SearcharxivSearch

arXiv · 2411.18838

Contrasting the optimal resource allocation to cybersecurity and cyber insurance using prospect theory versus expected utility theory

Abstract

Protecting against cyber-threats is vital for every organization and can be done by investing in cybersecurity controls and purchasing cyber insurance. However, these are interlinked since insurance premiums could be reduced by investing more in cybersecurity controls. The expected utility theory and the prospect theory are two alternative theories explaining decision-making under risk and uncertainty, which can inform strategies for optimizing resource allocation. While the former is considered a rational approach, research has shown that most people make decisions consistent with the latter, including on insurance uptakes. We compare and contrast these two approaches to provide important insights into how the two approaches could lead to different optimal allocations resulting in differing risk exposure as well as financial costs. We introduce the concept of a risk curve and show that identifying the nature of the risk curve is a key step in deriving the optimal resource allocation.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Chaitanya Joshi, Jinming Yang, Sergeja Slapnicar, Ryan K L Ko. 2024-11-28. Contrasting the optimal resource allocation to cybersecurity and cyber insurance using prospect theory versus expected utility theory. https://arxiv.org/abs/2411.18838

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Identification in Linear Quantile Panel Models

This paper studies identification in linear quantile panel models with unrestricted individual heterogeneity when the number of time periods is fixed and small. We impose strict exogeneity, whereby the conditional quantile restriction holds given the individual's complete regressor history and latent individual effect, but otherwise allow the disturbances to be arbitrarily dependent over time.

econ.EM

Experimental Design for Policy Choice

We show how to optimally design experiments when the resulting data will be used to choose a welfare-maximizing policy subject to constraints. A decision maker seeks to maximize Bayes expected welfare by choosing a policy whose effects depend on an unknown finite-dimensional parameter. The decision maker has access to a first wave of experimental data with a fixed design but may choose the design of a second wave that will be collected before choosing the policy. The resulting experimental design--policy choice problem is a very high-dimensional dynamic program that is generally intractable in finite samples. We propose a tractable approximation based on the limit experiment and show it is asymptotically optimal using a new asymptotic representation theorem for adaptive experiments with continuous treatments. We apply the method to a conditional cash transfer experiment and demonstrate the potential for large gains from tailoring the experiment to the policy choice.

econ.EM

Designing Spatial Treatments

Spatial treatments are interventions assigned to locations potentially distinct from those of the responding units. We study their optimal design under a general model in which a unit's response diminishes with distance to a treated site. Our estimand of interest is an ``uncontaminated'' effect equal to the average impact of a single intervention site over all hypothetical sites. We propose a novel design based on a Mat\'{e}rn point process which separates treatments by a distance of at least $r$. A larger choice of $r$ reduces bias by separating interventions but increases variance by reducing their numerosity. We choose $r$ to maximize the rate of convergence of a Horvitz-Thompson estimator and prove that this is minimax rate-optimal. We provide weak conditions under which the estimator is asymptotically normal and propose a variance estimator.

econ.EM