2019
DOI: 10.1287/isre.2018.0806
|View full text |Cite
|
Sign up to set email alerts
|

Bilateral Liability-Based Contracts in Information Security Outsourcing

Abstract: We study the efficiency of bilateral liability-based contracts in managed security services (MSSs). We model MSS as a collaborative service with the protection quality shaped by the contribution of both the service provider and the client. We adopt the negligence concept from the legal profession to design two novel contracts: threshold-based liability contract and variable liability contract. We find that they can achieve the first best outcome when postbreach effort verification is feasible. More importantly… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
9
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
7
1

Relationship

0
8

Authors

Journals

citations
Cited by 28 publications
(9 citation statements)
references
References 39 publications
0
9
0
Order By: Relevance
“…Many studies have been proposed to address privacy protection, and there is a wide range of research and tools available for exploration in this field. Hui et al (2019) conducted a study on managed security services and examined the effectiveness of bilateral liability-based contracts using a game model. They found that the designed contract can achieve optimal outcomes when post-breach effort verification is feasible.…”
Section: Information Securitymentioning
confidence: 99%
“…Many studies have been proposed to address privacy protection, and there is a wide range of research and tools available for exploration in this field. Hui et al (2019) conducted a study on managed security services and examined the effectiveness of bilateral liability-based contracts using a game model. They found that the designed contract can achieve optimal outcomes when post-breach effort verification is feasible.…”
Section: Information Securitymentioning
confidence: 99%
“…Zhang et al (2021) analyze whether two firms outsource to the common or different MSSPs. Lee et al (2013), Hui et al (2019), and Wu, Giri, et al (2021) develop different contract structures to decrease double moral hazard in information security outsourcing. Cezar et al (2017) discuss two competitive firms' decisions to outsource security operation with interdependent risks, in which both the MSSP's and the hacker's strategic behavior fails to be characterized.…”
Section: Literature Reviewmentioning
confidence: 99%
“…The third topic of interest revolves around cost, liability and security negligence. This includes research on the influence of customer restitution on customer outcomes post data breach (Goode et al, 2017), the efficiency of bilateral liability-based contracts in managed security services (MSSs) (Hui et al, 2019) and the importance of cloud service certifications as indicators of a cloud provider's future service quality (Lansing et al, 2019). Post-breach reputation management (Gwebu et al, 2018;Syed, 2019) also falls into the topic of interest, as reputation loss is an important cost to a company when recovering from a data breach.…”
Section: Published Topics Of Interestmentioning
confidence: 99%
“…This includes research on the influence of customer restitution on customer outcomes post data breach (Goode et al. , 2017), the efficiency of bilateral liability-based contracts in managed security services (MSSs) (Hui et al. , 2019) and the importance of cloud service certifications as indicators of a cloud provider's future service quality (Lansing et al.…”
Section: Published Topics Of Interestmentioning
confidence: 99%