Economics of Cyber Risk

The application of economic reasoning — incentives, externalities, investment under diminishing returns, and general-equilibrium feedback — to information security. The field’s founding claim (Anderson 2001) is that insecurity is at least as much a product of perverse incentives as of technical failure; its canonical investment model (Gordon–Loeb 2002) bounds rational security spending at a small fraction of expected loss; its current macro frontier (Baksy–Caratelli 2026) treats cyber risk as an aggregate drag measurable in GDP points. This page is the wiki’s bridge between the security cluster and the economics cluster.

Foundations: perverse incentives (Anderson 2001)

Ross Anderson’s “Why Information Security is Hard — An Economic Perspective” (ACSAC 2001) opened the economics-of-security field by arguing that the language of microeconomics — network externalities, asymmetric information, moral hazard, adverse selection, liability dumping, tragedy of the commons — explains security failure better than purely technical accounts. His canonical example: when US banks bore liability for disputed ATM transactions they protected their systems properly (spending less than European banks, but effectively); in Britain, Norway, and the Netherlands, where the burden of proof fell on the customer, banks grew careless and fraud epidemics followed. The general principle: when the party positioned to protect a system is not the party that suffers its failure, expect insecurity.1

Anderson extends this to market structure. Strong positive feedback in IT markets makes first-mover advantage enormous, so “ship it on Tuesday and get it right by version 3” is rational vendor behavior, not moral failure; support and security-administration costs get dumped on users because platforms compete for developers, not end users. Asymmetric information produces a market for lemons — buyers can’t evaluate security quality, so bad products drive out good — and evaluation regimes matter: the Orange Book worked because evaluations were paid for by the relying party (the government), while ITSEC/Common Criteria introduced the perverse innovation of vendors paying their own evaluators. In a post-9/11 postscript he notes the structural asymmetry that black hats can attack anywhere while white hats must defend everywhere, and draws the piracy-suppression analogy: suppressing an economically motivated global threat took treaties, naval action, and over a century.2

The Gordon–Loeb investment model (2002) and its externality extension

Gordon and Loeb’s “The Economics of Information Security Investment” (ACM TISSEC 2002) is the canonical model of how much a firm should spend on security. A risk-neutral firm faces vulnerability v (probability of breach absent investment), potential loss L, and chooses investment z; the security breach function S(z,v) gives the post-investment breach probability under regularity conditions (S(z,0)=0, S(0,v)=v, decreasing and strictly convex in z — diminishing returns — and approaching zero as z grows). The firm maximizes [v − S(z,v)]L − z, setting the marginal reduction in expected loss equal to marginal cost. For two broad functional classes the optimal investment never exceeds (1/e) ≈ 36.79% of expected loss vL — and is typically much less. A second result: firms should not necessarily concentrate on their most vulnerable information sets, since extremely vulnerable assets can be inordinately expensive to protect; midrange vulnerabilities often dominate.3

The 1/e rule survived a serious challenge. Willemson (2006) constructed breach functions satisfying all Gordon–Loeb assumptions whose optima approach 50% of expected loss, and showed that relaxing differentiability admits optima arbitrarily close to 100%. Lelarge (2012) and Baryshnikov (2012) resurrected the rule by strengthening convexity to log-convexity, under which z* ≤ vL/e holds in full generality.4

Gordon, Loeb, Lucyshyn and Zhou (2015) extended the model to externalities — breach costs borne by others (botnet DDoS launching pads, customer disruption) that lawsuits can’t fully internalize. With γ = externality/private loss ratio, the social optimum becomes z_SC < (1/e)(1+γ)vL_P: private firms systematically underinvest, and the gap widens with γ. In their worked example (v=0.64, private loss 60k), externality costs equal to 100% of private loss raise the social optimum to $126k — a 52% underinvestment; even 5% externality costs imply ~6% underinvestment. This is the formal bridge from firm-level cost-benefit to the policy case for minimum-requirement regulation.5

The macro layer: cyber risk in general equilibrium (Baksy–Caratelli 2026)

Baksy and Caratelli’s “The Economic Costs of Cyber Risk” (September 2026 working paper) is the first dynamic general-equilibrium treatment: heterogeneous firms invest in cybersecurity, attackers strategically choose targets and intensity, and a search-and-matching process (Diamond–Mortensen–Pissarides, with attackers as vacancy-posters and firms as unwilling match-seekers) governs contact, layered on Hopenhayn-style entry/exit. Successful attacks reduce firm output and — the key macro twist — aggregate productivity declines in the economy-wide share of firms under attack: an inverted Romer spillover propagating through supply chains, payment systems, and shared software dependencies.6

The paper’s organizing empirical fact is a steep size gradient in defense: using Revelio Labs LinkedIn data (~90M worker profiles/year over 25 years, 290k+ cybersecurity job spells across ~8M firms), the cybersecurity employment share rises rapidly with firm size (pronounced above 10,000 employees since the late 2010s), with a semi-elasticity of roughly one percentage point per doubling of firm size, robust to industry and firm fixed effects. Combined with attackers’ capacity constraints and financial-gain motivation, this generates the paper’s central result — inverse-U (hump-shaped) attack incidence: small firms are unattractive targets, large firms are heavily defended, and mid-sized firms are simultaneously a meaningful prize and a tractable target. Breach data corroborate: mid-record breaches (1,000–10,000 records) rose from 6.3% to ~34% of US attacks over two decades, and VERIS shows firms with 101–1,000 employees going from ~16% to ~36% of reported incidents (2010–2022).7

Calibrated to the US economy, introducing cyber risk (relative to a no-cyber-risk counterfactual) reduces firm entry by 3.6%, aggregate productivity by 0.6%, output by 1.8%, and consumption by 1.7% — losses arising from general-equilibrium adjustments in entry, firm-size distribution, and spillovers that partial-equilibrium analyses miss; the macro cost substantially exceeds measured direct firm-level losses. Policy experiments diverge sharply. Minimum cybersecurity requirements are the most robust instrument: a homogeneous floor of just 0.2% of labor raises the aggregate cybersecurity labor share 65% and output 0.14%, because it binds on underprotected small and mid-sized firms while leaving heavy investors unconstrained (progressive requirements backfire — large firms are already protected, so forcing them higher just misallocates labor). Subsidies help up to a point (75% coverage is output-maximizing in the benchmark) but their effectiveness is state-dependent: when risk rises through attack capacity (their proxy for AI-empowered attackers) subsidies disproportionately flow to large firms and turn fiscally corrosive, while risk rising through matching efficiency (digitalization) leaves subsidies effective to 90% coverage. Bailouts monotonically reduce output — moral hazard weakens investment, attack incidence rises, the externality strengthens, and entry falls. Cyber risk is most damaging when it expands the set of exposed firms rather than intensifying attacks on the already-exposed.8

Empirical loss data: U-shaped loss rates across banks (Dallas Fed 2025)

Murphy, Tindall, Klemme, Suek and Dunbar (Dallas Fed Working Paper 2520, May 2025) model average annual loss (AAL) rates from attritional cyber events at 3,622 US banks, using CyberCube scenario-simulation loss estimates crossed with standard bank performance data. Mean AAL is 1.19 basis points of revenue (LISCC megabanks 1.93 bps). The headline finding: loss rates are significantly U-shaped in bank size — falling to a minimum around $0.87B in assets (a small community banking organization), then rising — contradicting the prior supervisory view that cyber loss rates decline with size. The result survives OLS cubic splines, double machine learning, and Autometrics model selection. Beyond size, explanatory power is limited (large idiosyncratic component), though more profitable and more efficient banks show lower loss rates.9

Note the productive tension with Baksy–Caratelli rather than a contradiction: the inverse-U describes successful-attack incidence across all US firms (mid-sized most attacked), while the Dallas Fed U-shape describes expected loss rates across banks (mid-sized least costly). Both reject the monotonic intuition that bigger means proportionally safer or proportionally riskier, and both put mid-sized organizations at the center of the policy story — as the most-attacked population in one dataset and the preparedness/attractiveness sweet spot in the other. The papers’ candidate mechanisms rhyme: economies of scale in security investment, attacker payoff-versus-effort calculus, operational complexity, and recovery capacity.1011

Open questions

  • Underreporting. Cyberattacks are among the most under-reported crimes, and disclosure mandates skew toward large public firms; taking the inverse-U seriously implies mid-sized-business surveys are the critical data gap (Ponemon 2016: 55% of 100–1,000-employee firms reported an attack in the prior year — far above disclosure-based datasets).12
  • AI’s double effect. AI plausibly lowers attacker entry barriers (attack capacity) and aids defenders (earlier vulnerability discovery); Baksy–Caratelli explicitly leave the net effect to future work, and their counterfactuals show the policy answer changes with the source of rising risk.13
  • Catastrophic/systemic loss modeling. The Dallas Fed estimates cover attritional events; a catastrophic-loss version (multi-bank correlated events) is forthcoming — the layer that connects to financial-stability concerns.14
  • security-awareness-training — the private-investment lever with the weakest evidence base; the micro counterpart to this page’s “how much should firms spend” question
  • private-sector-hack-back — the reactive/deterrence pole of cyber policy (ACDC Act, NSPM deputization), which Baksy–Caratelli’s bailout-moral-hazard result complicates
  • ai-economic-growth-complementarity — sibling general-equilibrium modeling of a technology shock’s growth impact
  • competitive-rent-extraction — another page where firm-level strategic behavior aggregates into welfare-relevant equilibrium effects
  • nudges-vs-prices — policy-instrument comparison (subsidies vs mandates vs insurance) evaluated on welfare, same genre as this page’s subsidy/regulation/bailout triad

Sources

Footnotes

  1. Ross Anderson 2001 — Why Information Security is Hard — An Economic Perspective

  2. Ross Anderson 2001 — Why Information Security is Hard — An Economic Perspective

  3. 2015 — Externalities and the Magnitude of Cyber Security Underinvestment by Private Sector Firms: A Modification of the Gordon-Loeb Model

  4. 2015 — Externalities and the Magnitude of Cyber Security Underinvestment by Private Sector Firms: A Modification of the Gordon-Loeb Model

  5. 2015 — Externalities and the Magnitude of Cyber Security Underinvestment by Private Sector Firms: A Modification of the Gordon-Loeb Model

  6. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  7. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  8. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  9. Anthony Murphy, Michael L. Tindall, Kelly Klemme, Joseph I. Suek, and Seth J. Dunbar 2025 — What Drives Cyber Losses at U.S. Banks? Potential Statistical Markers

  10. Anthony Murphy, Michael L. Tindall, Kelly Klemme, Joseph I. Suek, and Seth J. Dunbar 2025 — What Drives Cyber Losses at U.S. Banks? Potential Statistical Markers

  11. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  12. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  13. Aniket Baksy and Daniele Caratelli 2026 — The Economic Costs of Cyber Risk

  14. Anthony Murphy, Michael L. Tindall, Kelly Klemme, Joseph I. Suek, and Seth J. Dunbar 2025 — What Drives Cyber Losses at U.S. Banks? Potential Statistical Markers