Security Pricing as Enabler of Cyber-Insurance A First Look at Differentiated Pricing Markets

نویسنده

  • Ranjan Pal
چکیده

Despite the promising potential of network risk management services (e.g., cyber-insurance) to improve information security, their deployment is relatively scarce, primarily due to such service companies being unable to guarantee profitability. As a novel approach to making cyber-insurance services more viable, we explore a symbiotic relationship between security vendors (e.g., Symantec) capable of price differentiating their clients, and cyber-insurance agencies having possession of information related to the security investments of their clients. The goal of this relationship is to (i) allow security vendors to price differentiate their clients based on security investment information from insurance agencies, (ii) allow the vendors to make more profit than in homogeneous pricing settings, and (iii) subsequently transfer some of the extra profit to cyber-insurance agencies to make insurance services more viable. In this paper, we perform a theoretical study of a market for differentiated security product pricing, primarily with a view to ensuring that security vendors (SVs) make more profit in the differentiated pricing case as compared to the case of non-differentiated pricing. In order to practically realize such pricing markets, we propose novel and computationally efficient consumer differentiated pricing mechanisms for SVs based on (i) the market structure, (ii) the communication network structure of SV consumers captured via a consumer’s Bonacich centrality in the network, and (iii) security investment amounts made by SV consumers. We validate our analytical model via extensive simulations conducted on practical SV client network topologies; main results show (through those simulations) that (a) a monopoly SV could improve its profit margin by upto ≈ 25% (based on the simulation setting) by accounting for clients’ investment information and network locations, whereas in an oligopoly setting, SVs could improve their profit margins by upto ≈ 18%, and (b) differentiated security pricing mechanisms are fair among SV consumers with respect to the total investment made by a consumer. To the best of knowledge, the proposed differentiated pricing framework is the first of its kind in the security products domain, and is generally applicable to usecases beyond the one investigated in this work.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Security Pricing as an Enabler of Cyber-Insurance: A First Look at Differentiated Pricing Markets

Despite the promising potential of network risk management services (e.g., cyber-insurance) to improve information security, their deployment is relatively scarce, primarily due to such service companies being unable to guarantee profitability. As a novel approach to making cyber-insurance services more viable, we explore a symbiotic relationship between security vendors (e.g., Symantec) capabl...

متن کامل

Realizing Efficient Cyber-Insurance Markets Via Price Discriminating Security Products

Current cyber-insurance research community has mainly focussed about studying the market success of an insurance-driven security ecosystem. Such an ecosystem comprises of several market elements like cyber-insurers, ISPs, network users (individuals and organizations), security vendors (SVs), regulatory agencies, etc.,which coexist with the goal of mutually satisfying one’s interests in order to...

متن کامل

Using Financial Instruments to Transfer the Information Security Risks

For many individuals and organizations, cyber-insurance is the most practical and only way of handling a major financial impact of an information security event. However, the cyber-insurance market suffers from the problem of information asymmetry, lack of product diversity, illiquidity, high transaction cost, and so on. On the other hand, in theory, capital market-based financial instruments c...

متن کامل

The Internet as an enabler for dynamic pricing of goods

The Internet offers the potential for dynamic pricing for a wide range of products across the supply chain. Dynamic pricing can be formally defined as the buying and selling of goods in markets where prices move quickly in response to supply and demand fluctuations. Unlike physical markets where change occurs slowly because of information delays, change occurs very rapidly on the Internet. In t...

متن کامل

Cyber-Insurance: Copula Pricing Framework and Implication for Risk Management

In recent years there has been a growing stream of research focusing on cyber-insurance. Risk transference with insurance has been suggested by both practitioners and academics to absorb losses caused by security breaches as well as to supplement the existing set of security tools to manage IT security residual risk after IT security investments are made. In this paper, we investigate pricing o...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017