Towards effective cybersecurity resource allocation: the Monte Carlo predictive modelling approach
by Tesleem Fagade; Konstantinos Maraslis; Theo Tryfonas
International Journal of Critical Infrastructures (IJCIS), Vol. 13, No. 2/3, 2017

Abstract: Organisations invest in technical and procedural capabilities to ensure the confidentiality, integrity and availability of information assets and sustain business continuity at all times. However, given growing productive assets and limited protective security budgets, there is a need for deliberate evaluation of information security investment. Optimal resource allocation to security is often affected by intrinsically uncertain variables, leading to disparities in resource allocation decisions. We explored how Monte Carlo predictive simulation model can be used within the context of information technology to reduce these disparities. Using a conceptual enterprise as a case study and verifiable historical cost of security breaches as parametric values, our model shows why using conventional risk assessment approach as budgeting process can result in significant over/under allocation of resources for cyber capabilities. Our model can serve as a benchmark for policy and decision support to aid stakeholders in optimising resource allocation for cyber security investments.

Online publication date: Thu, 30-Nov-2017

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Critical Infrastructures (IJCIS):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com