Cyber-incident Richter scale ‘a first’
An independent body in Britain claims to have developed a “world-first” classification system for cyber-incidents.
The Cyber Monitoring Centre (CMC) is a non-profit body that analyses and categorises cyber-events that impact British organisations.
It is chaired by Ciaran Martin, former chief executive of Britain’s National Cyber Security Centre.
Lawyers at Pinsent Masons said that the new scale could help insurers better understand the risks associated with cyber-incidents in a similar way to how the Richter scale helps the understanding of an earthquake’s strength and impact.
Financial impact
According to the CMC, it will categorise cyber-incidents on a scale running from one to five, “based on the percentage of British organisations impacted and the financial impact of the event”.
The assessment will include polling, technical indicators, incident data, and insights from those with first-hand knowledge of the event, with cyber-experts on the CMC’s technical committee reviewing the analysis before making the final determination on categorisation.
“If we crack this – and I’m confident that we will – ultimately it could be a huge boost to cyber-security efforts, not just here but internationally, too,” said Martin.
Standardised framework
Ellie Ludlam of Pinsent Masons said that categorising major cyber-incidents had been difficult.
This was due to a lack of standardisation, the complexity of measuring the impact of cyber-incidents, availability of data points, diversity of thought across the various cyber disciplines, and the ever-evolving threat landscape.
“The new CMC methodology seeks to overcome these hurdles,” she said.
“With a standardised framework for assessing cyber-incidents, insurers will be able to more accurately evaluate the risks associated with different cyber-threats, potentially leading to more precise underwriting and pricing of policies,” Ludlum stated, adding that the independence of the assessment could help build confidence in the cyber-insurance market.
Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland