{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T06:50:15Z","timestamp":1781938215833,"version":"3.54.5"},"reference-count":73,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T00:00:00Z","timestamp":1781913600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T00:00:00Z","timestamp":1781913600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","award":["101128013"],"award-info":[{"award-number":["101128013"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The cyber threat landscape is evolving with increasing sophistication, making robust risk management strategies essential. Cyber insurance has emerged as a key mechanism for organizations to transfer risk. While not yet mandatory, recent regulatory trends are encouraging the adoption of multiple technologies, potentially paving the way for broader implementation. However, traditional cyber insurance underwriting still relies heavily on questionnaire-based risk assessments, lacking a truly data-driven approach. This gap has received limited attention in existing research. In this survey we examine data-driven methodologies for cyber insurance as a critical component of modern risk management. We systematically review the literature on data sources, data collection practices, risk calculation methods, and pricing strategies. Traditional actuarial approaches are analyzed and contrasted with emerging AI-enabled methods, including supervised learning models, predictive analytics, and simulation-based techniques that enhance the estimation of incident likelihood and severity. We identify key challenges, such as data quality, lack of standardization, constrained data sharing, and model interpretability, and outline opportunities for future work aimed at integrating empirical, automated analyses into underwriting and pricing workflows. Overall, this survey offers a structured overview of existing approaches and highlights directions for developing more data-driven and AI-supported approaches to cyber insurance risk management.<\/jats:p>","DOI":"10.1007\/s10207-026-01275-5","type":"journal-article","created":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T05:58:34Z","timestamp":1781935114000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Risk management for cyber insurance: a survey for data-driven approaches with the use of AI"],"prefix":"10.1007","volume":"25","author":[{"given":"Antonios","family":"Paragioudakis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nikos","family":"Komninos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michail","family":"Smyrlis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georgios","family":"Spanoudakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christos","family":"Kloukinas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,20]]},"reference":[{"key":"1275_CR1","unstructured":"ISO\/IEC 27005:2022 Information security, cybersecurity and privacy protection \u2013 Information security risk management (2022). https:\/\/www.iso.org\/standard\/80585.html"},{"key":"1275_CR2","doi-asserted-by":"publisher","DOI":"10.1145\/3676283","author":"R Adriko","year":"2024","unstructured":"Adriko, R., Nurse, J.R.C.: Does cyber insurance promote cyber security best practice? An analysis based on insurance application forms. Digital Threats (2024). https:\/\/doi.org\/10.1145\/3676283","journal-title":"Digital Threats"},{"key":"1275_CR3","doi-asserted-by":"publisher","unstructured":"Alberts, C.J., Behrens, S.G., Pethia, R.D., Wilson, W.R.: Operationally critical threat, asset, and vulnerability evaluation (OCTAVE) framework, version 1.0). Tech. rep., Carnegie Mellon University (2018). https:\/\/doi.org\/10.1184\/R1\/6575906.v1","DOI":"10.1184\/R1\/6575906.v1"},{"key":"1275_CR4","doi-asserted-by":"publisher","first-page":"100989","DOI":"10.1016\/j.jfs.2022.100989","volume":"60","author":"I Aldasoro","year":"2022","unstructured":"Aldasoro, I., Gambacorta, L., Giudici, P., Leach, T.: The drivers of cyber risk. J. Financ. Stab. 60, 100989 (2022). https:\/\/doi.org\/10.1016\/j.jfs.2022.100989","journal-title":"J. Financ. Stab."},{"issue":"1","key":"1275_CR5","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1186\/s42400-021-00088-4","volume":"4","author":"S Arakelyan","year":"2021","unstructured":"Arakelyan, S., Arasteh, S., Hauser, C., Kline, E., Galstyan, A.: Bin2vec: learning representations of binary executable programs for security tasks. Cybersecurity 4(1), 26 (2021). https:\/\/doi.org\/10.1186\/s42400-021-00088-4","journal-title":"Cybersecurity"},{"key":"1275_CR6","doi-asserted-by":"publisher","unstructured":"Arasteh, S., Mirkovic, J., Raghothaman, M., Hauser, C.: BinHunter: A fine-grained graph representation for localizing vulnerabilities in binary executables*. In: 2024 Annual Computer Security Applications Conference (ACSAC), 1062\u20131074 (2024). https:\/\/doi.org\/10.1109\/ACSAC63791.2024.00087","DOI":"10.1109\/ACSAC63791.2024.00087"},{"issue":"1","key":"1275_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s13385-023-00341-9","volume":"13","author":"K Awiszus","year":"2023","unstructured":"Awiszus, K., Knispel, T., Penner, I., Svindland, G., Vo\u00df, A., Weber, S.: Modeling and pricing cyber insurance. Eur. Actuar. J. 13(1), 1\u201353 (2023). https:\/\/doi.org\/10.1007\/s13385-023-00341-9","journal-title":"Eur. Actuar. J."},{"key":"1275_CR8","doi-asserted-by":"publisher","first-page":"176124","DOI":"10.1109\/ACCESS.2024.3506332","volume":"12","author":"A Aziz","year":"2024","unstructured":"Aziz, A., Munir, K.: Anomaly detection in logs using deep learning. IEEE Access 12, 176124\u2013176135 (2024). https:\/\/doi.org\/10.1109\/ACCESS.2024.3506332","journal-title":"IEEE Access"},{"key":"1275_CR9","doi-asserted-by":"publisher","unstructured":"Aziz, B., Suhardi, Kurnia: A systematic literature review of cyber insurance challenges. In: 2020 International Conference on Information Technology Systems and Innovation (ICITSI), 357\u2013363 (2020). https:\/\/doi.org\/10.1109\/ICITSI50517.2020.9264966","DOI":"10.1109\/ICITSI50517.2020.9264966"},{"key":"1275_CR10","doi-asserted-by":"publisher","DOI":"10.3390\/computers14100430","author":"T Babenko","year":"2025","unstructured":"Babenko, T., Kolesnikova, K., Abramkina, O., Vitulyova, Y.: Automated OSINT techniques for digital asset discovery and cyber risk assessment. Computers (2025). https:\/\/doi.org\/10.3390\/computers14100430","journal-title":"Computers"},{"key":"1275_CR11","doi-asserted-by":"publisher","unstructured":"Branley-Bell, D., Coventry, L., Briggs, P.: Cyber insurance from the stakeholder\u2019s perspective: A qualitative analysis of barriers and facilitators to adoption. In: Proceedings of the 2022 European Symposium on Usable Security, EuroUSEC \u201922, p. 151\u2013159. Association for Computing Machinery, New York, NY, USA (2022). https:\/\/doi.org\/10.1145\/3549015.3554206","DOI":"10.1145\/3549015.3554206"},{"issue":"1","key":"1275_CR12","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1002\/qre.3411","volume":"40","author":"MC Calzarossa","year":"2024","unstructured":"Calzarossa, M.C., Giudici, P., Zieni, R.: Explainable machine learning for phishing feature detection. Qual. Reliab. Eng. Int. 40(1), 362\u2013373 (2024). https:\/\/doi.org\/10.1002\/qre.3411","journal-title":"Qual. Reliab. Eng. Int."},{"issue":"1","key":"1275_CR13","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1080\/23738871.2017.1296878","volume":"2","author":"M Camillo","year":"2017","unstructured":"Camillo, M.: Cyber risk and the changing role of insurance. J. Cyber Policy 2(1), 53\u201363 (2017). https:\/\/doi.org\/10.1080\/23738871.2017.1296878","journal-title":"J. Cyber Policy"},{"key":"1275_CR14","doi-asserted-by":"publisher","DOI":"10.3390\/risks13080144","author":"M Carannante","year":"2025","unstructured":"Carannante, M., Mazzoccoli, A.: An analytical review of cyber risk management by insurance companies: a mathematical perspective. Risks (2025). https:\/\/doi.org\/10.3390\/risks13080144","journal-title":"Risks"},{"key":"1275_CR15","doi-asserted-by":"publisher","first-page":"104439","DOI":"10.1016\/j.cose.2025.104439","volume":"154","author":"P Cheimonidis","year":"2025","unstructured":"Cheimonidis, P., Rantos, K.: A novel proactive and dynamic cyber risk assessment methodology. Comp. Secur. 154, 104439 (2025). https:\/\/doi.org\/10.1016\/j.cose.2025.104439","journal-title":"Comp. Secur."},{"key":"1275_CR16","doi-asserted-by":"publisher","unstructured":"Chen, Z., Liu, J., Gu, W., Su, Y., Lyu, M.R.: Experience report: Deep learning-based system log analysis for anomaly detection (2022). https:\/\/doi.org\/10.48550\/arXiv.2107.05908","DOI":"10.48550\/arXiv.2107.05908"},{"issue":"1","key":"1275_CR17","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/s42979-021-00858-4","volume":"3","author":"L Coppolino","year":"2021","unstructured":"Coppolino, L., Sgaglione, L., D\u2019Antonio, S., Magliulo, M., Romano, L., Pacelli, R.: Risk assessment driven use of advanced SIEM technology for cyber protection of critical e-health processes. SN Computer Sci. 3(1), 16 (2021). https:\/\/doi.org\/10.1007\/s42979-021-00858-4","journal-title":"SN Computer Sci."},{"key":"1275_CR18","doi-asserted-by":"publisher","first-page":"698","DOI":"10.1057\/s41288-022-00266-6","volume":"47","author":"F Cremer","year":"2022","unstructured":"Cremer, F., Sheehan, B., Fortmann, M., et al.: Cyber risk and cybersecurity: a systematic review of data availability. The Geneva Papers on Risk and Insurance - Issues and Practice 47, 698\u2013736 (2022). https:\/\/doi.org\/10.1057\/s41288-022-00266-6","journal-title":"The Geneva Papers on Risk and Insurance - Issues and Practice"},{"key":"1275_CR19","doi-asserted-by":"publisher","unstructured":"Dambra, S., Bilge, L., Balzarotti, D.: SoK: Cyber insurance \u2013 technical challenges and a system security roadmap. In: 2020 IEEE Symposium on Security and Privacy (SP), 1367\u20131383 (2020). https:\/\/doi.org\/10.1109\/SP40000.2020.00019","DOI":"10.1109\/SP40000.2020.00019"},{"key":"1275_CR20","doi-asserted-by":"publisher","unstructured":"Dontu, S., Vallabhaneni, R., Addula, S.R., Kumar\u00a0Pareek, P., Hussein, R.R.: Enhanced adaptive butterfly optimizer based feature selection for protecting the data in industry based wsn. In: 2024 International Conference on Intelligent Algorithms for Computational Intelligence Systems (IACIS), 1\u20136 (2024). https:\/\/doi.org\/10.1109\/IACIS61494.2024.10721956","DOI":"10.1109\/IACIS61494.2024.10721956"},{"key":"1275_CR21","doi-asserted-by":"publisher","unstructured":"Du, M., Li, F., Zheng, G., Srikumar, V.: DeepLog: Anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201917, p. 1285\u20131298. Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3133956.3134015","DOI":"10.1145\/3133956.3134015"},{"key":"1275_CR22","doi-asserted-by":"publisher","unstructured":"Dusane, H.N., Karyakarte, M.: Evaluating cyber risk insurance frameworks: Bridging cybersecurity threats with financial risk strategies through actuarial modeling and adaptive resilience. In: 2025 IEEE International Conference on Blockchain and Distributed Systems Security (ICBDS), 1\u20137 (2025). https:\/\/doi.org\/10.1109\/ICBDS67396.2025.11376756","DOI":"10.1109\/ICBDS67396.2025.11376756"},{"key":"1275_CR23","unstructured":"European Union, 2024: The EU Artificial Intelligence Act. https:\/\/artificialintelligenceact.eu\/ Accessed: 07-03-2026"},{"key":"1275_CR24","doi-asserted-by":"publisher","unstructured":"Fieblinger, R., Alam, M.T., Rastogi, N.: Actionable cyber threat intelligence using knowledge graphs and large language models. In: 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS & PW), 100\u2013111 (2024). https:\/\/doi.org\/10.1109\/EuroSPW61312.2024.00018","DOI":"10.1109\/EuroSPW61312.2024.00018"},{"key":"1275_CR25","unstructured":"FIRST.Org, 2023: Common Vulnerability Scoring System (CVSS). https:\/\/www.first.org\/cvss\/ Accessed: 04-03-2026"},{"key":"1275_CR26","unstructured":"FIRST.Org, 2025: Exploit Prediction Scoring System (EPSS). https:\/\/www.first.org\/epss\/ Accessed: 04-03-2026"},{"key":"1275_CR27","doi-asserted-by":"publisher","unstructured":"Franco, M.F., Mullick, A.R., Jha, S.: QBER: Quantifying cyber risks for strategic decisions (2024). https:\/\/doi.org\/10.48550\/arXiv.2405.03513","DOI":"10.48550\/arXiv.2405.03513"},{"issue":"3","key":"1275_CR28","doi-asserted-by":"publisher","first-page":"101059","DOI":"10.1016\/j.rie.2025.101059","volume":"79","author":"U Franke","year":"2025","unstructured":"Franke, U., Orlando, A.: Interdependent cyber risk and the role of insurers. Res. Econ. 79(3), 101059 (2025). https:\/\/doi.org\/10.1016\/j.rie.2025.101059","journal-title":"Res. Econ."},{"key":"1275_CR29","doi-asserted-by":"publisher","unstructured":"Giudici, P., Kolesnikov, V.: Safe AI metrics: An integrated approach. Machine Learning with Applications 23, 100821 (2026). https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266682702500204X. https:\/\/doi.org\/10.1016\/j.mlwa.2025.100821","DOI":"10.1016\/j.mlwa.2025.100821"},{"issue":"3","key":"1275_CR30","doi-asserted-by":"publisher","first-page":"1318","DOI":"10.1002\/qre.2939","volume":"38","author":"P Giudici","year":"2022","unstructured":"Giudici, P., Raffinetti, E.: Explainable AI methods in cyber risk management. Qual. Reliab. Eng. Int. 38(3), 1318\u20131326 (2022). https:\/\/doi.org\/10.1002\/qre.2939","journal-title":"Qual. Reliab. Eng. Int."},{"key":"1275_CR31","doi-asserted-by":"publisher","unstructured":"Grari, V., Charpentier, A., Detyniecki, M.: A fair pricing model via adversarial learning (2022). https:\/\/doi.org\/10.48550\/arXiv.2202.12008","DOI":"10.48550\/arXiv.2202.12008"},{"issue":"5","key":"1275_CR32","doi-asserted-by":"publisher","first-page":"5648","DOI":"10.1109\/TDSC.2025.3571045","volume":"22","author":"K Hu","year":"2025","unstructured":"Hu, K., Levi, R., Yahalom, R., Zerhouni, E.G.: Supply chain characteristics as predictors of cyber risk: a machine-learning assessment. IEEE Trans. Depend. Secure Comput. 22(5), 5648\u20135657 (2025). https:\/\/doi.org\/10.1109\/TDSC.2025.3571045","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"1275_CR33","unstructured":"IBM, Institute, P.: Cost of a Data Breach Report 2025: The AI Oversight Gap. https:\/\/www.ibm.com\/downloads\/documents\/us-en\/131cf87b20b31c91 (2025). Accessed: 04-03-2026"},{"key":"1275_CR34","unstructured":"IBM, 2025: Cost of a data breach: The industrial sector. https:\/\/www.ibm.com\/think\/insights\/cost-of-a-data-breach-industrial-sector Accessed: 04-03-2026"},{"key":"1275_CR35","unstructured":"Institution, F.: Factor analysis of information risk (FAIR) model. https:\/\/www.fairinstitute.org\/hubfs\/Standards (2025). Accessed: 04-03-2026"},{"key":"1275_CR36","unstructured":"ISACA: COBIT 2019 Framework: Introduction and Methodology. ISACA, Schaumburg, IL (2019)"},{"key":"1275_CR37","doi-asserted-by":"publisher","unstructured":"Jawhar, S., Kimble, C.E., Miller, J.R., Bitar, Z.: Enhancing cyber resilience with AI-powered cyber insurance risk assessment. In: 2024 IEEE 14th Annual Computing and Communication Workshop and Conference (CCWC), 0435\u20130438 (2024). https:\/\/doi.org\/10.1109\/CCWC60891.2024.10427965","DOI":"10.1109\/CCWC60891.2024.10427965"},{"key":"1275_CR38","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-08-2022-0139","author":"K Kannel\u00f8nning","year":"2023","unstructured":"Kannel\u00f8nning, K., Katsikas, S.: A systematic literature review of how cybersecurity-related behavior has been assessed. Inform. Comput. Secur. (2023). https:\/\/doi.org\/10.1108\/ICS-08-2022-0139","journal-title":"Inform. Comput. Secur."},{"key":"1275_CR39","doi-asserted-by":"publisher","unstructured":"Kasula, V. K., Yenugula, M., Konda, B., Yadulla, A. R., Tumma, C., Rakki, S.B.: Federated learning with secure aggregation for privacy-preserving deep learning in IoT environments. 1\u20137 (2025). https:\/\/doi.org\/10.1109\/ICCA65395.2025.11011120","DOI":"10.1109\/ICCA65395.2025.11011120"},{"key":"1275_CR40","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121599","author":"AN Kia","year":"2024","unstructured":"Kia, A.N., Murphy, F., Sheehan, B., Shannon, D.: A cyber risk prediction model using common vulnerabilities and exposures. Expert Syst. Appl. (2024). https:\/\/doi.org\/10.1016\/j.eswa.2023.121599","journal-title":"Expert Syst. Appl."},{"key":"1275_CR41","doi-asserted-by":"publisher","unstructured":"Kumar, S., deWitte, P., Gu, G.: Incentivizing security excellence in cyber liability insurance. In: 2025 IEEE 10th European Symposium on Security and Privacy (EuroS&P), 251\u2013267 (2025). https:\/\/doi.org\/10.1109\/EuroSP63326.2025.00023","DOI":"10.1109\/EuroSP63326.2025.00023"},{"key":"1275_CR42","doi-asserted-by":"publisher","first-page":"110689","DOI":"10.1016\/j.asoc.2023.110689","volume":"146","author":"Y Lee","year":"2023","unstructured":"Lee, Y., Kim, J., Kang, P.: LAnoBERT: system log anomaly detection based on bert masked language model. Appl. Soft Comput. 146, 110689 (2023). https:\/\/doi.org\/10.1016\/j.asoc.2023.110689","journal-title":"Appl. Soft Comput."},{"key":"1275_CR43","doi-asserted-by":"publisher","DOI":"10.3390\/risks12050083","author":"C Lef\u00e8vre","year":"2024","unstructured":"Lef\u00e8vre, C., Tamturk, M., Utev, S., Carenzo, M.: Cyber risk in insurance: a quantum modeling. Risks (2024). https:\/\/doi.org\/10.3390\/risks12050083","journal-title":"Risks"},{"key":"1275_CR44","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.insmatheco.2022.05.003","volume":"106","author":"M Malavasi","year":"2022","unstructured":"Malavasi, M., Peters, G.W., Shevchenko, P.V., Tr\u00fcck, S., Jang, J., Sofronov, G.: Cyber risk frequency, severity and insurance viability. Insur.: Math. Econ. 106, 90\u2013114 (2022). https:\/\/doi.org\/10.1016\/j.insmatheco.2022.05.003","journal-title":"Insur.: Math. Econ."},{"key":"1275_CR45","doi-asserted-by":"publisher","DOI":"10.3390\/risks11090154","author":"A Mazzoccoli","year":"2023","unstructured":"Mazzoccoli, A.: Optimal cyber security investment in a mixed risk management framework: examining the role of cyber insurance and expenditure analysis. Risks (2023). https:\/\/doi.org\/10.3390\/risks11090154","journal-title":"Risks"},{"key":"1275_CR46","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103162","author":"G Mott","year":"2023","unstructured":"Mott, G., Turner, S., Nurse, J.R., MacColl, J., Sullivan, J., Cartwright, A., Cartwright, E.: Between a rock and a hard(ening) place: Cyber insurance in the ransomware era. Comput. Secur. (2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103162","journal-title":"Comput. Secur."},{"issue":"2","key":"1275_CR47","doi-asserted-by":"publisher","first-page":"1470","DOI":"10.5281\/zenodo.10776750","volume":"9","author":"M Muthukrishnan","year":"2024","unstructured":"Muthukrishnan, M., Ikram Ahamed, M., Naveen, P.: Machine learning for cybersecurity threat detection and prevention. Int. J. Innov. Sci. Res. Technol. (IJISRT) 9(2), 1470\u20131476 (2024). https:\/\/doi.org\/10.5281\/zenodo.10776750","journal-title":"Int. J. Innov. Sci. Res. Technol. (IJISRT)"},{"key":"1275_CR48","doi-asserted-by":"publisher","unstructured":"National Institute of Standards and Technology: The NIST cybersecurity framework (CSF) 2.0. NIST Cybersecurity White Paper CSWP 29 (2024). https:\/\/doi.org\/10.6028\/NIST.CSWP.29","DOI":"10.6028\/NIST.CSWP.29"},{"key":"1275_CR49","unstructured":"National Institute of Standards and Technology (NIST), 2023: AI Risk Management Framework. https:\/\/www.nist.gov\/itl\/ai-risk-management-framework Accessed: 07-03-2026"},{"key":"1275_CR50","doi-asserted-by":"publisher","unstructured":"Nurse, J.R., Axon, L., Erola, A., Agrafiotis, I., Goldsmith, M., Creese, S.: The Data that Drives Cyber Insurance: A Study into the Underwriting and Claims Processes. In: 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), pp. 1\u20138 (2020). https:\/\/doi.org\/10.1109\/CyberSA49311.2020.9139703","DOI":"10.1109\/CyberSA49311.2020.9139703"},{"key":"1275_CR51","unstructured":"Organisation for Economic Co-operation and Development (OECD), 2024: AI principles. https:\/\/www.oecd.org\/en\/topics\/sub-issues\/ai-principles.html Accessed: 07-03-2026"},{"key":"1275_CR52","doi-asserted-by":"publisher","unstructured":"Ott, H., Bogatinovski, J., Acker, A., Nedelkoski, S., Kao, O.: Robust and transferable anomaly detection in log data using pre-trained language models (2021). https:\/\/doi.org\/10.48550\/arXiv.2102.11570","DOI":"10.48550\/arXiv.2102.11570"},{"key":"1275_CR53","doi-asserted-by":"publisher","unstructured":"Paragioudakis, A., Smyrlis, M., Spanoudakis, G.: ERMIS: A cybersecurity market for assurance and insurance-as-a-service. In: 2025 IEEE International Conference on Cyber Security and Resilience (CSR), pp. 765\u2013770 (2025). https:\/\/doi.org\/10.1109\/CSR64739.2025.11130152","DOI":"10.1109\/CSR64739.2025.11130152"},{"key":"1275_CR54","doi-asserted-by":"publisher","DOI":"10.3390\/risks10120222","author":"L Pavl\u00edk","year":"2022","unstructured":"Pavl\u00edk, L., Ficek, M., Rak, J.: Dynamic assessment of cyber threats in the field of insurance. Risks (2022). https:\/\/doi.org\/10.3390\/risks10120222","journal-title":"Risks"},{"key":"1275_CR55","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.15793533","author":"CP Ratnawat","year":"2025","unstructured":"Ratnawat, C.P.: Revolutionizing cyber insurance: AI-driven risk scorecards for SMEs. Sarcouncil J. Multidiscipl. (2025). https:\/\/doi.org\/10.5281\/zenodo.15793533","journal-title":"Sarcouncil J. Multidiscipl."},{"issue":"3","key":"1275_CR56","doi-asserted-by":"publisher","first-page":"618","DOI":"10.3390\/analytics2030035","volume":"2","author":"MS Rich","year":"2023","unstructured":"Rich, M.S.: Cyberpsychology: a longitudinal analysis of cyber adversarial tactics and techniques. Analytics 2(3), 618\u2013655 (2023). https:\/\/doi.org\/10.3390\/analytics2030035","journal-title":"Analytics"},{"key":"1275_CR57","unstructured":"Sadefo\u00a0Kamdem, J., Selambi, D.: Cyber-risk forecasting using machine learning models and generalized extreme value distributions (2022). https:\/\/hal.science\/hal-03814979"},{"key":"1275_CR58","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101593","author":"P Sakshyam","year":"2019","unstructured":"Sakshyam, P., Daniel, W.W., Aron, L., Andrew, F., Emmanouil, P.: Post-incident audits on cyber insurance discounts. Comput. Secur. (2019). https:\/\/doi.org\/10.1016\/j.cose.2019.101593","journal-title":"Comput. Secur."},{"key":"1275_CR59","doi-asserted-by":"publisher","unstructured":"Saravanan, S., Menon, A., Saravanan, K., Hariharan, S., Nelson, L., Gopalakrishnan, J.: Cybersecurity audits for emerging and existing cutting edge technologies. In: 2023 11th International Conference on Intelligent Systems and Embedded Design (ISED), 1\u20137 (2023). https:\/\/doi.org\/10.1109\/ISED59382.2023.10444536","DOI":"10.1109\/ISED59382.2023.10444536"},{"key":"1275_CR60","doi-asserted-by":"publisher","unstructured":"Skeoch, H., Pym, D.: Pricing cyber-insurance for systems via maturity models (2023). https:\/\/doi.org\/10.48550\/arXiv.2302.04734","DOI":"10.48550\/arXiv.2302.04734"},{"key":"1275_CR61","doi-asserted-by":"publisher","unstructured":"Slapni\u010dar, S., Axelsen, M., Eulerich, M.: Cyber risk management: an illusion of a risk-based approach. J. Manag. Control. (2025). https:\/\/doi.org\/10.1007\/s00187-025-00401-z","DOI":"10.1007\/s00187-025-00401-z"},{"key":"1275_CR62","doi-asserted-by":"publisher","first-page":"71749","DOI":"10.1109\/ACCESS.2022.3187211","volume":"10","author":"N Sun","year":"2022","unstructured":"Sun, N., Li, C.T., Chan, H., Islam, M.Z., Islam, M.R., Armstrong, W.: How do organizations seek cyber assurance? Investigations on the adoption of the common criteria and beyond. IEEE Access 10, 71749\u201371763 (2022). https:\/\/doi.org\/10.1109\/ACCESS.2022.3187211","journal-title":"IEEE Access"},{"key":"1275_CR63","unstructured":"Tenable, 2026: The Cloud and AI Velocity Trap: Why Governance Is Falling Behind Innovation. https:\/\/www.tenable.com\/blog\/cloud-ai-research-report-2026-governance-vs-innovation Accessed: 07-03-2026"},{"key":"1275_CR64","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10207-023-00660-8","volume":"22","author":"A Tsohou","year":"2023","unstructured":"Tsohou, A., Diamantopoulou, V., Gritzalis, S., Lambrinoudakis, C.: Cyber insurance: state of the art, trends and future directions. Int. J. Inf. Secur. 22, 1\u201312 (2023). https:\/\/doi.org\/10.1007\/s10207-023-00660-8","journal-title":"Int. J. Inf. Secur."},{"key":"1275_CR65","doi-asserted-by":"publisher","unstructured":"Vanini, C., Gruber, J., Hargreaves, C., Benenson, Z., Freiling, F., Breitinger, F.: Strategies and challenges of timestamp tampering for improved digital forensic event reconstruction (extended version) (2024). https:\/\/doi.org\/10.48550\/arXiv.2501.00175","DOI":"10.48550\/arXiv.2501.00175"},{"key":"1275_CR66","doi-asserted-by":"publisher","first-page":"998","DOI":"10.18860\/cauchy.v10i2.35972","volume":"10","author":"N Vita","year":"2025","unstructured":"Vita, N., Nina, F.: Transformation of traditional models to AI: Slr on the application of machine learning in mortality prediction. Cauchy 10, 998\u20131014 (2025). https:\/\/doi.org\/10.18860\/cauchy.v10i2.35972","journal-title":"Cauchy"},{"key":"1275_CR67","unstructured":"Woods, D.W., B\u00f6hme, R., Wolff, J., Schwarcz, D.: Lessons lost: incident response in the age of cyber insurance and breach attorneys. SEC \u201923. USENIX Association, USA (2023)"},{"key":"1275_CR68","doi-asserted-by":"publisher","DOI":"10.1145\/3434403","author":"DW Woods","year":"2021","unstructured":"Woods, D.W., Moore, T., Simpson, A.C.: The county fair cyber loss distribution: Drawing inferences from insurance prices. Digital Threats (2021). https:\/\/doi.org\/10.1145\/3434403","journal-title":"Digital Threats"},{"key":"1275_CR69","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyae028","author":"DW Woods","year":"2025","unstructured":"Woods, D.W., Wolff, J.: A history of cyber risk transfer. J. Cybersec. (2025). https:\/\/doi.org\/10.1093\/cybsec\/tyae028","journal-title":"J. Cybersec."},{"key":"1275_CR70","doi-asserted-by":"publisher","DOI":"10.1145\/3769676","author":"H Xu","year":"2025","unstructured":"Xu, H., Wang, S., Li, N., Wang, K., Zhao, Y., Chen, K., Yu, T., Liu, Y., Wang, H.: Large language models for cyber security: A systematic literature review. ACM Trans. Softw. Eng. Methodol. (2025). https:\/\/doi.org\/10.1145\/3769676","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"1275_CR71","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s13385-021-00290-1","volume":"12","author":"G Zeller","year":"2021","unstructured":"Zeller, G., Scherer, M.: A comprehensive model for cyber risk based on marked point processes and its application to insurance. Eur. Actuar. J. 12, 1\u201353 (2021). https:\/\/doi.org\/10.1007\/s13385-021-00290-1","journal-title":"Eur. Actuar. J."},{"key":"1275_CR72","doi-asserted-by":"publisher","DOI":"10.1057\/s41288-023-00289-7","author":"G Zeller","year":"2023","unstructured":"Zeller, G., Scherer, M.: Risk mitigation services in cyber insurance: optimal contract design and price structure. The Geneva Papers on Risk and Insurance - Issues and Practice (2023). https:\/\/doi.org\/10.1057\/s41288-023-00289-7","journal-title":"The Geneva Papers on Risk and Insurance - Issues and Practice"},{"issue":"3","key":"1275_CR73","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1007\/s13385-024-00381-9","volume":"14","author":"G Zeller","year":"2024","unstructured":"Zeller, G., Scherer, M.: Is accumulation risk in cyber methodically underestimated? Eur. Actuar. J. 14(3), 711\u2013748 (2024). https:\/\/doi.org\/10.1007\/s13385-024-00381-9","journal-title":"Eur. Actuar. J."}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01275-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-026-01275-5","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01275-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T05:58:42Z","timestamp":1781935122000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-026-01275-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,20]]},"references-count":73,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,8]]}},"alternative-id":["1275"],"URL":"https:\/\/doi.org\/10.1007\/s10207-026-01275-5","relation":{},"ISSN":["1615-5270"],"issn-type":[{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,20]]},"assertion":[{"value":"10 February 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"112"}}