An Analysis of Information Security Management Strategies in the Presence of Interdependent Security Risk
Woohyun Shim · Asia Pacific Journal of Information Systems · 2012
Recent widespread cyber attacks and security breaches have brought about a rapid increase in organizations’ information security investments. A number of studies have explored the optimal level of security investment in situations of independent risk. Issues related to security investment within the context of interdependent risks, however, have not yet been sufficiently investigated. Although previous studies have addressed the security underinvestment problem caused by interdependent risks, for instance, relatively little attention has been paid to the security overinvestment problem. In addition, most of these studies have focused on self-protection mechanisms but not taken insurance mechanisms into account. This study therefore expands the current body of research by exploring multiple scenarios of insufficient and excessive security investments caused by interdependent risks and the interplay between IT security investment and cyber insurance. I discuss how interdependent risk affects firms’ information security risk management with respect to the two different types of cyber attacks (i.e., targeted and untargeted attacks). Although the theoretical models upon which the analysis relies are based on expected utility theory, which is widely used in insurance research, this study derives unique propositions that have not been fully identified in other cyber insurance studies. A key finding is that organizations experiencing interdependent risks with different types of cyber attacks use different strategies in making IT security investment decisions and in purchasing cyber insurance policies for their information security risk management than firms that are facing independent risks. The study further provides an economic rationale for employing insurance mechanisms as a risk management solution for information security.