Cybersecurity and Incentives
Module 1 Topic 2 Lesson 4
Welcome back to class.
This lesson is approach to cybersecurity has been influenced by recent social
science research on the economics of cybersecurity.
This approach emphasizes the factor shaping the incentives of actors.
Incentives both to attack and to defend information systems, and
how those incentives can be shaped by policies, and institutions.
It also focuses attention on the way policies and
institutions guide in effect security incentives.
At the heart of this approach is the idea that security is an economic good.
By this, it's produced.
Better cybersecurity creates value for people and organizations.
So there's a demand for it and that demand will generate a supply if
security enhancing products, services and procedures.
But the supply if security is never free and that means that an organization's
investments in security will be subject to a marginal cost-benefit analysis.
Likewise, the actions of attackers are governed by economic incentives as well.
True, some of them may have political or personal motives.
But generally, the higher the benefits one can get from cyber attacks and the lower
the costs of conducting them, the more cyber attacks you're likely to get.
That may seem obvious, but linking cybersecurity to this economic
perspective puts a set of analytical tools at our disposal
that are often used to assess other public policy issues.
Here is a list of some of the key concepts we will use in examining the incentives of
cybersecurity.
Defense, offense and policy.
We need to understand the distinction between public goods and private goods.
We need to understand markets as an exchange of property rights and
how property rights are defined.
We need to understand the cost associated with searching, organizing, negotiating
and enforcing the market exchange which is known as transaction cost.
We need to understand what an externality is and we need to understand the impact
of incomplete, and asymmetric information on market transactions.
The reading assigned for this lesson describes these concepts
in more detail and applies them for particular cybersecurity issues.
These concepts are most relevant when we are talking about cybersecurity at
the industry level, the national level and the transnational level.
They apply to have different organizations transact with each other.
Accessing the role of government in cybersecurity,
the status of cybersecurity as a public good or private good comes into play.
A public good has two defining characteristics.
First, it means that the person's use of it does not prevent anyone else from
using it.
In other words, consumption is non-rival.
Second, it means that once the good is produced,
it is difficult to exclude others from enjoying it.
This can create what is called a free rider problem.
That is those who don't pay for the resource can't actually benefit from it.
So these two special economic characteristics tend to require collective
forms of production.
National defense is often used as an example of a public good.
Because when you're defending an entire country against a foreign military threat,
you have to defend the country as a whole.
You can't really exclude certain people or places from the defense process.
Does this mean that national defense is an appropriate model for
cybersecurity production?
Not for most types of cybersecurity.
In most instances, cybersecurity is a private good.
By private good, we mean something that a person or organization can purchase or
produce and restrict the benefits of the good or service to the purchaser.
In other words, people who don't buy the good don't get the benefit.
Although public security is often considered a governmental function,
many kinds of security are in fact private goods.
When you buy door locks, for example, or car alarms,
you are gaining physical security as a private good.
Your purchase makes your own home more secure and
it doesn't affect anyone else's.
They are private good and cybersecurity, as well.
When IT infrastructure operators install access control mechanisms or
encrypt their data or subscribe to spam filters or
install intrusion prevention devices and software,
they are buying production for their own systems not anyone else's.
Cyber-insurance markets and insurance markets
generally sit in a middle ground between a public, and private good.
In insurance markets, private risks are pooled together and
the costs are spread out over a population.
We'll talk more about cyber-insurance as a risk
mitigation strategy later on in module two.
Here's three more concepts from economics, property rights,
transaction costs and externalities and they're all closely related.
A property right is like a legally recognized
fence around a valuable resource.
It gives the owner the exclusive rights to use a good,
to reap profits from it or other benefits from it or to exchange the good or
transfer ownership to someone else.
Transaction costs are the cost associated with exchanging property rights or
a service contract.
They involve such costs as searching for the price or value data,
negotiating costs and monitoring the performance of contracts.
If transaction costs are too high,
then market transactions that would otherwise be efficient may not take place.
An externality on the other hand refers to economic costs or
benefits that occur to third parties who are not part of a market transaction.
Benefits are costs that are not captured by the way property rights are exchanged
or defined and that turns out to be an important concept in cybersecurity.
The concept of externalities is directly applicable to many
cybersecurity phenomenon.
When a company fails to invest in cybersecurity,
how much of the insecurity is confined to their own company?
And how much of the harm spillover are felt by others?
A clear externality was involved when
Internet of Things device manufacturers provided cheap devices, but
put easily guessable passwords in them or other kinds of lax security controls.
This became evident when thousands of these devices were taken over by a botnet
operator and use to mount a massive DDoS attack,
which actually shut down DNS in certain parts of the country.
The cost of that attack was not confined to the owners of the IoT devices.
A service contract is another example of how transactions, costs and
externalities might come into play.
A service contract between an internet service provider and corporate customer
is a negotiation of who has what rights when the corporation's networks,
and devices are connected to the network of the ISP.
The agreement may, for example,
give the internet service provider the right to terminate access to a customer in
the event of a security incident that affects the ISP as a whole.
In information markets that are multi-sided such as platform markets,
the platform intermediary may have incentives to internalize
certain externalities.
For example, the app stores that are run by platform providers like Apple or
Android, they may filter out certain apps or
review them in order to protect the security of their customers.
In this case, what might be an externality is being internalized by
the platform provider and you need to look at the incentives of the platform
providers to either internalize or not internalize certain externalities.
For information security to function as a private good,
buyers must be able to distinguish between more secure and less secure products.
But that requires a lot of knowledge that people may not have.
A subscriber looking to purchase internet access, for example,
may not be able to distinguish ISP's with strong security practices from
those with lax ones and this makes buyers unwilling to pay a premium for
the better product and consequently discourages suppliers from offering them.
Now, let's summarize some of the applications of these economic theories to
cybersecurity problems.
It's all about how actions shape incentives, the incentives of actors.
Specifically, policies can incentivize defenders and
disincentivize attackers if we get them right.
For example, if we are creating incentives for better defense,
we can try to target those incentives at specific actors in the ecosystem,
such as end users or infrastructure providers.
And we can do it by let's say, reducing information asymmetries,
by addressing negative externalities or even simply by educating people or
building their capacity to understand cybersecurity.
If we're trying to discourage attackers on the other hand, we can try to target our
disincentives at specific types of bad actors such as criminals or nation states.
We might for example try to deter them by punishing them.
So we can use various tools such as deterrents which might reduce
the benefits of a tax or we might disrupt a tact or resources, or
we might threaten retaliation.
All of which would distance and advise certain kinds of attacks.
So that's a quick overview of the economic concepts.
Next, we'll talk about basic concepts and vocabulary.