{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,14]],"date-time":"2025-10-14T00:51:20Z","timestamp":1760403080426,"version":"build-2065373602"},"reference-count":27,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:00:00Z","timestamp":1760313600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["IIS-2040800"],"award-info":[{"award-number":["IIS-2040800"]}]},{"name":"ARO","award":["W911NF1810208"],"award-info":[{"award-number":["W911NF1810208"]}]},{"name":"Ministry of Innovation and Technology from the National Research, Development, and Innovation Fund","award":["138903"],"award-info":[{"award-number":["138903"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>Misaligned incentives in secure software development have long been a challenge in security economics. Product liability, a powerful legal framework in other industries, has been largely ineffective for software products until recent times. However, the rapid regulatory responses to recent global cyber attacks by both the US and EU, together with the (relative) success of the General Data Protection Regulation in defining both duty and standard of care for software vendors, may enable regulators to use liability to re-align incentives for the benefit of the digital society. The United States National Cybersecurity Strategy suggests shifting responsibility for cyber incidents back to software vendors and proposes the concept of the liability waiver: if a software company voluntarily undergoes and passes an IT security audit, its future product liability is (fully or partially) waived.<\/jats:p>\n          <jats:p>This article examines this audit-liability framework from both vendor and auditor perspectives. For vendors, we model the decision process as a sequential problem: a vendor must pass an audit to release a product and can attempt the audit multiple times. We show that the optimal strategy for an opt-in vendor is to never quit and to exert cumulative investments in either a \u201cone-and-done\u201d or \u201cincremental\u201d manner. For auditors, we explore how to design audits that encourage voluntary participation while maximizing vendor effort. We further investigate dynamic audit designs that can amplify vendors\u2019 cumulative investments in security. Our findings provide insights into how liability waivers and audit strategies can re-align incentives, fostering a more secure digital ecosystem.<\/jats:p>\n          <jats:p\/>","DOI":"10.1145\/3765287","type":"journal-article","created":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T11:14:26Z","timestamp":1756552466000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Incentivizing Secure Software Development: The Role of Voluntary Audit and Liability Waiver"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8939-6456","authenticated-orcid":false,"given":"Ziyuan","family":"Huang","sequence":"first","affiliation":[{"name":"Electrical and Computer Engineering, University of Michigan-Ann Arbor","place":["Ann Arbor, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3891-3855","authenticated-orcid":false,"given":"Gergely","family":"Bicz\u00f3k","sequence":"additional","affiliation":[{"name":"Laboratory of Cryptography and System Security, Budapest University of Technology and Economics","place":["Budapest, Hungary"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3295-9200","authenticated-orcid":false,"given":"Mingyan","family":"Liu","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering, University of Michigan-Ann Arbor","place":["Ann Arbor, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"e_1_3_7_2_2","unstructured":"Donoghue v Stevenson. (n.d.). Retrieved from https:\/\/www.bailii.org\/uk\/cases\/UKHL\/1932\/100.html"},{"key":"e_1_3_7_3_2","unstructured":"MacPherson v Buick Motor Co. (n.d.). Retrieved from https:\/\/casetext.com\/case\/macpherson-v-buick-motor-co-2"},{"key":"e_1_3_7_4_2","unstructured":"United States v. Carroll Towing Co. (n.d.). Retrieved from https:\/\/casetext.com\/case\/united-states-v-carroll-towing-co-2\/"},{"key":"e_1_3_7_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2001.991552"},{"key":"e_1_3_7_6_2","doi-asserted-by":"publisher","unstructured":"Fouad Ben abdelaziz Souhir Neifar and Marc de Bourmont. 2015. Auditing and game theory: A survey. Multiple Criteria Decision Making in Finance Insurance and Investment (2015) 249\u2013272. DOI:10.1007\/978-3-319-21158-9","DOI":"10.1007\/978-3-319-21158-9"},{"key":"e_1_3_7_7_2","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"Bicz\u00f3k Gergely","year":"2025","unstructured":"Gergely Bicz\u00f3k, Sasha Romanosky, and Mingyan Liu. 2025. Realigning incentives to build better software: A holistic approach to vendor accountability. In Workshop on the Economics of Information Security (WEIS). (preprint on arXiv arXiv:2504.07766)."},{"key":"e_1_3_7_8_2","volume-title":"Workshop on the Economics of Information Security","author":"B\u00f6hme Rainer","year":"2010","unstructured":"Rainer B\u00f6hme and Galina Schwartz. 2010. Modeling cyber-insurance: Towards a unifying framework. In Workshop on the Economics of Information Security. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:14172008"},{"issue":"4","key":"e_1_3_7_9_2","first-page":"337","article-title":"Should the government provide insurance for catastrophes","volume":"88","author":"Cummins J. David","year":"2006","unstructured":"J. David Cummins et\u00a0al. 2006. Should the government provide insurance for catastrophes. Federal Reserve Bank of St. Louis Review 88, 4 (2006), 337\u2013379.","journal-title":"Federal Reserve Bank of St. Louis Review"},{"key":"e_1_3_7_10_2","doi-asserted-by":"publisher","DOI":"10.4230\/DagRep.11.10.36"},{"key":"e_1_3_7_11_2","article-title":"Standards for software liability: Focus on the product for liability, focus on the process for safe harbor","author":"Dempsey Jim","year":"2024","unstructured":"Jim Dempsey. 2024. Standards for software liability: Focus on the product for liability, focus on the process for safe harbor. Retrieved from https:\/\/www.lawfaremedia.org\/article\/standards-for-software-liability-focus-on-the-product-for-liability-focus-on-the-process-for-safe-harbor. Lawfare (January2024).","journal-title":"https:\/\/www.lawfaremedia.org\/article\/standards-for-software-liability-focus-on-the-product-for-liability-focus-on-the-process-for-safe-harbor"},{"key":"e_1_3_7_12_2","unstructured":"European Commission Directorate-General for Communications Networks Content and Technology. Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019\/1020. (n.d.). Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex:52022PC0454"},{"key":"e_1_3_7_13_2","unstructured":"European Commission Directorate-General for Internal Market Industry Entrepreneurship and SMEs. Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on liability for defective products. (n.d.). Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:52022PC0495"},{"key":"e_1_3_7_14_2","unstructured":"European Parliament and Council of the European Union. Regulation (EU) 2019\/881 of the European Parliament and of the Council (Cybersecurity Act). (n.d.). Retrieved from http:\/\/data.europa.eu\/eli\/reg\/2019\/881\/oj"},{"key":"e_1_3_7_15_2","unstructured":"European Parliament and Council of the European Union. Regulation (EU) 2016\/679 of the European Parliament and of the Council (General Data Protection Regulation). (n. d.). Retrieved from https:\/\/data.europa.eu\/eli\/reg\/2016\/679\/oj"},{"issue":"4","key":"e_1_3_7_16_2","first-page":"634","article-title":"Strategic Considerations in Auditing","volume":"60","author":"Fellingham John C.","year":"1985","unstructured":"John C. Fellingham and D. Paul Newman. 1985. Strategic Considerations in Auditing. The Accounting Review 60, 4 (1985), 634\u2013650. Retrieved fromhttp:\/\/www.jstor.org\/stable\/247459","journal-title":"The Accounting Review"},{"key":"e_1_3_7_17_2","doi-asserted-by":"publisher","DOI":"10.1111\/j.1911-3846.1994.tb00438.x"},{"key":"e_1_3_7_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-8714-3"},{"key":"e_1_3_7_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/CDC56724.2024.10885875"},{"key":"e_1_3_7_20_2","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyz010"},{"key":"e_1_3_7_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2812205"},{"key":"e_1_3_7_22_2","volume-title":"Embracing Risk Cyber Insurance as an Incentive Mechanism for Cybersecurity","author":"Liu Mingyan","year":"2022","unstructured":"Mingyan Liu. 2022. Embracing Risk Cyber Insurance as an Incentive Mechanism for Cybersecurity. Springer."},{"issue":"4","key":"e_1_3_7_23_2","first-page":"753","article-title":"Fraud detection: A theoretical foundation","volume":"67","author":"Matsumura Ella Mae","year":"1992","unstructured":"Ella Mae Matsumura and Robert R. Tucker. 1992. Fraud detection: A theoretical foundation. The Accounting Review 67, 4 (1992), 753\u2013782. Retrieved fromhttp:\/\/www.jstor.org\/stable\/248323","journal-title":"The Accounting Review"},{"key":"e_1_3_7_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2010.10.002"},{"key":"e_1_3_7_25_2","unstructured":"Parinaz Naghizadeh and Mingyan Liu. 2014. Voluntary participation in cyber-insurance markets. In Proceedings of the 2014 Annual Workshop on Economics in Information Security (WEIS\u201914). June 23-24 2014 State College Pennsylvania."},{"key":"e_1_3_7_26_2","doi-asserted-by":"publisher","DOI":"10.58812\/wsaf.v1i02.119"},{"key":"e_1_3_7_27_2","unstructured":"Wes Sonnenreich Jason Albanese and Bruce Stout. 2006. Return on security investment (ROSI) - A practical quantitative model. Journal of Research and Practice in Information Technology 38 1 (Feb. 2006) 45\u201356."},{"key":"e_1_3_7_28_2","article-title":"National Cybersecurity Strategy","author":"Washington The White House,","year":"2023","unstructured":"The White House, Washington. 2023. National Cybersecurity Strategy. Government Document. (2023). Retrieved from https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2023\/03\/National-Cybersecurity-Strategy-2023.pdf","journal-title":"Government Document"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3765287","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3765287","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T14:32:29Z","timestamp":1760365949000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3765287"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":27,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3765287"],"URL":"https:\/\/doi.org\/10.1145\/3765287","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-01-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-07-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}