A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs

作者:

Highlights:

• A System Dynamics approach to SMEs cyber risk assessment and evaluation (SMECRA) based on literature and the NIST framework

• SMECRA has a dynamic and reliable nature, being based on a System Dynamics simulation model

• SMECRA is customizable and reliable, as it is based on cybersecurity literature and standards, affordable and easy to use

• SMECRA can support SMEs in investment decisions and in their transition to a better risk posture

• SMECRA can support also third parties (banks, insurances, …) in assessing SMEs risk profiles and their potential to improve

摘要

The growing amount of cyberspace threats highlights the need to evaluate cybersecurity risks and to plan for effective investments. One internationally recognized document for cybersecurity risk management is the framework for Improving Critical Infrastructure Cybersecurity by the US National Institute of Standards and Technology (NIST). It provides guidelines, best practices and standards for cybersecurity risk management. Nevertheless, as other self-assessment frameworks, it produces a static view of an organization's cyber posture and does not capture the dynamics of organizational changes and cyberattacks. Moreover, the current situation sees small and medium enterprises (SMEs) in a critical position since they need to manage their cybersecurity while usually not being skilled or equipped enough to internalize this process. Therefore, there is a need for a practical and easily applicable model able to identify a cybersecurity risk profile and its dynamics. This study proposes a system dynamics methodology and tool (SMECRA - SME Cyber Risk Assessment) for supporting cybersecurity investment decisions for SMEs through the evaluation of cyber risk and previous investments. SMECRA addresses dynamic organizational complexity and can be used to assess cyber risks and related dynamics over time. Three case studies demonstrate its capability to assess a SME's cybersecurity status and to evaluate investments impacts on an organization's risk profile, raising cybersecurity awareness. This study is important for SMEs wishing to manage their own cybersecurity risk and for insurance companies in their economic evaluation of residual risks that SMEs wish to externalize.

论文关键词:Cybersecurity,SME,Risk assessment,Risk management,System dynamics,Modeling & simulation

论文评审过程:Received 26 June 2020, Revised 24 April 2021, Accepted 26 April 2021, Available online 29 April 2021, Version of Record 13 June 2021.

论文官网地址:https://doi.org/10.1016/j.dss.2021.113580