How Suboptimal is Work-From-Home Security in IT/ICS Enterprises? A Strategic Organizational Theory for Managers

Author:

Pal Ranjan1,Sequeira Rohan Xavier2,Zhu Yufei3,Marotta Angelica,Siegel Michael1,Hua Edward Y.4

Affiliation:

1. Massachusetts Institute of Technology, USA

2. Subaru Corporation, USA

3. University of Michigan, USA

4. MITRE Corporation, USA

Abstract

The COVID-19 pandemic (e.g., especially the first and second COVID waves) had forced firms (organizations) to radically shift a considerable (if not all) proportion of their employees to serve in a work-from-home (WFH) mode. Industry statistics showcase that despite ushering in significant work-flexibility (and other) benefits, the WFH mode has also expanded an organization’s cyber-vulnerability space, and increased the number of cyber-breaches in IT and IT-OT systems (e.g., ICSs). This leads us to an important fundamental question: is the WFH paradigm detrimental to IT and IoT-driven ICS security in general? While vulnerability reasoning and empirical statistics might qualitatively support an affirmative answer to this question, a rigorous, practically motivated, and strategic cost-benefit analysis is yet to be conducted to establish in principle whether and to what degree WFH-induced cyber-security in an IT/ICS system is sub-optimal when compared to that in the non-WFH work mode. We propose a novel and rigorous strategic method to dynamically quantify the degree of sub-optimal cyber-security in an IT/ICS organization of employees, all of whom work in heterogeneous WFH “siloes”. We first derive as benchmark for a WFH setting - the centrally-planned socially optimal aggregate employee effort in cyber-security best practices at any given time instant. We then derive and compute (using Breton’s Nash equilibrium computation algorithm for stochastic dynamic games) for for the same setting - the distributed time-varying strategic Nash equilibrium amount of aggregate employee effort in cyber-security. The time-varying ratios of these centralized and distributed estimates quantify the free riding dynamics, i.e., a proxy concept for security sub-optimality, within an IT/ICS organization for the WFH setting. We finally compare the free-riding ratio between WFH and non-WFH work modes to gauge the (possible) extent of the increase (lower bound) in security sub-optimality when the organization operates in a WFH mode. We counter-intuitively observe through extensive real-world-trace-driven Monte Carlo simulations that the maximum of the time-dependent median increase in the related security sub-optimality ranges around 25% but decreases fast with time to near 0% (implying security sub-optimality in the WFH mode equals that in the non-WFH mode) if the impact of employee security effort is time-accumulative (sustainable) even for short time intervals.

Publisher

Association for Computing Machinery (ACM)

Subject

General Computer Science,Management Information Systems

Reference79 articles.

1. Gediminas Adomavicius , Jesse  C Bockstedt , Alok Gupta , and Robert  J Kauffman . 2008. Making sense of technology trends in the information technology landscape: A design science approach. Mis Quarterly ( 2008 ), 779–809. Gediminas Adomavicius, Jesse C Bockstedt, Alok Gupta, and Robert J Kauffman. 2008. Making sense of technology trends in the information technology landscape: A design science approach. Mis Quarterly (2008), 779–809.

2. Ch D Aliprantis and KC Border. 1994. Infinite Dimensional Analysis (1994). Ch D Aliprantis and KC Border. 1994. Infinite Dimensional Analysis (1994).

3. On the interdependence of reliability and security in Networked Control Systems

4. Security of interdependent and identical networked control systems

5. Open-Loop Equilibria and Perfect Competition in Option Exercise Games

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3