Cyberattacks are a pervasive threat in the digital economy, with the potential to harm rms and their customers. Larger rms constitute more valuable targets to hack- ers, thereby creating negative network eects. These can be mitigated by investments in security, which play both a deterrent and a protective role. We study equilibrium investment in information security under imperfect competition in a model where con- sumers dier in terms of security savviness. We show that the competitive implications of security depend on rms' business models: when rms compete in prices, security intensies competition, which implies that it is always underprovided in equilibrium (unlike in the monopoly case). When rms are advertising-funded, security plays a business-stealing role, and may be overprovided. In terms of policy, we show that both the structure of the optimal liability regime and the ecacy of certication schemes also depend on rms' business model.
TSE Working Paper, n. 21-1285, December 2021