Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Why Information Security Is Hard: An Economic Perspective

Citation

Ross Anderson. “Why Information Security is Hard—An Economic Perspective.” ACSAC, 2001. University of Cambridge PDF. Accessed 2026-08-14.

Source type: research paper
Evidence quality: primary analytical work
Review status: checked

What it says

Many security failures are better explained by incentives than by missing technical mechanisms. The paper applies externalities, asymmetric information, moral hazard, adverse selection, liability dumping, and network economics to cases where those able to protect a system do not bear failure costs.

Important claims

  • Security investment follows incentives and liability allocation, not social harm automatically.
  • Network effects and lock-in can reward insecure products.
  • Technical correctness cannot compensate for actors being rewarded for the wrong outcome.

Weaknesses / disagreements

The examples are historically situated, and the paper is conceptual rather than an empirical model of modern platform abuse. It primarily examines defender and market incentives, not every attacker production function.

Implications for platform defense

The canvas must identify who controls a risk, who bears harm, who pays for mitigation, and whether metrics reward ecosystem integrity or only growth and throughput.

Chapters this affects

Chapters 2, 3, 6, 15, 19–21.