The potential for underinvestment in internet security: implications for regulatory policy
With the continuing growth of the use of the Internet for business purposes, the consequences of a possible cyber attack that could create a large scale outage of long time duration becomes a more and more serious economic issue. In this paper, we construct a game-theoretic model that addresses the economic motivations for investment in added Internet security and makes a case for a possible market failure in the form of underinvestment in the provision of Internet security. This result relies on the fact that the social value derived from consumption (which is at least equal to a fraction of the surplus derived from e-commerce) greatly exceeds the revenue at stake associated with the telecommunications companies’ and ISP’s security levels. If the ratio of social value to revenue at stake to Internet providers continues to grow, the likelihood of underinvestment in security becomes higher and some form of regulation may become necessary. We discuss the difficulties associated with designing and enforcing a regulatory scheme based upon mandatory security standards. Copyright Springer Science+Business Media, LLC 2007
References listed on IDEAS
Please report citation or reference errors to , or , if you are the registered author of the cited work, log in to your RePEc Author Service profile, click on "citations" and make appropriate adjustments.:
- Shapiro, Carl, 1983. "Premiums for High Quality Products as Returns to Reputations," The Quarterly Journal of Economics, MIT Press, vol. 98(4), pages 659-79, November.
- Giovannetti, Emanuele, 2001.
"Perpetual Leapfrogging in Bertrand Duopoly,"
International Economic Review,
Department of Economics, University of Pennsylvania and Osaka University Institute of Social and Economic Research Association, vol. 42(3), pages 671-96, August.
- Esther Gal-Or & Anindya Ghose, 2005. "The Economic Incentives for Sharing Security Information," Industrial Organization 0503004, EconWPA.
- Martin Cave & Robin Mason, 2001. "The Economics of the Internet: Infrastructure and Regulation," Oxford Review of Economic Policy, Oxford University Press, vol. 17(2), pages 188-201, Summer.
When requesting a correction, please mention this item's handle: RePEc:kap:regeco:v:31:y:2007:i:1:p:37-55. See general information about how to correct material in RePEc.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: (Sonal Shukla)or (Christopher F. Baum)
If references are entirely missing, you can add them using this form.