A system dynamics approach for cost-benefit simulation in designing policies to enhance the cybersecurity resilience of small and medium-sized enterprises
{"title":"A system dynamics approach for cost-benefit simulation in designing policies to enhance the cybersecurity resilience of small and medium-sized enterprises","authors":"Jihwon Song, Min Jae Park","doi":"10.1177/02666669241252996","DOIUrl":null,"url":null,"abstract":"The small and medium-sized enterprises (SMEs) with limited investment capacity are likely to be lax in enhancing their cybersecurity. Therefore, to strengthen cybersecurity at a national level, governments must intervene in the market by using support or regulatory policies to overcome market failures and address weaknesses. This study reviewed the efficiency of policy options to improve corporate cybersecurity resilience for SMEs that require government support, unlike large companies that can invest in security on their own. To achieve this, a causal loop diagram was created and analyzed from the perspective of system dynamics. The model incorporated government support variables and the decline in capabilities over time into the existing corporate security investment model reflecting the standard framework for cybersecurity from NIST. The simulation scenarios were constructed based on policy options considered by the Korean government. These include 1) pre-incident or post incident support services, and 2) management through tax credits and regulation. The results indicated that incentives, specifically tax credits, rather than regulation, were more effective in strengthening cyber resilience. This study describes the investment and internal capability development of a company affected by government policy, which is an external factor, and changes in profits can be observed by adding the company's profits and costs as variables. This profit variable allows for the comparison of a company's cyber resilience across scenarios. Additionally, if the government provides direct support immediately after a hacking incident, the company can recover more quickly. If these benefits are known and if the reporting of hacking damage is activated, cyber threat visibility will be secured by revealing hacking attacks that have been secretly conducted. Governments can use cyber threat visibility to strengthen national cybersecurity.","PeriodicalId":2,"journal":{"name":"ACS Applied Bio Materials","volume":null,"pages":null},"PeriodicalIF":4.6000,"publicationDate":"2024-05-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACS Applied Bio Materials","FirstCategoryId":"91","ListUrlMain":"https://doi.org/10.1177/02666669241252996","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"MATERIALS SCIENCE, BIOMATERIALS","Score":null,"Total":0}
引用次数: 0
Abstract
The small and medium-sized enterprises (SMEs) with limited investment capacity are likely to be lax in enhancing their cybersecurity. Therefore, to strengthen cybersecurity at a national level, governments must intervene in the market by using support or regulatory policies to overcome market failures and address weaknesses. This study reviewed the efficiency of policy options to improve corporate cybersecurity resilience for SMEs that require government support, unlike large companies that can invest in security on their own. To achieve this, a causal loop diagram was created and analyzed from the perspective of system dynamics. The model incorporated government support variables and the decline in capabilities over time into the existing corporate security investment model reflecting the standard framework for cybersecurity from NIST. The simulation scenarios were constructed based on policy options considered by the Korean government. These include 1) pre-incident or post incident support services, and 2) management through tax credits and regulation. The results indicated that incentives, specifically tax credits, rather than regulation, were more effective in strengthening cyber resilience. This study describes the investment and internal capability development of a company affected by government policy, which is an external factor, and changes in profits can be observed by adding the company's profits and costs as variables. This profit variable allows for the comparison of a company's cyber resilience across scenarios. Additionally, if the government provides direct support immediately after a hacking incident, the company can recover more quickly. If these benefits are known and if the reporting of hacking damage is activated, cyber threat visibility will be secured by revealing hacking attacks that have been secretly conducted. Governments can use cyber threat visibility to strengthen national cybersecurity.