Information risks represent one of the key challenges faced by modern organizations, as increasing digitalization of business processes leads to greater exposure to cyber incidents and their financial and non-financial consequences. The aim of this master’s thesis is to analyze information risk management in Slovenia and EU, with a focus on the regulatory framework, cybersecurity, and the role of cyber insurance as a risk management instrument. The thesis combines a theoretical overview of information risk management, an analysis of the European and national regulatory environment, and an empirical quantitative analysis of cyber incidents. Special attention is given to modeling the frequency of incidents, loss severity distributions, and aggregate losses, using methods from risk theory and extreme value theory. Based on these models, the applicability of quantitative approaches for cyber insurance premium calculation is also assessed. The results indicate that effective information risk management requires a holistic approach encompassing technical, organizational, and human factors, while regulation provides an important but not sufficient framework for risk mitigation. The empirical analysis confirms the presence of heavy-tailed loss distributions, which has significant implications for cyber insurance pricing and risk assessment. The thesis contributes to a better understanding of information risks and provides a foundation for further research and the development of more effective approaches to information risk management and cyber insurance.
|