Incentives for Human Agents to Share Security Information: a Model and an Empirical Test

Details

Ressource 1Download: Mermoud18WEIS.pdf (469.20 [Ko])
State: Public
Version: author
License: Not specified
Serval ID
serval:BIB_9A5416D0FB60
Type
Inproceedings: an article in a conference proceedings.
Collection
Publications
Institution
Title
Incentives for Human Agents to Share Security Information: a Model and an Empirical Test
Title of the conference
Proceedings of the 17th Workshop on the Economics of Information Security (WEIS)
Author(s)
Mermoud A., Keupp M., Huguenin K., Palmié M., Percia David D.
Address
Innsbruck, Austria
Publication state
Published
Issued date
06/2018
Peer-reviewed
Oui
Language
english
Abstract
In this paper, we investigate the role of incentives for Security Information Sharing (SIS)
between human agents working in institutions. We present an incentive-based SIS system model
that is empirically tested with an exclusive dataset. The data was collected with an online
questionnaire addressed to all participants of a deployed Information Sharing and Analysis
Center (ISAC) that operates in the context of critical infrastructure protection (N=262). SIS is
measured with a multidimensional approach (intensity, frequency) and regressed on five
specific predicators (reciprocity, value of information, institutional barriers, reputation, trust)
that are measured with psychometric scales. We close an important research gap by providing,
to the best of our knowledge, the first empirical analysis on previous theoretical work that
assumes SIS to be beneficial. Our results show that institutional barriers have a strong
influence on our population, i.e., SIS decision makers in Switzerland. This lends support to a
better institutional design of ISACs and the formulation of incentive-based policies that can
avoid non-cooperative and free-riding behaviours. Both frequency and intensity are influenced
by the extent to which decision makers expect to receive valuable information in return for SIS,
which supports the econometric structure of our multidimensional model. Finally, our policy
recommendations support the view that the effectiveness of mandatory security-breach
reporting to authorities is limited. Therefore, we suggest that a conducive and lightly regulated
SIS environment – as in Switzerland – with positive reinforcement and indirect suggestions can
“nudge” SIS decision makers to adopt a productive sharing behaviour.
Open Access
Yes
Create date
08/04/2018 16:24
Last modification date
20/08/2019 16:01
Usage data