Abstract:
Severe financial losses incurred by cyber security attacks with increasing complexity and frequency, as well as booming cyber security sector offering variety of products as investment options have led the focus of the research in the field to the economic dimension of cyber security. The need for determination of methods to be used when making cyber security investment decisions under budget constraints have become prominent.
In five sections as the cyber security investment strategies, risk identification and measurement, attack costs and impacts calculation, measurement of technology effectiveness and determination of optimum level of cyber security investments, this study reviews and evaluates the academic literature on economic aspects of cyber security for the last fifteen years and aims to provide research directions by pinpointing literature gaps.