Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment

10/27/2022
by   Kevin Hu, et al.
0

This paper provides the first large-scale data-driven analysis to evaluate the predictive power of different attributes for assessing risk of cyberattack data breaches. Furthermore, motivated by rapid increase in third party enabled cyberattacks, the paper provides the first quantitative empirical evidence that digital supply-chain attributes are significant predictors of enterprise cyber risk. The paper leverages outside-in cyber risk scores that aim to capture the quality of the enterprise internal cybersecurity management, but augment these with supply chain features that are inspired by observed third party cyberattack scenarios, as well as concepts from network science research. The main quantitative result of the paper is to show that supply chain network features add significant detection power to predicting enterprise cyber risk, relative to merely using enterprise-only attributes. Particularly, compared to a base model that relies only on internal enterprise features, the supply chain network features improve the out-of-sample AUC by 2.3%. Given that each cyber data breach is a low probability high impact risk event, these improvements in the prediction power have significant value. Additionally, the model highlights several cybersecurity risk drivers related to third party cyberattack and breach mechanisms and provides important insights as to what interventions might be effective to mitigate these risks.

READ FULL TEXT
research
11/26/2019

Assessing Supply Chain Cyber Risks

Risk assessment is a major challenge for supply chain managers, as it po...
research
07/05/2022

Regularized Predictive Models for Beef Eating Quality of Individual Meals

Faced with changing markets and evolving consumer demands, beef industri...
research
05/23/2023

Software supply chain: review of attacks, risk assessment strategies and security controls

The software product is a source of cyber-attacks that target organizati...
research
03/27/2018

Network Science approach to Modelling Emergence and Topological Robustness of Supply Networks: A Review and Perspective

Due to the increasingly complex and interconnected nature of global supp...
research
01/27/2022

Accountability and Insurance in IoT Supply Chain

Supply chain security has become a growing concern in security risk anal...
research
06/21/2018

Towards a Reconceptualisation of Cyber Risk: An Empirical and Ontological Study

The prominence and use of the concept of cyber risk has been rising in r...
research
02/18/2021

NATOs Mission-Critical Space Capabilities under Threat: Cybersecurity Gaps in the Military Space Asset Supply Chain

The North Atlantic Treaty Organizations (NATO) public-private Space Asse...

Please sign up or login with your details

Forgot password? Click here to reset