What language do CERTs need to speak to interact efficiently with insurers? Harmonising the quantification of harm
WHEN DOES AN INCIDENT… …cost someone money?
HARMONISE ON HARM/RISK Severity Frequency Technical quantum of harm Actuarial Questions: Tb/s Is DDoS more common on weekends? Which countries pay ransomware more Records lost often? Hours of DFIR How many breaches in 2016? Economic quantum of harm Predictive $ loss per Gb/s Are gaming companies more likely suffer a DDoS attack than universities? Price per record Will breaches be less frequent but larger and more costly in 2017 Ransomware payout
PREDICTIVE ANALYTICS
SECTORAL BREAKDOWN OF BREACHES
ACCUMULATION Technical Legal Attacker
Recommend
More recommend