Data Breaches and Identity Theft: When is Mandatory Disclosure Optimal?

Data Breaches and Identity Theft: When is Mandatory Disclosure Optimal?
复制标题

数据泄露和身份盗窃:强制披露何时是最佳选择?

DOI:
--
复制
发表时间:
2010
期刊:
Workshop on the Economics of Information Security
影响因子:
--
通讯作者:
A. Acquisti
A. Acquisti
中科院分区:
--
文献类型:
--
作者:
Sasha Romanosky;Richard Sharp;A. Acquisti

文献摘要

被引文献

相似文献

当个人消费者信息丢失或被盗时,就会发生数据泄露,并可能导致数百万条记录的丢失(例如,当地学校或小型零售店; TJX或Heartland)。它们可能发生在对包含个人信息的文件的不当处置、笔记本电脑或拇指驱动器的丢失或犯罪分子渗透公司网络窃取信息时。被泄露的个人数据包括个人的姓名、地址、社会安全号码、出生日期、驾驶执照、护照号码和财务数据。这些信息可以被用于犯罪,包括欺诈性失业申请(Goodin 2008),欺诈性纳税申报(McMillan 2008),欺诈性贷款(Hogan 2008),房屋净值欺诈(Krebs 2008)和支付卡欺诈。消费者还可能承受贷款利率上升的负担,被剥夺公用事业服务、民事诉讼或刑事调查(Baum 2004)。虽然信用卡欺诈给消费者带来的损失可以忽略不计,但自付费用可能达到数千美元(联邦贸易委员会,2007年)。由于这些损失,近年来,美国政策制定者颁布了法律,要求组织在个人身份信息丢失或被盗时通知个人。截至2009年底,45个州(以及世界其他国家)已经通过了数据泄露披露或安全泄露通知法律(Maurushat 2009)。除了两项研究(一项研究显示公司做法有所改善(萨缪尔森法,2007年),另一项研究发现消费者身份盗窃率仅略有下降(Romanosky等人,2008年)),然而,数据泄露披露法律的影响还有待严格研究。2通知法律的主要目的之一是授权消费者采取行动并减轻他们的损失(Majoras 2005)。此外,有人认为,由于数据泄露而可能造成损失以及由此产生的通知费用,迫使公司将更多的数据泄露费用内部化,从而促使它们增加对安全措施的投资。这反过来又有望降低未来违约的可能性或规模。简而言之,数据泄露披露“通过透明度和监督来推动业绩”(Mulligan 2007)。然而,批评者认为,如果公司确实已经承担了大部分损失(Lenard和Rubin 2005),或者丢失的数据在被访问之前就被恢复(Majoras 2005),那么这种法律会给公司和消费者带来不必要的成本。此外,当伤害风险较低时,不必要的通知可能会使个人失去敏感性,使他们在确实存在严重威胁时无法采取行动(Majoras 2005)。此外,消费者可能无法正确响应违规通知,因为通知可能会对跟踪行动造成巨大的认知和心理障碍,也导致他们反应不足(Romanosky和Acquisti 2009)。另一方面,新闻媒体和迅速发展的身份盗窃预防服务市场可能会滋生恐慌和混乱,导致消费者反应过度,不必要地购买此类产品,增加他们的预期成本。一方面,信息披露的成本很高。公司将承担通知、客户服务运营(呼叫中心、客户支持)、消费者补救(如身份盗窃保险或信用监测)、法律的费用、监管罚款以及潜在的市场估值损失或业务损失(客户流失)等成本(GAO 2007,Ponemon 2010)。另一方面,通知也可能促使消费者采取适当的行动,减少他们的伤害(通过防止或减轻身份盗窃)-这将降低企业自身的预期成本,因为企业内部化的消费者伤害的数量减少了。简而言之,目前还不清楚披露是否会导致企业,消费者或整体社会成本的净增加或减少。使用分析和数值模拟,我们表明,即使公司成本将更高的披露制度下,公司可以诱导增加他们的投资,在照顾,这可能会降低社会成本。此外,披露信息可以促使消费者提高其护理水平,从而降低其总成本。最后,我们发现,社会成本的变化通常是增加披露税(由于披露法律对公司施加的成本)和减少消费者赔偿(公司支付给消费者的赔偿)。然而,当企业仅对消费者的损失进行少量补偿时,为了最大限度地降低社会成本,可能需要征收一定的信息披露税。下一节将讨论与IT安全领域的信息披露相关的文献和(事故)法的经济学,我们将利用这些文献,在其他减少外部性的常见手段的背景下构建信息披露。然后,我们定义了在没有任何法律的制度的情况下数据泄露所涉及的成本,并说明了这些成本在强制性泄露披露下的变化。接下来,我们使用分析方法来确定披露降低社会成本的条件。最后,我们提供了讨论和实证验证,其次是一些模型扩展和我们的结论
Data breaches occur when personal consumer information is lost or stolen, and can result in the loss of hundreds or millions of records (e.g., local schools or small retail stores; TJX or Heartland). They can occur from the improper disposal of documents containing personal information, from the loss of a laptop or thumb-drive, or when criminals penetrate corporate networks to steal information. The personal data compromised include individuals’ names, addresses, social security numbers, dates of birth, driver’s licenses, passport numbers, and financial data. This information can then be used to commit crimes, including fraudulent unemployment claims (Goodin 2008), fraudulent tax returns (McMillan 2008), fraudulent loans (Hogan 2008), home equity fraud (Krebs 2008), and payment card fraud. Consumers can also suffer the burden of increased loan interest rates, being denied utility services, civil suits or criminal investigation (Baum 2004). While the consumer costs incurred from credit card fraud may be negligible, out of pocket expenses can reach thousands of dollars (Federal Trade Commission 2007).As a result of these losses, in recent years U.S. policy makers have enacted laws that require organizations to notify individuals when personally identifiable information has been lost or stolen. As of late 2009, 45 states (as well as other countries around the world) have adopted data breach disclosure, or security breach notification, laws (Maurushat 2009). Aside from two studies (one showing an improvement in firm practices (Samuelson Law 2007), and another finding only a marginal reduction in consumer rates of identity theft (Romanosky et al. 2008)), however, the effects of data breach disclosure laws have yet to be rigorously studied.One of the main intents of notification laws is to empower consumers to take action and mitigate their loss (Majoras 2005). In addition, the possibility of loss from a breach and resulting costs from notification, it is argued, forces firms to internalize more of the cost of a data breach, thereby inducing them to increase their investment in security measures. This, in turn, is expected to reduce the probability, or magnitude, of future breaches. In short, data breach disclosure “drive[s] performance through transparency and oversight” (Mulligan 2007).However, critics argue that such laws inflict unnecessary costs for both firms and consumers if indeed firms already bear most of the loss (Lenard and Rubin 2005) or when lost data is recovered before it is even accessed (Majoras 2005). Moreover, when the risk of harm is low, unnecessary notification may desensitize individuals, preventing them from acting when a serious threat does exist (Majoras 2005). Further, consumers may be unable to properly respond to the breach notifications, as the notices may present a substantial cognitive and psychological barrier to tacking action, also causing them to under-react (Romanosky and Acquisti 2009). Alternatively, news media and a burgeoning market of identity theft prevention services may breed panic and confusion, causing consumers to over-react by unnecessarily purchasing such products, increasing their expected costs.But mandatory disclosure may also affect firms in conflicting ways. On the one hand, disclosure is costly. Firms will incur costs of notification, customer services operations (call centers, customer support), consumer redress (such as identity theft insurance or credit monitoring), legal fees, regulatory fines, and the potential loss of market valuation or lost business (customer churn) (GAO 2007, Ponemon 2010). On the other hand, notifications may also cause consumers to take appropriate action and reduce their harm (either by preventing or mitigating identity theft) - this would lower the firm’s own expected costs, because the amount of consumer harm that the firm internalizes is reduced.In short, it is unclear whether disclosure would result in a net increase or decrease of firm, consumer, or overall social costs. Using both analytical and numerical modeling, we show that even though firm costs will be higher under disclosure regimes, firms can be induced to increase their investment in care, which may lower social costs. Moreover, disclosure can induce consumers to increase their level of care, thus lowering their total costs. Finally, we find that the change in social costs are typically increasing in disclosure tax (costs imposed on the firm due to disclosure laws) and decreasing in consumer redress (compensation paid by the firm to the consumer). However, when the firm compensates consumers for only a small amount of loss, some disclosure tax may be necessary to optimally reduce social costs.The next section discusses the literature related to information disclosure in IT security and the economics of (accident) law, which we leverage to frame information disclosure within the context of other common means of reducing externalities. We then define the costs involved in a data breach absent any legal regime, and illustrate how these costs change under mandatory breach disclosure.Next, we use analytical methods to determine the conditions under which disclosure reduces social costs. Finally, we provide discussion and empirical validation, followed by some model extensions and our conclusion