{"id":"https://openalex.org/W2508605860","doi":"https://doi.org/10.1093/cybsec/tyw001","title":"Examining the costs and causes of cyber incidents","display_name":"Examining the costs and causes of cyber incidents","publication_year":2016,"publication_date":"2016-08-25","ids":{"openalex":"https://openalex.org/W2508605860","doi":"https://doi.org/10.1093/cybsec/tyw001","mag":"2508605860"},"language":"en","primary_location":{"id":"doi:10.1093/cybsec/tyw001","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw001","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/121/10833225/tyw001.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/121/10833225/tyw001.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5002725626","display_name":"Sasha Romanosky","orcid":null},"institutions":[{"id":"https://openalex.org/I1309849503","display_name":"RAND Corporation","ror":"https://ror.org/00f2z7n96","country_code":"US","type":"nonprofit","lineage":["https://openalex.org/I1309849503"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Sasha Romanosky","raw_affiliation_strings":["RAND Corporation, 1200 South Hayes St, Arlington, VA 22202, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"RAND Corporation, 1200 South Hayes St, Arlington, VA 22202, USA","institution_ids":["https://openalex.org/I1309849503"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5002725626"],"corresponding_institution_ids":["https://openalex.org/I1309849503"],"apc_list":{"value":1864,"currency":"USD","value_usd":1864},"apc_paid":{"value":1864,"currency":"USD","value_usd":1864},"fwci":42.0993,"has_fulltext":false,"cited_by_count":232,"citation_normalized_percentile":{"value":0.99784715,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"tyw001","last_page":"tyw001"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.7331228256225586},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.6870684623718262},{"id":"https://openalex.org/keywords/incentive","display_name":"Incentive","score":0.6297388076782227},{"id":"https://openalex.org/keywords/order","display_name":"Order (exchange)","score":0.5829094052314758},{"id":"https://openalex.org/keywords/data-breach","display_name":"Data breach","score":0.5445310473442078},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.39127057790756226},{"id":"https://openalex.org/keywords/public-relations","display_name":"Public relations","score":0.34965288639068604},{"id":"https://openalex.org/keywords/accounting","display_name":"Accounting","score":0.33828824758529663},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.328204482793808},{"id":"https://openalex.org/keywords/finance","display_name":"Finance","score":0.31547993421554565},{"id":"https://openalex.org/keywords/economics","display_name":"Economics","score":0.2015463411808014}],"concepts":[{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.7331228256225586},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.6870684623718262},{"id":"https://openalex.org/C29122968","wikidata":"https://www.wikidata.org/wiki/Q1414816","display_name":"Incentive","level":2,"score":0.6297388076782227},{"id":"https://openalex.org/C182306322","wikidata":"https://www.wikidata.org/wiki/Q1779371","display_name":"Order (exchange)","level":2,"score":0.5829094052314758},{"id":"https://openalex.org/C165609540","wikidata":"https://www.wikidata.org/wiki/Q1172486","display_name":"Data breach","level":2,"score":0.5445310473442078},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.39127057790756226},{"id":"https://openalex.org/C39549134","wikidata":"https://www.wikidata.org/wiki/Q133080","display_name":"Public relations","level":1,"score":0.34965288639068604},{"id":"https://openalex.org/C121955636","wikidata":"https://www.wikidata.org/wiki/Q4116214","display_name":"Accounting","level":1,"score":0.33828824758529663},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.328204482793808},{"id":"https://openalex.org/C10138342","wikidata":"https://www.wikidata.org/wiki/Q43015","display_name":"Finance","level":1,"score":0.31547993421554565},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.2015463411808014},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.0},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.0},{"id":"https://openalex.org/C175444787","wikidata":"https://www.wikidata.org/wiki/Q39072","display_name":"Microeconomics","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1093/cybsec/tyw001","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw001","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/121/10833225/tyw001.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1093/cybsec/tyw001","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyw001","pdf_url":"https://academic.oup.com/cybersecurity/article-pdf/2/2/121/10833225/tyw001.pdf","source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":10,"referenced_works":["https://openalex.org/W2029598260","https://openalex.org/W2056075452","https://openalex.org/W2269519098","https://openalex.org/W2316695912","https://openalex.org/W2322673779","https://openalex.org/W2338036545","https://openalex.org/W2462830067","https://openalex.org/W2565682512","https://openalex.org/W6658020514","https://openalex.org/W6693696362"],"related_works":["https://openalex.org/W2149202530","https://openalex.org/W2921723332","https://openalex.org/W2482950156","https://openalex.org/W3042334625","https://openalex.org/W3139248031","https://openalex.org/W4200017362","https://openalex.org/W2807822918","https://openalex.org/W2305322260","https://openalex.org/W2118123121","https://openalex.org/W2472747690"],"abstract_inverted_index":{"In":[0],"2013,":[1],"the":[2,13,26,52,58,91,117,146,162,171,175,201,214,228,258,274,277],"US":[3],"President":[4],"signed":[5],"an":[6,41],"executive":[7],"order":[8],"designed":[9],"to":[10,34,63,77,89,100,110,186,213,219,248],"help":[11],"secure":[12],"nation\u2019s":[14],"critical":[15],"infrastructure":[16],"from":[17,178],"cyberattacks.":[18],"As":[19],"part":[20],"of":[21,51,60,95,119,126,148,156,204,231,260,289],"that":[22,38,70,132,173,197,221,241,250,257,284],"order,":[23],"he":[24],"directed":[25],"National":[27],"Institute":[28],"for":[29,44,108],"Standards":[30],"and":[31,93,98,115,140,154,164,169,189,206,233,283],"Technology":[32],"(NIST)":[33],"develop":[35],"a":[36,124,243,261],"framework":[37,53],"would":[39],"become":[40],"authoritative":[42],"source":[43],"information":[45,157],"security":[46,80,113,136,281],"best":[47],"practices.":[48],"Because":[49],"adoption":[50],"is":[54,268],"voluntary,":[55],"it":[56],"faces":[57],"challenge":[59],"incentivizing":[61],"firms":[62,76,109,220,249],"follow":[64],"along.":[65],"Will":[66],"frameworks":[67],"such":[68],"as":[69,152,276],"proposed":[71],"by":[72,167],"NIST":[73],"really":[74],"induce":[75],"adopt":[78],"better":[79],"controls?":[81],"And":[82],"if":[83],"not,":[84],"why?":[85],"This":[86],"research":[87],"seeks":[88],"examine":[90,123,161],"composition":[92],"costs":[94,177,185],"cyber":[96,130,179,263],"events,":[97],"attempts":[99],"address":[101],"whether":[102],"or":[103],"not":[104],"there":[105],"exist":[106],"incentives":[107],"improve":[111],"their":[112,290],"practices":[114],"reduce":[116],"risk":[118],"attack.":[120],"Specifically,":[121,254],"we":[122,144,255],"sample":[125,267],"over":[127],"12":[128],"000":[129,272],"events":[131],"include":[133],"data":[134],"breaches,":[135],"incidents,":[137],"privacy":[138],"violations,":[139],"phishing":[141],"crimes.":[142],"First,":[143],"analyze":[145],"characteristics":[147],"these":[149,184,223,252],"breaches":[150,205,232],"(such":[151],"causes":[153],"types":[155],"compromised).":[158],"We":[159,181],"then":[160,182],"breach":[163],"litigation":[165],"rate,":[166],"industry,":[168],"identify":[170],"industries":[172],"incur":[174],"greatest":[176],"events.":[180,224,253],"compare":[183],"bad":[187],"debts":[188],"fraud":[190],"within":[191],"other":[192],"industries.":[193],"The":[194],"findings":[195,240],"suggest":[196],"public":[198],"concerns":[199,226],"regarding":[200,227],"increasing":[202,229],"rates":[203,230],"legal":[207,234],"actions":[208],"may":[209],"be":[210],"excessive":[211],"compared":[212],"relatively":[215],"modest":[216],"financial":[217,246],"impact":[218,247],"suffer":[222,251],"Public":[225],"actions,":[235],"conflict,":[236],"however,":[237],"with":[238],"our":[239,266],"show":[242],"much":[244],"smaller":[245],"find":[256],"cost":[259],"typical":[262],"incident":[264],"in":[265],"less":[269],"than":[270],"$200":[271],"(about":[273],"same":[275],"firm\u2019s":[278],"annual":[279,292],"IT":[280],"budget),":[282],"this":[285],"represents":[286],"only":[287],"0.4%":[288],"estimated":[291],"revenues.":[293]},"counts_by_year":[{"year":2026,"cited_by_count":7},{"year":2025,"cited_by_count":27},{"year":2024,"cited_by_count":27},{"year":2023,"cited_by_count":24},{"year":2022,"cited_by_count":22},{"year":2021,"cited_by_count":33},{"year":2020,"cited_by_count":31},{"year":2019,"cited_by_count":27},{"year":2018,"cited_by_count":17},{"year":2017,"cited_by_count":16},{"year":2016,"cited_by_count":1}],"updated_date":"2026-05-21T09:19:25.381259","created_date":"2025-10-10T00:00:00"}
