Comparison of Information Security Decisions under Different Security and Business Environments

Yong Wu,Gengzhong Feng,Richard Y. K. Fung
DOI: https://doi.org/10.1057/s41274-017-0263-y
IF: 3.6
2018-01-01
Journal of the Operational Research Society
Abstract:Serious information security breaches have caused firms to suffer from customer churns directly or indirectly. To prevent customer churns, firms usually enhance their security protection through two measures, i.e. security investment and security information sharing. Prior studies seldom consider security environment and business environment simultaneously when making a firm’s optimal security decisions. Using game theory, this paper purports to demonstrate that a firm’s security decisions under a competitive environment differ significantly from those under an integrated environment. Moreover, distortions may surface if firms do not cooperate on security practices. Thus, this paper further analyses the measures that a social planner such as the government or industry association controls firms’ security decisions, and results show that these measures may not always be effective. Instead, social planners are recommended to enhance or attenuate the controlling level of the two security decisions based on realistic security and business environments.
What problem does this paper attempt to address?