{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T15:49:46Z","timestamp":1774367386449,"version":"3.50.1"},"reference-count":106,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2017,11,13]],"date-time":"2017-11-13T00:00:00Z","timestamp":1510531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2018,9,30]]},"abstract":"<jats:p>Cyber risk management largely reduces to a race for information between defenders of ICT systems and attackers. Defenders can gain advantage in this race by sharing cyber risk information with each other. Yet, they often exchange less information than is socially desirable, because sharing decisions are guided by selfish rather than altruistic reasons. A growing line of research studies these strategic aspects that drive defenders\u2019 sharing decisions. The present survey systematizes these works in a novel framework. It provides a consolidated understanding of defenders\u2019 strategies to privately or publicly share information and enables us to distill trends in the literature and identify future research directions. We reveal that many theoretical works assume cyber risk information sharing to be beneficial, while empirical validations are often missing.<\/jats:p>","DOI":"10.1145\/3124398","type":"journal-article","created":{"date-parts":[[2017,11,14]],"date-time":"2017-11-14T14:02:44Z","timestamp":1510668164000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Strategic Aspects of Cyber Risk Information Sharing"],"prefix":"10.1145","volume":"50","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3229-7710","authenticated-orcid":false,"given":"Stefan","family":"Laube","sequence":"first","affiliation":[{"name":"Westf\u00e4lische Wilhelms-Universit\u00e4t M\u00fcnster, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"B\u00f6hme","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Innsbruck, Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,11,13]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.7249\/RR1187"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906)","author":"Acquisti Alessandro","year":"2006","unstructured":"Alessandro Acquisti , Allan Friedman , and Rahul Telang . 2006 . Is there a cost to privacy breaches? An event study . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906) . University of Cambridge, UK. Alessandro Acquisti, Allan Friedman, and Rahul Telang. 2006. Is there a cost to privacy breaches? An event study. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906). University of Cambridge, UK."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/2882670.2882677"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.5555\/872016.872155"},{"key":"e_1_2_1_6_1","volume-title":"The economics of information security. Science 314, 5799","author":"Anderson Ross","year":"2006","unstructured":"Ross Anderson and Tyler Moore . 2006. The economics of information security. Science 314, 5799 ( 2006 ), 610--613. Ross Anderson and Tyler Moore. 2006. The economics of information security. Science 314, 5799 (2006), 610--613."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1050.0440"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infoecopol.2009.10.002"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1080.0226"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-006-9012-5"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1070.0771"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1070.0142"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1592761.1592780"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the USENIX Systems Administration Conference (LISA\u201902)","author":"Beattie Steve","year":"2002","unstructured":"Steve Beattie , Seth Arnold , Crispin Cowan , Perry Wagle , and Chris Wright . 2002 . Timing the application of security patches for optimal uptime . In Proceedings of the USENIX Systems Administration Conference (LISA\u201902) . Philadelphia, PA, 233--242. Steve Beattie, Seth Arnold, Crispin Cowan, Perry Wagle, and Chris Wright. 2002. Timing the application of security patches for optimal uptime. In Proceedings of the USENIX Systems Administration Conference (LISA\u201902). Philadelphia, PA, 233--242."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3013520"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5325\/jinfopoli.6.2016.0154"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/11766155_21"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/876661.876669"},{"key":"e_1_2_1_20_1","volume-title":"Wilson","author":"Caralli Richard A.","year":"2007","unstructured":"Richard A. Caralli , James F. Stevens , Lisa R. Young , and William R . Wilson . 2007 . Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process. Technical Report. Software Engineering Institute, Carnegie Mellon University . Richard A. Caralli, James F. Stevens, Lisa R. Young, and William R. Wilson. 2007. Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process. Technical Report. Software Engineering Institute, Carnegie Mellon University."},{"key":"e_1_2_1_21_1","volume-title":"IT doesn\u2019t matter. Harv. Bus. Rev. May","author":"Carr Nicholas G.","year":"2003","unstructured":"Nicholas G. Carr . 2003. IT doesn\u2019t matter. Harv. Bus. Rev. May ( 2003 ), 5--12. Nicholas G. Carr. 2003. IT doesn\u2019t matter. Harv. Bus. Rev. May (2003), 5--12."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.26"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1070.0794"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1080\/10864415.2004.11044320"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1005817.1005828"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyw005"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-6451.2010.00435.x"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906)","author":"Collins Michael","year":"2006","unstructured":"Michael Collins , Carrie Gates , and Gaurav Kataria . 2006 . A model for opportunistic network exploits: The case of P2P worms . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906) . University of Cambridge, UK. Michael Collins, Carrie Gates, and Gaurav Kataria. 2006. A model for opportunistic network exploits: The case of P2P worms. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201906). University of Cambridge, UK."},{"key":"e_1_2_1_29_1","unstructured":"Robert F. Dacey. 2003. Progress made but challenges remain to protect federal systems and the nation\u2019s critical infrastructures. Testimony. (2003).  Robert F. Dacey. 2003. Progress made but challenges remain to protect federal systems and the nation\u2019s critical infrastructures. Testimony. (2003)."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.elerap.2010.06.001"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535818"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the USENIX Security Symposium.273--288","author":"Finifter Matthew","year":"2013","unstructured":"Matthew Finifter , Devdatta Akhawe , and David Wagner . 2013 . An empirical study of vulnerability rewards programs . In Proceedings of the USENIX Security Symposium.273--288 . Matthew Finifter, Devdatta Akhawe, and David Wagner. 2013. An empirical study of vulnerability rewards programs. In Proceedings of the USENIX Security Symposium.273--288."},{"key":"e_1_2_1_34_1","volume-title":"IT-Security and Privacy: Design and Use of Privacy-enhancing Security Mechanisms, Gerhard Goos, Juris Hartmanis, andJan van Leeuwen (Eds.),Lecture Notes in Computer Science","author":"Fischer-H\u00fcbner Simone","unstructured":"Simone Fischer-H\u00fcbner . 2001. IT-security . In IT-Security and Privacy: Design and Use of Privacy-enhancing Security Mechanisms, Gerhard Goos, Juris Hartmanis, andJan van Leeuwen (Eds.),Lecture Notes in Computer Science , Vol. 1958 . Springer , Berlin , 35--105. Simone Fischer-H\u00fcbner. 2001. IT-security. In IT-Security and Privacy: Design and Use of Privacy-enhancing Security Mechanisms, Gerhard Goos, Juris Hartmanis, andJan van Leeuwen (Eds.),Lecture Notes in Computer Science, Vol.1958. Springer, Berlin, 35--105."},{"key":"e_1_2_1_35_1","volume-title":"Economics of Information Security and Privacy","author":"Frei Stefan","unstructured":"Stefan Frei , Dominik Schatzmann , Bernhard Plattner , and Brian Trammell . 2010. Modeling the security ecosystem -- The dynamics of (in)security . In Economics of Information Security and Privacy , Tyler Moore, David Pym, andChristosIoannidis (Eds.). Springer , New York , 79--106. Stefan Frei, Dominik Schatzmann, Bernhard Plattner, and Brian Trammell. 2010. Modeling the security ecosystem -- The dynamics of (in)security. In Economics of Information Security and Privacy, Tyler Moore, David Pym, andChristosIoannidis (Eds.). Springer, New York, 79--106."},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the IMF 2007: IT-Incident Management 8 IT-Forensics, Sandra Frings, Oliver G\u00f6bel, Detlef G\u00fcnther, Hardo G","author":"Freiling Felix","unstructured":"Felix Freiling and Bastian Schwittay . 2007. A common process model for incident response and digital forensics . In Proceedings of the IMF 2007: IT-Incident Management 8 IT-Forensics, Sandra Frings, Oliver G\u00f6bel, Detlef G\u00fcnther, Hardo G . Hase, Jens Nedon, Dirk Schadt, andArslan Br\u00f6mme (Eds.), Lecture Notes in Informatics, Vol. 114 . Gesellschaft f\u00fcr Informatik, Stuttgart, Germany , 13--40. Felix Freiling and Bastian Schwittay. 2007. A common process model for incident response and digital forensics. In Proceedings of the IMF 2007: IT-Incident Management 8 IT-Forensics, Sandra Frings, Oliver G\u00f6bel, Detlef G\u00fcnther, Hardo G. Hase, Jens Nedon, Dirk Schadt, andArslan Br\u00f6mme (Eds.), Lecture Notes in Informatics, Vol.114. Gesellschaft f\u00fcr Informatik, Stuttgart, Germany, 13--40."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1050.0053"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-6296.2010.01178.x"},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916)","author":"Gay Sebastien","year":"2016","unstructured":"Sebastien Gay . 2016 . Strategic news bundling and privacy breach disclosures . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916) . Berkeley, CA. Sebastien Gay. 2016. Strategic news bundling and privacy breach disclosures. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916). Berkeley, CA."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/581271.581274"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jaccpubpol.2003.09.001"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jaccpubpol.2015.05.001"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/2017470.2017479"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/1971852.1971854"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jaccpubpol.2007.10.001"},{"key":"e_1_2_1_46_1","first-page":"245","article-title":"A strategic analysis of information sharing among cyber attackers","volume":"12","author":"Hausken Kjell","year":"2015","unstructured":"Kjell Hausken . 2015 . A strategic analysis of information sharing among cyber attackers . J. Inf. Syst. Technol. Manage. 12 , 2 (2015), 245 -- 270 . Kjell Hausken. 2015. A strategic analysis of information sharing among cyber attackers. J. Inf. Syst. Technol. Manage. 12, 2 (2015), 245--270.","journal-title":"J. Inf. Syst. Technol. Manage."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/44530.13.3.20040701\/83067.5"},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the International Workshop on the Economics of Securing the Information Infrastructure (WESII\u201906)","author":"Ishiguro Masaki","year":"2006","unstructured":"Masaki Ishiguro , Hideyuki Tanaka , Kanta Matsuura , and Ichiro Murase . 2006 . The effect of information security incidents on corporate values in the Japanese stock market . In Proceedings of the International Workshop on the Economics of Securing the Information Infrastructure (WESII\u201906) . Washington, DC. Masaki Ishiguro, Hideyuki Tanaka, Kanta Matsuura, and Ichiro Murase. 2006. The effect of information security incidents on corporate values in the Japanese stock market. In Proceedings of the International Workshop on the Economics of Securing the Information Infrastructure (WESII\u201906). Washington, DC."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3003147"},{"key":"e_1_2_1_50_1","first-page":"1293","article-title":"Research joint ventures and R&D cartels","volume":"82","author":"Kamien Morton I.","year":"1992","unstructured":"Morton I. Kamien , Eitan Muller , and Israel Zang . 1992 . Research joint ventures and R&D cartels . Am. Econ. Rev. 82 , 5 (1992), 1293 -- 1306 . Morton I. Kamien, Eitan Muller, and Israel Zang. 1992. Research joint ventures and R&D cartels. Am. Econ. Rev. 82, 5 (1992), 1293--1306.","journal-title":"Am. Econ. Rev."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.99"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.2753\/JEC1086-4415120103"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1040.0357"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251086.1251120"},{"key":"e_1_2_1_55_1","volume-title":"Decision and Game Theory for Security, Radha Poovendran andWalid Saad (Eds.),Lecture Notes in Computer Science","author":"Khouzani Arman M. H. R.","unstructured":"Arman M. H. R. Khouzani , Viet Pham , and Carlos Cid . 2014. Strategic discovery and sharing of vulnerabilities in competitive environments . In Decision and Game Theory for Security, Radha Poovendran andWalid Saad (Eds.),Lecture Notes in Computer Science , Vol. 8840 . Springer International Publishing , 59--78. Arman M. H. R. Khouzani, Viet Pham, and Carlos Cid. 2014. Strategic discovery and sharing of vulnerabilities in competitive environments. In Decision and Game Theory for Security, Radha Poovendran andWalid Saad (Eds.),Lecture Notes in Computer Science, Vol.8840. Springer International Publishing, 59--78."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.2307\/2555403"},{"key":"e_1_2_1_57_1","first-page":"13","article-title":"The impact of information security breaches on financial performance of the breached firms: An empirical investigation","volume":"17","author":"Ko Myung","year":"2006","unstructured":"Myung Ko and Carlos Dorantes . 2006 . The impact of information security breaches on financial performance of the breached firms: An empirical investigation . J. Inf. Technol. Manage. 17 , 2 (2006), 13 -- 22 . Myung Ko and Carlos Dorantes. 2006. The impact of information security breaches on financial performance of the breached firms: An empirical investigation. J. Inf. Technol. Manage. 17, 2 (2006), 13--22.","journal-title":"J. Inf. Technol. Manage."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-27937-9_5"},{"key":"e_1_2_1_59_1","unstructured":"Olaf Kruidhof. 2014. Evolution of national and corporate CERTs\u2014Trust the key factor. In Best Practices in Computer Network Defense: Incident Detection and Response Melissa E. Hathaway (Ed.).81--96.  Olaf Kruidhof. 2014. Evolution of national and corporate CERTs\u2014Trust the key factor. In Best Practices in Computer Network Defense: Incident Detection and Response Melissa E. Hathaway (Ed.).81--96."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1024119208153"},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201915)","author":"Kwon Juhee","unstructured":"Juhee Kwon and M. Eric Johnson . 2015. The market effect of healthcare security: Do patients care about data breaches? In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201915) . Juhee Kwon and M. Eric Johnson. 2015. The market effect of healthcare security: Do patients care about data breaches? In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201915)."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/185403.185412"},{"key":"e_1_2_1_63_1","volume-title":"The Communication of Ideas: A Series of Addresses","author":"Lasswell Harold D.","unstructured":"Harold D. Lasswell . 1948. The structure and function of communication in society . In The Communication of Ideas: A Series of Addresses , Lyman Bryson (Ed.). Harper and Brothers , New York , 37--51. Harold D. Lasswell. 1948. The structure and function of communication in society. In The Communication of Ideas: A Series of Addresses, Lyman Bryson (Ed.). Harper and Brothers, New York, 37--51."},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635673"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808132"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyw002"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-007-9047-2"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2011.05.007"},{"key":"e_1_2_1_69_1","first-page":"13","article-title":"Event studies in economics and finance","volume":"35","author":"MacKinlay A. Craig","year":"1997","unstructured":"A. Craig MacKinlay . 1997 . Event studies in economics and finance . J. Econ. Lit. 35 , 1 (1997), 13 -- 39 . A. Craig MacKinlay. 1997. Event studies in economics and finance. J. Econ. Lit. 35, 1 (1997), 13--39.","journal-title":"J. Econ. Lit."},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1140\/epjb\/e2010-00120-8"},{"key":"e_1_2_1_71_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916)","author":"Maillart Thomas","year":"2016","unstructured":"Thomas Maillart , Mingyi Zhao , Jens Grossklags , and John Chuang . 2016 . Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916) . Berkeley, CA. Thomas Maillart, Mingyi Zhao, Jens Grossklags, and John Chuang. 2016. Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201916). Berkeley, CA."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785733"},{"key":"e_1_2_1_73_1","doi-asserted-by":"crossref","unstructured":"Leigh Metcalf and Jonathan M. Spring. 2014. Blacklist Ecosystem Analysis Update: 2014. Technical Report. Carnegie Mellon University.  Leigh Metcalf and Jonathan M. Spring. 2014. Blacklist Ecosystem Analysis Update: 2014. Technical Report. Carnegie Mellon University.","DOI":"10.1145\/2808128.2808129"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2015.0587"},{"key":"e_1_2_1_75_1","volume-title":"Proceedings of the European Conference on Information Systems (ECIS\u201999)","author":"Daniel","unstructured":"Daniel L. Moody and Peter Walsh. 1999. Measuring the value of information -- An asset valuation approach . In Proceedings of the European Conference on Information Systems (ECIS\u201999) . Daniel L. Moody and Peter Walsh. 1999. Measuring the value of information -- An asset valuation approach. In Proceedings of the European Conference on Information Systems (ECIS\u201999)."},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ECRIME.2008.4696968"},{"key":"e_1_2_1_77_1","first-page":"45","article-title":"The impact of public information on phishing attack and defense","volume":"1","author":"Moore Tyler","year":"2011","unstructured":"Tyler Moore and Richard Clayton . 2011 . The impact of public information on phishing attack and defense . Commun. Strat. 1 , 81 (2011), 45 -- 68 . Tyler Moore and Richard Clayton. 2011. The impact of public information on phishing attack and defense. Commun. Strat. 1, 81 (2011), 45--68.","journal-title":"Commun. Strat."},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/1900546.1900559"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/1047671.1047674"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITA.2016.7888179"},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infoecopol.2006.10.001"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1287\/ijoc.1070.0222"},{"key":"e_1_2_1_87_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201905)","author":"\u00d6\u011f\u00fct Hulisi","year":"2005","unstructured":"Hulisi \u00d6\u011f\u00fct , Nirup Memon , and Srinivasan Raghunathan . 2005 . Cyber insurance and IT security investment: Impact of interdependent risk . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201905) . Hulisi \u00d6\u011f\u00fct, Nirup Memon, and Srinivasan Raghunathan. 2005. Cyber insurance and IT security investment: Impact of interdependent risk. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201905)."},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314257.1314261"},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the USENIX Security Symposium.93--104","author":"Ozment Andy","unstructured":"Andy Ozment and Stuart E. Schechter . 2006. Milk or wine: Does software security improve with age? In Proceedings of the USENIX Security Symposium.93--104 . Andy Ozment and Stuart E. Schechter. 2006. Milk or wine: Does software security improve with age? In Proceedings of the USENIX Security Symposium.93--104."},{"key":"e_1_2_1_90_1","volume-title":"Economics of Information Security and Privacy III","author":"Ransbotham Sam","unstructured":"Sam Ransbotham and Sabyasachi Mitra . 2013. The impact of immediate disclosure on attack diffusion and volume . In Economics of Information Security and Privacy III , Bruce Schneier (Ed.). Springer , New York , 1--12. Sam Ransbotham and Sabyasachi Mitra. 2013. The impact of immediate disclosure on attack diffusion and volume. In Economics of Information Security and Privacy III, Bruce Schneier (Ed.). Springer, New York, 1--12."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.5555\/2208955.2208959"},{"key":"e_1_2_1_92_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Rescorla Eric","year":"2003","unstructured":"Eric Rescorla . 2003 . Security holes ...who cares? In Proceedings of the USENIX Security Symposium. Eric Rescorla. 2003. Security holes ...who cares? In Proceedings of the USENIX Security Symposium."},{"key":"e_1_2_1_93_1","first-page":"121","article-title":"Examining the costs and causes of cyber incidents","volume":"2","author":"Romanosky Sasha","year":"2016","unstructured":"Sasha Romanosky . 2016 . Examining the costs and causes of cyber incidents . J. Cybersecur. 2 , 2 (2016), 121 -- 135 . Sasha Romanosky. 2016. Examining the costs and causes of cyber incidents. J. Cybersecur. 2, 2 (2016), 121--135.","journal-title":"J. Cybersecur."},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1111\/jels.12035"},{"key":"e_1_2_1_95_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201910)","author":"Romanosky Sasha","year":"2010","unstructured":"Sasha Romanosky , Richard Sharp , and Alessandro Acquisti . 2010 . Data breaches and identity theft: When is mandatory disclosure optimal? In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201910) . Sasha Romanosky, Richard Sharp, and Alessandro Acquisti. 2010. Data breaches and identity theft: When is mandatory disclosure optimal? In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201910)."},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1002\/pam.20567"},{"key":"e_1_2_1_98_1","unstructured":"Bruce Schneier. 2000. Secret 8 Lies: Digital Security in a Networked World. John Wilesy 8 Sons 318--333.   Bruce Schneier. 2000. Secret 8 Lies: Digital Security in a Networked World. John Wilesy 8 Sons 318--333."},{"key":"e_1_2_1_99_1","volume-title":"Proceedings of the International Conference on Software Engineering (ICSE\u201912)","author":"Shahzad Muhammad","unstructured":"Muhammad Shahzad , Muhammad Z. Shafiq , and Alex X. Liu . 2012. A large scale exploratory analysis of software vulnerability life cycles . In Proceedings of the International Conference on Software Engineering (ICSE\u201912) . 771--781. Muhammad Shahzad, Muhammad Z. Shafiq, and Alex X. Liu. 2012. A large scale exploratory analysis of software vulnerability life cycles. In Proceedings of the International Conference on Software Engineering (ICSE\u201912). 771--781."},{"key":"e_1_2_1_100_1","volume-title":"Varian","author":"Shapiro Carl","year":"1998","unstructured":"Carl Shapiro and Hal R . Varian . 1998 . Information Rules : A Strategic Guide to the Network Economy. Harvard Business Review Press . Carl Shapiro and Hal R. Varian. 1998. Information Rules: A Strategic Guide to the Network Economy. Harvard Business Review Press."},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.04.003"},{"key":"e_1_2_1_102_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security (WEIS\u201913)","author":"Tang Qian","unstructured":"Qian Tang , Leigh Linden , John S. Quarterman , and Andrew B. Whinston . 2013. Improving Internet security through social information and social comparison: A field quasi-experiment . In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201913) . Qian Tang, Leigh Linden, John S. Quarterman, and Andrew B. Whinston. 2013. Improving Internet security through social information and social comparison: A field quasi-experiment. In Proceedings of the Workshop on the Economics of Information Security (WEIS\u201913)."},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.70712"},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39959-3"},{"key":"e_1_2_1_105_1","volume-title":"Economics of Information Security","author":"Varian Hal R.","unstructured":"Hal R. Varian . 2002. System reliability and free riding . In Economics of Information Security , L. Jean Camp and Stephen Lewis (Eds.), Advances in Information Security, Vol. 12 . Springer , New York, 1--15. Hal R. Varian. 2002. System reliability and free riding. In Economics of Information Security, L. Jean Camp and Stephen Lewis (Eds.), Advances in Information Security, Vol. 12. Springer, New York, 1--15."},{"key":"e_1_2_1_106_1","volume-title":"Proceedings of the Workshop on Cyber Secrurity Experimentation and Test (CSET\u201912)","author":"Vasek Marie","year":"2012","unstructured":"Marie Vasek and Tyler Moore . 2012 . Do malware reports expedite cleanup? An experimental study . In Proceedings of the Workshop on Cyber Secrurity Experimentation and Test (CSET\u201912) . Marie Vasek and Tyler Moore. 2012. Do malware reports expedite cleanup? An experimental study. In Proceedings of the Workshop on Cyber Secrurity Experimentation and Test (CSET\u201912)."},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994539.2994548"},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1145\/2716260"},{"key":"e_1_2_1_109_1","volume-title":"Theory of Games and Economic Behavior","author":"von Neumann John","unstructured":"John von Neumann and Oskar Morgenstern . 1944. Theory of Games and Economic Behavior . Princeton University Press . John von Neumann and Oskar Morgenstern. 1944. Theory of Games and Economic Behavior. Princeton University Press."},{"key":"e_1_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994539.2994542"},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1120.0437"},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813704"},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586130"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3124398","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3124398","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:11:22Z","timestamp":1750212682000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3124398"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11,13]]},"references-count":106,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2018,9,30]]}},"alternative-id":["10.1145\/3124398"],"URL":"https:\/\/doi.org\/10.1145\/3124398","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,11,13]]},"assertion":[{"value":"2017-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2017-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2017-11-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}