Cyber Risk Taxonomies: Statistical Analysis of Cybersecurity Risk Classifications
This paper argues that traditional cyber risk classifications are too restrictive for effective out-of-sample forecasting. It recommends focusing on dynamic, impact-based classifications for better predictions of cyber risk losses, suggesting that risk types are more useful for modeling event frequency rather than severity.