TITLE:
Cybersecurity Investment Guidance: Extensions of the Gordon and Loeb Model
AUTHORS:
Scott Farrow, Jules Szanton
KEYWORDS:
Cybersecurity, Investment, Externality, Log-Convexity, Law
JOURNAL NAME:
Journal of Information Security,
Vol.7 No.2,
March
16,
2016
ABSTRACT: Extensions of the
Gordon-Loeb [1] and the Gordon-Loeb-Lucyshyn-Zhou [2] models are presented
based on mathematical equivalency with a generalized homeland security model. The
extensions include limitations on changes in the probability of attack,
simultaneous effects on probability and loss, diversion of attack, and shared
non-information defenses. Legal cases are then investigated to assess
approximate magnitudes of external effects and the extent they are internalized
by the legal system.