The Economics of Cybercrime and Security
Why Firms Underinvest in Security
How externalities, information gaps and misaligned incentives lead companies and software makers to spend too little on cybersecurity.
Many firms spend too little on cybersecurity. Economics helps explain why.
Externalities
- When a firm is hacked, customers, partners and others suffer too.
- The firm doesn’t bear the full cost, so it underinvests.
- Infected computers in botnets harm others while their owners notice little.
Information asymmetry
- Customers can’t easily judge a firm’s security.
- Firms that invest in security may not be rewarded by the market.
- This resembles the “market for lemons”.
Software incentives
Software makers compete on features and speed to market; security flaws are often found only later, when costs fall on users.
Invisible benefits
Security spending prevents attacks that never happen, making its value hard to see.
Solutions
- Regulation: mandatory standards and breach reporting.
- Liability for software makers, as proposed in the EU’s Cyber Resilience Act (2024).
- Disclosure requirements for listed companies.
- Cyber insurance pricing that rewards good security.
The weak password
A small online shop skips security upgrades to save money. When hacked, its customers' card details leak, costing banks and customers far more than the shop saved.
Thinking firms always protect themselves optimally
Externalities and information gaps cause underinvestment.
Key takeaways
- Firms don't bear the full costs of breaches.
- Customers can't judge security, weakening rewards for it.
- Software makers prioritise features and speed.
- Regulation, liability and disclosure can help.
No recording for this one yet - EconReader can read it aloud for you.