Attack-prevention and damage-control investments in cybersecurity

被引:9
作者
Lam, Wing Man Wynne [1 ]
机构
[1] Univ Liege ULg, HEC Management Sch, Liege Competit & Innovat Inst, Liege, Belgium
关键词
Cybersecurity; Investment; Standard; Liability; Bilateral care; PRODUCTS-LIABILITY; SOFTWARE SECURITY; ECONOMIC-ANALYSIS; VAPORWARE; HARM;
D O I
10.1016/j.infoecopol.2016.10.003
中图分类号
F [经济];
学科分类号
02 ;
摘要
This paper examines investments in cybersecurity made by users and software providers with a focus on the latter's concerning attack prevention and damage control. I show that full liability, whereby the provider is liable for all damage, is inefficient, owing namely to underinvestment in attack prevention and overinvestment in damage control. On the other hand, the joint use of an optimal standard, which establishes a minimum compliance framework, and partial liability can restore efficiency. Implications for cybersecurity regulation and software versioning are discussed. (C) 2016 Elsevier B.V. All rights reserved.
引用
收藏
页码:42 / 51
页数:10
相关论文
共 31 条
  • [1] Acemoglu Daron., 2013, Network Security and Contagion
  • [2] Information security: where computer science, economics and psychology meet
    Anderson, Ross
    Moore, Tyler
    [J]. PHILOSOPHICAL TRANSACTIONS OF THE ROYAL SOCIETY A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 2009, 367 (1898): : 2717 - 2727
  • [3] [Anonymous], J LAW EC ORG
  • [4] [Anonymous], 2016, Internet security threat report
  • [5] Network software security and user incentives
    August, Terrence
    Tunca, Tunay I.
    [J]. MANAGEMENT SCIENCE, 2006, 52 (11) : 1703 - 1720
  • [6] Who Should Be Responsible for Software Security? A Comparative Analysis of Liability Policies in Network Environments
    August, Terrence
    Tunca, Tunay I.
    [J]. MANAGEMENT SCIENCE, 2011, 57 (05) : 934 - 959
  • [7] Truth or consequences: An analysis of vaporware and new product announcements
    Bayus, BL
    Jain, S
    Rao, AG
    [J]. JOURNAL OF MARKETING RESEARCH, 2001, 38 (01) : 3 - 13
  • [8] Belleflamme P., 2010, IND ORG MARKETS STRA, P309
  • [9] Böhme R, 2010, LECT NOTES COMPUT SC, V6434, P10, DOI 10.1007/978-3-642-16825-3_2
  • [10] TOWARD AN ECONOMIC THEORY OF LIABILITY
    BROWN, JP
    [J]. JOURNAL OF LEGAL STUDIES, 1973, 2 (02) : 323 - 349