How To Stay Ahead of Cyber Risk

Effective Cybersecurity Requires an Interdisciplinary Approach

Dec 04, 2019

SMITH BRAIN TRUST  Cyber risk can come from data breaches or cyber attacks, but to really root out cyber threats and prepare for risks, organizations need to take a new approach. Efforts must extend beyond computer science to pull fields such as behavioral science, economics, law, management science and political science, according to a new article published in Science magazine.

Maryland Smith’s Lawrence A. Gordon collaborated with 18 other researchers from institutions around the world on the article that lays out how to advance the science of cyber risk by taking an interdisciplinary research approach. The article also discusses the barriers to the approach.

“By addressing cyber risk terminology, standards, and implementation principles in a cross-disciplinary fashion, such guidance can be interpretable and usable by a wide variety of companies and nonprofit and governmental organizations that have different agendas,” the researchers write. “Diversity of thought will likely contribute to richer cyber risk insights. There is also value to classifying the variety of cyber risks so that they can be addressed appropriately.”

The authors concede avoiding all cyber risk is unrealistic, but they point to ways to decrease risk in some scenarios, includings designing and building software and hardware systems to avoid certain security issues. They say organizations could also minimize cyber risk by “minimizing the use of connected computing systems in certain environments.”

The researchers say a concrete step toward reducing cyber risk is to share information about threats to help other organizations prevent similar future attacks, and they push for that with the article.

“Given the critical nature of cyber risk in today's interconnected digital world, this article should resonate with anyone interested in issues related to cyber risk, privacy, and/or cybersecurity,” Gordon says.

Gordon, Smith’s EY Alumni Professor of Managerial Accounting and Information Assurance, is considered a pioneer in the area of cybersecurity economics. Gordon and Smith professor Martin P. Loeb developed a mathematical framework, the Gordon-Loeb model, to help organizations figure out how much they should invest in cybersecurity.

Cyber Risk Research Impeded by Disciplinary Barriers” is featured in the Nov. 29, 2019 issue of Science.



About the Expert(s)


Dr. Lawrence A. Gordon is an internationally known scholar in the area of managerial accounting. His work focuses on such issues as performance measures, economic aspects of information security, cost management systems, the interface between managerial accounting and information technology, and capital investments. Dr. Gordon is considered to be one of the pioneers on the emerging field of cybersecurity economics.


Dr. Loeb's early research was in economic mechanism design, incentive regulation, cost allocations, and cost-based procurement contracting. His current research (with Professor Lawrence Gordon) deals with economic aspects of information security and the interface between managerial accounting and information technology. In addition to being a Professor at the Smith School, he holds an Affiliate Professorship in University of Maryland Institute for Advanced Computer Studies (UMIACS).

More In


Summer Reading List 2020

It's the 17th annual Summer Reading List for Business Leaders – your summer reading guide as recommended by Maryland Smith's faculty experts.

May 27, 2020
Tax Advice for the Pandemic Era

Your tax donations, your home office, your added childcare costs. Here's the tax advice our expert is giving to his clients.

Mar 23, 2020
Tax Rules for College Students And Their Parents

A Maryland Smith expert describes the clever – and entirely legal – loophole his dad used to reduce his income tax and how that loophole has changed.

Jan 21, 2020