The economics of mandatory security breach reporting to authorities

被引:31
|
作者
Laube, Stefan [1 ]
Boehme, Rainer [2 ]
机构
[1] Westfalische Wilhelms Univ Munster, Dept Informat Syst, Leonardo Campus 3, D-48149 Munster, Germany
[2] Univ Innsbruck, Dept Comp Sci, Technikerstr 21A, A-6020 Innsbruck, Austria
来源
JOURNAL OF CYBERSECURITY | 2016年 / 2卷 / 01期
关键词
Economics - Economic and social effects;
D O I
10.1093/cybsec/tyw002
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Legislators in many countries enact security breach notification regulation to address a lack of information security. The laws designate authorities to collect breach reports and advise firms. We devise a principal-agent model to analyze the economic effect of mandatory security breach reporting to authorities. The model assumes that firms (agents) have few incentives to unilaterally report breaches. To enforce the law, regulators (principals) can introduce security audits and sanction noncompliance. However, audits cannot differentiate between concealment and nescience of the agents. Even under optimistic assumptions regarding the effectiveness of mandatory security breach reporting to authorities in reducing individual losses, our model predicts that it may be difficult to adjust the sanction level such that breach notification laws generate social benefit.
引用
收藏
页码:29 / 41
页数:13
相关论文
共 50 条
  • [21] THE IMPACT OF MANDATORY REPORTING LEGISLATION ON REPORTING BEHAVIOR
    LAMOND, DAP
    CHILD ABUSE & NEGLECT, 1989, 13 (04) : 471 - 480
  • [22] Mandatory Reporting Laws: A Change in Reporting Behavior?
    Vallett, Joel
    CHILD CARE IN PRACTICE, 2024,
  • [23] Tarasoff ruling and reporting to the authorities
    Balon, R
    Mufti, R
    AMERICAN JOURNAL OF PSYCHIATRY, 1997, 154 (09): : 1321 - 1321
  • [24] Mandatory data breach notification requirements for medical practice
    Carter, David J.
    Hartridge, Samuel
    MEDICAL JOURNAL OF AUSTRALIA, 2018, 209 (05) : 204 - +
  • [25] The importance of mandatory data breach notification to identity crime
    Holm, Eric
    Mackenzie, Geraldine
    2014 THIRD INTERNATIONAL CONFERENCE ON CYBER SECURITY, CYBER WARFARE AND DIGITAL FORENSIC (CYBERSEC), 2014, : 6 - 11
  • [26] The first breach of computer security?
    Grier, DA
    IEEE ANNALS OF THE HISTORY OF COMPUTING, 2001, 23 (02) : 78 - 79
  • [27] Mandatory reporting laws - In reply
    Houry, DE
    Feldhaus, KM
    Abbott, J
    ANNALS OF EMERGENCY MEDICINE, 2000, 35 (04) : 404 - 404
  • [28] MANDATORY REPORTING OF SEXUAL ABUSE
    GOODYEARSMITH, F
    NEW ZEALAND MEDICAL JOURNAL, 1993, 106 (969) : 530 - 530
  • [29] Mandatory reporting and the retaliation factor
    Sippel, Franne
    Meister, Karyl L.
    Miller, Pamela J.
    Howard, Jeff N.
    Can, Ahmet
    Bowden, Theresa
    Garlick, Andrea
    CHILDREN AND YOUTH SERVICES REVIEW, 2023, 144
  • [30] Mandatory reporting of domestic violence
    Feder, Gene
    LANCET, 2008, 371 (9617): : 986 - 986