EconReads
Donate

War, Peace & Security Economics

The Economics of Cybersecurity

Why companies and individuals often underinvest in cybersecurity, how ransomware became a business, and what policies aim to fix the incentives.

Cyber attacks can shut down hospitals, freeze company systems, steal personal data and disrupt power grids. Economists study cybersecurity not only as a technical problem but as a problem of incentives.

Why security is underprovided

Many organisations spend less on cybersecurity than would be best for society. Economists point to several reasons:

  • Externalities: when a company’s systems are breached, the harm often falls on others, such as customers whose data is stolen or partners whose systems are infected. The company does not bear the full cost, so it invests too little.
  • Hidden quality: buyers of software and devices cannot easily judge how secure they are, so makers have weak incentives to invest in security.
  • Invisible success: when security works, nothing happens, making it hard to justify the spending.
  • Weakest link: a network is only as secure as its least protected part.

Ransomware as a business

Ransomware attacks encrypt a victim’s files and demand payment, usually in cryptocurrency, to unlock them. Ransomware has become an organised criminal business, with some groups offering their tools to others in exchange for a share of the ransom.

In May 2021, a ransomware attack on Colonial Pipeline, which carries fuel along the U.S. East Coast, led the company to shut down the pipeline for several days, causing fuel shortages and panic buying. The company paid a ransom of about 4.4 million dollars, part of which U.S. authorities later recovered.

The decision to pay

A hospital hit by ransomware faces a hard choice. Paying may restore systems quickly and protect patients, but it funds criminals and encourages further attacks. Refusing may mean days or weeks of disruption. Each individual victim may find paying worthwhile, yet collectively payments make attacks more profitable. This is a classic conflict between individual and collective interest.

Policy responses

Governments use several tools:

  • Reporting rules requiring companies to disclose breaches.
  • Security standards for critical infrastructure such as power and water.
  • Liability rules that make companies responsible for harm from poor security.
  • International cooperation to pursue cybercriminals across borders.
  • Guidance against paying ransoms, and in some cases restrictions on payments.
Thinking cybersecurity is only an IT department problem

Cybersecurity involves incentives, laws, insurance and human behaviour as much as technology. Many breaches start with a simple human mistake, like clicking a malicious link. Good security depends on training, management decisions and policy as well as software.

Key takeaways
  • Organisations often underinvest in cybersecurity because much of the harm falls on others.
  • Buyers cannot easily judge security, and successful security is invisible.
  • Ransomware has become an organised criminal business, as the 2021 Colonial Pipeline attack showed.
  • Reporting rules, standards, liability and international cooperation aim to improve incentives.
4 min read

No recording for this one yet - EconReader can read it aloud for you.

Welcome to EconReads

This site is made for visually impaired learners, so our read-aloud reader is already switched on to help you explore hands-free.

You're in control - turn it off any time using the Reader button at the top of the page.

EconReader Ready