IDEAS home Printed from https://ideas.repec.org/a/gam/jrisks/v10y2022i11p200-d950584.html
   My bibliography  Save this article

Modeling Under-Reporting in Cyber Incidents

Author

Listed:
  • Seema Sangari

    (School of Data Science and Analytics, Kennesaw State University, 3391 Town Point Dr. NW, Kennesaw, GA 30144, USA)

  • Eric Dallal

    (Verisk Extreme Event Solutions, Lafayette City Center, 2 Ave de Lafayette 2nd Floor, Boston, MA 02111, USA)

  • Michael Whitman

    (School of Data Science and Analytics, Kennesaw State University, 3391 Town Point Dr. NW, Kennesaw, GA 30144, USA
    Institute of Cybersecurity Workforce Development, Kennesaw State University, 3203 Campus Loop Road, Kennesaw, GA 30144, USA)

Abstract

Under-reporting in cyber incidents is a well-established problem. Due to reputational risk and the consequent financial impact, a large proportion of incidents are never disclosed to the public, especially if they do not involve a breach of protected data. Generally, the problem of under-reporting is solved through a proportion-based approach, where the level of under-reporting in a data set is determined by comparison to data that is fully reported. In this work, cyber insurance claims data is used as the complete data set. Unlike most other work, however, our goal is to quantify under-reporting with respect to multiple dimensions: company revenue, industry, and incident categorization. The research shows that there is a dramatic difference in under-reporting—a factor of 100—as a function of these variables. Overall, it is estimated that only approximately 3% of all cyber incidents are accounted for in databases of publicly reported events. The output of this work is an under-reporting model that can be used to correct incident frequencies derived from data sets of publicly reported incidents. This diminishes the “barrier to entry” in the development of cyber risk models, making it accessible to researchers who may not have the resources to acquire closely guarded cyber insurance claims data.

Suggested Citation

  • Seema Sangari & Eric Dallal & Michael Whitman, 2022. "Modeling Under-Reporting in Cyber Incidents," Risks, MDPI, vol. 10(11), pages 1-14, October.
  • Handle: RePEc:gam:jrisks:v:10:y:2022:i:11:p:200-:d:950584
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2227-9091/10/11/200/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2227-9091/10/11/200/
    Download Restriction: no
    ---><---

    References listed on IDEAS

    as
    1. Kjartan Palsson & Steinn Gudmundsson & Sachin Shetty, 2020. "Analysis of the impact of cyber events for cyber insurance," The Geneva Papers on Risk and Insurance - Issues and Practice, Palgrave Macmillan;The Geneva Association, vol. 45(4), pages 564-579, October.
    2. Charlie McMurdie, 2016. "The cybercrime landscape and our policing response," Journal of Cyber Policy, Taylor & Francis Journals, vol. 1(1), pages 85-93, January.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Martin Eling & Kwangmin Jung, 2022. "Heterogeneity in cyber loss severity and its impact on cyber risk measurement," Risk Management, Palgrave Macmillan, vol. 24(4), pages 273-297, December.
    2. Lukáš Pavlík & Martin Ficek & Jakub Rak, 2022. "Dynamic Assessment of Cyber Threats in the Field of Insurance," Risks, MDPI, vol. 10(12), pages 1-21, November.

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jrisks:v:10:y:2022:i:11:p:200-:d:950584. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.