Not logged in.

Contribution Details

Type Master's Thesis
Scope Discipline-based scholarship
Title MeritMiner4CI: A Novel Approach for Risk Assessment in Cyber Insurance Based on Process Mining
Organization Unit
Authors
  • Viktor Matejka
Supervisors
  • Muriel Figueredo Franco
  • Eder John Scheid
  • Burkhard Stiller
Language
  • English
Institution University of Zurich
Faculty Faculty of Business, Economics and Informatics
Date 2022
Abstract Text The market for cyber insurance seems to be at a turning point in the recent years. Premiums are surging at record rates with new claims continuing to be driven by ransomware attacks, as well as by insider threats. The cyber insurance capacity is becoming limited and it is clear that many challenges still need to be tackled in order to avoid market failure. For one, it is clear that traditional risk assessment methods currently applied do not sufficiently address the issues of information asymmetries and the adverse selection and moral hazard that go hand-in hand with them. Therefore, new approaches to audit and assess the level of self-protection of the insureds need to be developed. Taking this into account, this thesis focuses on the assessment of operational cyber risks related to failed internal processes and proposes a novel approach to apply the methods of process mining in cyber insurance. For this purpose, MeritMiner4CI approach was designed and developed. Also, the fundamental challenges and requirements of cyber insurance at the coverage level were clearly mapped to specific process mining methods. The MeritMiner4CI approach was evaluated by conducting a survey with experts and also by considering case study scenarios. The results of this survey provide strong indication that the analyses of the proposed method can be applied by practitioners and have an impact on the ratings of confidence factors that are applied in the industry. Furthermore, quantitative evaluations were conducted to evaluate the performance of the applied methods. Finally, this thesis also highlights how MeritMiner4CI can be integrated with other cybersecurity risk assessment approaches, such as SecRiskAI and MENTOR.
PDF File Download
Export BibTeX