Cyber warranties: market fix or marketing trick?

The market for information security products is plagued by information asymmetry, dysfunctional brand reputation and principal-agent problems. Mechanisms to address the resulting market for lemons include certification schemes, liability laws, and information disclosure. Unfortunately there has been...

Full description

Bibliographic Details
Main Authors: Woods, D, Moore, T
Format: Journal article
Language:English
Published: Association for Computing Machinery 2020
Description
Summary:The market for information security products is plagued by information asymmetry, dysfunctional brand reputation and principal-agent problems. Mechanisms to address the resulting market for lemons include certification schemes, liability laws, and information disclosure. Unfortunately there has been limited success thus far. An emerging form of risk transfer, cyber warranties, could address the market failure. We analyse 15 warranties to identify what is covered and what is excluded. The results suggest cyber warranties do not transfer much risk at present. However, they do force transparency regarding the limitations of information security products.