The economics of mandatory security breach reporting to authorities

被引:31
|
作者
Laube, Stefan [1 ]
Boehme, Rainer [2 ]
机构
[1] Westfalische Wilhelms Univ Munster, Dept Informat Syst, Leonardo Campus 3, D-48149 Munster, Germany
[2] Univ Innsbruck, Dept Comp Sci, Technikerstr 21A, A-6020 Innsbruck, Austria
来源
JOURNAL OF CYBERSECURITY | 2016年 / 2卷 / 01期
关键词
Economics - Economic and social effects;
D O I
10.1093/cybsec/tyw002
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Legislators in many countries enact security breach notification regulation to address a lack of information security. The laws designate authorities to collect breach reports and advise firms. We devise a principal-agent model to analyze the economic effect of mandatory security breach reporting to authorities. The model assumes that firms (agents) have few incentives to unilaterally report breaches. To enforce the law, regulators (principals) can introduce security audits and sanction noncompliance. However, audits cannot differentiate between concealment and nescience of the agents. Even under optimistic assumptions regarding the effectiveness of mandatory security breach reporting to authorities in reducing individual losses, our model predicts that it may be difficult to adjust the sanction level such that breach notification laws generate social benefit.
引用
收藏
页码:29 / 41
页数:13
相关论文
共 50 条
  • [11] MANDATORY REPORTING MODELS
    OTWELL, J
    AMERICAN JOURNAL OF NURSING, 1985, 85 (07) : 784 - 784
  • [12] In opposition to mandatory reporting
    Schillinger, D
    Hyman, A
    WESTERN JOURNAL OF MEDICINE, 1999, 171 (02): : 121 - 123
  • [13] MANDATORY REPORTING LAWS
    CONSTANTINE, LL
    AMERICAN JOURNAL OF ORTHOPSYCHIATRY, 1982, 52 (04) : 748 - 749
  • [14] Mandatory reporting of incompetence
    Coates, J
    NEW ZEALAND MEDICAL JOURNAL, 2001, 114 (1130) : 193 - 193
  • [15] Mandatory reporting laws
    Geiderman, J
    ANNALS OF EMERGENCY MEDICINE, 2000, 35 (04) : 403 - 404
  • [16] Mandatory Data Breach Disclosure and Insider Trading
    Chen, Xi
    Hilary, Gilles
    Tian , Xiaoli
    JOURNAL OF BUSINESS FINANCE & ACCOUNTING, 2024,
  • [17] RFID security breach
    不详
    CONTROL ENGINEERING, 2008, 55 (08) : 49 - 49
  • [18] Mandatory reporting of incompetence
    Loeber, D
    NEW ZEALAND MEDICAL JOURNAL, 2001, 114 (1137) : 366 - 366
  • [19] How mandatory is the mandatory reporting of children at risk?
    Isaacs, David
    Britton, Philip N.
    Kilham, Henry A.
    Bag, Shopna
    Marks, Susan
    JOURNAL OF PAEDIATRICS AND CHILD HEALTH, 2018, 54 (11) : 1189 - 1192
  • [20] ECONOMICS OF MANDATORY RETIREMENT
    SCHULZ, JH
    INDUSTRIAL GERONTOLOGY, 1974, 1 (01): : 1 - 10