Outsourcing Internet Security: Economic Analysis of Incentives for Managed Security Service Providers
نویسندگان
چکیده
Firms hesitate to outsource their network security to outside security providers (called Managed Security Service Providers or MSSPs) because an MSSP may shirk secretly to increase profits. In economics this secret shirking behavior is commonly referred to as the Moral Hazard problem. There is a counter argument that this moral hazard problem is not as significant for the Internet security outsourcing market because MSSPs work hard to build and maintain their reputations which are crucial to surviving competition. Both arguments make sense and should be considered to write a successful contract. This paper studies the characteristics of optimal contracts (payment to MSSPs) for security outsourcing market by setting up an economic framework that combines both effects. It is shown that an optimal contract should be performance-based. The degree of performance dependence decreases if the reputation effect becomes more significant. We also show that if serving a large group of customers helps the provider to improve service quality significantly (which is observed in the internet security outsourcing market), an optimal contract should always be performance-based even if a strong reputation effect exists.
منابع مشابه
Outsourcing Internet Security: The Effect of Transaction Costs on Managed Service Providers
Transaction costs are a significant factor in outsourcing decisions. In the case of Internet security, outsourcing has higher transaction costs for two major reasons: (1) the outsourcing process is not yet standardized and (2) there is uncertainty about the frequency and impact of cyber attacks creating large variations in coordination costs. In this paper we study the effects of transaction co...
متن کاملEconomics of Internet Security Outsourcing: Simulation Results Based on the Schneier Model
Dynamic and complex information security risks facing organizations are forcing them to take a hard look at outsourcing to Managed Security Service Providers (MSSPs). The potential advantage of outsourcing is to improve security levels at lower costs. Potential risks of outsourcing to an MSSP includes service quality uncertainty and the business risk of MSSP bankruptcy. In this paper we present...
متن کاملManaging Security Service Providers: Issues in Outsourcing Security
The issue of trust and risk in outsourced relationships was extended beyond traditional outsourcing models with the introduction of Application Service Providers (ASPs). As ASPs evolve, Managed Security Service Providers (MSSPs) have emerged as external providers of security for firms facing increasing information assurance threats. This research-in-progress paper develops a conceptual model of...
متن کاملHow to improve security by contracting security outsourcing
There is an increasing number of articles and internet forums against outsourcing security and contracting Managed Security Services. In this type of articles and forums, outsourcing providers professionals are presented as a security threat to their customers.(An extreme example of this can be seen at Cio.com Forum (6)). The aim of this paper is to show customers the possible advantages of con...
متن کاملOn the Effects of Authentication and Authorisation Infrastructures on E-Commerce Environments
Authentication and Authorisation Infrastructures (AAIs) support service providers on the Internet in outsourcing security services. AAIs influence and change the process of e-commerce transactions on multiple points. Changes influence users, service providers, and provider federations likewise. This work analyses the alterations implied by an AAI, comparing various AAI paradigms and traditional...
متن کامل