Modelling maximum cyber incident losses of German organisations: an empirical study and modified extreme value distribution approach
Bennet Skarczinski (),
Mathias Raschke () and
Frank Teuteberg ()
Additional contact information
Bennet Skarczinski: PricewaterhouseCoopers
Mathias Raschke: Ecclesia Re
Frank Teuteberg: University Osnabrueck
The Geneva Papers on Risk and Insurance - Issues and Practice, 2023, vol. 48, issue 2, No 7, 463-501
Abstract:
Abstract Cyber incidents are among the most critical business risks for organisations and can lead to large financial losses. However, previous research on loss modelling is based on unassured data sources because the representativeness and completeness of op-risk databases cannot be assured. Moreover, there is a lack of modelling approaches that focus on the tail behaviour and adequately account for extreme losses. In this paper, we introduce a novel ‘tempered’ generalised extreme value (GEV) approach. Based on a stratified random sample of 5000 interviewed German organisations, we model different loss distributions and compare them to our empirical data using graphical analysis and goodness-of-fit tests. We differentiate various subsamples (industry, size, attack type, loss type) and find our modified GEV outperforms other distributions, such as the lognormal and Weibull distributions. Finally, we calculate losses for the German economy, present application examples, derive implications as well as discuss the comparison of loss estimates in the literature.
Keywords: Cyber incident losses; Loss size distribution; Extreme value distribution; Tapered distribution; Information security management; Data breach (search for similar items in EconPapers)
Date: 2023
References: View references in EconPapers View complete reference list from CitEc
Citations:
Downloads: (external link)
http://link.springer.com/10.1057/s41288-023-00293-x Abstract (text/html)
Access to full text is restricted to subscribers.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:pal:gpprii:v:48:y:2023:i:2:d:10.1057_s41288-023-00293-x
Ordering information: This journal article can be ordered from
http://www.springer.com/finance/journal/41288/PS2
DOI: 10.1057/s41288-023-00293-x
Access Statistics for this article
The Geneva Papers on Risk and Insurance - Issues and Practice is currently edited by Christophe Courbage
More articles in The Geneva Papers on Risk and Insurance - Issues and Practice from Palgrave Macmillan, The Geneva Association Contact information at EDIRC.
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().