<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2015.61003</article-id><article-id pub-id-type="publisher-id">JIS-52952</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Externalities and the Magnitude of Cyber Security Underinvestment by Private Sector Firms: A Modification of the Gordon-Loeb Model
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>awrence</surname><given-names>A. Gordon</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Martin</surname><given-names>P. Loeb</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>William</surname><given-names>Lucyshyn</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Lei</surname><given-names>Zhou</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Robert H. Smith School of Business, University of Maryland, College Park, USA</addr-line></aff><aff id="aff2"><addr-line>School of Public Policy, University of Maryland, University of Maryland, College Park, USA</addr-line></aff><author-notes><corresp id="cor1">* E-mail:<email>lgordon@rhsmith.umd.edu(AAG)</email>;<email>mloeb@rhsmith.umd.edu(MPL)</email>;<email>lucyshyn@umd.edu(WL)</email>;<email>lzhou@rhsmith.umd.edu(LZ)</email>;</corresp></author-notes><pub-date pub-type="epub"><day>17</day><month>12</month><year>2014</year></pub-date><volume>06</volume><issue>01</issue><fpage>24</fpage><lpage>30</lpage><history><date date-type="received"><day>23</day>	<month>September</month>	<year>2014</year></date><date date-type="rev-recd"><day>20</day>	<month>October</month>	<year>2014</year>	</date><date date-type="accepted"><day>14</day>	<month>November</month>	<year>2014</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  Cyber security breaches inflict costs to consumers and businesses. The possibility also exists that a cyber security breach may shut down an entire critical infrastructure industry, putting a nation’s whole economy and national defense at risk. Hence, the issue of cyber security investment has risen to the top of the agenda of business and government executives. This paper examines how the existence of well-recognized externalities changes the maximum a firm should, from a social welfare perspective, invest in cyber security activities. By extending the cyber security investment model of Gordon and Loeb [1] to incorporate externalities, we show that the firm’s social optimal investment in cyber security increases by no more than 37% of the expected externality loss.
 
</p></abstract><kwd-group><kwd>Economics of Information Security</kwd><kwd> Cyber Security Investment</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>With economic activity and national defense heavily and increasingly dependent on networked computer systems, cyber security issues continue to draw increasing attention by the media, as well as by executives at the highest levels of government, industry, and nonprofit organizations.<sup>1</sup> A key reason for this increasing attention on cyber security issues by governments around the world is the eminent threat posed by cyber security breaches to a nation’s national defense and the nation’s economic strength [<xref ref-type="bibr" rid="scirp.52952-ref2">2</xref>] .</p><p>Firms in the private sector of many countries own a large share of critical infrastructure assets.<sup>2</sup> Hence, cyber security breaches in private sector firms could cause a major disruption of a critical infrastructure industry (e.g., delivery of electricity), resulting in massive losses throughout the economy, putting the defense of the nation at risk. Moreover, the cyber security activities of a given firm affect not only the probability of that firm suffering a cyber security breach, but also the probability that other firms (and individuals) suffer cyber security breaches. As one example, consider a firm that is not adequately protected against malware that infects the firm’s computer system and, although undetected, use that firm’s computer as part of a botnet to attack other firms. Since there is no practical way for a firm to be made liable for the entirety of losses from breaches to other firms caused by the vulnerabilities to its own computer systems, complete reliance on market mechanisms to overcome the externalities problem breaks down (i.e., using the terminology of economics, there are market failures). In fact, it is well known that in the absence of government incentives and/or regulations (hereafter incentives/regulations) firms will under invest in cyber security activities relative to the quantity that maximizes social welfare (e.g., [<xref ref-type="bibr" rid="scirp.52952-ref5">5</xref>] -[<xref ref-type="bibr" rid="scirp.52952-ref8">8</xref>] ). Thus, governments have an interest in providing incentives/regulations to firms to invest in cyber security activities at a level that takes into account not only the private losses incurred by firms from breaches of cyber security, but also the costs of externalities resulting from such beaches.<sup>3,4 </sup></p><p>A prelude to developing incentives/regulations that take into consideration the costs of externalities, as well as the private costs, is an understanding of the relationship between the magnitude of externalities and the magnitude of cyber security underinvestment. Thus, the objective of this paper is to investigate the magnitude of under- investment in cyber security activities by a private sector firm that considers only its private costs and benefits without regard to externalities. This investigation will take place in the context of the influential Gordon-Loeb Model presented in [<xref ref-type="bibr" rid="scirp.52952-ref1">1</xref>] , hereafter referred to as GL Model, for deriving the appropriate level of cyber security investment.<sup>5</sup> Earlier work, while recognizing that externalities results in underinvestment, has not sought to characterize the specific degree of underinvestment.</p><p>The primary contribution of this paper is to show how the existence of externalities changes the GL rule for the maximum a firm should, from a social welfare perspective, invest in cyber security activities. By analyzing the degree to which ignoring externalities causes underinvestment by firms in the absence of government regulations and incentives, the paper provides a basis for future examinations of potential actions designed to counteract cyber security underinvestment by private sector firms.</p><p>The remainder of this paper will proceed as follows. In the next, second, section of the paper we review the influential GL Model for making information security (cyber security) investments, and the subsequent literature dealing with the model. In the third section, we examine the effect of externalities on the optimal level of cyber security investment among private sector firms. We start by analyzing a specific example and then provide a general result characterizing the effect of externalities on the upper bound of a firm’s optimal level of cyber security investment. The fourth, and final, section of this paper will present some concluding comments.</p></sec><sec id="s2"><title>2. GL Model Literature</title><p>In order to investigate the magnitude of a firm’s underinvestment (from a social welfare perspective), we analyze and extend the GL Model. Considering only the firm’s private cost and benefits, GL characterized a firm’s optimal amount to invest in cyber security activities. In doing so, they defined a security breach function that captured the relationship between the level of cyber security activity expenditures and the probability of a cyber security breach. As such, GL were able to address the fundamental question of particular interest to organizations concerning how much to spend on cyber security activities.<sup>6</sup> GL present a single period economic model to examine the problem of a risk-neutral firm selecting the optimal level of expenditures on cyber security activities. The GL Model examines how the firm’s optimal level of cyber security expenditures, denoted<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x7.png" xlink:type="simple"/></inline-formula>, varies with two parameters: 1)<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x8.png" xlink:type="simple"/></inline-formula>, the probability that a cyber security attack will be successful in the absence of any cyber security expenditures, and 2)<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x9.png" xlink:type="simple"/></inline-formula>, the expected loss to the firm if the attack is successful. The model is briefly summarized below.</p><p>Denote <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x10.png" xlink:type="simple"/></inline-formula> as the firm’s security breach function, defined as the probability that an information security breach occurs and where <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x11.png" xlink:type="simple"/></inline-formula> is the firm’s monetary investments in cyber security and <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x12.png" xlink:type="simple"/></inline-formula> <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x13.png" xlink:type="simple"/></inline-formula> represents firm’s the underlying vulnerability to security breaches. GL postulate that the security breach function is twice continuously differentiable and meets the following five regularity conditions: 1) for all<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x14.png" xlink:type="simple"/></inline-formula>,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x15.png" xlink:type="simple"/></inline-formula>; 2) for all<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x16.png" xlink:type="simple"/></inline-formula>,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x17.png" xlink:type="simple"/></inline-formula>; 3) for all <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x18.png" xlink:type="simple"/></inline-formula> and for all <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x19.png" xlink:type="simple"/></inline-formula> and<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x20.png" xlink:type="simple"/></inline-formula>; 4) for all <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x21.png" xlink:type="simple"/></inline-formula> and for all<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x22.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x23.png" xlink:type="simple"/></inline-formula>and; 5) for all<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x23.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x24.png" xlink:type="simple"/></inline-formula>,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x23.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x24.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x25.png" xlink:type="simple"/></inline-formula>. That is, 1) if the firm’s information is perfectly invulnerable, then it will remain so for all levels of cyber security investments; 2) if there is no investment in cyber security, the probability of a successful breach will be the underlying vulnerability; 3) increases in cyber security investment will decrease the probability of a successful breach; 4) the security breach function is strictly convex in<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x23.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x24.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x25.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x26.png" xlink:type="simple"/></inline-formula>, i.e., there are diminishing returns to cyber security investment and; 5) by investing sufficiently in cyber security the probability of a successful breach can be made arbitrarily close to zero.</p><p>When making the security investment decision, the firm would choose an investment level <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x27.png" xlink:type="simple"/></inline-formula> so that the total expected net benefits from the investment is maximized:</p><disp-formula id="scirp.52952-formula169"><label>, (1)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x28.png"  xlink:type="simple"/></disp-formula><p>and needs to satisfy the following condition:</p><disp-formula id="scirp.52952-formula170"><label>. (2)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x29.png"  xlink:type="simple"/></disp-formula><p>For security breach functions meeting the aforementioned five regularity conditions, GL provide some general results concerning the relation between the optimal level of cyber security investment, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x30.png" xlink:type="simple"/></inline-formula>, and the prior level of vulnerability,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x30.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x31.png" xlink:type="simple"/></inline-formula>. The principal result demonstrated by GL, however, is that for a risk-neutral firm, the optimal investment in information security is generally a small fraction of the expected loss of a breach. Specifically, GL show that for the two broad classes of security breach functions satisfying the regularity conditions given below:</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x32.png" xlink:type="simple"/></inline-formula>,, (3)</p><p>and</p><disp-formula id="scirp.52952-formula171"><label>. (4)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x34.png"  xlink:type="simple"/></disp-formula><disp-formula id="scirp.52952-formula172"><graphic  xlink:href="http://html.scirp.org/file/3-7800247x35.png"  xlink:type="simple"/></disp-formula><p><sup>7</sup>A function <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x36.png" xlink:type="simple"/></inline-formula> is log-convex if “the composition of the logarithmic function with<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x36.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x37.png" xlink:type="simple"/></inline-formula>, is a convex function” (http://en.wikipedia.org/wiki/Logarithmically_convex_function). A log-convex function is necessarily convex, but a convex function may not be log-convex.</p><p>The optimal investment in information security is always less than or equal to <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x38.png" xlink:type="simple"/></inline-formula> (approximately, 36.79%) of the expected loss from a security breach (i.e., <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x38.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x39.png" xlink:type="simple"/></inline-formula>, GL Proposition 3). Beyond the two specified classes of security breach functions (and a third class given in [<xref ref-type="bibr" rid="scirp.52952-ref1">1</xref>] , footnote 18), GL conjectured that the <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x38.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x39.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x40.png" xlink:type="simple"/></inline-formula> rule holds for all security breach functions satisfying the specified regularity conditions.</p><p>Willemson [<xref ref-type="bibr" rid="scirp.52952-ref19">19</xref>] provided a method for constructing a security breach function meeting all the assumptions of GL for which the optimal level of investment could be made to be arbitrarily close to 50% of the expected loss. Furthermore, by relaxing the GL assumption that the security breach function is continuously twice differentiable, [<xref ref-type="bibr" rid="scirp.52952-ref19">19</xref>] demonstrated that security breach functions could be constructed such that the optimal cyber security investment is arbitrarily close to the expected loss.</p><p>While the result of [<xref ref-type="bibr" rid="scirp.52952-ref19">19</xref>] appeared to severely limit the generality of the <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x41.png" xlink:type="simple"/></inline-formula> rule, analysis by [<xref ref-type="bibr" rid="scirp.52952-ref8">8</xref>] and [<xref ref-type="bibr" rid="scirp.52952-ref20">20</xref>] proved that the rule “holds in full generality, thus justifying the intuition” ([<xref ref-type="bibr" rid="scirp.52952-ref20">20</xref>] , p.1) of GL. In order to resurrect the <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x41.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x42.png" xlink:type="simple"/></inline-formula> rule, [<xref ref-type="bibr" rid="scirp.52952-ref8">8</xref>] and [<xref ref-type="bibr" rid="scirp.52952-ref20">20</xref>] assumed that security breach function was not just convex but log-convex.<sup>7</sup> Thus, if the security breach function satisfies regularity conditions (1), (2), (3), (4’) and (5), where (4’) is the conditions that the security breach function is log-convex, then the optimal investment in information security for a risk- neutral firm is always less than or equal to <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x41.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x42.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x43.png" xlink:type="simple"/></inline-formula> of the expected loss from a security breach, i.e.,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x41.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x42.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x43.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x44.png" xlink:type="simple"/></inline-formula>. Furthermore, [<xref ref-type="bibr" rid="scirp.52952-ref20">20</xref>] provided some assumptions on the nature of cybersecurity activities that would be sufficient to give rise to the security breach function being log-convex.</p></sec><sec id="s3"><title>3. Modifying the GL Model to Incorporate Externalities</title><p>In modeling a firm’s selection of the optimal amount to invest in information security, GL only considered the private costs to be borne by a firm that result from an information (cyber) security breach. The private costs of a breach, denoted by <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x45.png" xlink:type="simple"/></inline-formula> in the GL Model, take into account not only items such as the costs of remediation, the cost of lost sales from downtime on sales websites and loss in competitive position through the loss of trade and strategic secrets, but also the loss from potential suits by other firms and customers who were would be hurt by the firm’s information security breach. Thus, to the extent that judgments and settlements expected from lawsuits resulting from a breach will account for the losses imposed on others, the externalities (spillover effects) would be fully internalized via the GL Model.<sup>8</sup></p><p>There are good reasons, however, to believe that expected legal judgments and settlements would not fully internalize the externalities associated with an information security breach. For example, suppose a security breach results in malware that allows an attacker to gain complete control over the affected computer. That firm’s computer can then be controlled remotely to connect back to a central server, and become part of a network of compromised computers or “botnet” (often just called a “bot”). This network can be used for a variety of malicious purposes, such as conducting a distributed denial of service (DDOS) attack. The DDOS attack may well cause substantial losses to other organizations, yet the contribution of one computer (or one firm’s computers) towards the overall loss would be so small that the threat of legal repercussions to the firm owning the compromised computer(s) would be insignificant. Similarly, in addition to the cost of lost sales faced by the firm victimized by a DDOS attack, customers may face non-pecuniary costs in lost time and frustration in attempting to access the attacked firm’s website. While the costs to an individual customer may be small and difficult to detect and measure, the aggregate costs to all customers could be substantial. Still, because the individual losses are small, legal action spurred by these losses would not likely be taken on behalf of these customers. In addition, even if legal actions were to occur, where the final responsibility for covering these costs rests is unclear. The extension of the GL Model that follows is an attempt to show the impact of considering these, as well as other, externalities, on the adequacy of cyber security investments.</p><p>Let <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x46.png" xlink:type="simple"/></inline-formula> represent the externality (spillover) costs of an information security breach, defined as the total loss to consumers and other firms, not captured within the private loss<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x46.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x47.png" xlink:type="simple"/></inline-formula>, from a breach of information security. Let <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x46.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x47.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x48.png" xlink:type="simple"/></inline-formula> represent the total social costs of an information security breach defined as the sum of the firm’s pri-</p><p>vate loss plus the externality costs (i.e.,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x49.png" xlink:type="simple"/></inline-formula>).</p><p>The GL Model can then be easily extended to incorporate the externalities. The social optimal level of investment for the firm, denoted<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x50.png" xlink:type="simple"/></inline-formula>, is the level that maximizes expected benefits net of both the private loss and externality costs:</p><disp-formula id="scirp.52952-formula173"><label>, (5)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x51.png"  xlink:type="simple"/></disp-formula><p>so that <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x53.png" xlink:type="simple"/></inline-formula> satisfies the first-order condition:</p><disp-formula id="scirp.52952-formula174"><label>. (6)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x54.png"  xlink:type="simple"/></disp-formula><p>By comparing (6) and (2), and assuming <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x55.png" xlink:type="simple"/></inline-formula> and that increasing information security investment decrea- ses the probability of an information security breach, but at a decreasing rate (<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x55.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x56.png" xlink:type="simple"/></inline-formula>and<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x55.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x56.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x57.png" xlink:type="simple"/></inline-formula>, i.e., regularity assumptions 3 and 4), one can see that<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x55.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x56.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x57.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x58.png" xlink:type="simple"/></inline-formula>. That is, the socially optimal amount for the firm to invest in information security is greater than the firm’s (private) optimal amount. This is merely a formal demonstration that firms, without additional incentives, will under invest in information security.</p><p>In order to examine the possible magnitude of a firm’s under investment in information security relative to the amount that maximizes social welfare, we first examine security breach function of the class I type specified by (3). Then, the firm’s (private) optimal investment in information security is given by (GL equation (6)):</p><disp-formula id="scirp.52952-formula175"><label>. (7)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x59.png"  xlink:type="simple"/></disp-formula><p>Now suppose for the firm’s initial probability of an information security breach<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x60.png" xlink:type="simple"/></inline-formula>, the parameters<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x60.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x61.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x60.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x61.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x62.png" xlink:type="simple"/></inline-formula>, and the firm’s private loss from an information security breach is $400,000. Then, from (7), the firm’s optimal investment in information security is $60,000 (which equals exactly 23.4375 % of its expected private loss). Suppose now that the externality costs were 5% of its private loss, or $20,000, so the total social costs of a breach, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x60.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x61.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x63.png" xlink:type="simple"/></inline-formula>, equals $420,000. Using<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x60.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x61.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x63.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x64.png" xlink:type="simple"/></inline-formula>, the socially optimal amount for the firm to invest would be $63,951. Thus, externality costs of 5% results in a 6.18% (=3,951/63,951) under investment in information’s security. If externality costs were 100% of the private loss, then the social welfare maximizing investment would be $126,274, so that a firm focusing only on its own private costs would, from a societal perspective, be under investing by 52.48% (=[126,274 ? 66,274]/126,274).</p><p>The preceding discussion illustrates that in the presence of externalities, social costs diverge from private costs resulting in underinvestment by the firm. <xref ref-type="table" rid="table1">Table 1</xref> provides additional data on how underinvestment percentage changes with externality costs for the specified example.</p><p>The following proposition, a generalization of the GL rule, shows how externalities affect the magnitude of a firm’s maximum socially optimal investment in cyber security.</p><p>Proposition 1: Suppose the security breach probability function satisfies regularity conditions (1), (2), (3), (4’) and (5). Denote <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x65.png" xlink:type="simple"/></inline-formula> That is, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x65.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x66.png" xlink:type="simple"/></inline-formula>is the ratio of externality losses to private losses for a successful cyber breach, (or 1/100 of the percent externality cost). Then the inequality below characterizes the maximum a risk-neutral firm should invest to protect information set, taking into account externalities as well as private costs:</p><disp-formula id="scirp.52952-formula176"><label>. (8)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x67.png"  xlink:type="simple"/></disp-formula><p>Proof: The maximum socially optimal amount is found by substituting <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x68.png" xlink:type="simple"/></inline-formula> for <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x68.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x69.png" xlink:type="simple"/></inline-formula> in the GL model. This yields the rule that the socially optimal investment amount is less than or equal to <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x68.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x69.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x70.png" xlink:type="simple"/></inline-formula> of the total social costs:</p><disp-formula id="scirp.52952-formula177"><label>. (9)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/3-7800247x71.png"  xlink:type="simple"/></disp-formula><p>The desired result, inequality (8), follows since<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x72.png" xlink:type="simple"/></inline-formula>. Q.E.D.</p><p>Notice that for the special case where there are no externalities, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x73.png" xlink:type="simple"/></inline-formula>, (8) reduces to the GL Model result. <xref ref-type="table" rid="table2">Table 2</xref> shows how the maximums social optimal changes as the magnitude of externalities increases. For example, when the potential external losses due to externalities equal 40% of the potential private losses, the maximum social investment in cyber security is at most 51.5% of the firm’s private expected loss. When the externalities are extremely large (e.g., 180% of the private costs of a breach), the social optimal calls for an investment greater than the firm’s private expected loss.</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Relationship between externalities and underinvestment in cybersecurity for security breach probability function<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x74.png" xlink:type="simple"/></inline-formula></title></caption><table><tbody><thead><tr><th align="center" valign="middle" >(1)</th><th align="center" valign="middle" >(2)</th><th align="center" valign="middle" >(3)</th><th align="center" valign="middle" >(4)</th><th align="center" valign="middle" ><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x75.png" xlink:type="simple"/></inline-formula></th></tr></thead><tr><td align="center" valign="middle" >Percent Externality Cost <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x76.png" xlink:type="simple"/></inline-formula></td><td align="center" valign="middle" >Private Loss (i.e., costs) from a Successful Cyber Security Breach<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x77.png" xlink:type="simple"/></inline-formula></td><td align="center" valign="middle" >Optimal Cyber security Investment Based on Private Costs</td><td align="center" valign="middle" >Optimal Cyber security Investment Based on Total Social (Private + Externality) Costs</td><td align="center" valign="middle" >Percent Underinvestment by Failing to Consider Externalities</td></tr><tr><td align="center" valign="middle" >0%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >0%</td></tr><tr><td align="center" valign="middle" >20%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$75,271</td><td align="center" valign="middle" >20.29%</td></tr><tr><td align="center" valign="middle" >40%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$89,315</td><td align="center" valign="middle" >32.82%</td></tr><tr><td align="center" valign="middle" >60%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$102,386</td><td align="center" valign="middle" >41.40%</td></tr><tr><td align="center" valign="middle" >80%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$114,663</td><td align="center" valign="middle" >47.67%</td></tr><tr><td align="center" valign="middle" >100%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$126,274</td><td align="center" valign="middle" >52.48%</td></tr><tr><td align="center" valign="middle" >120%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$137,318</td><td align="center" valign="middle" >56.31%</td></tr><tr><td align="center" valign="middle" >140%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$147,871</td><td align="center" valign="middle" >59.42%</td></tr><tr><td align="center" valign="middle" >160%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$157,992</td><td align="center" valign="middle" >62.02%</td></tr><tr><td align="center" valign="middle" >180%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$167,731</td><td align="center" valign="middle" >64.23%</td></tr><tr><td align="center" valign="middle" >200%</td><td align="center" valign="middle" >$400,000</td><td align="center" valign="middle" >$60,000</td><td align="center" valign="middle" >$177,128</td><td align="center" valign="middle" >66.13%</td></tr></tbody></table></table-wrap><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Maximum social optimal investment as externalities vary</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Percent Externality Cost<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x78.png" xlink:type="simple"/></inline-formula></th><th align="center" valign="middle" >Maximum Social Optimal Cybersecurity Investment as a Percent of Firm’s Expected Private Expected Loss <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/3-7800247x79.png" xlink:type="simple"/></inline-formula></th></tr></thead><tr><td align="center" valign="middle" >0%</td><td align="center" valign="middle" >36.79%</td></tr><tr><td align="center" valign="middle" >20%</td><td align="center" valign="middle" >44.15%</td></tr><tr><td align="center" valign="middle" >40%</td><td align="center" valign="middle" >51.50%</td></tr><tr><td align="center" valign="middle" >60%</td><td align="center" valign="middle" >58.86%</td></tr><tr><td align="center" valign="middle" >80%</td><td align="center" valign="middle" >66.22%</td></tr><tr><td align="center" valign="middle" >100%</td><td align="center" valign="middle" >73.58%</td></tr><tr><td align="center" valign="middle" >120%</td><td align="center" valign="middle" >80.93%</td></tr><tr><td align="center" valign="middle" >140%</td><td align="center" valign="middle" >88.29%</td></tr><tr><td align="center" valign="middle" >160%</td><td align="center" valign="middle" >95.65%</td></tr><tr><td align="center" valign="middle" >180%</td><td align="center" valign="middle" >103.01%</td></tr><tr><td align="center" valign="middle" >200%</td><td align="center" valign="middle" >110.36%</td></tr></tbody></table></table-wrap><p>Since most firms in the private sector look only at their private costs of security breaches, it is rational to expect them to under invest in cyber security activities relative to the social optimal. Accordingly, in order to move towards socially optimal levels of cyber security investments, there is a compelling argument for governments (or some other entity focusing on increasing social welfare) to explore a variety of regulations and/or incentives that are designed to get private sector firms to increase their cyber security investments.</p></sec><sec id="s4"><title>4. Concluding Comments</title><p>The primary objective of this paper has been to extend the GL Model for deriving the optimal level of investment in cyber security activities. This extension focused on examining the impact of considering the costs associated with the externalities of cyber security breaches (i.e., spill-over effects, of cyber security breaches to other organizations and individuals), in addition to private costs (i.e., the costs to the individual organizations experiencing the cyber security breaches), on a private sector firm’s optimal level of cyber security investment level as viewed from a social welfare perspective. For a risk-neutral firm, under specified regularity conditions, we show that the firm’s social optimal investment in cyber security increases by no more than 37% of the expected externality loss. Unless private sector firms consider the costs of breaches associated with externalities, in addition to the private costs resulting from breaches, underinvestment in cyber security activities is essentially a given. Thus, cyber security underinvestment poses a serious threat to the national security and to the economic prosperity of a nation. Accordingly, governments around the world are justified in considering regulations and/or incentives designed to increase cyber security investments by private sector firms.</p><p>In the U.S. there is a general preference for developing market-based incentive mechanisms rather than new regulations to get private sector firms to increase their investment on cyber security activities. The efficacy of such an approach has, to date, been problematic. Indeed, the problems associated with successfully developing and implementing such incentives have led many in the U.S. to call for regulations requiring private sector firms to invest enough into cyber security activities to cover externalities as well as private sector costs.<sup>9</sup> In other countries, which are more heavily government controlled, regulations requiring private sector firms to increase their investment in cyber security activities to cover externalities (as well as private costs) may well be the clearly preferred method for handling the cyber security underinvestment concern.</p></sec><sec id="s5"><title>Acknowledgements</title><p>This research has been supported by the United States Department of Homeland Security (DHS) Science and Technology Directorate, the Netherlands National Cyber Security Centre (NCSC) and Sweden MSB (Myndighetenf&#246;rsamh&#228;llsskyddochberedskap)―Swedish Civil Contingencies Agency.</p></sec><sec id="s6"><title>NOTES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.52952-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L.A. and Loeb, M.P. (2002) The Economics of Information Security Investment. ACM Transactions on Information System Security, 5, 438-457. http://dx.doi.org/10.1145/581271.581274</mixed-citation></ref><ref id="scirp.52952-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">U.S. Department of Homeland Security (2013) Executive Order 1636: Improving Critical Infrastruc- 
ture, Department of Homeland Security Integrated Task Force, Incentives Study. Washington DC.</mixed-citation></ref><ref id="scirp.52952-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Presidential Executive Order 13636 (2013) Improving Critical Infrastructure Cybersecurity. Federal Registrar, 78, 11739-11743. https://www.federalregister.gov/articles/2013/02/19/2013-03915/improving-critical-infrastructure-cybersecurity</mixed-citation></ref><ref id="scirp.52952-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Presidential Policy Directive/PPD-21 (2013) Critical Infrastructure Security and Resilience. 
http://www.whitehouse.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infra- 
structure-security-and-resil</mixed-citation></ref><ref id="scirp.52952-ref5"><label>5</label><mixed-citation publication-type="book" xlink:type="simple">Varian, H. (2004) System Reliability and Free Riding. In Camp, L. and Lewis, S., Eds., Economics of Information Security, Springer US, 1-15. http://dx.doi.org/10.1007/1-4020-8090-5_1</mixed-citation></ref><ref id="scirp.52952-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L.A., Loeb, M.P. and Lucyshyn, W. (2003) Sharing Information on Computer Systems Security: An Economic Analysis. Journal of Accounting and Public Policy, 22, 461-485. http://dx.doi.org/10.1016/j.jaccpubpol.2003.09.001</mixed-citation></ref><ref id="scirp.52952-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Kunreuther, H. and Heal, G. (2003) Interdependent Security. Journal of Risk and Uncertainty, 26, 231-249.</mixed-citation></ref><ref id="scirp.52952-ref8"><label>8</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Lelarge</surname><given-names> M. </given-names></name>,<etal>et al</etal>. (<year>2012</year>)<article-title>Coordination in Network Security Games: A Monotone Comparative Statics Approach</article-title><source> IEEE Journal on Selected Areas in Communications</source><volume> 30</volume>,<fpage> 2210</fpage>-<lpage>2219</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.52952-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Treasury Department Report to the President on Cybersecurity Incentives Pursuant to Executive Order 13636. (2013). http://www.treasury.gov/press-center/Documents/Supporting Analysis Treasury Report to the Presi- 
dent on Cybersecurity Incentives_FINAL.pdf</mixed-citation></ref><ref id="scirp.52952-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">U.S. Department of Homeland Security (2013) Executive Order 13636: Improving Critical Infrastructure, Department of Homeland Security Integrated Task Force, Incentives Study Analytic Report.  
http://www.dhs.gov/sites/default/files/publications/dhs-eo13636-analytic-report-cybersecurity-incentives-study.pdf</mixed-citation></ref><ref id="scirp.52952-ref11"><label>11</label><mixed-citation publication-type="book" xlink:type="simple">B&amp;oumlhme, R. (2010) Security Metrics and Security Investment Models. In: Echizen, I., Kunihiro, N. and Sasaki, R., Eds., Advances in Information and Computer Security, Springer-Verlag, Berlin, Heidelberg, 10-24.  
http://dx.doi.org/10.1007/978-3-642-16825-3_2</mixed-citation></ref><ref id="scirp.52952-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Campbell, K., Gordon, L.A., Loeb, M.P. and Zhou, L. (2003) The Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market. Journal of Computer Security, 11, 431-448.</mixed-citation></ref><ref id="scirp.52952-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Cavusoglu, H., Mishra, B. and Raghunathan, S. (2004) The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers. International Journal of Electronic Commerce, 9, 69-104.</mixed-citation></ref><ref id="scirp.52952-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L.A., Loeb, M.P. and Zhou, L. (2011) The Impact of Information Security Breaches: Has There Been a Downward Shift in Cost? Journal of Computer Security, 19, 33-56.</mixed-citation></ref><ref id="scirp.52952-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Gal-Or, E. and Ghose, A. (2005) The Economic Incentives for Sharing Security Information. Information Systems Research, 16, 186-208. http://dx.doi.org/10.1287/isre.1050.0053</mixed-citation></ref><ref id="scirp.52952-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Hausken, K. (2007) Information Sharing among Firms and Cyber Attacks. Journal of Accounting and Public Policy, 26, 639-688. http://dx.doi.org/10.1016/j.jaccpubpol.2007.10.001</mixed-citation></ref><ref id="scirp.52952-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Gansler, J.S. and Lucyshyn, W. (2005) Improving the Security of Financial Management Systems: What Are We to Do? Journal of Accounting and Public Policy, 24, 1-9. http://dx.doi.org/10.1016/j.jaccpubpol.2004.12.001</mixed-citation></ref><ref id="scirp.52952-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L.A., Loeb, M.P. and Sohail, T. (2010) Market Value of Voluntary Disclosures Concerning Information Security. MIS Quarterly, 34, 567-594.</mixed-citation></ref><ref id="scirp.52952-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Willemson, J. (2006) On the Gordon &amp; Loeb Model for Information Security Investment. The Fifth Workshop on the Economics of Information Security (WEIS), University of Cambridge, 26-28 June.  
http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.60.9931&amp;rep=rep1&amp;type=pdf</mixed-citation></ref><ref id="scirp.52952-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Baryshnikov, Y. (2012) IT Security Investment and Gordon-Loeb’s 1/e Rule. 2012 Workshop on Economics and Information Security, Berlin, 25-26 June. http://weis2012.econinfosec.org/papers/Baryshnikov_WEIS2012.pdf</mixed-citation></ref></ref-list></back></article>