<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2016.72002</article-id><article-id pub-id-type="publisher-id">JIS-64591</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Cybersecurity Investment Guidance: Extensions of the Gordon and Loeb Model
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>cott</surname><given-names>Farrow</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Jules</surname><given-names>Szanton</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Department of Economics, UMBC, Baltimore, USA</addr-line></aff><aff id="aff2"><addr-line>Center for Health and Homeland Security, University of Maryland, Baltimore, USA</addr-line></aff><pub-date pub-type="epub"><day>16</day><month>03</month><year>2016</year></pub-date><volume>07</volume><issue>02</issue><fpage>15</fpage><lpage>28</lpage><history><date date-type="received"><day>10</day>	<month>November</month>	<year>2015</year></date><date date-type="rev-recd"><day>accepted</day>	<month>13</month>	<year>March</year>	</date><date date-type="accepted"><day>16</day>	<month>March</month>	<year>2016</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  Extensions of the Gordon-Loeb [1] and the Gordon-Loeb-Lucyshyn-Zhou [2] models are presented based on mathematical equivalency with a generalized homeland security model. The extensions include limitations on changes in the probability of attack, simultaneous effects on probability and loss, diversion of attack, and shared non-information defenses. Legal cases are then investigated to assess approximate magnitudes of external effects and the extent they are internalized by the legal system.
 
</p></abstract><kwd-group><kwd>Cybersecurity</kwd><kwd> Investment</kwd><kwd> Externality</kwd><kwd> Log-Convexity</kwd><kwd> Law</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>The most pressing cyberthreats once came from emailed viruses, but today’s cyberattacks increasingly take the form of massive identity and intellectual property thefts and the potential for physical damage to critical infrastructure. As cyberattacks have proven to be increasingly disruptive to the economy, a growing body of scholarship examines how much firms should invest in protection and what are appropriate roles for governments. Gordon and Loeb, GL [<xref ref-type="bibr" rid="scirp.64591-ref1">1</xref>] , and later, Gordon, Loeb, Lucyshyn and Zhou, GLLZ [<xref ref-type="bibr" rid="scirp.64591-ref2">2</xref>] , are leaders in examining the optimal level of spending that organizations should optimally invest in cybersecurity. Their approach uses an unconstrained expected profit maximization model where cybersecurity investments are separable from other activities of the firm. The benefit to the firm from a cybersecurity investment is a cost reduction; the remaining probability of a security breach (S(z)) times the loss (L), which can be altered based on investing in cybersecurity, z. GL analyzed direct (private) damages while GLLZ extended the model to include external damages.</p><p>GL and GLLZ investigate the implications of their model in some detail after first deriving the condition that the optimum (interior) investment is found where the incremental benefits of information security equal the incremental costs. As the optimal investment is shown to be increasing in damages (losses), including external damages increases the optimal level of investment. As with standard models of investment, an organization that only considers private losses in its optimization is correct if there are no external losses; but if external losses exist then optimum social expenditures increase. By investigating several functional forms for the security breach function, GL and later researchers showed that it is not uncommon for investments to have a maximum of about 37 percent of expected losses although this result is conditional on the specification.</p><p>This paper proceeds by investigating extensions to the GL and GLLZ models implied by a general investment model for homeland security expenditures. A review of legal cases involving cybersecurity breaches is then used to assess the implications of including external costs in the optimal investment model.</p></sec><sec id="s2"><title>2. Extensions of the GL and GLLZ Models Using a Homeland Security Model</title><p>While GL and GLLZ examine how much an individual firm should invest in preventing a cyberattack, related work by Farrow [<xref ref-type="bibr" rid="scirp.64591-ref3">3</xref>] investigates a set of expected, constrained cost minimization models for homeland security expenditures. The models were originally conceived to support Government performance audits in the US Government Accountability Office. The GL, GLLZ and Farrow models make similar simplifying assumptions about the relevance of expected value decision-making, continuity and derivatives of key functions<sup>1</sup>. The core similarities and differences are investigated below followed by several extensions presented in Farrow. The extensions illustrate modifications to investment rules where there are different types of constraints, interactions, and investment alternatives.</p><p>A summary of the definitions for the general homeland security investment model based on Farrow [<xref ref-type="bibr" rid="scirp.64591-ref3">3</xref>] is below. The “organization” referred to was originally modeled as the government, since governments are expected to consider both direct and external effects and assumed to select the socially optimal outcome. The organization could also be a firm or consumer. However, these organizations are typically modeled as having different objective functions. While the government is concerned with minimizing overall social costs, a self-interested firm or consumer will not consider the external effects of its choices unless there is some feedback mechanism, such as legal liability, which incentivizes the firm or individual to internalize the costs it creates for others.</p><p>Define:</p><p>e<sub>i</sub>: organizational security expenditures on site i.</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/1-7800333x6.png" xlink:type="simple"/></inline-formula>: an aggregate expenditure constraint over all sites and pathways.</p><p>P(e<sub>i</sub>): probability of an event. P′ &lt; 0; P″ &gt; 0 where P' is the partial derivative and functions are assumed to be twice continuously differentiable. This assumes some behavior or reaction function on the part of the attacker such that expenditures could alter their choice of targets or the expenditures could lead to capture prior to an attack.</p><p>S(e<sub>i</sub>): additional costs incurred as a result of the investment expenditure whether for the expending organization or third parties such as time in security lines or changes in productivity which are not part of the budget constraint, expect S′ &gt; 0.</p><p>C(e<sub>i</sub>): social cost given an event happens, C′ &lt; 0; C″ &gt; 0, which includes direct costs to the organization, C<sup>D</sup>(e<sub>i</sub>) and costs external to the organization (external costs) C<sup>E</sup>(e<sub>i</sub>). Note that the constrained expenditure amount e<sub>i</sub> is always assumed to be obligated and spent whether or not an attack occurs. It is the social cost, C, that is conditional on the event occurring.</p><p>The organization’s investment problem is stated as choosing the level of expenditure at each site (<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/1-7800333x8.png" xlink:type="simple"/></inline-formula>) in order to minimize expected social cost:</p><p>Min</p><disp-formula id="scirp.64591-formula162"><graphic  xlink:href="http://html.scirp.org/file/1-7800333x9.png"  xlink:type="simple"/></disp-formula><p>Subject to:</p><disp-formula id="scirp.64591-formula163"><graphic  xlink:href="http://html.scirp.org/file/1-7800333x10.png"  xlink:type="simple"/></disp-formula><p>The unconstrained minimization form of the problem is that used by Baryshnikov [<xref ref-type="bibr" rid="scirp.64591-ref5">5</xref>] in his extension of the underlying mathematical properties of the GL model and by Gordon, Loeb and Lucyshyn [<xref ref-type="bibr" rid="scirp.64591-ref6">6</xref>] . The GL and GLLZ models can be seen as the dual of the Farrow model prior to the inclusion of constraints―maximizing cost reductions is the dual of minimizing costs for an interior solution [<xref ref-type="bibr" rid="scirp.64591-ref6">6</xref>] .</p><p>GL and GLLZ do not consider a budget constraint, although they note that conflict between the Chief Information Officer and the Chief Executive Officer may affect the derivation of the optimal amount. In many instances, a budget constraint may be a more realistic decision context. In the budget constrained problem, a budget larger than the optimum expenditure yields the unconstrained solution (the constraint is not binding) while a binding constraint implies a shadow price affecting the expenditure allocation. At the same time, the parameterization in GL adds greater interpretation to the Farrow results.</p><p>The notation changes and constraints to place the GL model in the Farrow notation are as below (<xref ref-type="table" rid="table1">Table 1</xref>).</p><p>Farrow investigated several cases which can be considered extensions of the GL and GLLZ models<sup>2</sup>. Security and investment concerns modeled by these extensions include:</p><p>1) Multiple sites with a budget constraint: The primary difference compared to GL and GLLZ is inclusion of the shadow price of the constraint. First order conditions require that the marginal (incremental) benefit of the investment equal the marginal cost at each site where the marginal cost takes into account the shadow price associated with the binding constraint. Further, marginal expected social costs avoided―the benefits―are to be equated across sites. Where such equality cannot occur, some sites have zero optimal investment. In application, GL appear to follow such an approach for multiple information sets [<xref ref-type="bibr" rid="scirp.64591-ref7">7</xref>] .</p><p>2) Probability and consequence reductions: Investments may reduce not only the probability of an attack but the loss from the attack. When these impacts are separated, investments should occur until the incremental return per dollar invested is the same across the probability and consequence domains. Recent cybersecurity approaches echo this conclusion by extending cybersecurity beyond protecting access to actions designed to limit internal and external damage.</p><p>3) Attacker diversion: Investments in defense by one organization may divert attacker effort to another site. If larger firms are better protected than smaller firms, whether in the defense industry or elsewhere; the probability of attack may increase at less defended sites.</p><p>4) Continuous asymmetric focus or advanced persistent attack: Limitations on ability to defend a site or consequences of an attack may lead to optimal inequality of defense across sites and information sets as security may not be reducible to the level desired in the absence of such persistent attacks.</p><p>5) Shared filtering or defenses: The benefit of the investment includes the sum of benefits across all units to the extent that defensive activity reduces damages at other sites through positive external effects. This may occur for example if government or the private sector provides centralized hacker detection. The centralization</p>
<table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Notation changes and equivalencies</title></caption></table-wrap></sec></body>
<back><ref-list><title>References</title><ref id="scirp.64591-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L. and Loeb, M. (2002) The Economics of Information Security Investment. ACM Transactions on Information and System Security, 5, 438-457. http://dx.doi.org/10.1145/581271.581274</mixed-citation></ref><ref id="scirp.64591-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L., Loeb, M., Lucyshyn and Zhou, L. (2015) Externalities and the Magnitude of Cyber Security Underinvestment by Private Sector Firms: A Modification of the Gordon-Loeb Model. Journal of Information Security, 6, 4-30. http://dx.doi.org/10.4236/jis.2015.61003</mixed-citation></ref><ref id="scirp.64591-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Farrow, S. (2007) The Economics of Homeland Security Expenditures: Foundational Expected Cost-Effectiveness Approaches. Contemporary Economic Policy, 25, 14-26. http://dx.doi.org/10.1111/j.1465-7287.2006.00029.x</mixed-citation></ref><ref id="scirp.64591-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Hausken, K. (2006) Returns to Information Security Investment: The Effect of Alternative Information Security Breach Functions on Optimal Investment and Sensitivity to Vulnerability. Information Systems Frontiers, 8, 338-349. http://dx.doi.org/10.1007/s10796-006-9011-6</mixed-citation></ref><ref id="scirp.64591-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Baryshnikov, Y. (2012) IT Security Investment and Gordon-Loeb’s 1/e Rule. Proceedings of the 11th Workshop on the Economics of Information Security (WEIS), Berlin, 25-26 June 2012.</mixed-citation></ref><ref id="scirp.64591-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L., Loeb, M. and Lucyshyn, W. (2003) Sharing Information on Computer Systems Security: An Economic Analysis. Journal of Accounting and Public Policy, 22, 461-485. http://dx.doi.org/10.1016/j.jaccpubpol.2003.09.001</mixed-citation></ref><ref id="scirp.64591-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Gordon, L. and Loeb, M. (2011) You May Be Fighting the Wrong Security Battles. Wall Street Journal, September 26.</mixed-citation></ref><ref id="scirp.64591-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Kunreuther, H. and Heal, G. (2003) Interdependent Security. Journal of Risk and Uncertainty, 26, 231-249. http://dx.doi.org/10.1023/A:1024119208153</mixed-citation></ref><ref id="scirp.64591-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Willemson, J. (2010) Extending the Gordon and Loeb Model for Information Security Investment. 2010 International Conference on Availability, Reliability and Security, Krakow, 15-18 February 2010, 258-261. http://dx.doi.org/10.1109/ARES.2010.37</mixed-citation></ref><ref id="scirp.64591-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Bagnoli, M. and Bergstrom, T. (2005) Log-Concave Probability and Its Applications. Economic Theory, 26, 445-469. http://dx.doi.org/10.1007/s00199-004-0514-4</mixed-citation></ref><ref id="scirp.64591-ref11"><label>11</label><mixed-citation publication-type="book" xlink:type="simple">Cohen, M.A. (2000) Measuring the Costs and Benefits of Crime and Justice. In: Duffee, D., Ed., Measurement and Analysis of Crime and Justice, Criminal Justice 2000, Vol. 4, National Institute of Justice, Washington DC, 263-316.http://www.ncjrs.org/criminal_justice2000/vol_4/04f.pdf</mixed-citation></ref><ref id="scirp.64591-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Heartland Payment Systems, Inc., Customer Data Security Breach Litigation (2012) 851 F. Supp. 2d 1040 (S.D. Tex.).</mixed-citation></ref><ref id="scirp.64591-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Graves, J., Acquisti, A. and Christin, N. (2014) Should Payment Card Issuers Reissue Cards in Response to a Data Breach? WEIS: Workshop on the Economics of Information Security, Pennsylvania State University, State College, 23-24 June 2014. http://www.econinfosec.org/archive/weis2014/papers/GravesAcquistiChristin-WEIS2014.pdf</mixed-citation></ref><ref id="scirp.64591-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Crosman, P. (2014) How Much Do Data Breaches Cost? Two Studies Attempt a Tally. American Banker. http://www.americanbanker.com/issues/179_176/how-much-do-data-breaches-cost-two-studies-attempt- 
a-tally-1069893-1.html</mixed-citation></ref><ref id="scirp.64591-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Silver-Greenberg, J. and Schwartz, N. (2012) MasterCard and Visa Investigate Data Breach. The New York Times, 31 March 2012. http://www.nytimes.com/2012/03/31/business/mastercard-and-visa-look-into-possible-attack.html?_r=0</mixed-citation></ref><ref id="scirp.64591-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Clapper v. Amnesty International (2013) 133 S. Ct. 1138.</mixed-citation></ref><ref id="scirp.64591-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Lujan v. Defenders of Wildlife (1992) 504 U.S. 555, 560-61.</mixed-citation></ref><ref id="scirp.64591-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Zappos.com, Inc., Customer Data Sec. Breach Litig. (2015). No. 3:12-cv-00325-RCJ-VPC, (D. Nev.).</mixed-citation></ref><ref id="scirp.64591-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Willett, B. (2015) Employees Can’t Sue Hospital for Negligence, Breach of Contract, After Personal Data Breach. Reed Smith Technology Law Dispatch, 12 June 2015.</mixed-citation></ref><ref id="scirp.64591-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">The Huntington National Bank v. Kokoska, et al. (2011) Docket No. 1:11-cv-00063 (N.D. W. Va. Apr 25).</mixed-citation></ref><ref id="scirp.64591-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Schmidt, M. and Sanger, D. (2014) 5 in China Army Face U.S. Charges of Cyberattacks. The New York Times, 19 May 2014. http://www.nytimes.com/2014/05/20/us/us-to-charge-chinese-workers-with-cyberspying.html</mixed-citation></ref><ref id="scirp.64591-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">Andrijcic, E. and Horowitz, B. (2006) A Macro-Economic Framework for Evaluation of Cyber Security Risks Related to Protection of Intellectual Property. Risk Analysis, 26, 907-923. http://dx.doi.org/10.1111/j.1539-6924.2006.00787.x</mixed-citation></ref><ref id="scirp.64591-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Critical Infrastructures Protection Act (2001) 42 U.S.C. § 5195c(e).</mixed-citation></ref><ref id="scirp.64591-ref24"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Miller, C. (2009) Russia Confirms Involvement with Estonia DDOS Attacks. SC Magazine, 12 March 2009. http://www.scmagazine.com/russia-confirms-involvement-with-estonia-ddos-attacks/article/128737/</mixed-citation></ref><ref id="scirp.64591-ref25"><label>25</label><mixed-citation publication-type="other" xlink:type="simple">Tanner, J. (2007) Estonia Moves Soviet Statue to Cemetery. The Associated Press, 30 April 2007. http://www.washingtonpost.com/wp-dyn/content/article/2007/04/30/AR2007043000478.html</mixed-citation></ref><ref id="scirp.64591-ref26"><label>26</label><mixed-citation publication-type="other" xlink:type="simple">Hollis, D. (2011) Cyberware Case Study: Georgia 2008. Small Wars Journal, 6 January 2011. http://smallwarsjournal.com/blog/journal/docs-temp/639-hollis.pdf</mixed-citation></ref><ref id="scirp.64591-ref27"><label>27</label><mixed-citation publication-type="other" xlink:type="simple">Markoff, J. (2008) Before the Gunfire, Cyberattacks. The New York Times, 13 August 2008. http://www.nytimes.com/2008/08/13/technology/13cyber.html?_r=0</mixed-citation></ref><ref id="scirp.64591-ref28"><label>28</label><mixed-citation publication-type="other" xlink:type="simple">Keizer, G. (2010) Estonia Blamed Russia for Backing 2007 Cyberattacks, Says Leaked Cable. Computer World, 9 December 2010. http://www.computerworld.com/article/2511704/vertical-it/estonia-blamed-russia-for-backing-2007-cyberattacks 
--says-leaked-cable.html</mixed-citation></ref><ref id="scirp.64591-ref29"><label>29</label><mixed-citation publication-type="other" xlink:type="simple">Landler, M. and Markoff, J. (2007) Digital Fears Emerge After Data Siege in Estonia. The New York Times, 29 May 2007. http://www.nytimes.com/2007/05/29/technology/29estonia.html?pagewanted=all</mixed-citation></ref><ref id="scirp.64591-ref30"><label>30</label><mixed-citation publication-type="other" xlink:type="simple">Richards, J. (2009) Denial-of-Service: The Estonian Cyberwar and Its Implications for US National Security. International Affairs Review, 18. http://www.iar-gwu.org/node/65</mixed-citation></ref><ref id="scirp.64591-ref31"><label>31</label><mixed-citation publication-type="other" xlink:type="simple">Hobemagi, T. (2010) Price of Cyberattacks to Hansabank: 10 Million Euros. Baltic Business News, 12 August 2010.http://balticbusinessnews.com/article/2010/12/08/Price-of-cyberattacks-to-Hansabank-10-million-euros</mixed-citation></ref><ref id="scirp.64591-ref32"><label>32</label><mixed-citation publication-type="other" xlink:type="simple">Herzog, S. (2011) Revisiting the Estonian Cyber Attacks: Digital Threats and Multinational Responses. Journal of Strategic Security, 4, 49-60.http://scholarcommons.usf.edu/cgi/viewcontent.cgi?article=1105&amp;context=jss http://dx.doi.org/10.5038/1944-0472.4.2.3</mixed-citation></ref><ref id="scirp.64591-ref33"><label>33</label><mixed-citation publication-type="other" xlink:type="simple">Crawford, J. (2014) The US Government Thinks China Could Take Down the Power Grid. CNN.com, 21 November 2014. http://www.cnn.com/2014/11/20/politics/nsa-china-power-grid/</mixed-citation></ref><ref id="scirp.64591-ref34"><label>34</label><mixed-citation publication-type="other" xlink:type="simple">Lloyd’s of London (2015) Business Blackout: The Insurance Implications of a Cyber Attack on the US Power Grid. Lloyd’s Emerging Risk Report-2015. https://www.lloyds.com/~/media/files/news%20and%20insight/risk%20insight/2015/business 
%20blackout/business%20blackout20150708.pdf</mixed-citation></ref><ref id="scirp.64591-ref35"><label>35</label><mixed-citation publication-type="other" xlink:type="simple">Liptak, A. (2003) The Blackout of 2003: Lawsuits; Plaintiffs to Face Hurdles Proving Liability. The New York Times, 15 August 2003. http://www.nytimes.com/2003/08/15/us/the-blackout-of-2003-lawsuits-plaintiffs-to-face-hurdles- 
proving-liability.html</mixed-citation></ref><ref id="scirp.64591-ref36"><label>36</label><mixed-citation publication-type="other" xlink:type="simple">Garrison v. Pac. Nw. Bell (1980) 608 P.2d 1206, 1211.</mixed-citation></ref><ref id="scirp.64591-ref37"><label>37</label><mixed-citation publication-type="other" xlink:type="simple">Food Pageant, Inc. v. Consol. Edison Co. (1981) 429 N.E.2d 738, 740.</mixed-citation></ref><ref id="scirp.64591-ref38"><label>38</label><mixed-citation publication-type="other" xlink:type="simple">Singer Co., Link Simulation Sys. Div. v. Baltimore Gas &amp; Elec. Co. (1989) 558 A.2d 419, 428.</mixed-citation></ref><ref id="scirp.64591-ref39"><label>39</label><mixed-citation publication-type="other" xlink:type="simple">Frankel, A. (2012) Can Customers Sue Power Companies for Outages? Yes, But It’s Hard to Win. Reuters.com, 9 November 2012.http://blogs.reuters.com/alison-frankel/2012/11/09/can-customers-sue-power-companies-for-outages-yes -but-its-hard-to-win/</mixed-citation></ref><ref id="scirp.64591-ref40"><label>40</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Zhang</surname><given-names> Z. </given-names></name>,<etal>et al</etal>. (<year>2013</year>)<article-title>Cybersecurity Policy for the Electricity Sector: The First Step to Protecting Our Critical Infrastructure from Cyber Threats</article-title><source> Boston University Journal of Science and Technology Law</source><volume> 19</volume>,<fpage> 319</fpage>-<lpage>366</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.64591-ref41"><label>41</label><mixed-citation publication-type="other" xlink:type="simple">Wei, L., Debaise, C. and Bray, C. (2003) Blackout Exposes Power Companies to Potential Lawsuits. Dow Jones Newswires New York, 18 August 2003. http://www.oandb.com/blackoutexposes.html</mixed-citation></ref><ref id="scirp.64591-ref42"><label>42</label><mixed-citation publication-type="other" xlink:type="simple">Venable LLP (2014) The SAFETY Act: Providing Critical Liability Protections for Cyber and Physical Security Efforts.https://www.venable.com/files/Publication/6c0b031e-c2c5-4029-9ac7-13cb1d8c0d07/Presentation/ 
PublicationAttachment/e81d24a3-fc57-4ece-8e1f-179418baf994/The_SAFETY_Act_Providing_ 
Critical_Liability_Protections_for_Cyber_and_Physical_Securi.pdf</mixed-citation></ref><ref id="scirp.64591-ref43"><label>43</label><mixed-citation publication-type="other" xlink:type="simple">Eeckhoudt, L., Gollier, C. and Schlesinger, H. (2005) Economic and Financial Decisions under Risk. Princeton University Press, Princeton.</mixed-citation></ref><ref id="scirp.64591-ref44"><label>44</label><mixed-citation publication-type="other" xlink:type="simple">Huang, C.D., Hu, Q. and Behara, R.S. (2008) An Economic Analysis of the Optimal Information Security Investment in the Case of a Risk-Averse Firm. International Journal of Production Economics, 114, 793-804. http://dx.doi.org/10.1016/j.ijpe.2008.04.002</mixed-citation></ref><ref id="scirp.64591-ref45"><label>45</label><mixed-citation publication-type="other" xlink:type="simple">Cook, P. and Graham, D. (1977) The Demand for Insurance and Protection: A Case of Irreplaceable Commodities. Quarterly Journal of Economics, 92, 143-156. http://dx.doi.org/10.2307/1883142</mixed-citation></ref><ref id="scirp.64591-ref46"><label>46</label><mixed-citation publication-type="other" xlink:type="simple">Lucas, D. (2014) Rebutting Arrow and Lind: Why Governments Should Use Market Rates for Discounting. Journal of Natural Resources Policy Research, 6, 85-91. http://dx.doi.org/10.1080/19390459.2013.874106</mixed-citation></ref><ref id="scirp.64591-ref47"><label>47</label><mixed-citation publication-type="other" xlink:type="simple">Stewart, M., Ellingwood, B. and Mueller, J. (2011) Homeland Security: A Case Study in Risk Aversion for Public Decision Making. International Journal of Risk Assessment and Management, 15, 367-386. http://dx.doi.org/10.1504/IJRAM.2011.043690</mixed-citation></ref><ref id="scirp.64591-ref48"><label>48</label><mixed-citation publication-type="other" xlink:type="simple">Stewart, M. and Mueller, J. (2013) Aviation Security, Risk Assessment, and Risk Aversion for Public Decisionmaking. Journal of Policy Analysis and Management, 32, 615-633. http://dx.doi.org/10.1002/pam.21704</mixed-citation></ref><ref id="scirp.64591-ref49"><label>49</label><mixed-citation publication-type="other" xlink:type="simple">Farrow, S. and Scott, M. (2013) Comparing Multi-State Expected Damages, Option Price and Cumulative Prospect Measures for Valuing Flood Protection. Water Resources Research, 49, 2638-2648. http://dx.doi.org/10.1002/wrcr.20217</mixed-citation></ref></ref-list></back></article>