2000 character limit reached
Decision-Making Frameworks for Network Resilience -- Managing and Mitigating Systemic (Cyber) Risk (2312.13884v3)
Published 21 Dec 2023 in q-fin.RM, cs.CR, cs.DM, cs.NI, cs.SY, and eess.SY
Abstract: We introduce a decision-making framework tailored for the management of systemic risk in networks. This framework is constructed upon three fundamental components: (1) a set of acceptable network configurations, (2) a set of interventions aimed at risk mitigation, and (3) a cost function quantifying the expenses associated with these interventions. While our discussion primarily revolves around the management of systemic cyber risks in digital networks, we concurrently draw parallels to risk management of other complex systems where analogous approaches may be adequate.
- Hamed Amini, Rama Cont and Andreea Minca “Resilience to contagion in financial networks” In Mathematical Finance 26.2, 2016, pp. 329–365 DOI: https://doi.org/10.1111/mafi.12051
- Yeftanus Antonio, Sapto Wahyu Indratno and Rinovia Simanjuntak “Cyber Insurance Ratemaking: A Graph Mining Approach” In Risks 9.12, 2021 DOI: 10.3390/risks9120224
- “Multivariate Shortfall Risk Allocation and Systemic Risk” In SIAM Journal on Financial Mathematics 9.1, 2018, pp. 90–126 DOI: 10.1137/16M1087357
- “Coherent Measures of Risk” In Mathematical Finance 9.3, 1999, pp. 203–228
- “Building Resilience in Cybersecurity” In Journal of Risk and Insurance, 2023
- “Modeling and pricing cyber insurance” In European Actuarial Journal 13, 2023, pp. 1–53
- “Contagion in cyber security attacks” In Journal of the Operational Research Society 68, 2017, pp. 780–791 DOI: 10.1057/jors.2016.37
- “Emergence of scaling in random networks” In Science 286, 1999, pp. 509–512
- Alain Barrat, Marc Barthélemy and Alessandro Vespignani “Dynamical Processes on Complex Networks” Cambridge University Press, 2008
- Yannick Bessy-Roland, Alexandre Boumezoued and Caroline Hillairet “Multivariate Hawkes process for cyber insurance” In Annals of Actuarial Science 15, 2021, pp. 14–39
- “A unified approach to systemic risk measures via acceptance sets” In Mathematical Finance 29.1, 2019, pp. 329–367 DOI: https://doi.org/10.1111/mafi.12170
- Alexandre Boumezoued, Yousra Cherkaoui and Caroline Hillairet “Cyber risk modeling using a two-phase Hawkes process with external excitation”, 2023 arXiv:2311.15701 [math.ST]
- Alex Cassidy, Zachary Feinstein and Arye Nehorai “Risk measures for power failures in transmission systems” In Chaos: An Interdisciplinary Journal of Nonlinear Science 26.11, 2016, pp. 113110 DOI: 10.1063/1.4967230
- Chen Chen, Garud Iyengar and Ciamac C. Moallemi “An Axiomatic Approach to Systemic Risk” In Management Science 59.6 INFORMS, 2013, pp. 1373–1388 URL: http://www.jstor.org/stable/23443854
- “Cyber Network Resilience Against Self-Propagating Malware Attacks” In Computer Security – ESORICS 2022 Cham: Springer International Publishing, 2022, pp. 531–550
- Stefano Chiaradonna, Petar Jevtić and Nicolas Lanchier “Framework for cyber risk loss distribution of hospital infrastructure: Bond percolation on mixed random graphs approach” In Risk Analysis, 2023
- Michel Dacorogna, Nehla Debbabi and Marie Kratz “Building up cyber resilience by better grasping cyber risk via a new algorithm for modelling heavy-tailed data” In European Journal of Operational Research 311.2, 2023, pp. 708–729 DOI: https://doi.org/10.1016/j.ejor.2023.05.003
- “Managing cyber risk, a science in the making” In Scandinavian Actuarial Journal Taylor & Francis, 2023 DOI: 10.1080/03461238.2023.2191869
- “Systemic Risk in Networks” In Network Science. An Aerial View Springer, 2019, pp. 59–77
- “Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (Text with EEA relevance)”, https://eur-lex.europa.eu/eli/dir/2022/2555, 2022 European Union
- Thomas M. Eisenbach, Anna Kovner and Michael Junho Lee “Cyber Risk and the U.S. Financial System: A Pre-Mortem Analysis”, 2021
- Larry Eisenberg and Thomas H. Noe “Systemic Risk in Financial Systems” In Management Science 47.2 INFORMS, 2001, pp. 236–249 URL: http://www.jstor.org/stable/2661572
- Martin Eling “Cyber risk research in business and actuarial science” In European Actuarial Journal Springer, 2020, pp. 1–31
- “Mitigating systemic cyber risk”, 2022 European Systemic Risk Board
- “Systemic cyber risk”, 2020 European Systemic Risk Board
- Ernesto Estrada, Naomichi Hatano and Michele Benzi “The physics of communicability in complex networks” In Physics Reports 514.3, 2012, pp. 89–119 DOI: https://doi.org/10.1016/j.physrep.2012.01.006
- Tolulope Fadina, Yang Liu and Ruodu Wang “A Framework for Measures of Risk under Uncertainty”, 2023 arXiv:2110.10792 [q-fin.RM]
- Matthias Fahrenwaldt, Stefan Weber and Kerstin Weske “Pricing of cyber insurance contracts in a network model” In ASTIN Bulletin: The Journal of the IAA 48.3, 2018, pp. 1175–1218
- Zachary Feinstein, Marcel Kleiber and Stefan Weber “Acceptable designs of traffic networks: stochastic cell transmission models and systemic risk”, 2023
- Zachary Feinstein, Birgit Rudloff and Stefan Weber “Measures of systemic risk” In SIAM Journal on Financial Mathematics 8.1, 2017, pp. 672–708
- Hans Föllmer “Spatial risk measures and their local specification: The locally law-invariant case” In Statistics & Risk Modeling 31.1, 2014, pp. 79–101 DOI: doi:10.1515/strm-2013-5001
- “Spatial Risk Measures: Local Specification and Boundary Risk” In Stochastic Analysis and Applications 2014 Cham: Springer International Publishing, 2014, pp. 307–326
- “Stochastic Finance: An Introduction in Discrete Time” Walter de Gruyter, 2016
- “The Axiomatic Approach to Risk Measures for Capital Determination” In Annual Review of Financial Economics 7.1, 2015, pp. 301–337 DOI: 10.1146/annurev-financial-111914-042031
- “Systemic Cyber Risk: A Primer”, 2022
- “Handbook on Systemic Risk” Cambridge University Press, 2013 DOI: 10.1017/CBO9781139151184
- Axel Gandy and Luitgard A.M. Veraart “A Bayesian Methodology for Systemic Risk Assessment in Financial Networks” In Management Science 63.12, 2017, pp. 4428–4446 DOI: 10.1287/mnsc.2016.2546
- “Community structure in social and biological networks” In Proceedings of the National Academy of Sciences of the United States of America 99.12 National Academy of Sciences, Washington, DC, 2002, pp. 7821–7826 DOI: 10.1073/pnas.122653799
- “Propagation of cyber incidents in an insurance portfolio: counting processes combined with compartmental epidemiological models” In Scandinavian Actuarial Journal Taylor & Francis, 2021, pp. 1–24
- “Cyber-contagion model with network structure applied to insurance” In Insurance: Mathematics and Economics 107, 2022, pp. 88–101
- Caroline Hillairet, Anthony Réveillac and Mathieu Rosenbaum “An expansion formula for Hawkes processes and application to cyber-insurance derivatives” In Stochastic Processes and their Applications 160, 2023, pp. 89–119 DOI: https://doi.org/10.1016/j.spa.2023.02.012
- Hannes Hoffmann, Thilo Meyer-Brandis and Gregor Svindland “Risk-consistent conditional systemic risk measures” In Stochastic Processes and their Applications 126.7, 2016, pp. 2014–2037 DOI: https://doi.org/10.1016/j.spa.2016.01.002
- Hannes Hoffmann, Thilo Meyer-Brandis and Gregor Svindland “Strongly consistent multivariate conditional risk measures” In Mathematics and Financial Economics 12, 2018, pp. 413–444
- Thomas R. Hurd “Contagion! Systemic Risk in Financial Networks” Springer, 2016 DOI: 10.1007/978-3-319-33930-6
- Matthew O. Jackson and Agathe Pernoud “Systemic Risk in Financial Networks: A Survey” In Annual Review of Economics 13.1, 2021, pp. 171–202 DOI: 10.1146/annurev-economics-083120-111540
- “Dynamic structural percolation model of loss distribution for cyber risk of small and medium-sized enterprises for tree-based LAN topology” In Insurance: Mathematics and Economics 91, 2020, pp. 209–223
- István Z. Kiss, Joel C. Miller and Péter L. Simon “Mathematics of Epidemics on Networks” 46, Interdisciplinary Applied Mathematics Springer, 2017 DOI: 10.1007/978-3-319-50806-1
- “Finding shortest and nearly shortest path nodes in large substantially incomplete networks by hyperbolic mapping” In Nature Communications 14.186, 2023
- “Efficient Behavior of Small-World Networks” In Phys. Rev. Lett. 87 American Physical Society, 2001, pp. 198701 DOI: 10.1103/PhysRevLett.87.198701
- “Cyber-insurance survey” In Computer Science Review, 2017
- “A critical point for random graphs with a given degree sequence” In Random Structures & Algorithms 6.2-3, 1995, pp. 161–180
- Mark Newman “Networks” Oxford University Press, 2018
- “Epidemic processes in complex networks” In Reviews of Modern Physics 87, 2015, pp. 925–979
- Derek de Solla Price “A general theory of bibliometric and other cumulative advantage processes” In Journal of the American Society for Information Science 27.5, 1976, pp. 292–306
- Derek de Solla Price “Networks of Scientific Papers” In Science 149.3683, 1965, pp. 510–515
- “Resilience Decision-Making for Complex Systems” In ASCE-ASME J Risk and Uncert in Engrg Sys Part B Mech Engrg 6.2, 2020, pp. 020901 DOI: 10.1115/1.4044907
- Chaoming Song, Shlomo Havlin and Hernán A. Makse “Self-similarity of complex networks” In Nature 433, 2005, pp. 392–395
- Jonathan W. Welburn and Aaron M. Strong “Systemic Cyber Risk and Aggregate Impacts” In Risk Analysis 42.8, 2022, pp. 1606–1622
- “Cybersecurity insurance: Modeling and pricing” In North American Actuarial Journal 23.2 Taylor & Francis, 2019, pp. 220–249
- “A comprehensive model for cyber risk based on marked point processes and its application to insurance” In European Actuarial Journal, 2021, pp. 1–53
- “Is Accumulation Risk In Cyber Systematically Underestimated?”, 2023
- “Risk mitigation services in cyber insurance: optimal contract design and price structure” In The Geneva Papers on Risk and Insurance - Issues and Practice 48, 2023, pp. 502–547