Bilateral liability-based contracts in information security outsourcing

Kai Lung Hui, Ping Fan Ke, Yuxi Yao, Wei T. Yue

Research output: Contribution to journalJournal Articlepeer-review

30 Citations (Scopus)

Abstract

We study the efficiency of bilateral liability-based contracts in managed security services (MSSs). We model MSS as a collaborative service with the protection quality shaped by the contribution of both the service provider and the client. We adopt the negligence concept from the legal profession to design two novel contracts: thresholdbased liability contract and variable liability contract. We find that they can achieve the first best outcome when postbreach effort verification is feasible. More importantly, they are more efficient than a multilateral contract when the MSS provider assumes limited liability. Our results show that bilateral liability-based contracts can work in the real world. Hence, more research is needed to explore their properties. We discuss the related implications.

Original languageEnglish
Pages (from-to)411-429
Number of pages19
JournalInformation Systems Research
Volume30
Issue number2
DOIs
Publication statusPublished - 2019

Bibliographical note

Publisher Copyright:
© 2019 INFORMS.

Keywords

  • Auditing error
  • Liability-based contracts
  • Limited liability
  • Managed security service
  • Negligence

Fingerprint

Dive into the research topics of 'Bilateral liability-based contracts in information security outsourcing'. Together they form a unique fingerprint.

Cite this