Economics of security
Economics of security, sometimes called economics of information security, studies privacy and computer security decisions as economic decisions, not just technical ones. The field blends two views of human behavior: the purely rational actor economists call homo economicus, and the more realistic picture offered by behavioral economics. Under this lens, individuals and organizations are not simply following best practice when they buy or ignore a security tool. They are making market decisions, weighing costs against benefits like any other purchase. That framing raises a pointed question: why would anyone knowingly accept a security risk when a technical fix for it already exists? Answering that question needed economists as much as engineers. This documentary follows who built the tools to measure it, and what they found once economic analysis was pointed at real security problems.
In 2000, the researcher Ross Anderson wrote a paper titled Why Information Security is Hard. Anderson's central argument was that security technology fails when its incentives are not aligned with the people meant to adopt it. A security system only gets used, he wrote, if it lets the party actually at risk invest to reduce that risk themselves. Without that alignment, its designers are left counting on altruism alone to drive adoption. Many researchers still treat this paper as the field's starting point, an idea that Harvard researchers would soon test from a different angle.
At Harvard that same year, Camp, based in the School of Government, and Wolfram, in the Department of Economics, argued that security itself is not a public good. Instead, they said, every vulnerability carries its own negative externality value, a cost imposed on others when it is left unpatched. In their argument, vulnerabilities themselves could be treated and traded like ordinary goods. Six years later, that idea had become practice: iDEFENSE, ZDI, and Mozilla were all running functioning markets for vulnerabilities.
In 2000, scientists at the Computer Emergency Response Team at Carnegie Mellon University proposed one of the first mechanisms for assessing security risk. They called it the Hierarchical Holographic Model, the first tool designed to evaluate security investments from multiple angles at once. It applied the science of risk to a decision organizations had mostly made on instinct. Since then, CERT has expanded that early model into a full suite of systematic risk-evaluation tools called OCTAVE. Which version of OCTAVE an organization uses depends on its own size and expertise. A year later, two professors from Maryland would attack the same investment question with an entirely different tool: game theory.
In 2001, Lawrence A. Gordon and Martin P. Loeb published a paper called Using Information Security as a Response to Competitor Analysis System. Both were professors at Maryland's Smith School of Business. A working paper version had circulated a year earlier, in 2000. The published article laid out a game-theoretic framework showing how strong information security can stop rival firms from gaining access to sensitive information. Framed this way, the question becomes a cost-benefit calculation like any other business decision. Gordon and Loeb then built on that work, developing what became a recurring flagship event: the Workshop on the Economics of Information Security. That workshop became the annual home for the field's biggest findings, from why spam filters need pricing logic to what really counts as private.
Spam has one specific enemy in this field: proof of work, a technology built to make sending each message cost real computing effort. An early paper in the field argued flatly that proof of work, by itself, cannot function as a spam deterrent. A later paper, titled Proof of Work can Work, showed why. The technique only succeeds once it is paired with price discrimination, charging different senders different real costs.
Andrew Odlyzko authored a related paper called Privacy and price discrimination that reframes the debate entirely. In economic terms, Odlyzko argued, the true opposite of privacy is not anonymity but price discrimination itself. What looks from the outside like a company mishandling customer data, he wrote, is often just rational organizational behavior. It sorts customers by what each one will pay. That finding matters directly for understanding current data practices in the United States. Hal Varian would soon build on this same idea of rational self-interest, using a metaphor drawn from something much older than computers: a wall.
Hal Varian modeled computer security using the height of a wall built around an entire town. In one version of his model, security behaves like an ordinary good, bought in proportion to what a person or firm can afford. In a second version, it acts like a public good that benefits everyone whether they contributed to it or not. In a third, it produces externalities, costs or benefits that spill onto people who never chose to invest in it at all. Free riding turns out to be the result in all three versions, no matter which model best fits a given case. That shared outcome, everyone defaulting to relying on someone else's defenses, left one question unresolved: not whether to invest in security, but exactly how much.
Lawrence A. Gordon and Martin P. Loeb answered that question directly in a paper called Economics of Information Security Investment. The Gordon-Loeb model that resulted is widely regarded as the first economic model built specifically for this purpose. It calculates the optimal amount an organization should spend to protect a given set of information. The calculation weighs two things together. It accounts for how vulnerable that information already is to a breach, and how much the organization stands to lose if a breach actually happens. Once that number is calculated, it gives an organization something concrete to argue over. The question is no longer whether a piece of information is worth defending, but exactly how much defending it is worth.
Common questions
Who is credited with founding the field of economics of security?
Ross Anderson is widely credited with founding the field through his 2000 paper Why Information Security is Hard, which argued that security technology fails without incentives aligned to the people who adopt it. That same year, Camp and Wolfram at Harvard published a related argument that security is not a public good.
What is the Gordon-Loeb model in economics of security?
The Gordon-Loeb model, introduced by Lawrence A. Gordon and Martin P. Loeb in a paper called Economics of Information Security Investment, is considered the first economic model built to calculate the optimal amount an organization should spend protecting a given set of information. It weighs the information's vulnerability to breach against the potential loss from a breach.
Why does economics of security treat computer security vulnerabilities as tradable goods?
Camp and Wolfram argued in 2000 that each vulnerability carries its own negative externality value and can be treated as a tradable good rather than a shared public risk. Six years later, iDEFENSE, ZDI, and Mozilla were running actual markets for buying and selling vulnerabilities.
What does Hal Varian's wall metaphor show in economics of security?
Hal Varian modeled security using the height of a wall around a town to show it can behave as a normal good, a public good, or a good with externalities. In every version of his model, free riding was the eventual result.
Why can't proof of work stop spam on its own, according to economics of security?
An early paper in the field found that proof of work cannot function as a spam deterrent by itself. A later paper, titled Proof of Work can Work, showed it only succeeds once combined with price discrimination.
What does economics of security say is the true opposite of privacy?
Andrew Odlyzko argued in his paper Privacy and price discrimination that the true economic opposite of privacy is not anonymity but price discrimination. He wrote that what looks like a company mishandling customer data is often just rational behavior aimed at sorting customers by what they will pay.
All sources
1 references cited across the entry
- 1JournalThe Economics of Information Security InvestmentLawrence A. Gordon et al. — November 2002