Agency Problems in Information Security : Theory and Application to Korean Business
Woohyun Shim · 인터넷전자상거래연구 · 2015
Many researchers have argued that security measures are not effective for protecting IT systems against cyber-attacks because they cannot keep up with attack strategies and are often developed reactively. However, according to principal-agent theory, the low effectiveness of security measures might be the outcome of moral hazard which results in suboptimal efforts of users to maintain IT systems appropriately. In order to identify empirical evidence elucidated by principal-agent theory, a regression analysis using data from 2,401 Korean firms is performed. In accord with the findings in the previous literature on principal-agent theory, the empirical results confirm that moral hazard contributes to the low effectiveness of security measures, and can be attenuated by employing security training programs.