{"title":"Investing in security-as-a-service for e-commerce infrastructure by small and medium enterprises: a Monte Carlo approach","authors":"D. Nazareth, Jae Choi, Thomas L. Ngo-Ye","doi":"10.1108/jsit-04-2023-0071","DOIUrl":null,"url":null,"abstract":"Purpose\nThis paper aims to examine the conditions under which small and medium enterprises (SMEs) invest in security services when they migrate their e-commerce applications to the cloud environment. Using a risk management perspective, the paper assesses the impact of security service pricing, security incident prevalence and virulence to estimate SME security spending at the market level and draw out implications for SMEs and security service providers.\n\nDesign/methodology/approach\nSecurity risks are inherently characterized by uncertainty. This study uses a Monte Carlo approach to understand the role of uncertainty in the decision to adopt security services. A model relating key security constructs is assembled based on key constructs from the domain. By manipulating security service costs and security incident types, the model estimates the market-level adoption of services, security incidents and damages incurred, along with measures of their relative dispersion.\n\nFindings\nThree key findings emerge from this study. First, adoption of services and protection is higher when tiered security services are provided, indicating that SMEs prefer to choose their security services rather than accept uniformly priced products. Second, SMEs are considered price-sensitive, resulting in a maximum level of spending in the market. Third, results indicate that security incidents and damages can be much higher than the mean in some cases, and this should serve as a cautionary note to SMEs.\n\nOriginality/value\nSecurity spending has been modeled at the firm level. Adopting a market-level perspective represents a novel contribution. Additionally, the Monte Carlo approach provides managers with tangible measures of uncertainty, affording additional information and insight when making security service adoption decisions.\n","PeriodicalId":38615,"journal":{"name":"Journal of Systems and Information Technology","volume":"91 4","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-04-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Systems and Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1108/jsit-04-2023-0071","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 0
Abstract
Purpose
This paper aims to examine the conditions under which small and medium enterprises (SMEs) invest in security services when they migrate their e-commerce applications to the cloud environment. Using a risk management perspective, the paper assesses the impact of security service pricing, security incident prevalence and virulence to estimate SME security spending at the market level and draw out implications for SMEs and security service providers.
Design/methodology/approach
Security risks are inherently characterized by uncertainty. This study uses a Monte Carlo approach to understand the role of uncertainty in the decision to adopt security services. A model relating key security constructs is assembled based on key constructs from the domain. By manipulating security service costs and security incident types, the model estimates the market-level adoption of services, security incidents and damages incurred, along with measures of their relative dispersion.
Findings
Three key findings emerge from this study. First, adoption of services and protection is higher when tiered security services are provided, indicating that SMEs prefer to choose their security services rather than accept uniformly priced products. Second, SMEs are considered price-sensitive, resulting in a maximum level of spending in the market. Third, results indicate that security incidents and damages can be much higher than the mean in some cases, and this should serve as a cautionary note to SMEs.
Originality/value
Security spending has been modeled at the firm level. Adopting a market-level perspective represents a novel contribution. Additionally, the Monte Carlo approach provides managers with tangible measures of uncertainty, affording additional information and insight when making security service adoption decisions.
期刊介绍:
The Journal provides an avenue for scholarly work that researches systems thinking applications, information systems, electronic business, data analytics, information sciences, information management, business intelligence, and complex adaptive systems in the application domains of the business environment, health, the built environment, cultural settings, and the natural environment. Papers examine the wider implications of the systems or technology being researched. This means papers consider aspects such as social and organisational relevance, business value, cognitive implications, social implications, impact on individuals or community perspectives, and the development of solutions, rather than focusing solely on the technology. The Journal of Systems and Information Technology is open to a wide range of research methodologies and paper styles including case studies, surveys, experiments, review papers, design science, design thinking and both theoretical and methodological papers. The focus of the journal will be to publish work that fits into the following broad areas of research: Behavioural Information Systems and Human-Computer Interaction, Data Analytics, Data, Information and Security, E-Business, Intelligent Systems and Applications, Logistics and Supply Chain Management/Optimisation, Social Media Analysis, Technology Enhanced Learning.