Javascript must be enabled to continue!
Mitigating Risk: Insurance for the Internet of Unexpected Things
View through CrossRef
The Internet of Things will provide 50 billion new opportunities for interdependent devices to malfunction. The recent Mirai botnet attack demonstrated that the Internet of Things is already capable of creating widespread interruptions in the Internet and the activities that depend on it.
Realizing the promise and positive benefits of the IoT will require not only technical innovation, but changes in how regulation, business, security, and risk in the system are handled. The current IoT ecosystem suffers from flaws that include vulnerability to cyberattack, technical system failures, and the problem of free riders who depend upon security and other safeguards in the network to compensate for their own insecure devices, protocols, and software. Cyberattacks and failures undermine confidence in the IoT and serve as a reminder that regardless of how much IoT security is improved, there will always be vulnerabilities and exploits. Networked failures can have significant socioeconomic consequences.
This paper proposes an insurance system for the Internet of Things. The intent is to address technical and market failures in the IoT ecosystem, propose a method of distributing risk more equitably, and examine ways to fund necessary responses to large scale incidents. Making insurance mandatory, or at least available and desirable, would promote security audits and formal internal procedures for the insured, leading to improved security, prevention, incident response, and recovery planning in the IoT ecosystem. An insurance model has not been widely adopted in the traditional Internet, but the increasing number and reach of IoT devices increases the risk and consequences of a network failure and suggests the need for a risk management solution.
This paper applies the concept of insurance as an accepted method of risk management to the Internet of Things ecosystem. We take a constructivist approach to creating a new insurance business model framework, and a policy planning approach to creating policy and regulatory guidelines for IoT insurance. The proposed insurance business models would permit insurance to be offered by interested companies beyond traditional insurers, such as Internet service providers, telephone companies, cloud providers, or others with experience in assessing and managing security technology. Necessary regulation includes constructing a better-defined liability framework to avoid the current "shell game" of responsibility. Also, disclosure requirements for companies that know of vulnerabilities or experience security incidents to assist in building actuarial data that would help insurance companies determine the actual risks, appropriate insurance products, and pricing structure. Regulation would also streamline the legal and procedural difficulties that currently exist when trying to make a claim, and assist in defining the rights and roles of insurers and claimants. Regulation would help establish what is currently an immature market and could encourage standardization in products and procedures.
A regulatory framework for an IoT insurance system would help align the objectives of device manufacturers, network operators, services, and end users. With a proper insurance framework for the IoT, market solutions could develop that foster greater security, trust, and confidence in the IoT ecosystem.
Title: Mitigating Risk: Insurance for the Internet of Unexpected Things
Description:
The Internet of Things will provide 50 billion new opportunities for interdependent devices to malfunction.
The recent Mirai botnet attack demonstrated that the Internet of Things is already capable of creating widespread interruptions in the Internet and the activities that depend on it.
Realizing the promise and positive benefits of the IoT will require not only technical innovation, but changes in how regulation, business, security, and risk in the system are handled.
The current IoT ecosystem suffers from flaws that include vulnerability to cyberattack, technical system failures, and the problem of free riders who depend upon security and other safeguards in the network to compensate for their own insecure devices, protocols, and software.
Cyberattacks and failures undermine confidence in the IoT and serve as a reminder that regardless of how much IoT security is improved, there will always be vulnerabilities and exploits.
Networked failures can have significant socioeconomic consequences.
This paper proposes an insurance system for the Internet of Things.
The intent is to address technical and market failures in the IoT ecosystem, propose a method of distributing risk more equitably, and examine ways to fund necessary responses to large scale incidents.
Making insurance mandatory, or at least available and desirable, would promote security audits and formal internal procedures for the insured, leading to improved security, prevention, incident response, and recovery planning in the IoT ecosystem.
An insurance model has not been widely adopted in the traditional Internet, but the increasing number and reach of IoT devices increases the risk and consequences of a network failure and suggests the need for a risk management solution.
This paper applies the concept of insurance as an accepted method of risk management to the Internet of Things ecosystem.
We take a constructivist approach to creating a new insurance business model framework, and a policy planning approach to creating policy and regulatory guidelines for IoT insurance.
The proposed insurance business models would permit insurance to be offered by interested companies beyond traditional insurers, such as Internet service providers, telephone companies, cloud providers, or others with experience in assessing and managing security technology.
Necessary regulation includes constructing a better-defined liability framework to avoid the current "shell game" of responsibility.
Also, disclosure requirements for companies that know of vulnerabilities or experience security incidents to assist in building actuarial data that would help insurance companies determine the actual risks, appropriate insurance products, and pricing structure.
Regulation would also streamline the legal and procedural difficulties that currently exist when trying to make a claim, and assist in defining the rights and roles of insurers and claimants.
Regulation would help establish what is currently an immature market and could encourage standardization in products and procedures.
A regulatory framework for an IoT insurance system would help align the objectives of device manufacturers, network operators, services, and end users.
With a proper insurance framework for the IoT, market solutions could develop that foster greater security, trust, and confidence in the IoT ecosystem.
Related Results
Macroeconomic and Social Precursors of Suicide Rates in the Philippines: A Quantitative Analysis (Preprint)
Macroeconomic and Social Precursors of Suicide Rates in the Philippines: A Quantitative Analysis (Preprint)
BACKGROUND
Suicide is a complex, serious and multifaceted public health issue that poses significant challenges to societies worldwide. In fact, it represen...
A Study on new Insurance Distribution Channel’s Right to Receive the Duty of Disclosure and Legal Issues: Focusing on AI (Artificial Intelligence) Insurance Solicitors and Insurance Companies Specializing in Insurance Product Sales
A Study on new Insurance Distribution Channel’s Right to Receive the Duty of Disclosure and Legal Issues: Focusing on AI (Artificial Intelligence) Insurance Solicitors and Insurance Companies Specializing in Insurance Product Sales
The insurance industry has undergone many changes due to the era of the 4th industrial revolution, which interconnects our digital and real worlds. Advances in big data have cleare...
Commercial Agents and Insurance Agents under the Korean Commercial Act
Commercial Agents and Insurance Agents under the Korean Commercial Act
This article considers the legal concepts, powers and duties of agents under the Commercial Act (Part 2) and insurance agents under the Commercial Act (Part 4), and considers to wh...
Functional roles of the insurance broker in the agricultural insurance market
Functional roles of the insurance broker in the agricultural insurance market
In modern conditions, the agricultural sector is one of the most risky branches of economy. Every year, farmers face significant losses due to various natural disasters, diseases a...
Insurance Products in Rastin Profit and Loss Sharing Banking
Insurance Products in Rastin Profit and Loss Sharing Banking
Purpose: This paper aims to explain new insurance products and policies in Rastin Profit and Loss Sharing (PLS) Banking. Rastin Banking is a full Islamic Banking System with all ne...
MODERN CAR INSURANCE SYSTEM IN UKRAINE
MODERN CAR INSURANCE SYSTEM IN UKRAINE
The article structures the car insurance system in Ukraine under the influence of legislative changes in 2024. In particular, the category of the automobile insurance system is...
Risk management in crop farming
Risk management in crop farming
The agricultural sector is heavily exposed to the impact of climate change and the more common extreme weather events. This exposure can have significant impacts on agricultural pr...
Factors affecting the use of forage index insurance
Factors affecting the use of forage index insurance
Purpose
The purpose of this paper is to examine factors affecting the use of forage index insurance. Forage is a difficult crop to insure, and index insurance may be well suited fo...

