4.6 Article

Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements

Journal

JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
Volume 30, Issue 1, Pages 123-152

Publisher

ROUTLEDGE JOURNALS, TAYLOR & FRANCIS LTD
DOI: 10.2753/MIS0742-1222300104

Keywords

cyberinsurance; information security; interdependent risks; managed security services; risk management; risk pooling

Funding

  1. National Science Foundation [0831338]
  2. Division Of Computer and Network Systems
  3. Direct For Computer & Info Scie & Enginr [1228990] Funding Source: National Science Foundation
  4. Division Of Computer and Network Systems
  5. Direct For Computer & Info Scie & Enginr [0831338] Funding Source: National Science Foundation

Ask authors/readers for more resources

The interdependency of information security risks often induces firms to invest inefficiently in information technology security management. Cyberinsurance has been proposed as a promising solution to help firms optimize security spending. However, cyberinsurance is ineffective in addressing the investment inefficiency caused by risk interdependency. In this paper, we examine two alternative risk management approaches: risk pooling arrangements (RPAs) and managed security services (MSSs). We show that firms can use an RPA as a complement to cyberinsurance to address the overinvestment issue caused by negative externalities of security investments; however, the adoption of an RPA is not incentive-compatible for firms when the security investments generate positive externalities. We then show that the MSS provider serving multiple firms can internalize the externalities of security investments and mitigate the security investment inefficiency. As a result of risk interdependency, collective outsourcing arises as an equilibrium only when the total number of firms is small.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available