Risk mitigation services in cyber insurance: optimal contract design and price structure.
Geneva Pap Risk Insur Issues Pract
; 48(2): 502-547, 2023.
Article
en En
| MEDLINE
| ID: mdl-37207020
As the cyber insurance market is expanding and cyber insurance policies continue to mature, the potential of including pre-incident and post-incident services into cyber policies is being recognised by insurers and insurance buyers. This work addresses the question of how such services should be priced from the insurer's viewpoint, i.e. under which conditions it is rational for a profit-maximising, risk-neutral or risk-averse insurer to share the costs of providing risk mitigation services. The interaction between insurance buyer and seller is modelled as a Stackelberg game, where both parties use distortion risk measures to model their individual risk aversion. After linking the notions of pre-incident and post-incident services to the concepts of self-protection and self-insurance, we show that when pricing a single contract, the insurer would always shift the full cost of self-protection services to the insured; however, this does not generally hold for the pricing of self-insurance services or when taking a portfolio viewpoint. We illustrate the latter statement using toy examples of risks with dependence mechanisms representative in the cyber context. Supplementary Information: The online version contains supplementary material available at 10.1057/s41288-023-00289-7.
Texto completo:
1
Banco de datos:
MEDLINE
Tipo de estudio:
Etiology_studies
/
Health_economic_evaluation
/
Risk_factors_studies
Idioma:
En
Año:
2023
Tipo del documento:
Article