The economics of mandatory security breach reporting to authorities

被引:31
|
作者
Laube, Stefan [1 ]
Boehme, Rainer [2 ]
机构
[1] Westfalische Wilhelms Univ Munster, Dept Informat Syst, Leonardo Campus 3, D-48149 Munster, Germany
[2] Univ Innsbruck, Dept Comp Sci, Technikerstr 21A, A-6020 Innsbruck, Austria
来源
JOURNAL OF CYBERSECURITY | 2016年 / 2卷 / 01期
关键词
Economics - Economic and social effects;
D O I
10.1093/cybsec/tyw002
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Legislators in many countries enact security breach notification regulation to address a lack of information security. The laws designate authorities to collect breach reports and advise firms. We devise a principal-agent model to analyze the economic effect of mandatory security breach reporting to authorities. The model assumes that firms (agents) have few incentives to unilaterally report breaches. To enforce the law, regulators (principals) can introduce security audits and sanction noncompliance. However, audits cannot differentiate between concealment and nescience of the agents. Even under optimistic assumptions regarding the effectiveness of mandatory security breach reporting to authorities in reducing individual losses, our model predicts that it may be difficult to adjust the sanction level such that breach notification laws generate social benefit.
引用
收藏
页码:29 / 41
页数:13
相关论文
共 50 条
  • [41] MANDATORY REPORTING - UNLIKELY TO WORK
    Beran, Roy G.
    MEDICINE AND LAW, 2016, 35 (03): : 441 - 449
  • [42] MANDATORY REPORTING OF TRANSPLANT TOURISM
    Matas, David
    TRANSPLANT INTERNATIONAL, 2019, 32 : 53 - 53
  • [43] Drug safety and mandatory reporting
    Behles, Christian
    Hoffmann, Robert
    Lex, Dennis
    SCHMERZ, 2025,
  • [44] State agency security breach
    不详
    COMPUTERS & SECURITY, 2004, 23 (03) : 187 - 188
  • [45] Android Applications and Security Breach
    Noemi Benitez-Mejia, Diana Gabriela
    Sanchez-Perez, Gabriel
    Karina Toscano-Medina, Linda
    2016 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION PROCESSING, DATA MINING, AND WIRELESS COMMUNICATIONS (DIPDMWC), 2016, : 164 - 169
  • [46] SEXUAL ABUSE AND MANDATORY REPORTING
    FANCOURT, R
    BROADMORE, J
    NEW ZEALAND MEDICAL JOURNAL, 1993, 106 (966) : 461 - 461
  • [47] Certificates of Confidentiality and Mandatory Reporting
    Wolf, Leslie E.
    Ram, Natalie
    Letourneau, Elizabeth J.
    JAMA PEDIATRICS, 2024, 178 (07) : 639 - 640
  • [48] REPORTING OF FEMALE GENITAL MUTILATION Clarifying the difference between mandatory recording and mandatory reporting of FGM
    Hartley, Helen
    BMJ-BRITISH MEDICAL JOURNAL, 2015, 351
  • [49] THE ECONOMICS OF MANDATORY FAIR TRADE
    Hession, Charles H.
    JOURNAL OF MARKETING, 1950, 14 (05) : 707 - 720
  • [50] Medical errors: Mandatory reporting, voluntary reporting, or both?
    Grepperud S.
    European Journal of Law and Economics, 2005, 20 (1) : 99 - 112