A game-theoretical model of firm security reactions responding to a strategic hacker in a competitive industry. Issue 4 (24th March 2022)
- Record Type:
- Journal Article
- Title:
- A game-theoretical model of firm security reactions responding to a strategic hacker in a competitive industry. Issue 4 (24th March 2022)
- Main Title:
- A game-theoretical model of firm security reactions responding to a strategic hacker in a competitive industry
- Authors:
- Wu, Yong
Xiao, Haocheng
Dai, Tao
Cheng, Dong - Abstract:
- Abstract: The tendency of strategic hackers to attack specific industries brings new challenges for information security management. This paper examines the interaction between firms in a specific industry and a strategic hacker by considering industry-specific characteristics including the intrinsic vulnerability, intentions of the hacker, competition between firms, and similarity of security technologies. We find that firms in an overly dangerous industry should consider reforming their business mode to reduce the intrinsic vulnerability rather than investing heavily in security protection. Moreover, we distinguish the hacker as profit-seeking and fame-seeking and find that different intentions generate different hacker's behaviour. Furthermore, keep exerting effort is still a better strategy for the firms when the competition becomes more intense even the threat of the hacker reduces. Besides, the technical similarity enhances the hacker's incentive to exert attack effort while induces a free-riding problem for competitive firms. Accordingly, we introduce a social planner to regulate the security decisions of competitive firms, and identify that the supervision of a social planner could partly alleviate the free-riding behaviour, but will only be accepted by competitive firms when facing a less or highly competitive environment. Our results imply that introducing a social planner to enforce security protection may not be advisable for all industries. Finally, we extendAbstract: The tendency of strategic hackers to attack specific industries brings new challenges for information security management. This paper examines the interaction between firms in a specific industry and a strategic hacker by considering industry-specific characteristics including the intrinsic vulnerability, intentions of the hacker, competition between firms, and similarity of security technologies. We find that firms in an overly dangerous industry should consider reforming their business mode to reduce the intrinsic vulnerability rather than investing heavily in security protection. Moreover, we distinguish the hacker as profit-seeking and fame-seeking and find that different intentions generate different hacker's behaviour. Furthermore, keep exerting effort is still a better strategy for the firms when the competition becomes more intense even the threat of the hacker reduces. Besides, the technical similarity enhances the hacker's incentive to exert attack effort while induces a free-riding problem for competitive firms. Accordingly, we introduce a social planner to regulate the security decisions of competitive firms, and identify that the supervision of a social planner could partly alleviate the free-riding behaviour, but will only be accepted by competitive firms when facing a less or highly competitive environment. Our results imply that introducing a social planner to enforce security protection may not be advisable for all industries. Finally, we extend our model to discuss two additional cases, including the case of sequential game and the case of asymmetric condition. … (more)
- Is Part Of:
- Journal of the Operational Research Society. Volume 73:Issue 4(2022)
- Journal:
- Journal of the Operational Research Society
- Issue:
- Volume 73:Issue 4(2022)
- Issue Display:
- Volume 73, Issue 4 (2022)
- Year:
- 2022
- Volume:
- 73
- Issue:
- 4
- Issue Sort Value:
- 2022-0073-0004-0000
- Page Start:
- 716
- Page End:
- 740
- Publication Date:
- 2022-03-24
- Subjects:
- Strategic hacker -- competitive firm -- industry characteristics -- similarity of security technologies -- decision analysis
Operations research -- Periodicals
658.4034 - Journal URLs:
- http://www.jstor.org/journals/01605682.html ↗
http://www.palgrave-journals.com/jors/index.html ↗
http://www.palgrave.com/home/index.asp ↗
http://firstsearch.oclc.org ↗
http://firstsearch.oclc.org/journal=0160-5682;screen=info;ECOIP ↗ - DOI:
- 10.1080/01605682.2020.1854631 ↗
- Languages:
- English
- ISSNs:
- 0160-5682
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4835.900000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 21255.xml