The economics of cybersecurity: Principles and policy options
نویسنده
چکیده
Economics puts the challenges facing cybersecurity into perspective better than a purely technical approach does. Systems often fail because the organizations that defend them do not bear the full costs of failure. For instance, companies operating critical infrastructures have integrated control systems with the Internet to reduce near-term, measurable costs while raising the risk of catastrophic failure, whose losses will be primarily borne by society. As long as anti-virus software is left to individuals to purchase and install, there may be a less than optimal level of protection when infected machines cause trouble for other machines rather than their owners. In order to solve the problems of growing vulnerability and increasing crime, policy and legislation must coherently allocate responsibilities and liabilities so that the parties in a position to fix problems have an incentive to do so. In this paper, we outline the various economic challenges plaguing cybersecurity in greater detail: misaligned incentives, information asymmetries and externalities. We then discuss the regulatory options that are available to overcome these barriers in the cybersecurity context: ex ante safety regulation, ex post liability, information disclosure, and indirect intermediary liability. Finally, we make several recommendations for policy changes to improve cybersecurity: mitigating malware infections via ISPs by subsidized cleanup, mandatory disclosure of fraud losses and security incidents, mandatory disclosure of control system incidents and intrusions, and aggregating reports of cyber espionage and reporting to the World Trade Organization (WTO).
منابع مشابه
The Economics of Cybersecurity: Principles and Policy Options1
Economics puts the challenges facing cybersecurity into perspective better than a purely technical approach does. Systems often fail because the organizations that defend them do not bear the full costs of failure. For instance, companies operating critical infrastructures have integrated control systems with the Internet to reduce near-term, measurable costs while raising the risk of catastrop...
متن کاملPolicy Options to Reduce Fragmentation in the Pooling of Health Insurance Funds in Iran
There are fragmentations in Iran’s health insurance system. Multiple health insurance funds exist, without adequate provisions for transfer or redistribution of cross subsidy among them. Multiple risk pools, including several private secondary insurance schemes, have resulted in a tiered health insurance system with inequitable benefit packages for different segments of the population. Also fra...
متن کاملImproving Injectable Medicines Prescription in Outpatient Services: A Path Towards Rational Use of Medicines in Iran
Injection is one of the most common medical procedures in the health sector. Annually up to 16 billion injections are prescribed in low- and middle-income countries (LMICs), many of them are not necessary for the patients, increase the healthcare costs and may result in side effects. Currently over 40% of outpatient prescriptions in Iran contain at least one injectable medicine. To address the ...
متن کاملاقتصاددانان رفتاری و نظریههای آنها
Today, in the eyes of most inside or outside economic observers, economics apparently equals to the elements of neo-classical economics in short, methods and solutions of neo-classical economies define the principles of economics. However, in spite of such dominance and notwithstanding all evident accomplishments of neo-classical economics, it has always been subject to myriads of critique and...
متن کاملAttack-prevention and damage-control investments in cybersecurity
This paper examines investments in cybersecurity made by users and software providers with a focus on the latter’s concerning attack prevention and damage control. I show that full liability, whereby the provider is liable for all damage, is inefficient, owing namely to underinvestment in attack prevention and overinvestment in damage control. On the other hand, the joint use of an optimal stan...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- IJCIP
دوره 3 شماره
صفحات -
تاریخ انتشار 2010