’ exposure quantify combines bow-tie model matrix produce rating likelihood cyber-threat occurring potential resulting consequences. The can accommodate both data expert opinion previously score Threats, Barriers Escalators framework. resultant framework applied large city hospital Europe. results highlighted weaknesses actions should be taken bolster defences. provide quick visual guide assessable experts management. It also provides practical allows insurers assess risks, visualise areas concern record effectiveness implementing control barriers.
منابع مشابه
Bow-Tie Diagrams in Downstream Hazard Identification and Risk Assessment
Bow-tie diagrams are emerging as a very useful tool to depict and maintain an up-to-date, real-time, working risk management system embedded in daily operations. They are a proven concept in the worldwide offshore industry. These diagrams provide a pictorial representation of the risk assessment process. This article introduces the bow-tie concept to the downstream and chemical process industri...
متن کاملThe Social Bow Tie
Understanding tie strength in social networks, and the factors that influence it, have received much attention in a myriad of disciplines for decades. Several models incorporating indicators of tie strength have been proposed and used to quantify relationships in social networks, and a standard set of structural network metrics have been applied to predominantly online social media sites to pre...
متن کاملA System-Fault-Risk Framework for cyber attack classification
Computer and network systems fall victim to many cyber attacks of different forms. To reduce the risks of cyber attacks, an organization needs to understand and assess them, make decisions about what types of barriers or protection mechanisms are necessary to defend against them, and decide where to place such mechanisms. Understanding cyber attack characteristics (threats, attack activities, s...
متن کاملProject Risk Assessment Framework
This study presents a framework for calculating the risk of various projects, especially projects under uncertain circumstances. First, the related literature is reviewed and then the relationship between risk and projects is examined. Using a case study an approach is provided to determine the project risk in uncertain circumstances where sufficient data is not available for decision-making. I...
متن کاملProject Risk Assessment Framework
This study presents a framework for calculating the risk of various projects, especially projects under uncertain circumstances. First, the related literature is reviewed and then the relationship between risk and projects is examined. Using a case study an approach is provided to determine the project risk in uncertain circumstances where sufficient data is not available for decision-making. I...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Journal of Risk Research
سال: 2021
ISSN: ['1366-9877', '1466-4461']
DOI: https://doi.org/10.1080/13669877.2021.1900337