On Gaps in Enterprise Cyber Attack Reporting.

EuroS&P Workshops(2023)

引用 0|浏览3
暂无评分
摘要
It has long been lamented that firms underreport cyber attacks. In recent years, regulators have begun mandating that certain organizations must publicly report when incidents occur. Adherence to these requirements is an empirical question that has been largely unexamined to date. In this paper, we study regulatory filings by U.S. public companies to the Securities Exchange Commission and to the Department Health and Human Services that discuss cyber attacks. We also compare the findings against crowdsourced reports of cyber incidents appearing in media outlets. We find substantial gaps in coverage, both in terms of attacks that make the news but do not appear in regulatory filings and vice versa. We conclude by discussing the implications for the study of cyber attack and defense as well as for policymakers.
更多
查看译文
关键词
cyber incidents,department health,enterprise cyberattack reporting,human services,media outlets,regulatory filings,Securities Exchange Commission,U.S public companies
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要