Cybersecurity is an inseparable component of business operations in any industry that utilizes information systems. Hence, the problem of cybersecurity investment, defined by the cost-effectiveness of investing on cybersecurity countermeasures, is an important financial and operational decision for most businesses. We propose a modeling framework that incorporates major components relevant to cybersecurity practice, and study the characteristics of optimal cybersecurity investment decisions for a firm. The uncertainty in the problem is captured through a stochastic programming framework. A case study based on real cybersecurity practice of an organization is also presented, where the results cast managerial insights for cybersecurity investment that can be widely applicable in typical businesses.
Track: Student Paper Competition
Published in: 5th Annual International Conference on Industrial Engineering and Operations Management, Dubai, United Arab Emirates
Publisher: IEOM Society International
Date of Conference: March 3
-5
, 2015
ISBN: 978-0-9855497-2-5
ISSN/E-ISSN: 2169-8767