Related papers: Mitigating Moral Hazard in Cyber Insurance Using R…
In this paper, a novel cyber-insurance model design is proposed based on system risk evaluation with smart technology applications. The cyber insurance policy for power systems is tailored via cyber risk modeling, reliability impact…
In the classical principal-agent problem, a principal must design a contract to incentivize an agent to perform an action on behalf of the principal. We study the classical principal-agent problem in a setting where the agent can be of one…
We introduce a game-theoretic model to investigate the strategic interaction between a cyber insurance policyholder whose premium depends on her self-reported security level and an insurer with the power to audit the security level upon…
We study a moral hazard problem with adverse selection: a risk-neutral agent can directly control the output distribution and possess private information about the production environment. The principal designs a menu of contracts satisfying…
In an ever more connected world, awareness has grown towards the hazards and vulnerabilities that the networking on sensitive digitized information pose for all parties involved. This vulnerability rests in a number of factors, both human…
On information security outsourcing market, an important reason that firms do not want to let outside firms(usually called MSSPs-Managed Security Service Providers) to take care of their security need is that they worry about service…
We study the impact of data sharing policies on cyber insurance markets. These policies have been proposed to address the scarcity of data about cyber threats, which is essential to manage cyber risks. We propose a Cournot duopoly…
Protecting against cyber-threats is vital for every organization and can be done by investing in cybersecurity controls and purchasing cyber insurance. However, these are interlinked since insurance premiums could be reduced by investing…
In this study an exploration of insurance risk transfer is undertaken for the cyber insurance industry in the United States of America, based on the leading industry dataset of cyber events provided by Advisen. We seek to address two core…
This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cybersecurity cascade…
I study a moral hazard problem between a principal and multiple agents who experience positive peer effects represented by a (weighted) network. Under the optimal linear contract, the principal provides high-powered incentives to central…
We consider a contracting problem in which a principal hires an agent to manage a risky project. When the agent chooses volatility components of the output process and the principal observes the output continuously, the principal can…
Cyber threats affect all kinds of organisations. Risk analysis is an essential methodology for cybersecurity as it allows organisations to deal with the cyber threats potentially affecting them, prioritise the defence of their assets and…
This paper has a double aim. One the one hand, we introduce a uni-nodal network model for cyber risks with firewalled edges and SIR intra-edge spreading. In connection to this, we formulate an insurance problem in which one seeks the…
We study a model of moral hazard with heterogeneous beliefs where each of agent's actions gives rise to a pair of probability distributions over output levels, one representing the beliefs of the agent and the other those of the principal.…
We study optimal rating design under moral hazard and strategic manipulation. An intermediary observes a noisy indicator of effort and commits to a rating policy that shapes market beliefs and pay. We characterize optimal ratings via…
Cyber insurance, which protects insured organizations against financial losses from cyberattacks and data breaches, can be difficult and expensive to obtain for many organizations. These difficulties stem from insurers difficulty in…
I revisit the standard moral-hazard model, in which an agent's preference over contracts is rooted in costly effort choice. I characterise the behavioural content of the model in terms of empirically testable axioms, and show that the…
When undertaking cyber security risk assessments, we must assign numeric values to metrics to compute the final expected loss that represents the risk that an organization is exposed to due to cyber threats. Even if risk assessment is…
We examine the trade-off between the provision of incentives to exert costly effort (ex-ante moral hazard) and the incentives needed to prevent the agent from manipulating the profit observed by the principal (ex-post moral hazard).…