首页    期刊浏览 2025年06月18日 星期三
登录注册

文章基本信息

  • 标题:Cyber operational risk scenarios for insurance companies
  • 本地全文:下载
  • 作者:R.Egan ; S.Cartagena ; R.Mohamed
  • 期刊名称:British Actuarial Journal
  • 印刷版ISSN:1357-3217
  • 电子版ISSN:2044-0456
  • 出版年度:2019
  • 卷号:24
  • 页码:1-24
  • DOI:10.1017/S1357321718000284
  • 语种:English
  • 出版社:Cambridge University Press
  • 摘要:Cyber Operational Risk: Cyber risk is routinely cited as one of the most important sources of operational risks facing organisations today, in various publications and surveys. Further, in recent years, cyber risk has entered the public conscience through highly publicised events involving affected UK organisations such as TalkTalk, Morrisons and the NHS. Regulators and legislators are increasing their focus on this topic, with General Data Protection Regulation (“GDPR”) a notable example of this. Risk actuaries and other risk management professionals at insurance companies therefore need to have a robust assessment of the potential losses stemming from cyber risk that their organisations may face. They should be able to do this as part of an overall risk management framework and be able to demonstrate this to stakeholders such as regulators and shareholders. Given that cyber risks are still very much new territory for insurers and there is no commonly accepted practice, this paper describes a proposed framework in which to perform such an assessment. As part of this, we leverage two existing frameworks – the Chief Risk Officer (“CRO”) Forum cyber incident taxonomy, and the National Institute of Standards and Technology (“NIST”) framework – to describe the taxonomy of a cyber incident, and the relevant cyber security and risk mitigation items for the incident in question, respectively.
国家哲学社会科学文献中心版权所有