IDEAS home Printed from https://ideas.repec.org/a/inm/ormksc/v45y2026i2p318-334.html

A Model of Information Security and Competition

Author

Listed:
  • Alexandre de Cornière

    (Toulouse School of Economics, University of Toulouse Capitole, 31000 Toulouse, France)

  • Greg Taylor

    (Oxford Internet Institute, University of Oxford, Oxford OX1 3JS, United Kingdom)

Abstract

Cyberattacks are a pervasive threat in the digital economy, with the potential to harm firms and their customers. Larger firms constitute more valuable targets to hackers, thereby creating negative network effects. These can be mitigated by investments in security, which play both a deterrent and a protective role. We study equilibrium investment in information security under imperfect competition in a model where consumers differ in terms of security savviness. We show that the competitive implications of security depend on firms’ business models: when firms compete in prices, security intensifies competition, which implies that it is always underprovided in equilibrium (unlike in the monopoly case). When firms are advertising-funded platforms, security plays a business-stealing role, and may be overprovided. Regarding policy, the structure of the optimal liability regime also depends on firms’ business model.

Suggested Citation

  • Alexandre de Cornière & Greg Taylor, 2026. "A Model of Information Security and Competition," Marketing Science, INFORMS, vol. 45(2), pages 318-334, March.
  • Handle: RePEc:inm:ormksc:v:45:y:2026:i:2:p:318-334
    DOI: 10.1287/mksc.2023.0513
    as

    Download full text from publisher

    File URL: http://dx.doi.org/10.1287/mksc.2023.0513
    Download Restriction: no

    File URL: https://libkey.io/10.1287/mksc.2023.0513?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    References listed on IDEAS

    as
    1. Alessandro Fedele & Cristian Roner, 2022. "Dangerous games: A literature review on cybersecurity investments," Journal of Economic Surveys, Wiley Blackwell, vol. 36(1), pages 157-187, February.
    2. Ramesh Johari & Gabriel Y. Weintraub & Benjamin Van Roy, 2010. "Investment and Market Structure in Industries with Congestion," Operations Research, INFORMS, vol. 58(5), pages 1303-1317, October.
    3. Dziubiński, Marcin Konrad & Goyal, Sanjeev, 2017. "How do you defend a network?," Theoretical Economics, Econometric Society, vol. 12(1), January.
    4. Simon P. Anderson & Stephen Coate, 2005. "Market Provision of Broadcasting: A Welfare Analysis," The Review of Economic Studies, Review of Economic Studies Ltd, vol. 72(4), pages 947-972.
    5. Alfredo Garcia & Barry Horowitz, 2007. "The potential for underinvestment in internet security: implications for regulatory policy," Journal of Regulatory Economics, Springer, vol. 31(1), pages 37-55, February.
    6. Tyler Moore & Richard Clayton & Ross Anderson, 2009. "The Economics of Online Crime," Journal of Economic Perspectives, American Economic Association, vol. 23(3), pages 3-20, Summer.
    7. Arora, Ashish & Forman, Chris & Nandkumar, Anand & Telang, Rahul, 2010. "Competition and patching of security vulnerabilities: An empirical analysis," Information Economics and Policy, Elsevier, vol. 22(2), pages 164-177, May.
    8. Dan Geer & Eric Jardine & Eireann Leverett, 2020. "On market concentration and cybersecurity risk," Journal of Cyber Policy, Taylor & Francis Journals, vol. 5(1), pages 9-29, July.
    9. Sam Ransbotham & Sabyasachi Mitra, 2009. "Choice and Chance: A Conceptual Model of Paths to Information Security Compromise," Information Systems Research, INFORMS, vol. 20(1), pages 121-139, March.
    10. Yi Liu & Pinar Yildirim & Z. John Zhang, 2022. "Implications of Revenue Models and Technology for Content Moderation Strategies," Marketing Science, INFORMS, vol. 41(4), pages 831-847, July.
    11. Jay Pil Choi & Chaim Fershtman & Neil Gandal, 2010. "Network Security: Vulnerabilities And Disclosure Policy," Journal of Industrial Economics, Wiley Blackwell, vol. 58(4), pages 868-894, December.
    12. Gordon, Lawrence A. & Loeb, Martin P. & Lucyshyn, William, 2003. "Sharing information on computer systems security: An economic analysis," Journal of Accounting and Public Policy, Elsevier, vol. 22(6), pages 461-485.
    13. Terrence August & Marius Florin Niculescu & Hyoduk Shin, 2014. "Cloud Implications on Software Network Structure and Security Risks," Information Systems Research, INFORMS, vol. 25(3), pages 489-510, September.
    14. Matthew G. Nagler, 2011. "Negative Externalities, Competition And Consumer Choice," Journal of Industrial Economics, Wiley Blackwell, vol. 59(3), pages 396-421, September.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Kjell Hausken, 2017. "Security Investment, Hacking, and Information Sharing between Firms and between Hackers," Games, MDPI, vol. 8(2), pages 1-23, May.
    2. Kjell Hausken, 2018. "Proactivity and Retroactivity of Firms and Information Sharing of Hackers," International Game Theory Review (IGTR), World Scientific Publishing Co. Pte. Ltd., vol. 20(01), pages 1-30, March.
    3. Kjell Hausken, 2017. "Information Sharing Among Cyber Hackers in Successive Attacks," International Game Theory Review (IGTR), World Scientific Publishing Co. Pte. Ltd., vol. 19(02), pages 1-33, June.
    4. Alessandro Fedele & Cristian Roner, 2022. "Dangerous games: A literature review on cybersecurity investments," Journal of Economic Surveys, Wiley Blackwell, vol. 36(1), pages 157-187, February.
    5. Stefano Comino & Alessandro Fedele & Fabio Manenti, 2025. "Cyber(in)security and Interoperability in Digital Services," BEMPS - Bozen Economics & Management Paper Series BEMPS116, Faculty of Economics and Management at the Free University of Bozen.
    6. Xing Gao & Weijun Zhong, 2016. "A differential game approach to security investment and information sharing in a competitive environment," IISE Transactions, Taylor & Francis Journals, vol. 48(6), pages 511-526, June.
    7. Nan Clement & Daniel Arce, 2025. "Dynamics of Shared Security in the Cloud," Information Systems Research, INFORMS, vol. 36(2), pages 916-943, June.
    8. Xing Gao, 2023. "A competitive analysis of software quality investment with technology diversification and security concern," Electronic Commerce Research, Springer, vol. 23(4), pages 2691-2712, December.
    9. Beknazar-Yuzbashev, George & Jimenez-Duran, Rafael & Simonov, Andrey & Mateusz Stalinsk, Mateusz, 2026. "Social Media Advertising Loads as Prices," The Warwick Economics Research Paper Series (TWERPS) 1602, University of Warwick, Department of Economics.
    10. Yonghua Ji & Subodha Kumar & Vijay Mookerjee, 2016. "When Being Hot Is Not Cool: Monitoring Hot Lists for Information Security," Information Systems Research, INFORMS, vol. 27(4), pages 897-918, December.
    11. Jeon, Doh-Shin & Ichihashi, Shota & Kim, Byung-Cheol, 2024. "Mechanism Design for Ad - Suppo rted Platforms," TSE Working Papers 24-1591, Toulouse School of Economics (TSE), revised Nov 2025.
    12. Dan Kovenock & Brian Roberson & Roman M. Sheremeta, 2019. "The attack and defense of weakest-link networks," Public Choice, Springer, vol. 179(3), pages 175-194, June.
    13. Xing Gao & Weijun Zhong & Shue Mei, 2014. "A game-theoretic analysis of information sharing and security investment for complementary firms," Journal of the Operational Research Society, Palgrave Macmillan;The OR Society, vol. 65(11), pages 1682-1691, November.
    14. Lam, Wing Man Wynne, 2016. "Attack-prevention and damage-control investments in cybersecurity," Information Economics and Policy, Elsevier, vol. 37(C), pages 42-51.
    15. Terrence August & Duy Dao & Kihoon Kim, 2019. "Market Segmentation and Software Security: Pricing Patching Rights," Management Science, INFORMS, vol. 65(10), pages 4575-4597, October.
    16. Beknazar-Yuzbashev, George & Jiménez-Durán, Rafael & Simonov, Andrey & Stalinski, Mateusz, 2026. "Social Media Advertising Loads as Prices," CAGE Online Working Paper Series 792, Competitive Advantage in the Global Economy (CAGE).
    17. Paul, Jomon A. & Zhang, Minjiao, 2021. "Decision support model for cybersecurity risk planning: A two-stage stochastic programming framework featuring firms, government, and attacker," European Journal of Operational Research, Elsevier, vol. 291(1), pages 349-364.
    18. Lam, Wing Man Wynne, 2014. "Ex Ante and Ex Post Investments in Cybersecurity," TSE Working Papers 14-519, Toulouse School of Economics (TSE).
    19. Ying Bao & Jessie Liu, 2025. "Spiral of Silence: How Neutral Moderation Polarizes Content Creation," Papers 2511.19680, arXiv.org.
    20. Terrence August & Tunay I. Tunca, 2011. "Who Should Be Responsible for Software Security? A Comparative Analysis of Liability Policies in Network Environments," Management Science, INFORMS, vol. 57(5), pages 934-959, May.

    More about this item

    Keywords

    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:inm:ormksc:v:45:y:2026:i:2:p:318-334. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Chris Asher (email available below). General contact details of provider: https://edirc.repec.org/data/inforea.html .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.