Cyber risk propagation and budget optimization in financial networks: a Monte Carlo approach
摘要
This study develops a Monte Carlo based cyber risk simulation model tailored for interconnected financial ecosystems comprising 15 heterogeneous nodes, including banks, fintech firms, vendors, and data centers. Each node is characterized by its vulnerability, compliance level, threat intelligence, and control effectiveness. The model captures cyber-attack probabilities and residual risk propagation through a weighted adjacency matrix representing interdependencies. Using 10,000 stochastic iterations, the model evaluates key outcomes under uncertain conditions, incorporating multi component cyber security costs investment, insurance, penalties, and operational losses. A constrained optimization algorithm based on sequential least squares quadratic programming (SLSQP) minimizes total costs and residual risk, subject to IT budget constraints. Simulation results show that high vulnerability, low compliance nodes such as Vendor_C and Vendor_H experienced the highest attack probabilities (≈0.063–0.065), while compliant entities like Bank_A and Data Center_E maintained lower risk levels (≈0.005–0.010). Despite strong individual defenses, nodes like Bank_A inherited systemic risk through network links to more vulnerable entities, demonstrating the cascading nature of digital threats. Optimized budget allocations, ranging from 0.25 to 3.6 M USD per node, effectively prioritized critical nodes, reducing residual risk without breaching financial constraints. These findings underscore the importance of network aware, risk informed cybersecurity investments. The proposed framework is a decision support tool for financial institutions seeking to balance compliance, resilience, and cost efficiency in dynamic digital environments.