用保险科技增强数据,为每家企业定制网络安全风险评估。
Entity-Specific Cyber Risk Assessment using InsurTech Empowered Risk Factors
- 引入保险科技特征,补足公开数据中企业特异性信息缺失
- 机器学习模型准确预测各类网络事件发生类型与年频率
- 结果透明可解释,适合保险公司和企业做风控决策
缺乏高质量的公开网络攻击数据限制了网络安全风险评估的实证研究与预测建模。由于企业不愿披露可能损害声誉或投资者信心的事件,这一问题长期存在。从精算角度出发,解决路径包括提升现有数据集质量和应用先进建模技术以优化数据利用。现有数据驱动方法普遍缺少实体特有的组织特征。为此,我们提出一种新型保险科技框架,通过融入企业特异性属性丰富网络事件数据。构建多标签分类模型预测事件类型(如隐私泄露、数据泄露、欺诈勒索、IT错误等),以及多输出回归模型估算其年度频率。虽尝试使用分类器链与回归器链探索事件类型间依赖关系,但未发现显著相关性。结合多种可解释机器学习方法,交叉验证保险科技衍生的风险因子。结果显示,融合保险科技特征后,事件发生预测与频率估计的鲁棒性显著优于仅使用传统因子的情况。该框架生成透明、个性化的网络安全风险画像,支持定制化承保与主动风险缓解,为保险机构与企业决策提供数据驱动支持。
原文摘要 · Abstract (English)
The lack of high-quality public cyber incident data limits empirical research and predictive modeling for cyber risk assessment. This challenge persists due to the reluctance of companies to disclose incidents that could damage their reputation or investor confidence. Therefore, from an actuarial perspective, potential resolutions conclude two aspects: the enhancement of existing cyber incident datasets and the implementation of advanced modeling techniques to optimize the use of the available data. A review of existing data-driven methods highlights a significant lack of entity-specific organizational features in publicly available datasets. To address this gap, we propose a novel InsurTech framework that enriches cyber incident data with entity-specific attributes. We develop various machine learning (ML) models: a multilabel classification model to predict the occurrence of cyber incident types (e.g., Privacy Violation, Data Breach, Fraud and Extortion, IT Error, and Others) and a multioutput regression model to estimate their annual frequencies. While classifier and regressor chains are implemented to explore dependencies among cyber incident types as well, no significant correlations are observed in our datasets. Besides, we apply multiple interpretable ML techniques to identify and cross-validate potential risk factors developed by InsurTech across ML models. We find that InsurTech empowered features enhance prediction occurrence and frequency estimation robustness compared to only using conventional risk factors. The framework generates transparent, entity-specific cyber risk profiles, supporting customized underwriting and proactive cyber risk mitigation. It provides insurers and organizations with data-driven insights to support decision-making and compliance planning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。