Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements

被引:67
|
作者
Zhao, Xia [1 ]
Xue, Ling [1 ]
Whinston, Andrew B. [2 ]
机构
[1] Univ North Carolina Greensboro, Bryan Sch Business & Econ, Greensboro, NC 27411 USA
[2] Univ Texas Austin, Ctr Res Elect Commerce, Austin, TX 78712 USA
基金
美国国家科学基金会;
关键词
cyberinsurance; information security; interdependent risks; managed security services; risk management; risk pooling; MORAL HAZARD; ORGANIZATIONAL FORM; INSURANCE; SYSTEM; ECONOMICS; MARKETS;
D O I
10.2753/MIS0742-1222300104
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The interdependency of information security risks often induces firms to invest inefficiently in information technology security management. Cyberinsurance has been proposed as a promising solution to help firms optimize security spending. However, cyberinsurance is ineffective in addressing the investment inefficiency caused by risk interdependency. In this paper, we examine two alternative risk management approaches: risk pooling arrangements (RPAs) and managed security services (MSSs). We show that firms can use an RPA as a complement to cyberinsurance to address the overinvestment issue caused by negative externalities of security investments; however, the adoption of an RPA is not incentive-compatible for firms when the security investments generate positive externalities. We then show that the MSS provider serving multiple firms can internalize the externalities of security investments and mitigate the security investment inefficiency. As a result of risk interdependency, collective outsourcing arises as an equilibrium only when the total number of firms is small.
引用
收藏
页码:123 / 152
页数:30
相关论文
共 50 条
  • [1] Information Security Risks and Managed Security Service
    Navarro, Luis
    [J]. Information Security Technical Report, 2001, 6 (03): : 28 - 36
  • [2] Managing Information Technology Security Risk
    Gilliam, DP
    [J]. SOFTWARE SECURITY - THEORIES AND SYSTEMS, 2004, 3233 : 296 - 317
  • [3] Managing Security Risks
    Abrahamson, Donald W.
    Sepeda, Adrian L.
    [J]. CHEMICAL ENGINEERING PROGRESS, 2009, 105 (07) : 41 - 47
  • [4] Cooperative security against interdependent risks
    Gopalakrishnan, Sanjith
    Sankaranarayanan, Sriram
    [J]. PRODUCTION AND OPERATIONS MANAGEMENT, 2023, 32 (11) : 3504 - 3520
  • [5] Mitigating risks of digitalization through managed industrial security services
    Jansen, Christoph
    Jeschke, Sabina
    [J]. AI & SOCIETY, 2018, 33 (02) : 163 - 173
  • [6] A STUDY ON INFORMATION SECURITY IMPACT ON THE DELIVERY OF IT MANAGED SERVICES
    Ionescu, Razvan Cristian
    Olaru, Marieta
    Lampe, Georg Sven
    Fogoros, Teodora Elena
    [J]. 2020 BASIQ INTERNATIONAL CONFERENCE: NEW TRENDS IN SUSTAINABLE BUSINESS AND CONSUMPTION, 2020, : 958 - 965
  • [7] Corporate IT Risk Management Model: a Holistic view at Managing Information System Security Risks
    Spremic, Mario
    [J]. PROCEEDINGS OF THE ITI 2012 34TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES (ITI), 2012, : 299 - 304
  • [8] Dynamic Control and Mitigation of Interdependent IT Security Risks
    Mounzer, Jeffrey
    Alpcan, Tansu
    Bambos, Nick
    [J]. 2010 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2010,
  • [9] Managing software security risks
    McGraw, G
    [J]. COMPUTER, 2002, 35 (04) : 99 - 101
  • [10] Managing security risks with 80001
    Mankovich, Nick
    Fitzgerald, Brian
    [J]. Biomedical Instrumentation and Technology, 2011, 45 (FALL): : 27 - 32