{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T03:55:31Z","timestamp":1783569331193,"version":"3.55.0"},"reference-count":62,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2022,6,16]],"date-time":"2022-06-16T00:00:00Z","timestamp":1655337600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>In the context of growing vulnerabilities, cyber-risk management cannot rely on a one-off approach, instead calling for a continuous re-assessment of the risk and adaptation of risk management strategies. Under the mixed investment\u2013insurance approach, where both risk mitigation and risk transfer are employed, the adaptation implies the re-computation of the optimal amount to invest in security over time. In this paper, we deal with the problem of computing the optimal balance between investment and insurance payments to achieve the minimum overall security expense when the vulnerability grows over time according to a logistic function, adopting a greedy approach, where strategy adaptation is carried out periodically at each investment epoch. We consider three liability degrees, from full liability to partial liability with deductibles. We find that insurance represents by far the dominant component in the mix and may be relied on as a single protection tool when the vulnerability is very low.<\/jats:p>","DOI":"10.3390\/a15060211","type":"journal-article","created":{"date-parts":[[2022,6,16]],"date-time":"2022-06-16T03:01:22Z","timestamp":1655348482000},"page":"211","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Optimizing Cybersecurity Investments over Time"],"prefix":"10.3390","volume":"15","author":[{"given":"Alessandro","family":"Mazzoccoli","sequence":"first","affiliation":[{"name":"Department of Law, Economics, Politics and Modern Languages, LUMSA University, Via Marcantonio Colonna 19, 00192 Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0903-398X","authenticated-orcid":false,"given":"Maurizio","family":"Naldi","sequence":"additional","affiliation":[{"name":"Department of Law, Economics, Politics and Modern Languages, LUMSA University, Via Marcantonio Colonna 19, 00192 Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,16]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1140\/epjb\/e2010-00120-8","article-title":"Heavy-tailed distribution of cyber-risks","volume":"75","author":"Maillart","year":"2010","journal-title":"Eur. Phys. J. B"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1140\/epjb\/e2015-60754-4","article-title":"The extreme risk of personal data breaches and the erosion of privacy","volume":"89","author":"Wheatley","year":"2016","journal-title":"Eur. Phys. J. B"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"564","DOI":"10.1057\/s41288-020-00171-w","article-title":"Analysis of the impact of cyber events for cyber insurance","volume":"45","author":"Palsson","year":"2020","journal-title":"Geneva Pap. Risk Insur.-Issues Pract."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"2119","DOI":"10.1111\/risa.13309","article-title":"Risk and the Five Hard Problems of Cybersecurity","volume":"39","author":"Scala","year":"2019","journal-title":"Risk Anal."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1111\/risa.12844","article-title":"Cyber risk management for critical infrastructure: A risk analysis model and three case studies","volume":"38","author":"Kuypers","year":"2018","journal-title":"Risk Anal."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Refsdal, A., Solhaug, B., and St\u00f8len, K. (2015). Cyber-risk management. Cyber-Risk Management, Springer.","DOI":"10.1007\/978-3-319-23570-7"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Murphy, D.R., and Murphy, R.H. (2013, January 12). Teaching cybersecurity: Protecting the business environment. Proceedings of the 2013 on InfoSecCD\u201913: Information Security Curriculum Development Conference, Kennesaw, GA, USA.","DOI":"10.1145\/2528908.2528913"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1111\/rmir.12169","article-title":"Cyber risk management: History and future research directions","volume":"24","author":"Eling","year":"2021","journal-title":"Risk Manag. Insur. Rev."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1057\/gpp.2014.19","article-title":"Insurability of cyber risk: An empirical analysis","volume":"40","author":"Biener","year":"2015","journal-title":"Geneva Pap. Risk Insur.-Issues Pract."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1016\/j.cose.2017.04.010","article-title":"The cyber insurance market in Sweden","volume":"68","author":"Franke","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"690","DOI":"10.1057\/s41288-020-00176-5","article-title":"Cyber insurance offering and performance: An analysis of the US cyber insurance market","volume":"45","author":"Xie","year":"2020","journal-title":"Geneva Pap. Risk Insur.-Issues Pract."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1108\/ICS-01-2019-0012","article-title":"The cyber-insurance market in Norway","volume":"28","author":"Franke","year":"2019","journal-title":"Inf. Comput. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Strupczewski, G. (2018, January 22\u201325). Current state of the cyber insurance market. Proceedings of the Economics and Finance Conferences, London, UK.","DOI":"10.20472\/EFC.2018.010.034"},{"key":"ref_14","first-page":"4","article-title":"Cyber risk management: An actuarial point of view","volume":"14","author":"Carfora","year":"2019","journal-title":"J. Oper. Risk"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1016\/j.ijcip.2016.04.001","article-title":"A framework for incorporating insurance in critical infrastructure cyber risk strategies","volume":"14","author":"Young","year":"2016","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"550","DOI":"10.1111\/risa.13416","article-title":"Robustness of Optimal Investment Decisions in Mixed Insurance\/Investment Cyber Risk Management","volume":"40","author":"Mazzoccoli","year":"2019","journal-title":"Risk Anal."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"448","DOI":"10.1002\/asmb.2451","article-title":"Enterprise security economics: A self-defense versus cyber-insurance dilemma","volume":"35","author":"Miaoui","year":"2019","journal-title":"Appl. Stoch. Model. Bus. Ind."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1781","DOI":"10.1016\/j.ress.2008.03.005","article-title":"Critical infrastructures at risk: A need for a new conceptual approach and extended analytical tools","volume":"93","year":"2008","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"332","DOI":"10.1049\/iet-cps.2018.5079","article-title":"Assets focus risk management framework for critical infrastructure cybersecurity risk management","volume":"4","author":"Kure","year":"2019","journal-title":"IET Cyber-Phys. Syst. Theory Appl."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"438","DOI":"10.1145\/581271.581274","article-title":"The economics of information security investment","volume":"5","author":"Gordon","year":"2002","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_21","first-page":"49","article-title":"Investing in Cybersecurity: Insights from the Gordon-Loeb Model","volume":"7","author":"Gordon","year":"2016","journal-title":"J. Inf. Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Naldi, M., and Flamini, M. (2017, January 5\u20137). Calibration of the Gordon-Loeb Models for the Probability of Security Breaches. Proceedings of the 2017 UKSim-AMSS 19th International Conference on Computer Modelling & Simulation (UKSim), Cambridge, UK.","DOI":"10.1109\/UKSim.2017.18"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1016\/j.ijpe.2012.06.022","article-title":"Economics of information security investment in the case of concurrent heterogeneous attacks with budget constraints","volume":"141","author":"Huang","year":"2013","journal-title":"Int. J. Prod. Econ."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/s12525-017-0276-z","article-title":"Negligence and sanctions in information security investments in a cloud environment","volume":"28","author":"Naldi","year":"2018","journal-title":"Electron. Mark."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"519","DOI":"10.1016\/j.ijpe.2016.09.018","article-title":"An economic model to evaluate information security investment of risk-taking small and medium enterprises","volume":"182","author":"Mayadunne","year":"2016","journal-title":"Int. J. Prod. Econ."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1016\/j.jsis.2012.10.004","article-title":"The economic impact of cyber terrorism","volume":"22","author":"Hua","year":"2013","journal-title":"J. Strateg. Inf. Syst."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"423","DOI":"10.1007\/s10796-013-9411-3","article-title":"Security investment and information sharing under an alternative security breach probability function","volume":"17","author":"Gao","year":"2015","journal-title":"Inf. Syst. Front."},{"key":"ref_28","first-page":"3","article-title":"Increasing cybersecurity investments in private sector firms","volume":"1","author":"Gordon","year":"2015","journal-title":"J. Cybersecur."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"6132","DOI":"10.1016\/j.eswa.2015.03.033","article-title":"Game of information security investment: Impact of attack types and network vulnerability","volume":"42","author":"Wu","year":"2015","journal-title":"Expert Syst. Appl."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1795","DOI":"10.1111\/risa.13713","article-title":"The Benefits and Costs of Cybersecurity Risk Reduction: A Dynamic Extension of the Gordon and Loeb Model","volume":"41","author":"Krutilla","year":"2021","journal-title":"Risk Anal."},{"key":"ref_31","first-page":"2","article-title":"Incentivizing Cyber Security Investment in the Power Sector Using An Extended Cyber Insurance Framework","volume":"15","author":"Rosson","year":"2019","journal-title":"Homel. Secur. Aff."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1368","DOI":"10.1080\/00207543.2020.1856442","article-title":"A linear model for optimal cybersecurity investment in Industry 4.0 supply chains","volume":"60","author":"Sawik","year":"2022","journal-title":"Int. J. Prod. Res."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Mazzoccoli, A., and Naldi, M. (2021). Optimal Investment in Cyber-Security under Cyber Insurance for a Multi-Branch Firm. Risks, 9.","DOI":"10.3390\/risks9010024"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"338","DOI":"10.1007\/s10796-006-9011-6","article-title":"Returns to information security investment: The effect of alternative information security breach functions on optimal investment and sensitivity to vulnerability","volume":"8","author":"Hausken","year":"2006","journal-title":"Inf. Syst. Front."},{"key":"ref_35","unstructured":"Wang, S. (2022, May 15). Optimal Level and Allocation of Cybersecurity Spending: Model and Formula. Available online: https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3010029."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"101173","DOI":"10.1016\/j.pacfin.2019.101173","article-title":"Integrated framework for information security investment and cyber insurance","volume":"57","author":"Wang","year":"2019","journal-title":"Pac.-Basin Financ. J."},{"key":"ref_37","unstructured":"Feng, S., Xiong, Z., Niyato, D., Wang, P., Wang, S.S., and Shen, X.S. (2020). Joint Pricing and Security Investment in Cloud Security Service Market with User Interdependency. IEEE Trans. Serv. Comput., 1\u201311."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1016\/j.ijinfomgt.2008.02.002","article-title":"An economic modelling approach to information security risk management","volume":"28","year":"2008","journal-title":"Int. J. Inf. Manag."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"1109","DOI":"10.1016\/j.ejor.2018.07.021","article-title":"What are the actual costs of cyber risk events?","volume":"272","author":"Eling","year":"2019","journal-title":"Eur. J. Oper. Res."},{"key":"ref_40","unstructured":"Arcuri, M.C., Brogi, M., and Gandolfi, G. (2017, January 17\u201320). How Does Cyber Crime Affect Firms? The Effect of Information Security Breaches on Stock Returns. Proceedings of the ITASEC, Venice, Italy."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1046\/J.1098-1616.2003.026.x","article-title":"The impact of denial-of-service attack announcements on the market value of firms","volume":"6","author":"Hovav","year":"2003","journal-title":"Risk Manag. Insur. Rev."},{"key":"ref_42","unstructured":"World Economic Forum (2015). Partnering for Cyber Resilience: Towards the Quantification of Cyber Threats, World Economic Forum. Technical Report."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"719","DOI":"10.1016\/j.jfineco.2019.05.019","article-title":"Risk management, firm reputation, and the impact of successful cyberattacks on target firms","volume":"139","author":"Kamiya","year":"2021","journal-title":"J. Financ. Econ."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"128","DOI":"10.4236\/ib.2018.103008","article-title":"Pricing the Cost of Cybercrime\u2014A Financial Protection Approach","volume":"10","author":"Poufinas","year":"2018","journal-title":"iBusiness"},{"key":"ref_45","unstructured":"The Ponemon Institute (2016). 2016 Cost of Data Breach Study: Global Analysis, The Ponemon Institute. Technical Report."},{"key":"ref_46","unstructured":"Zhuo, Y., and Solak, S. (June, January 31). Measuring and optimizing cybersecurity investments: A quantitative portfolio approach. Proceedings of the IIE Annual Conference, Montreal, QC, Canada."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.cosrev.2017.01.001","article-title":"Cyber-insurance survey","volume":"24","author":"Marotta","year":"2017","journal-title":"Comput. Sci. Rev."},{"key":"ref_48","unstructured":"Kesan, J.P., Majuca, R.P., and Yurcik, W.J. (2004). The Economic Case for Cyberinsurance, University of Illinois College of Law. Technical Report 2."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Bolot, J., and Lelarge, M. (2009). Cyber insurance as an incentive for Internet security. Managing Information Risk and the Economics of Security, Springer.","DOI":"10.1007\/978-0-387-09762-6_13"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.peva.2013.10.003","article-title":"Security adoption and influence of cyber-insurance markets in heterogeneous networks","volume":"74","author":"Yang","year":"2014","journal-title":"Perform. Eval."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Pal, R., Golubchik, L., Psounis, K., and Hui, P. (May, January 27). Will cyber-insurance improve network security? A market analysis. Proceedings of the INFOCOM, 2014 Proceedings IEEE, Toronto, ON, Canada.","DOI":"10.1109\/INFOCOM.2014.6847944"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Shetty, N., Schwartz, G., Felegyhazi, M., and Walrand, J. (2010). Competitive cyber-insurance and internet security. Economics of Information Security and Privacy, Springer.","DOI":"10.1007\/978-1-4419-6967-5_12"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1145\/1592761.1592780","article-title":"Why IT managers don\u2019t go for cyber-insurance products","volume":"52","author":"Bandyopadhyay","year":"2009","journal-title":"Commun. ACM"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"1526","DOI":"10.1109\/TIFS.2018.2881694","article-title":"A coalitional cyber-insurance framework for a common platform","volume":"14","author":"Vakilinia","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"997","DOI":"10.1007\/s10796-017-9808-5","article-title":"Cyber risk assessment and mitigation (CRAM) framework using logit and probit models for cyber insurance","volume":"21","author":"Mukhopadhyay","year":"2019","journal-title":"Inf. Syst. Front."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Mazzoccoli, A., and Naldi, M. (2020). The Expected Utility Insurance Premium Principle with Fourth-Order Statistics: Does It Make a Difference?. Algorithms, 13.","DOI":"10.3390\/a13050116"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"2226","DOI":"10.1109\/TIFS.2018.2812205","article-title":"Designing cyber insurance policies: The role of pre-screening and security interdependence","volume":"13","author":"Khalili","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Mastroeni, L., Mazzoccoli, A., and Naldi, M. (2019). Service Level Agreement Violations in Cloud Storage: Insurance and Compensation Sustainability. Future Internet, 11.","DOI":"10.3390\/fi11070142"},{"key":"ref_59","first-page":"7","article-title":"Copula-based actuarial model for pricing cyber-insurance policies","volume":"2","author":"Herath","year":"2011","journal-title":"Insur. Mark. Co. Anal. Actuar. Comput."},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/MSP.2015.137","article-title":"Mitigating risk with cyberinsurance","volume":"13","author":"Meland","year":"2015","journal-title":"IEEE Secur. Priv."},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1057\/s41288-018-0078-3","article-title":"Reducing informational disadvantages to improve cyber risk management","volume":"43","author":"Shetty","year":"2018","journal-title":"Geneva Pap. Risk Insur.-Issues Pract."},{"key":"ref_62","unstructured":"Aven, T., Ben-Haim, Y., Boje Andersen, H., Cox, T., Droguett, E.L., Greenberg, M., Guikema, S., Kr\u00f6ger, W., Renn, O., and Thompson, K.M. (2018). Society for Risk Analysis Glossary, Society for Risk Analysis."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/15\/6\/211\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:32:37Z","timestamp":1760139157000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/15\/6\/211"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,16]]},"references-count":62,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["a15060211"],"URL":"https:\/\/doi.org\/10.3390\/a15060211","relation":{},"ISSN":["1999-4893"],"issn-type":[{"value":"1999-4893","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,16]]}}}