Hello,
This is my first post on the site so forgive me if I don't follow etiquette correctly.
I am working on a project that is looking at the Cyber Security within schools. I have had numerous chats with a variety of school officials from School IT Staff, Governors, Head Teachers etc.. and there appears to be a reluctance to sometimes share information openly (understandable when we're talking and looking into how a Cyber attack occurred. We Hypothesis that usually time, money & resource are major factors behind why attacks happen.
What I want to try and do is quantify some of those things and understand what the Direct & more importantly the Indirect costs are. I have added a table below that defines what I mean by Direct & Indirect. I have also have a browse through the forum and found what look like really useful pages (sadly some of them are hidden behind restricted walls)
[TABLE=width: 0]
[TR]
[TD][/TD]
[TD]Short Term (Days)[/TD]
[TD]Medium Term (Weeks)[/TD]
[TD]Long Term (Months)[/TD]
[/TR]
[TR]
[TD]Direct Costs[/TD]
[TD]* Consultant fees
* Cyber ransom and extortion losses
* Financial theft
* Insurance excess
* Staff response (overtime)
* Staff response costs (contracting external staff)[/TD]
[TD]* Changes in cyber security practices
* Compensation/discounts
* Complaints (external)
* Fines
* Investigation (external)
* Legal
* PR/marketing activities (external)
* Recruitment costs
* Third party liability[/TD]
[TD]* Credit rating/insurance premiums
* Cyber security improvements
* Investment/donor/funding loss
* Staff costs (long term)
* Training costs
* Training costs (external resources)
[/TD]
[/TR]
[TR]
[TD]Indirect Costs[/TD]
[TD]* Containment
* Data and software loss
* Intellectual property theft
* Interruption of staffs’ business as usual activities (opportunity cost)
* IT equipment damage
* Notification costs (authorities)
* Notification costs (customer)
* Physical equipment damage (not including IT equipment damage)
* Interruption of service
[/TD]
[TD]* Complaints (internal)
* Investigation (internal)
* Post-breach customer protection
* PR/marketing activities (internal)[/TD]
[TD]* Customer attrition
* Cyber security improvements (opportunity cost)
* Long term productivity
* Supply chain attrition
* Training costs (internal resources)
* Training costs (opportunity cost)
[/TD]
[/TR]
[/TABLE]
Any information, data or papers that people would be willing and able to share would be greatly appreciated.
Thanks