What do we know about cyber risk and cyber risk insurance?
Abstract
Purpose
This paper aims to provide an overview of the main research topics in the emerging fields of cyber risk and cyber risk insurance. The paper also illustrates future research directions, from both academic and practical points of view.
Design/methodology/approach
The authors conduct a literature review on cyber risk and cyber risk insurance using a standardized search and identification process that has been used in various academic articles. Based upon this selection process, a database of 209 papers is created. The main research results findings are extracted and organized in seven clusters.
Findings
The results illustrate the immense difficulties to insure cyber risk, especially due to a lack of data and modelling approaches, the risk of change and incalculable accumulation risks. The authors discuss various ways to overcome these insurability limitations, such as mandatory reporting requirements, pooling of data or public–private partnerships in which the government covers parts of the risk.
Originality/value
Despite its increasing relevance for businesses at present, research on cyber risk is limited. Many papers can be found in the IT domain, but relatively little research has been done in the business and economics literature. The authors illustrate where research stands currently and outline directions for future research.
Keywords
Acknowledgements
This paper was prepared as part of the Geneva Association Cyber Stocktaking Initiative and greatly profited from discussion with numerous academics and practitioners. An extended working paper version of this paper, including all supplemental material, is available on the website of the Geneva Association. The authors are especially grateful to Daljitt Barn, Nick Beecroft, Maya Bundt, Eric Durand, José Fidalgo, David Ho, Ruo Jia, Kwangmin Jung, Benno Keller, Martin Lehmann, Philipp Lienau, Patrick Smolka, Fabian Sommerrock and Jan Wirfs for their valuable feedback and comments.
Citation
Eling, M. and Schnell, W. (2016), "What do we know about cyber risk and cyber risk insurance?", Journal of Risk Finance, Vol. 17 No. 5, pp. 474-491. https://doi.org/10.1108/JRF-09-2016-0122
Publisher
:Emerald Group Publishing Limited
Copyright © 2016, Emerald Group Publishing Limited