Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms
Over the last decade, cybersecurity threats have drastically increased in scale, impact and frequency across the United States. As a result, companies and governments require active monitoring of their cyber risk. While cyber risk management frameworks such as the National Institute of Standards and...
Main Author: | |
---|---|
Other Authors: | |
Format: | Thesis |
Published: |
Massachusetts Institute of Technology
2022
|
Online Access: | https://hdl.handle.net/1721.1/144678 https://orcid.org/0000-0002-1121-7809 |
_version_ | 1826211558324174848 |
---|---|
author | Spiewak, Rebecca |
author2 | Weitzner, Daniel J. |
author_facet | Weitzner, Daniel J. Spiewak, Rebecca |
author_sort | Spiewak, Rebecca |
collection | MIT |
description | Over the last decade, cybersecurity threats have drastically increased in scale, impact and frequency across the United States. As a result, companies and governments require active monitoring of their cyber risk. While cyber risk management frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework are helpful, in practice this framework is actualized through formalized approaches to cyber risk measurements. While the emphasis on entity-level loss is valuable in the continued fight against cybercrime and acts of cyberterrorism, the individual-level impact is often neglected, to the detriment of everyday users of vulnerable technologies. Negative impacts to individuals as an outcome of organizations being hacked are often not captured today, thereby artificially excluding costs to individuals from loss calculations.
Through this body of research, we propose a novel approach to size negative externalities in relation to cybersecurity incidents. In contrast to prior research, this approach emphasizes the harm experienced by individuals rather than financial losses to enterprises. We present a new Taxonomy of Individual Cyber Harms, a formalized harm assessment methodology, and a cyber risk forecasting model to predict probable estimates of individual harms through a series of Monte Carlo Simulations. Through the analysis, we show that not only do harms exist for individuals as a result of cyber incidents, but that the extent of this harm is sizeable and can be greater than the harm to the entity for specific types of cyber incidents. Our results demonstrate that harms to individuals make up 42% of total losses experienced due to cyber attacks on US municipalities, or an additional 72% of harms currently captured. From a policy perspective, a discussion follows providing recommendations for avenues for remedy and redress for individuals who have experienced harm from cyber attacks. |
first_indexed | 2024-09-23T15:07:54Z |
format | Thesis |
id | mit-1721.1/144678 |
institution | Massachusetts Institute of Technology |
last_indexed | 2024-09-23T15:07:54Z |
publishDate | 2022 |
publisher | Massachusetts Institute of Technology |
record_format | dspace |
spelling | mit-1721.1/1446782022-08-30T03:12:25Z Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms Spiewak, Rebecca Weitzner, Daniel J. Reynolds, Taylor Massachusetts Institute of Technology. Institute for Data, Systems, and Society Over the last decade, cybersecurity threats have drastically increased in scale, impact and frequency across the United States. As a result, companies and governments require active monitoring of their cyber risk. While cyber risk management frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework are helpful, in practice this framework is actualized through formalized approaches to cyber risk measurements. While the emphasis on entity-level loss is valuable in the continued fight against cybercrime and acts of cyberterrorism, the individual-level impact is often neglected, to the detriment of everyday users of vulnerable technologies. Negative impacts to individuals as an outcome of organizations being hacked are often not captured today, thereby artificially excluding costs to individuals from loss calculations. Through this body of research, we propose a novel approach to size negative externalities in relation to cybersecurity incidents. In contrast to prior research, this approach emphasizes the harm experienced by individuals rather than financial losses to enterprises. We present a new Taxonomy of Individual Cyber Harms, a formalized harm assessment methodology, and a cyber risk forecasting model to predict probable estimates of individual harms through a series of Monte Carlo Simulations. Through the analysis, we show that not only do harms exist for individuals as a result of cyber incidents, but that the extent of this harm is sizeable and can be greater than the harm to the entity for specific types of cyber incidents. Our results demonstrate that harms to individuals make up 42% of total losses experienced due to cyber attacks on US municipalities, or an additional 72% of harms currently captured. From a policy perspective, a discussion follows providing recommendations for avenues for remedy and redress for individuals who have experienced harm from cyber attacks. S.M. 2022-08-29T16:04:08Z 2022-08-29T16:04:08Z 2022-05 2022-06-22T15:00:06.215Z Thesis https://hdl.handle.net/1721.1/144678 https://orcid.org/0000-0002-1121-7809 In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/ application/pdf Massachusetts Institute of Technology |
spellingShingle | Spiewak, Rebecca Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title | Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title_full | Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title_fullStr | Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title_full_unstemmed | Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title_short | Overlooking the Little Guy: An Analysis of Cyber Incidents and Individual Harms |
title_sort | overlooking the little guy an analysis of cyber incidents and individual harms |
url | https://hdl.handle.net/1721.1/144678 https://orcid.org/0000-0002-1121-7809 |
work_keys_str_mv | AT spiewakrebecca overlookingthelittleguyananalysisofcyberincidentsandindividualharms |