Understanding incentives for cybersecurity investments: Development and application of a typology

Martijn Wessels, Puck van den Brink, Thijmen Verburgh, Beatrice Cadet, Theo van Ruijven
{"title":"Understanding incentives for cybersecurity investments: Development and application of a typology","authors":"Martijn Wessels,&nbsp;Puck van den Brink,&nbsp;Thijmen Verburgh,&nbsp;Beatrice Cadet,&nbsp;Theo van Ruijven","doi":"10.1016/j.digbus.2021.100014","DOIUrl":null,"url":null,"abstract":"<div><p>Digitalisation has tremendous benefits while simultaneously elevating cybersecurity to a prominent theme in modern societies. All businesses and organisations need invest in and manage their cybersecurity measures to ensure the continuation of their processes. However, the academic understanding regarding different incentives for these investments are fragmented throughout many different studies and a clear overview of these types of incentives for cybersecurity is lacking. This research aims to fill this deficiency by providing clarity on how incentives can be conceptualised, and what they mean in the context of investing and managing cybersecurity. This article provides a typology of cybersecurity incentives of organisations that can be used by scholars and professionals to understand the (lack of) adoption of cybersecurity measures. The typology is developed on the basis of a literature study encompassing different theoretical perspectives on incentives, and illustrated and further scrutinised with an empirical case about the adoption of secure e-mail standards. We present a typology of six categories of incentives that may explain why organisations are (not) willing to invest in cybersecurity measures: economic-, normative-, historic- and feasibility incentives, network externalities, and the presence of competing cybersecurity issues and solutions. This typology can serve as a starting point for future research to develop a (full) conceptual framework for identifying and understanding incentives for cybersecurity. Furthermore, cybersecurity professionals (e.g. Chief Information Security Officers) and policy makers can use this typology in their work to enhance the cybersecurity of organisations and society.</p></div>","PeriodicalId":100376,"journal":{"name":"Digital Business","volume":"1 2","pages":"Article 100014"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://sci-hub-pdf.com/10.1016/j.digbus.2021.100014","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Digital Business","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2666954421000132","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Digitalisation has tremendous benefits while simultaneously elevating cybersecurity to a prominent theme in modern societies. All businesses and organisations need invest in and manage their cybersecurity measures to ensure the continuation of their processes. However, the academic understanding regarding different incentives for these investments are fragmented throughout many different studies and a clear overview of these types of incentives for cybersecurity is lacking. This research aims to fill this deficiency by providing clarity on how incentives can be conceptualised, and what they mean in the context of investing and managing cybersecurity. This article provides a typology of cybersecurity incentives of organisations that can be used by scholars and professionals to understand the (lack of) adoption of cybersecurity measures. The typology is developed on the basis of a literature study encompassing different theoretical perspectives on incentives, and illustrated and further scrutinised with an empirical case about the adoption of secure e-mail standards. We present a typology of six categories of incentives that may explain why organisations are (not) willing to invest in cybersecurity measures: economic-, normative-, historic- and feasibility incentives, network externalities, and the presence of competing cybersecurity issues and solutions. This typology can serve as a starting point for future research to develop a (full) conceptual framework for identifying and understanding incentives for cybersecurity. Furthermore, cybersecurity professionals (e.g. Chief Information Security Officers) and policy makers can use this typology in their work to enhance the cybersecurity of organisations and society.

理解网络安全投资的动机:类型学的发展和应用
数字化带来了巨大的好处,同时将网络安全提升为现代社会的一个突出主题。所有企业和组织都需要投资和管理其网络安全措施,以确保其流程的连续性。然而,在许多不同的研究中,对这些投资的不同激励机制的学术理解是分散的,并且缺乏对这些类型的网络安全激励机制的清晰概述。本研究旨在通过明确激励如何概念化,以及它们在投资和管理网络安全方面的意义,来填补这一不足。本文提供了组织的网络安全激励类型,学者和专业人员可以使用它来理解(缺乏)采用网络安全措施。该类型学是在一项文献研究的基础上发展起来的,该研究涵盖了关于激励的不同理论观点,并通过一个关于采用安全电子邮件标准的实证案例加以说明和进一步审查。我们提出了六种激励类型,可以解释为什么组织(不)愿意投资于网络安全措施:经济激励、规范激励、历史激励和可行性激励、网络外部性激励以及竞争性网络安全问题和解决方案的存在。这种类型可以作为未来研究的起点,为识别和理解网络安全激励制定一个(完整的)概念框架。此外,网络安全专业人员(如首席信息安全官)和政策制定者可以在他们的工作中使用这种类型来增强组织和社会的网络安全。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
7.40
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信