Valuing information security from a phishing attack
Kenneth D. Nguyen, Heather Rosoff, Richard S. John · Journal of Cybersecurity · 2017
The extent to which users take precautionary actions against cyber risks is conditional upon how they perceive the value of information security relative to other important personal goals. In most cyber security contexts, users are faced with trade-offs between information security and other important attributes that they desire to maximize. We examined this issue by eliciting the “security premiums” that users were willing to sacrifice to protect their information security in a phishing context. We also examined the effect of usage contexts on value of information security using an experimental design. Respondents from Amazon Mechanical Turk were randomized into one of three conditions in which the context of a phishing attack was varied. Respondents were asked to make trade-offs between pairs of attributes including security, cost, latency, and productivity, from which we could quantify security premiums. Results indicated that half of the respondents were willing to pay a premium between $9 and $11 per month, willing to wait between 8 and 9 additional minutes, and willing to forgo their access to 21–29 valid pieces of information, to obtain a more effective phishing filter that reduces the number of false negatives from 24 to 6 per month. Interestingly, the value of information security was sensitive to the usage context, such that social media invoked greater security premiums in terms of productivity than email and web surfing. We also found that vulnerability and perceived net benefit significantly correlated with security premiums in terms of monthly cost. These results offer valuable insights for the design of more usable information security systems.