Information Security Economics 1
Running Head: Information Security Economics Considerations
Module 4 – Case
Course #: ITM517
Information Security Overview for Managers and Policy Makers
Information Security Economics 2
Introduction
Firewalls are common; email encryption is rare: not because of the relative effectiveness
of the technologies, but because of the economic pressures that drive companies to install them
(Anderson and Schneier, 2005). Economics is the answer to most information security issues.
Companies rarely publicize information about intrusions because of economic incentives against
doing so. An insecure operating system is the international standard, in part because its economic
effects are largely borne not by the company that builds the operating system, but by the
customers that buy it (Anderson and Schneier, 2005). This paper begins by outlining some major
information security economics considerations, followed by a discussion on how an
understanding of economics can help in information security and conclude with a discussion on
network externalities.
Major Economics considerations in Information Security and Management:
Information security is often viewed as a technical issue, however, economic considerations are
everywhere in information security, from the value of the information itself to the coat of
securing and protecting it.
The economic value of information is perhaps one of the most obvious considerations.
Most companies will agree that one of their most valuable assets is their information. It is the
economic value of information why information security exists in the first place. According to
Bruce Schneier, “there are companies whose information assets are worth more than their
physical assets.”
Another important consideration is that attackers are driven by economic reasons.
Criminals are now the dominant attackers on the Internet. Hacking as a hobby is now a thing of
the past (Schneier, 2007). Most computer hackers in this day and age have criminal intentions
Information Security Economics 3
with the aim of obtaining some financial reward. This is evident in cybercrimes such as, identity
theft, Internet fraud, spamming, denial of service extortion and the list continues. Inside attacks
which consist of 80% of information system attacks are also driven by economics. Employees
know the value of their company’s information and will engage in the selling of such
information or they may use the information otherwise to obtain some financial gain.
Security is a trade-off; whether it's trading some additional home security against the
inconvenience of having to carry a key around in your pocket and stick it into a door every time
you want to get into your house; or trading additional security from a particular kind of airplane
terrorism, against the time and expense of searching every passenger, all security is a trade-off.
(Scheiner, 2008). In other words, security cost, convenience, time and money. A bank for
example, may not be able to offer the convenient online banking to its customers due to security
risks. The technicality that accompanies some security mechanisms may at times slow down
some business processes. For the organization to implement such security mechanisms in the
first place requires money. There is also a cost to security failures which can affect a company in
various ways. If a company’s security fails they can lose valuable information or private
information may become exposed or corrupted. Such failure can also cause companies to lose
customers who may believe that such companies are incapable of protecting their privacy. In
other words, security failures are economic failures (Bruce, 2007). These failures occur when
companies get their trade-offs wrong. The reality is that sometimes people make trade-off based
on the feelings of security rather than the reality of security. Scheiner stated, “we make the best
security trade-offs--and by that I mean trade-offs that give us genuine security for a reasonable
cost--when our feeling of security matches the reality of security. It's when the two are out of
alignment that we get security wrong.”
Information Security Economics 4
How can understanding economics help? Economics is the answer to most information
security issues. Information security failure is an economic failure and security success is an
economic success, therefore the economics of information security should not be ignored.
Information security is an economic issue as much as it is a technical issue. There are countless
economic issues that surround information security but how can understanding the ones already
discussed in this paper help?
The first consideration is the economic value of information. If an organization does not
believe that their information has an economic value, it will not have an appreciation of
information security and will therefore, not put the proper measures in place to safeguard its
information.
The second consideration is that attackers (both internal and external) are driven by
economic reasons. This consideration should force organizations to implement the very best
information security since the attackers are motivated by economic reasons, meaning they will
stop at nothing to break into the organization’s information system. This should also alert the
organization not to focus only on the outside attackers, but to also monitor employees who might
be more detrimental, attacking from the inside.
The final consideration is that security is a trade-off. This consideration is understood by
many organizations however, it is getting the trade-off right that poses the problem for many
organizations. If an organization gets its information security trade-offs wrong it runs the risk of
operating what Scheiner refers to as a security theatre- the illusion that one is secure when the
reality is the total opposite. Therefore IT managers should endeavour to get their security trade-
offs right by bringing the reality of security as close as possible to the feelings of security.
Information Security Economics 5
Economics Mechanisms that help improve Information Security and Management:
Information security is often seen as a technical problem, however, many of the problems can be
explained more clearly and convincingly using the language of microeconomics such as network
externalities. Network externalities mean the more people use a typical network, the more
valuable it becomes (Anderson n.d). For example, the more people use the Windows platform
the more value it has and consequently more people will want to use it. This means that the
winner takes all as in the case of Microsoft. But what do network externalities have to do with
information security? The answer is fount in the words of Scheiner “an insecure operating
system is the international standard…” Even though network externalities often adds value to a
product as it multiplies, it also can trigger a negative effect and such negative effects can cause
information security implications for organizations. Microsoft Windows is perhaps the most
popular operating system due its network externalities, yet it is perhaps one of the most insecure.
First it is a closed source software and the security illusion created by obscurity is no secret.
Secondly its popularity makes it more vulnerable to attacks since attackers possess more
knowledge about it. This goes to show that economics concepts such as network externalities
should not be overlooked when making information security decisions.
Conclusion
Information security is not just a technical issue but it is also surrounded by countless
economics issues and understanding such issues helps in making good information security
decisions. The information itself has economic value and that is why there is the need for
information security in the first place. Attackers both internal and external are also motivated by
economic gain. Information security is an economic trade-off. Finally, understanding
Information Security Economics 6
microeconomics concepts such as network externalities have a vital part to play in making good
information security decisions.
Information Security Economics 7
Reference
Anderson, R., Schneier B. (2005). Economics of information security. IEEE Security and Privacy
3 (1), pp. 12-13. Retrieved February 23, 2010 from [Link]
[Link]
Anderson, R. (n.d). Why information security is heard: an economic perspective. University of
Cambridge Computer Laborator. Retrieved February 28, 2010 from
[Link]
Scheiner, B. (2008). The psychology of security. Retrieved January 28, 2010 from
[Link]
Schneier, B (2008). Reconceptualizing security on topics of security feeling, reality and model.
Infosecurity Europe. Retrieved January 2010, from
[Link]
video/[Link]
Schneier, B. (2007). The economics of information security. Public lecture at the London School
of Economics. Retrieved February 27, 2010 from
[Link]