Social Business Journal

Social Business Journal

Creating Cyber Insurance Market in Iran, The Institutional Role of Government and its Impact on Enterprises

Document Type : Original Article

Authors
Faculty of ICT Security Research, Iran Telecommunication Research Center, Tehran, Iran.
Abstract
Cyber attacks can have severe and damaging consequences on businesses, governments and individuals, resulting in financial losses, harm to reputation and disruptions to essential infrastructure. As the digital landscape evolves and cyber threats escalate, the need for more robust cyber risk management strategies has led to the expansion of the cyber insurance market as a vital defense against the threats. Cyber insurance not only acts as a stand-alone risk control measure but also impacts other risk management practices. The growth of this market benefits the overall insurance industry and enhances its market penetration. However, despite the cyber insurance market becoming a primary method for managing cyber risk in many countries over the past thirty years, various businesses in Iran lack access to such a market. This study aims to explore the reasons behind the absence of a cyber insurance market in the Iran’s economy. By reviewing the literature on market failures in economics and proposing a conceptual model for the cyber insurance market, the findings suggest that the high relative level of cyber risk and excessive transaction costs pose significant obstacles to establishing this market in Iran. It is recommended to create a platform named the Cyber Insurance Market Guide, focused on designing and implementing government institutional policies to foster the development of the cyber insurance market.
Keywords

دادگر, یدالله. (1386). نقش قضیه Coase و هزینه مبادله در تحولات جدید اقتصادی. دوفصلنامۀ علمی مطالعات و سیاست‌های اقتصادی، 11، 89-114.
عاقلی, لطفعلی, سحابی, بهرام و صلح خواه, نسرین. (1396). تأثیر هزینه مبادله بر توسعه مالی در کشورهای منتخب اوپک. پژوهش ها و چشم اندازهای اقتصادی،17(1)، 95-120..
عبدی, جابر, تقی نژادعمران, وحید و عباسی نژاد, حسین. (1401). بازنگری قضیه کوز با لحاظ هزینه مبادله مثبت؛ رهیافتی برای بررسی نقش دولت در تسهیل مبادلات بازاری. فصلنامه تحقیقات اقتصادی، 57(3)، 505-531.
Abdi, J., Taghinejadimran, & Abbasinejad. (2022). Revisiting the Coase theorem with positive transaction costs: An approach to examine the role of government in facilitating market exchanges. Journal of Economic Research, 57(3), 505-531 (In Persian).
Agheli L, Sahabi B, Solhkhah N. (2017). The Impact of Transaction Cost on Financial Development in Selected OPEC Members. The Economic Research, 17(1), 95-120 (In Persian).
Alhassan, A.‌L., & Biekpe, N. (2016). Insurance market development and economic growth. International Journal of Social Economics, 43(3), 321-339.
Australian Government, Australian Cyber Security Centre. (2023). Cyber Security Small Business Program. https://www.cyber.gov.au/acsc/view-all-content/programs-and-initiatives/cyber-security-small-business-program.
Baker, W., & Wallace, L. (2007). Is Information Security Under Control? Proceedings of the 2007 ACM SIGMIS CPR Conference on Computer Personnel Research.
Bandyopadhyay, T., Mookerjee, V. S., & Rao, R. C. (2009). Why IT managers don't go for cyber-insurance products. Communications of the ACM, 52(11), 68-73.
Bannister, F., & Connolly, R. (2018). Risk Management and Governance: A Practical GuideInternational Journal of Information Management, 38(1), 236-244.
Biener, C., Eling, M., & Wirfs, J. H. (2015). Insurability of cyber risk: An empirical analysis. The Geneva Papers on Risk and Insurance-Issues and Practice40, 131-158.
Böhme, R., & Moore, T. (2012). The Blockchain and Cyber Insurance: A New Paradigm, Proceedings of the 2012 Workshop on the Economics of Information Security.
Böhme, R., & Schwartz, G. (2010). Modeling cyber-insurance: towards a unifying framework. In WEIS.
Bruce, M., Lusthaus, J., Kashyap, R., Phair, N., & Varese, F. (2024). Mapping the global geography of cybercrime with the World Cybercrime Index. Plos one, 19(4), e0297312.
Council of Europe. (2001). Convention on Cybercrime. https://www.coe.int/en/web/conventions/full-list/-/conventions/treaty/185.
Cyber Security Agency of Singapore. (2024). SingCERT. https://www.csa.gov.sg/singcert
Dadgar. (2007). The role of the Coase theorem and transaction costs in recent economic developments. Scientific Journal of Economic Studies and Policies, (11), 89-114 (In Persian).
Deloitte. (2022). Cyber insurance: What you need to know.
Doherty, N.F., & Fulford, H. (2017). Cyber Insurance: The Role of Insurance in Managing Cyber Risk. The Journal of Risk Finance, 18(5), 513-528.
Eling, M., & Schnell, W. (2016). What do we know about cyber risk and cyber risk insurance?. The Journal of Risk Finance.
European Commission. (2016). General Data Protection Regulation (GDPR). https://ec.europa.eu/info/law/law-topic/data-protection_en.
European Union. (2016). Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. Retrieved from https://eur-lex.europa.eu/eli/dir/2016/1148/oj.
Fenwick, M. (2018). May States Regulate Innovation Under Federal Law? A Proposed Framework for State Patent Policy.
Foray, D. (2011). The economics of knowledge. MIT Press.
Franke, U., Holm, H., König, J. (2014). The distribution of time to recovery of enterprise IT services. IEEE T Reliab; 63(4):858–67. http://dx.doi.org/10.1109/TR.2014.2336051.
Franke, U. (2017). The cyber insurance market in Sweden. Computers and Security, 68, 130-144.‌
Fraser, J., & Simkins, B. (2016). Enterprise Risk Management: Today's Leading Research and Best Practices for Tomorrow's Executives. John Wiley and Sons.
Fruhlinger, J. (2019). What is a managed security service provider (MSSP)? A vital resource for security. CSO Online. Retrieved from https://www.csoonline.com/article/2122440/managed-security-service-provider-definition-and-solutions.html.
Gatzert, N., & Schmeiser, H. (2012). The merits of pooling claims revisited. The Journal of Risk Finance, 13(3), 184-198.
Gordon, L.A., & Loeb, M.P. (2018). The Economics of Cybersecurity: Evidence from the Field. Journal of Cybersecurity, 4(1), 1-14.
Harrington, S.E., & Niehaus, G.R. (2019). Risk management and insurance (2nd ed.). McGraw-Hill Education.
Hillson, D. (2020). The risk management of projects: A strategic approach to managing risk. International Journal of Project Management, 38(8), 429-439. https://doi.org/10.1016/j.ijproman.2020.06.006
IBM Security. (2022). 2022 Cost of a Data Breach Report. https://www.ibm.com/reports/data-breach
IBM. (2023). Cost of a Data Breach Report 2023.
ITU-T. (2021). Cyber insurance acquisition guidelines (ITU-T Recommendation X.1061). International Telecommunication Union.
Kak, A., & Goyal, P. (2020). Emerging Trends in Cyber Insurance: A Review. Journal of Cybersecurity and Privacy, 1(2), 123-139.
Kieninger, A., Straeten, D., Kimbrough, S., Schmitz, B., & Satzger, G. (2013). Leveraging service incident analytics to determine cost-optimal service offers.‌
KPMG. (2023). Cyber insurance: A growing necessity.
Kshetri, N. (2017). Cybersecurity and Cyber Insurance: An Overview. Journal of Business Research, 70, 353-365.
Kumar, S., & Singh, S. (2019). Managed Security Services Providers: A Comprehensive Overview. International Journal of Information Security, 18(1), 51-67.
Mankiw, N.G. (2020). Principles of economics (8th ed.). Cengage Learning.
MarketsandMarkets. (2020). Managed Security Services Market with COVID-19 Impact Analysis by Service Type, Organization Size, Vertical, and Region - Global Forecast to 2025. Retrieved from https://www.marketsandmarkets.com/Market-Reports/managed-security-services-market-1251.html.
McCann, L. (2004). Induced institutional innovation and transaction costs: The case of the Australian National Native Title Tribunal. Review of Social Economy, 62(1), 67-82.
McCann, L. (2013). Transaction costs and environmental policy design. Ecological Economics88, 253-262.
Miller, A. (2023). The evolving landscape of cyber insurance. Risk Management Journal, 12(4), 45-59.
Mohammad, R.S. (2014). Governance Transactions Costs in National Iranian Oil Company. Iranian Energy Economics Research, 4(3), 117-168 (In Persian).
National Cyber Security Centre. (2023). CyberFirst overview. https://www.ncsc.gov.uk/cyberfirst/overview.
North, D.C. (1990). Institutions, Institutional Change and Economic Performance. Cambridge University Press.
Williamson, O. E. (1985). The Economic Institutions of Capitalism. Free Press.
NSW Department of Industry. (2017). Market failure guide: A guide to categorising market failures for government policy development and evaluation. State of New South Wales. https://www.opengov.nsw.gov.au/publications/17004
Renani, M. (1997). Market or non-market. Tehran: Management and Planning Organization Publications (In Persian).
Reports and Data. (2022). Cyber Insurance Market Size to Reach $28.6 Billion by 2030 | CAGR: 20.1%. https://www.reportsanddata.com/report-detail/cyber-insurance-market.
Todorova, T. (2016). Transaction costs, market failures and economic development. Journal of Advanced Research in Law and Economics (JARLE)7(17), 678-684.
U.S. Department of Defense. (2020). Cybersecurity Maturity Model Certification (CMMC). Retrieved from https://www.acq.osd.mil/cmmc/.
U.S. Department of Homeland Security. (2015). Automated Indicator Sharing (AIS). https://www.dhs.gov/automated-indicator-sharing.
Varian, H. R. (2019). Intermediate microeconomics: A modern approach (9th ed.). W. W. Norton and Company.
Vaughan, E. J., & Vaughan, T. M. (2014). Fundamentals of risk and insurance (11th ed.). Wiley.
World Bank. (2019). World Development Report 2019: The Changing Nature of Work.
Zhao, Y., Wang, J., & Li, X. (2023). The role of cyber insurance in improving cybersecurity posture. Journal of Cybersecurity, 5(1), 15-30.