How To Stay Ahead of Cyber Risk

Effective Cybersecurity Requires an Interdisciplinary Approach

Jan 21, 2020
As Featured In 

Cyber risk can come from data breaches or cyber attacks, but to really root out cyber threats and prepare for risks, organizations need to take a new approach. Efforts must extend beyond computer science to pull fields such as behavioral science, economics, law, management science and political science, according to a new article published in Science magazine.

Maryland Smith’s Lawrence A. Gordon collaborated with 18 other researchers from institutions around the world on the article that lays out how to advance the science of cyber risk by taking an interdisciplinary research approach. The article also discusses the barriers to the approach.

“By addressing cyber risk terminology, standards, and implementation principles in a cross-disciplinary fashion, such guidance can be interpretable and usable by a wide variety of companies and nonprofit and governmental organizations that have different agendas,” the researchers write. “Diversity of thought will likely contribute to richer cyber risk insights. There is also value to classifying the variety of cyber risks so that they can be addressed appropriately.”

The authors concede avoiding all cyber risk is unrealistic, but they point to ways to decrease risk in some scenarios, includings designing and building software and hardware systems to avoid certain security issues. They say organizations could also minimize cyber risk by “minimizing the use of connected computing systems in certain environments.”

The researchers say a concrete step toward reducing cyber risk is to share information about threats to help other organizations prevent similar future attacks, and they push for that with the article.

“Given the critical nature of cyber risk in today's interconnected digital world, this article should resonate with anyone interested in issues related to cyber risk, privacy, and/or cybersecurity,” Gordon says.

Gordon, Smith’s EY Alumni Professor of Managerial Accounting and Information Assurance, is considered a pioneer in the area of cybersecurity economics. Gordon and Smith professor Martin P. Loeb developed a mathematical framework, the Gordon-Loeb model, to help organizations figure out how much they should invest in cybersecurity.

Cyber Risk Research Impeded by Disciplinary Barriers” is featured in the Nov. 29, 2019 issue of Science.

About the Author(s)


Dr. Lawrence A. Gordon is an internationally known scholar in the area of managerial accounting. His work focuses on such issues as performance measures, economic aspects of information security, cost management systems, the interface between managerial accounting and information technology, and capital investments. Dr. Gordon is considered to be one of the pioneers on the emerging field of cybersecurity economics.


Dr. Loeb's early research was in economic mechanism design, incentive regulation, cost allocations, and cost-based procurement contracting. His current research (with Professor Lawrence Gordon) deals with economic aspects of information security and the interface between managerial accounting and information technology. In addition to being a Professor at the Smith School, he holds an Affiliate Professorship in University of Maryland Institute for Advanced Computer Studies (UMIACS).

More in


Do Innovative Firms Communicate More?
New research finds that successful innovation, measured in patents, leads firms to issue more voluntary management forecasts, which can then spur more investment in the firm.
May 07, 2020
The Value of the CAPEX Forecast
New research looks at the capital expenditure, or CAPEX, forecast to see how it influences company investment behavior.
Apr 28, 2020
Confused by Unclear Accounting Information
In the grand scheme of the economy, the accounting information that individual firms report can have big impacts.
Sep 05, 2019