Source-linked AI summary

Future developments in cyber risk assessment for the internet of things

Petar Radanliev, David Charles De Roure, Razvan Nicolescu, Michael Huth, Rafael Mantilla Montalvo, Stacy Cannady, Peter Burnap

arXiv:1809.05229v1cs.CY

TL;DR

IoT cyber risk requires economic assessment that reflects diverse IoT vectors, vertices, and emerging vulnerabilities. The paper adapts CyVaR and MicroMort into an IoT risk model, tests it with more than 310,000 BullGuard IoT Scanner scans and Gartner device data, and concludes that acceptable economic-impact assessment is possible despite unresolved uncertainties.

  • Problem

    Existing cyber-risk research and standards provide limited coverage of the economic impact of cyber risk across diverse IoT verticals and IoT-specific risk vertices.

  • Method

    The paper combines CyVaR and MicroMort, re-categorizes IoT risk vectors and vertices, and develops an IoT MicroMort model for economic-impact assessment.

  • Results

    The model was tested and validated with more than 310,000 BullGuard IoT Scanner scans and Gartner data, using current-state and future-forecast calculations.

  • Takeaways & Limitations

    The study concludes that mathematical formalisms provide acceptable ways to assess the economic impact of IoT cyber risk despite challenges involving risk dependencies and interactions.

  • Takeaways & Limitations

    The model’s example calculations use total IoT-device counts even though the malware cases affect specific device classes, and sector-specific quantification requires additional data.

Abstract

from arXiv · show

This article is focused on the economic impact assessment of Internet of Things (IoT) and its associated cyber risks vectors and vertices - a reinterpretation of IoT verticals. We adapt to IoT both the Cyber Value at Risk model, a well-established model for measuring the maximum possible loss over a given time period, and the MicroMort model, a widely used model for predicting uncertainty through units of mortality risk. The resulting new IoT MicroMort for calculating IoT risk is tested and validated with real data from the BullGuard's IoT Scanner - over 310,000 scans - and the Garner report on IoT connected devices. Two calculations are developed, the current state of IoT cyber risk and the future forecasts of IoT cyber risk. Our work therefore advances the efforts of integrating cyber risk impact assessments and offer a better understanding of economic impact assessment for IoT cyber risk.

1. Introduction

The paper addresses the need to assess the economic impact of IoT cyber risk as adoption expands across diverse applications and attack surfaces. It proposes adapting CyVaR and MicroMort approaches to create reusable, IoT-specific economic risk models.

  • Motivation: IoT adoption is expanding across diverse sectors, while corporate adopters may lack clear estimates of its possible economic impact.The paper highlights financial markets, banks, healthcare, manufacturing, building automation, finance, insurance, logistics, and retail as relevant contexts.
  • Motivation: Increasing attack surfaces and capabilities, including threats such as Mirai, could make future IoT/IT attacks more severe than observed attacks.The paper frames future attack severity as an economic-impact assessment problem.
  • Contribution: The study adapts Cyber Value at Risk and MicroMort models to calculate the economic impact of IoT cyber risks.CyVaR measures maximum possible loss over a specified period, while MicroMort represents uncertainty through mortality-risk units.
  • Research question: Government and business strategies need economic analysis of cyber-attack costs and frequencies to evaluate whether IoT cybersecurity measures are sufficient.The proposed analysis is intended to inform frameworks for mitigating the economic impact of cyber risk in commercial IoT deployments.
  • Research gap: Because IoT verticals and their vulnerabilities differ substantially, existing pre-IoT assessment methodologies may overlook IoT-specific aspects of risk and impact.The paper therefore distinguishes IoT risk vectors and vertices and proposes a re-categorised impact model for complex IoT infrastructures.

2. Literature review

The literature review organizes cyber risk assessment around identification, estimation, and prioritization while showing that IoT introduces risks not covered by existing standards. It argues that impact assessment must account for complex dependencies, privacy, ownership, and economic consequences.

  • Existing approaches: Existing standards define trustworthiness and governance, but evolving cyber risk remains difficult to quantify through historical measures.The review describes risk-based adaptive assessment as requiring prediction of problems and impacts, planned actions, and reduced exposure.
  • Assessment taxonomy: The review classifies cyber risk assessment requirements into risk identification, risk estimation, and risk prioritization strategies.This taxonomy structures the review of impact-measurement methods and IoT cyber-risk requirements.
  • IoT-specific risk: IoT capabilities create cyber-risk types that existing cyber-risk assessment standards neither anticipate nor consider.The paper responds by identifying IoT-specific risk vertices and integrating them into a holistic impact-assessment model.
  • IoT-specific risk: IoT risk assessment must address dependencies across objects, networks, humans, and critical infrastructure, including effects on data ownership, privacy, and digital-asset lifespans.The review notes that digital assets can outlive their owners and that IoT integration creates ethical as well as economic questions.

3. Research methodology

The methodology combines literature review, taxonomy construction, SWOT analysis, and quantitative modeling. The quantitative model adapts CyVaR and MicroMort to assess IoT cyber-risk impact.

  • Method design: The study begins with a literature review that creates a taxonomic categorization of impact-assessment classes.The review supplies the conceptual structure for subsequent framework analysis and model development.
  • Method design: A SWOT analysis examines existing frameworks before the paper develops a new quantitative IoT impact-assessment model.This sequence is used to address the complexities of designing an assessment model for IoT cyber risk.
  • Quantitative model: The model adopts Cyber Value-at-Risk for measuring market cyber risk and MicroMort for defining individual risk units.The methodology combines multidisciplinary approaches with established risk-measurement methods.

4. Analysis of cyber risk frameworks, methods, systems and models

The framework analysis finds that existing methods differ in scope and quantification capability, leaving gaps in assessing high-risk digital-asset loss scenarios. These limitations motivate a unified approach integrating economic impact, IoT complexity, and risk measurement.

  • Framework comparison: CVSS translates expert judgments into numerical severity scores, but its basic formalism may create an unwarranted sense of certainty.Its 0–10 scoring is simplified into three color-coded levels, so different vulnerabilities may receive similar classifications.
  • Framework comparison: The reviewed approaches divide responsibilities across standards, quantitative models, questionnaires, vulnerability scores, supply-chain assessments, and enterprise processes.NIST covers documented assessment and management processes; FAIR and CyVaR provide quantitative approaches; OCTAVE, TARA, CVSS, Exostar, and CMMI address narrower needs.
  • Framework comparison: ISO promotes global standardization but depends on voluntary compliance and consensus across 161 countries and 778 technical committees and subcommittees.The paper identifies coordination and implementation as difficult while cyber risks evolve more quickly.
  • Quantitative models: CyVaR can use Monte Carlo simulations but requires data such as standard deviation, mean, and median of recorded cyber-attack losses.This data requirement is identified as a weakness in applying the model.
  • Cross-framework findings: Existing cyber-risk frameworks assess security posture but are not effective for high-risk loss scenarios centered on critical digital assets.The review also identifies inconsistency in cyber-risk measurement because methodologies lack a common point of reference.
  • Economic valuation: Economic impact assessment is complicated because digital assets can lose future value even after early detection and because cyber risk motivations may extend beyond financial gain.The paper therefore calls for models integrating cyber risk directly with economic functions and impact.

5. The model

The model combines established risk measures with IoT-specific asset, vertical, and vertex classifications to estimate economic cyber risk. It defines IoT MicroMort units and extends them toward Value-at-Risk calculations, while acknowledging substantial data and valuation constraints.

  • Risk representation: IoT cyber risk is represented through verticals, associated vertices, and margins, with probability terms used to estimate their impacts.The model distinguishes risk associated with an IoT vertical from risk associated with its vertices and defines conditional and marginal probabilities for these relationships.
  • Risk measurement: The framework combines MicroMort and Value-at-Risk methods to define IoT-specific risk units and estimate losses across digital assets.IoTMM2 represents the value of reducing a given IoTMM, while a 12-month IoTMM2 VaR represents an affordable loss limit from cyber incidents.
  • Asset classification: IoT assets are classified into core-value and operational assets, with digitised and born-digital assets distinguished to support economic valuation.The proposed International IoT Asset Classification is intended to enable profit and loss calculations for individual IoT assets.
  • IoT MicroMort: IoT MicroMortD denotes a one-in-a-million probability of digital death for a class D asset, valued by the amount an enterprise would pay to reduce that risk.Digital death is defined as loss of all economic value for the relevant asset class.
  • Data requirements: The proposed valuation may require years or decades of structured data collection because validation depends on broad data coverage and advanced analytics.The framework identifies non-technological barriers and the lack of statistically available residual IoTMM data as important constraints.

6. Applying the proposed model for IoT MicroMort calculations

The proposed IoT MicroMort model is applied to observed 2017 vulnerability data and forecast 2020 device and security-spending data. The calculations produce IoTMM estimates and a device-specific willingness-to-pay framework, but the resulting economic value remains approximate.

  • 2017 application: The model uses 310,000 BullGuard IoT Scanner scans and estimated connected-device totals to calculate the 2017 IoTMM.The scans identified 4.5 percent of nearly 14,000 devices as vulnerable, alongside an estimate of 378 million potentially vulnerable devices among 8.4 billion connected devices.
  • IoT MicroMort calculations: 0.045 in 2017 and 0.044 in 2020 are the calculated IoTMM values for the model’s current-state and forecast applications.The 2017 calculation uses estimated vulnerable devices among connected devices, while the 2020 value is forecast from available IoT data.
  • Economic valuation: Enterprise willingness to pay is defined as the cost of reducing one IoTMM for a specific device category over the relevant period.The paper frames this as the cost an enterprise may accept to avoid a one-in-a-million IoT risk.
  • Valuation limits: The 2020 IoTMM economic value is presented as guidance rather than a precise risk valuation because security-spending estimates and utility functions lack sufficient supporting data.The paper notes that applying total connected-device counts can produce values exceeding estimated IoT security spending.

7. Analysis of results

The model is illustrated with real or reported IoT data, including device-infection examples, but the analysis emphasizes that these calculations are provisional. Their precision is limited by missing classifications, broad device denominators, and sparse IoT cyber-risk data.

  • Model verification: Real-data calculations are used to verify that MicroMort can assess the economic impact of IoT cyber risk under the proposed model.The examples are presented as validation-oriented applications rather than definitive estimates of IoT-wide risk.
  • Scope and limitations: The model cannot yet provide precise IoT risk valuations because international asset classifications, key IoT cyber-risk factors, and statistically available residual IoTMM data are not established.The paper states that these missing foundations prevent more precise willingness-to-pay calculations.
  • Data limitations: IoT cyber-risk analysis is further constrained by scarce data on attacks, losses, profits, and insurance valuations across emerging IoT risk verticals.The paper notes that existing security-spending forecasts do not cover IoT, industrial control systems, or the industrial Internet of Things.
  • Case-study examples: The illustrative examples calculate IoT MicroMort values for malware affecting specific device populations, including Persirai-infected IP cameras.Persirai affected at least 1,250 IP camera models, with 600,000 infected hosts reported in 2017.
  • Case-study limitations: The example calculations use total IoT-device counts even when malware targets narrower device classes, creating a calculation flaw tied to the denominator.Persirai is limited to IP-based cameras, while Mirai targets DVRs, routers, and CCTV cameras; the authors distinguish this flaw from a flaw in the model itself.

8. Discussion

The discussion positions IoT MicroMort as a first quantitative model for IoT cyber-risk economic impact, while emphasizing that it should complement other models and sector-specific data. It also frames vectors, vertices, asset classification, and standards as foundations for more unified assessment.

  • 8. Discussion: The model adapts Cyber Value at Risk and MicroMort approaches to calculate IoT risk and distinguish IoT risk vectors from vertices.The study also proposes a taxonomic classification of risk-assessment requirements.
  • 8. Discussion: The proposed asset units comply with IDAC, while the study proposes an International IoT Asset Classification to categorize IoT digital assets.This classification is intended to support the proposed measurement framework.
  • 8. Discussion: Validation uses over 310,000 BullGuard IoT Scanner scans and Gartner data to calculate both current IoT risk and future risk associated with installed devices and emerging vulnerabilities.The two calculations address present conditions and future forecasts.
  • 8. Discussion: IoT MicroMort is presented as the first attempt to quantify the economic impact of IoT cyber risk, but not as an all-encompassing model.The authors state that it could work in combination with future IoT risk-quantification approaches.
  • 8. Discussion: The authors retain established risk frameworks and models as complementary tools because economic cyber-risk assessment requires multiple calculations rather than a single measure.They specifically note inherited weaknesses from MicroMort and Cyber Value at Risk.

9. Conclusion

The conclusion argues that IoT cyber-risk economic impact can be assessed with mathematical formalisms centered on a future-oriented CyVaR approach. It presents IoT MicroMort as a unified quantitative framework, while limiting its sector-specific validity because individual sectors and products require their own data.

  • 9. Conclusion: The study concludes that acceptable assessment of IoT cyber-risk economic impact is possible despite uncertainties about cyber-risk types, dependencies, and interactions.Its mathematical formalism focuses on evaluating the future rather than explaining the past through historical analysis.
  • 9. Conclusion: The proposed framework combines new risk metrics, valuation methods, regulatory and standardization needs, asset classifications, and IoT-specific risk factors.The conclusion identifies IIoTAC and KIoTCRF as components of this broader assessment approach.
  • 9. Conclusion: The adapted CyVaR determines maximum-loss sensitivity and adjusts acceptable IoT risk levels using metrics derived from new operating conditions.The model is described as integrating established risk approaches with existing cyber-risk frameworks.
  • 9. Conclusion: IoT MicroMort provides an overall quantitative description of IoT risk and can be adapted to specific sectors and products, but those applications require individual quantification and data.The article therefore presents premises for a unified approach rather than sector-specific risk estimates.
  • 9. Conclusion: The model calculates event probabilities rather than absolute event values, and missing IIoTAC and KIoTCRF prevent absolute-certainty validation of MicroMort probabilities.Unknown future vulnerabilities and unidentified exploiters remain a major valuation challenge.
Loading 1809.05229v1…