The paper proposes a new methodology to measure cyber risks which, instead of using quantitative loss data, often not available, employs ordinal data. The method relies on the construction of a criticality index, whose properties are discussed and compared with alternative measures employed in operational risk measurement. The methodology is illustrated on data regarding cyber attacks collected at the worldwide level.Theproposedmeasureisfoundtobequiteeffectivetorankcyberrisktypes.Thus, from a policy perspective, it can be useful to guide the implementation of preventive actions.
Facchinetti, S., Giudici, P., Osmetti, S. A., Cyber risk measurement with ordinal data, <<STATISTICAL METHODS & APPLICATIONS>>, 2021; 29 (1): 173-185. [doi:10.1007/s10260-019-00470-0] [http://hdl.handle.net/10807/136329]
Cyber risk measurement with ordinal data
Facchinetti, Silvia;Osmetti, Silvia Angela
2020
Abstract
The paper proposes a new methodology to measure cyber risks which, instead of using quantitative loss data, often not available, employs ordinal data. The method relies on the construction of a criticality index, whose properties are discussed and compared with alternative measures employed in operational risk measurement. The methodology is illustrated on data regarding cyber attacks collected at the worldwide level.Theproposedmeasureisfoundtobequiteeffectivetorankcyberrisktypes.Thus, from a policy perspective, it can be useful to guide the implementation of preventive actions.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.