Decisions making in information security outsourcing: Impact of complementary and substitutable firms

被引:19
|
作者
Wu, Yong [1 ,2 ]
Fung, Richard Y. K. [2 ]
Feng, Gengzhong [1 ]
Wang, Nengmin [1 ]
机构
[1] Xi An Jiao Tong Univ, Sch Management, Xian, Shaanxi, Peoples R China
[2] City Univ Hong Kong, Dept Syst Engn & Engn Management, Hong Kong, Peoples R China
基金
中国国家自然科学基金;
关键词
Managed security service providers; Information security investment; Information security outsourcing; Complementary; Substitutable; INVESTMENT; GAME; ECONOMICS; SERVICES; SERIES; ATTACK; RISKS;
D O I
10.1016/j.cie.2017.05.018
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
This paper constructs a contract-theory model to investigate tow an MSSP's (Managed Security Service Provider) operating characteristics of cost efficiency, multiple clients, security externality and firms' information nature affect the MSSP's strategic decisions, including the contract structure and the optimum investment level for firms. The analysis shows that firms' information nature, either complementary or substitutable, plays a crucial role in influencing an MSSP's decisions. First, the MSSP tends to provider a contract with a lower refund and exert a lower security investment level when the degree of complementation is higher while tending to provider a contract with a higher refund and exert a higher security investment level when the degree of substitution is higher. Second, there is a lot of differences that how the security externality affects the decisions of the MSSP who serves complementary firms and that who serves substitutable firms. Third, the MSSP's optimum refund (service fee) to complementary firms is greater than firms' expected loss (expected cost), while the MSSP's optimum refund (service fee) to substitutable firms is smaller than firms' expected loss (expected cost). Fourth, serving a smaller number of substitutable firms is more economic for an MSSP while serving complementary firms the more the better. In addition, the optimum contract structures between an MSSP and complementary (and substitutable) firms are discussed in this paper. These findings give some insights that can guide an MSSP to determine an optimum contract structure and investment level for firms. Future research directions are discussed based on the limitations and possible extensions of this study. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [1] Information security investment for complementary and substitutable firms: The role of technology similarity
    Gao, Xing
    Qiu, Manting
    Gong, Siyu
    Wang, Ying
    Zhang, Yanfang
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2023, 225
  • [2] An economic analysis of information security outsourcing with competitive firms
    Gao, Xing
    Gong, Siyu
    [J]. MANAGERIAL AND DECISION ECONOMICS, 2022, 43 (07) : 2748 - 2758
  • [3] Information sharing and security investment for substitutable firms: A game-theoretic analysis
    Gao, Xing
    Gong, Siyu
    Wang, Ying
    Zhang, Yanfang
    [J]. JOURNAL OF THE OPERATIONAL RESEARCH SOCIETY, 2024, 75 (04) : 799 - 820
  • [4] Incentive contracts research of information security outsourcing for complementary firms in supply chain under double moral hazard
    Wu Y.
    Wang L.
    Feng G.
    [J]. Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2022, 42 (11): : 2916 - 2926
  • [5] Information security decisions of firms considering security risk interdependency
    Wu, Yong
    Wang, Linping
    Cheng, Dong
    Dai, Tao
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2021, 178
  • [6] An economic analysis of information security investment decision making for substitutable enterprises
    Li, Xiaotong
    Xue, Qianyao
    [J]. MANAGERIAL AND DECISION ECONOMICS, 2021, 42 (05) : 1306 - 1316
  • [7] Security investment and information sharing in the market of complementary firms: impact of complementarity degree and industry size
    Liu, Xinbao
    Qian, Xiaofei
    Pei, Jun
    Pardalos, Panos M.
    [J]. JOURNAL OF GLOBAL OPTIMIZATION, 2018, 70 (02) : 413 - 436
  • [8] Security investment and information sharing in the market of complementary firms: impact of complementarity degree and industry size
    Xinbao Liu
    Xiaofei Qian
    Jun Pei
    Panos M. Pardalos
    [J]. Journal of Global Optimization, 2018, 70 : 413 - 436
  • [9] The impact of the information technology (IT) on making decisions
    Radu, CV
    Benga, R
    [J]. REVISTA DE CHIMIE, 2003, 54 (05): : 453 - 454
  • [10] Information security decisions of security-interdependent firms in the presence of consumer sensitivity
    Wu, Yong
    Jin, Zhijie
    Dai, Tao
    Yang, Dong
    [J]. MANAGERIAL AND DECISION ECONOMICS, 2024,