Annotated Bibliography

profiletchyar
Transactionsecurityinvestmentsinonlinemarketplaces-Ananalyticalexaminationoffinancialliabilities.pdf

Decision Support Systems 92 (2016) 91–102

Contents lists available at ScienceDirect

Decision Support Systems

journal homepage: www.elsevier.com/locate/dss

Transaction security investments in online marketplaces: An analytical examination of financial liabilities

Se-Hak Chun a, Wooje Cho b,⁎, Ramanath Subramanyam c a Seoul National University of Science and Technology, 232 Gongneung-ro, Nowon-gu, Seoul, 139-743, South Korea b University of Seoul, 163 Seoulsiripdaero, Dongdaemun-gu, Seoul, 130-743, South Korea c University of Illinois at Urbana-Champaign, 1206 S. Sixth St., Champaign, IL 61820, USA

⁎ Corresponding author. E-mail addresses: [email protected] (S.-H. Chun

[email protected] (R. Subramanyam). 1 http://www.internetretailer.com/trends/sales/us-e

(last accessed April 2016). 2 The term e-commerce refers to Internet-based busine

selling products or services via electronic means using a c ogy, mobile commerce, electronic funds transfers, and ma

3 http://research.gigaom.com/report/are-apps-safe-dig (last accessed April 2016).

http://dx.doi.org/10.1016/j.dss.2016.09.015 0167-9236/© 2016 Elsevier B.V. All rights reserved.

a b s t r a c t

a r t i c l e i n f o

Available online 21 September 2016

With the proliferation of electronic web-based and mobile payment systems, the concern about ownership of liabilities for potentially fraudulent transactions has come under the spotlight. This study investigates the conse- quences of alternative legal regimes on online transaction security, with a specific focus on burden of proof. The two types of online transaction regulations are analyzed by comparing the profits of transacting firms (mer- chants) and their optimal levels of investment in security. Our findings show that in a market where investments in security are highly effective, a legal regime that imposes the burden of proof on the merchant will enable them to achieve higher profits than will a legal regime that places the onus on the customer. In addition, depending on the effectiveness of investments in online transaction security in a given market, even when firms invest less in security, firms will be more profitable under a legal regime that imposes the burden of proof on the merchant, compared with a framework that imposes it on the customer. Furthermore, our findings imply that, depending on the effectiveness of investments in online transaction security in a given market, firms could have an incentive to invest more in security and such an action could yield higher social welfare when burden of proof is imposed on firms.

© 2016 Elsevier B.V. All rights reserved.

Keywords: Information security Burden of proof Internet security breach Optimal investment in security Fraudulent online transactions Online business law

1. Introduction

Internet- and mobile-enabled online commerce has flourished over the last decade, and is still growing. A recent Forrester report1 estimated that e-commerce2 sales in the U.S. alone will reach nearly $500bn. Fur- thermore, the report states that while the growth in online businesses in developed countries has matured, the rate of growth in developing countries should remain in the double digits for several years. This growth is accompanied by a proliferation of online and mobile payment systems such as Apple PayR, Android Pay ™, and Paypal ™. However, on- line transaction security has been a critical concern for consumers [13], and the security risk of online transactions has increased in scope and scale along with the growth in online marketplaces3 [22]. Although

), [email protected] (W. Cho),

-commerce-sales-2013-2017/

ss activities, such as buying and ombination of Internet technol- ny other Internet technologies. ital-security-and-the-b2c-app/

firms have invested in securing online transactions, serious incidents have frequently occurred, including credit card fraud and hacking. In 2013, the total online loss attributable to fraud was estimated at $3.4 billion in North America [7].

Laws provide frameworks of operations for Internet firms and con- sumer behavior, although not always with the same predictability or results for each type of security incident ([19], P. 266). Among the many perspectives from which to view security issues in online transac- tion, including technological, human, and policy viewpoints, this study focuses on regulatory influence. To our knowledge, information systems researchers have paid limited attention to legal issues compared to human and technological factors when examining online marketplaces. This research contributes to the information systems literature by inves- tigating the effect of the legal regime on online transaction security. Bhattacharjee et al. [4], investigated the impact of legal threats on online users' behavior in the context of music file-sharing and found consider- able differences in how individuals in different customer segments responded to legal threats. Similarly, we believe that it is valuable to understand the impact of the legal environment, which complements prior research examining the effects of human or technical factors in e-commerce.

Liability regulations play a vital role in determining who is the victim of fraud in online marketplaces because the person committing the

92 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

fraud in cyberspaces is rarely identified [27]. The burden of proof is the “requirement of a litigant to pursue the trier of the facts (the jury or the judge) that the allegations made against the other party are true” ([9], p. 92). The Latin maxim semper necessitas probandi incumbit ei qui agit epitomizes the burden of proof (Latin: onus probandi), which can be translated as “the necessity of proof always lies with the person who lays charges.”4 When an economic party bears the burden of proof in a legal dispute involving a security incident, the party must prove that it was not at fault for the security breach to avoid a legal charge or finan- cial penalty. A party that does not carry the burden of proof will have the benefit of assumption, meaning that the party does not need to support the claims until the burden of proof is tossed to the party. Therefore, the discussion of the burden of proof is equivalent to the question of which party will be imposed the default position of charges in disputes pertaining to security breach incidents.

The purpose of this study is to investigate the effect of alternative legal regimes on online transaction security. Laws are a significant macro-level factor determining firms' decisions, and countries have developed laws for online transactions as online markets grew. In particular, the market requires appropriate legal frameworks governing fraudulent online transactions to protect consumers and help firms secure e-commerce transactions. Anderson [1] emphasizes microeconomic factors, arguing that we should consider both technical and microeconomic issues in solv- ing security problems. The question of who should bear the burden of proof in fraud incidents affecting merchants and consumers is important because it would determine the level of firms' investment in security as well as influence consumers' online behavior.

Two common types of security breaches are unauthorized charges and unauthorized disclosure [8]. Unauthorized charges cause direct fi- nancial damage to credit card or bank account holders, and unautho- rized disclosures of customer information may bring financial damages if it is possible to misuse the disclosed personal data for addi- tional financial transactions. Between them, our study focuses on unau- thorized charges. In the U.S., online customers are spared responsibility for online credit card fraud in most cases ([19], P. 277) and the burden of proof lies with the merchant in most disputes between a customer and a merchant for a fraudulent card transaction [10]. The merchant will incur a financial loss from a security incident unless it can provide evidence that it is not at fault. In fraudulent credit card transactions, we assume that the bank issuing the credit card plays a mediating role between a customer and a merchant; thus, we have simplified the model by not considering banks (credit card companies). In practice, the bank issuing the credit card appears to bear the burden of proving whether a card- holder authorized a card transaction according to the Fair Credit Billing Act. However, banks recover the payment from the merchant in most cases in accordance with the merchant's terms and conditions [23,24]. Thus, in the U.S., it is the merchant, not the bank, that assumes the de facto burden of proof and bears the loss in cases when the bank assumes the responsibility [26].

Our study examines the effect of two contrasting kinds of laws pertaining to investments in online transactions security, focusing on whether the burden of proof in legal disputes between a firm and a cus- tomer lies with the former (Case 1) or the latter (Case 2). The results from the analytical models show that in a market in where security in- vestments are highly effective, a legal regime that imposes the burden of proof on the merchant will be more profitable for the merchant than a regime placing the onus on the customer, in equilibrium. In addi- tion, depending on the effectiveness of investments in security, firms will be more profitable when the merchant carries the burden of proof rather than the customer, even when they invest less in security, in equilibrium. We also find that consumer surplus under the two legal re- gimes are equal and the relative magnitude of social welfare, between

4 Commentary on Trans-Lex Principle, http://www.trans-lex.org/966000 (last accessed April 2016).

the two cases is a function of the effectiveness of investments in IT secu- rity in a given market.

2. Research background

Security risks can influence the performance of online merchants in many ways. Insecure e-commerce platforms can decrease sales revenue because they discourage potential customers from purchasing goods, or because such systems could be susceptible to security breaches that im- pose non-trivial financial losses on merchants. According to a survey con- ducted by TRUSTe in 2013, 89% of Internet users worried about their privacy and security [21], and as observed through a Harris Interactive survey, the threat of a security breach was one of the main reasons users avoided purchasing from online merchants [17]. Trust between merchants and customers, and consumers and the e-commerce systems influence online shopping decisions [20]. Belanger et al. [3] investigated four common indices of trust and found that the security features on websites were the most important index of trust for online consumers.

As the threat of security breaches increases, firms are likely to increase budgetary allocations for security technologies [12]. Cavusoglu et al. [6] proposed a method of making security investment decisions based on a game-theoretic model of firm-hacker behavior. Gordon and Loeb [11] found that the optimal level of investment to protect specific information did not always increase with the vulnerability of the information set. Other empirical studies established the relationship between a firm's vul- nerability and its investment in information security (e.g., [29]).

Firms make a number of decisions about e-commerce security. To enhance online transaction security, firms must approach the issue from both a managerial and a technical perspective. Typical managerial security issues include risk analysis, risk management, privacy and ethics, security evaluation, and security policy design, whereas technical issues include database security, web security, network security, and system security management [18]. To firms considering these issues, the level of investment or the budget allocated for security is one of the most essential decisions since it determines the planned and imple- mented technical and managerial solutions. Thus, we assume that a firm's level of investment in security is positively associated with the se- curity of its online business.

In addition to managerial and technical issues, firms need to under- stand the laws and regulations governing online marketplaces, and the focus in this study is on how laws governing online transactions affect firms' strategic decisions related to investment in security. Fraudulent online transactions usually result in a financial loss for merchants in the U.S. because either the merchant or the credit card company has to assume responsibility according to U.S. federal law ([19], P. 277). In 2008 alone, airlines worldwide lost more than $1.4 billion to online fraudsters, which is approximately 1.3% of airlines' online revenue worldwide.5 On average, merchants expect to lose 1.4% of their online revenue to fraudulent transactions.6 Thus, e-commerce firms have a strong incentive to maintain high security and prevent security incidents.

Online transactions definitely offer consumers several benefits, in- cluding reducing their search costs and eliminating the physical dis- tance between the customer and retailer. However, such benefits are often accompanied by threats of increasingly sophisticated security breaches [19]. One important factor in an online merchant's success is the customers' trust in the website, which is determined by its security features [2,14,16], and customers' perceptions of security control influ- ence their acceptance of online commerce, mediated by trust [28]. We propose that the legal locus of the burden of proof influences firm be- havior and consumer actions, as well as the latter's perceived notions

5 Source: CyberSource, http://www.cybersource.com/news_and_events/view.php? page_id=1732 (last accessed July 2015).

6 Source: CyberSource, http://www.cybersource.com/news_and_events/view.php? page_id=1721 (last accessed July 2015).

Table 1 Summary of Notations in the Model for a Monopolistic Market.

Notation Definition (Explanation)

z The amount a firm invests in security s The firm's vulnerability to security breaches when it does not invest in

any kind of security k A measure of the effectiveness of investment in security for firms in a

country p The price of an item q The demand for an item by the online customer v The customer's reservation price for an item: v ∈ [0, V] L(z,s,k) The expected loss from a security incident θf The probability that a firm will lose a lawsuit when the burden of proof

lies with the firm, or the average share of the firm's financial loss when the burden of proof lies with the firm

θc The probability that a customer will lose a lawsuit when the burden of proof lies with the customer, or the average share of the financial loss taken by the customer when the burden of proof lies with the customer

β A parameter that represents the degree of additional cost that the party incurs when the burden of proof is imposed on that party

93S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

of security. For instance, if the law imposes the burden of proof on con- sumers in disputed security incidents, a consumer would have a greater disutility to participate in online transactions. Conversely, when mer- chants must assume the burden of proof, consumers will have a stron- ger incentive to engage in online transactions. The legal environment could be more favorable to customers than to companies while the se- curity technologies most internet firms employ might be unavailable to customers in their daily transactions [5].

3. The model

3.1. Model setup

We consider an online merchant (firm) that produces a digital product7 and sells it online to maximize its profits through its online channel; thus, the firm's decisions about investments in the security of its e-commerce systems should meet that objective. Online customers purchase the product through the firm's website, recognizing that there is some vulnerability in their online transactions. The payoff for a customer participating in the online transaction will depend on the preserved value of the item, its price, and the disutility from the poten- tial loss from the online transaction through a security breach.

We assume that the item's preserved value (or the customer's reser- vation price), v, is uniformly distributed along [0, V] and that a customer purchases at most one unit of the item (e.g., [15]). A customer with a reservation price of v will buy the item using an online transaction when the price of the item, p, is less than v. In a traditional market, the customer will obtain utility U(v)=v−p from buying the product. How- ever, in an online market, the customer may feel psychological disutility from the expectation of a fraudulent online transaction, and the customer's net utility can be given by (v)=v−p−l, where l denotes the disutility of a possible fraudulent transaction. Consumers whose val- uation of the product is greater than p + l will buy the product, since their net utility will be greater than zero, U(v)N0. Consumer surplus is the sum of the differences between a customer's valuation of the service and p + l for all customers, and thus consumer surplus, CS, is

CS ¼ : Z V pþl

v−p−lð Þdv ð1Þ

The firm's profit is determined by the gross profit earned by selling the item, pq, the average loss from security breaches, L(z,s,k), and the firm's investment in security, z in this model. The firm's profit is then

∏ ¼ pq−L z; s; kð Þ−z: ð2Þ

The gross profit of the firm from sales is determined by the price of the item, p, and the demand, q. For simplicity, we consider a firm that produces and sells digital products, which have negligible marginal pro- duction costs. The variable z is the firm's monetary (e.g., dollar) invest- ment in security (z ≥0). In addition, without a loss of generality in comparing firms' profits in the two legal systems, we set other fixed costs at zero. The average security loss L(z,s,k) refers to the average fi- nancial loss from security breaches, determined by the probability of a security breach and the amount of online sales, as in Gordon and Loeb [11] security investment model. We define the average loss from a secu- rity incident as

L z; s; kð Þ ¼ s 1 þ kz � p � q pð Þ: ð3Þ

We assume a linear association between the average loss and the size of sales revenues p⋅q(p) because the potential damage or loss

7 As we explain below, this assumption relates to the marginal production cost, which is negligible.

from a security breach is likely to increase as the size of the business in- creases. The term s1þkz represents the probability of a security incident per sale, where s is the vulnerability of the online transaction (0 b s b 1) and k is a measure of the effectiveness of security invest- ments in terms of how much a firm can reduce its vulnerability to secu- rity breaches with a unit increase of investment in security technology (k ≥ 0).

We assume that k is a macro-level property, such as a market or a country. A low k means that a marginal investment in security improve- ment has a small effect and vice versa. That is to say, if a market has a higher k, an online merchant in the market will be able to reduce vul- nerability to a greater degree by making an additional unit of invest- ment in security. For example, k can be determined by the information technology (IT) security infrastructure, culture, and citizens' risk aver- sion. It will be less costly for a firm to secure its systems and reduce se- curity breaches in a country or market where many vendors competitively provide security solutions than in a setting where few vendors provide security solutions.

Next, we consider outcomes of lawsuits involving security loss- related disputes between merchants and consumers. A party will as- sume the loss from a security incident when the party loses the lawsuit. We redefine L by considering the probability of losing a lawsuit:

L z; s; k; θ; βð Þ ¼ θ s 1 þ kz pq þ β

s 1 þ kz pq: ð4Þ

The term on the left, θ s1þkz pq, represents the financial damage that the party with the burden of proof has to pay as a victim. θ refers to the probability that the party with the burden of proof will lose a law- suit, or the average share of the financial loss taken by the party with the burden of proof in a lawsuit over a security incident. The term on the right, β s1þkz pq; refers to the average cost of having the burden of proof where β is the parameter referring to the costs of having the bur- den of proof. For instance, β determines the amount of expenses to have systems for documents or records that can be used as an evidence in lawsuits. We assume that θ is a function of β, θ=θ(β), because the costs for the proof will affect the likelihood of winning the lawsuit. In the following section, we use two functions of θ. θf(β) is the probability the firm loses a lawsuit when the firm has the burden of proof, and θc(β) is the probability the customer loses a lawsuit when the customer has the burden of proof. (see Table 1.)

ρ A parameter that represents the degree of handicap that a customer will have in providing proof when the burden is imposed on the customer as opposed to the firm

94 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

3.2. Modeling alternative online transaction regulations

Countries worldwide have laws governing online businesses (e.g., e-commerce laws), though some laws have different provi- sions. Therefore, we examine two scenarios (legal regimes): (1) when laws impose the burden of proof on the firm, and (2) when laws impose the burden of proof of the fraudulent transac- tion on the customer [1]. This question essentially relates to which party will incur the financial burden in case of disputes related to se- curity breaches, although the burden will pass to the other party if the original bearer successfully fulfills it.

3.2.1. Case 1: burden of proof lies with the online merchant Here, we consider a merchant in a legal environment where the bur-

den of proof is on the merchant. Thus, in a lawsuit, a customer will lose (1−θf) share of the security loss ð1−θf Þ s1þkz1 p1; where the subscript 1 refers to the first case analyzed. A customer with a reservation price v will obtain net utility UðvÞ ¼ v−p1−ð1−θf Þ s1þkz1 p1 from buying an item from an online merchant and will buy the product if U(v)N0. This utility may represent cases when a customer feels psychological disutility from the fear of potentially fraudulent transactions. Thus, the demand, q1, will be

q1 ¼ V−p1− 1−θf � � s

1 þ kz1 p1 ð5Þ

and the firm's profit function is

Π1 ¼ p1q1−L z1; s; k; θf ; β � �

−z1 ¼ 1− θf þ β � � s

1 þ kz1

� � p1q1−z1: ð6Þ

The term L ¼ ðθf þ βÞ s1þkz1 p1q1 is the overall loss from a security incident. The last term, z1, represents the firm's investment in secu- rity. From the first-order conditions of (5), we find the optimal price and the level of investment in security that maximizes the firm's profit:

p�1 ¼ V 2 − 1−θf � � ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffis

1 þ βð Þk r

; ð7Þ

z�1 ¼ v 2

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ βð Þs

k

r −

1 þ 1−θf � �

s k

; ð8Þ

Π�1 ¼ V2

4 þ 1−sθf þ s

k −V

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi s 1 þ βð Þ

k

r : ð9Þ

From Eqs. (1), (7), and (8), consumer surplus at p=p1⁎ and z=z1⁎ is

CS�1 ¼ V2

8 ð10Þ

We define social welfare, SW, as the sum of the firm's profit and the consumer surplus. The social welfare at p=p1⁎ and z=z1⁎ is

SW�1 ¼ CS�1 þ Π�1 ¼ 3V2

8 þ 1−sθf þ s

k −V

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi s 1 þ βð Þ

k

r : ð11Þ

3.2.2. Case 2: burden of proof lies with the online customer Alternatively, customers may bear the burden of proof. In this

case, the probability that a firm will lose a lawsuit is (1−θc), where θc is the probability that the customer loses in court. The consumer will have financial damage of the amount lost through the security breach θc s1þkz2 p2 and will bear the additional cost of having the bur- den of proof ρβ s1þkz2 p2, where the subscript 2 refers to the second case analyzed. The parameter ρ refers to the degree of handicap

that a customer will have in providing proof compared with the cost for a merchant providing proof. We assume that the customer has a greater burden of proof cost than the firm because it would be more costly for customers than firms to collect evidence (ρ≥1). Con- sumers usually have a disadvantage in providing a greater degree of proof to the court than do firms [27] because, customers generally can- not access security technologies easily in their daily transactions [5]. Merchants are likely to have more experience with and information about security incidents and thus have advantages in litigation com- pared to consumers. A consumer with a reservation price of v will ob- tain net utility UðvÞ ¼ v−p2−ðθc þ ρβÞ s1þkz2 p2 from purchasing a product and will buy it if U(v)N0. Thus, the demand, q2, will be equal to V−½1 þ ðθc þ ρβÞ s1þkz2�p2 and the firm's profit function is

Π2 ¼ p2q2− 1−θcð Þ s

1 þ kz2 p2q2−z2 ¼ 1− 1−θcð Þ

s 1 þ kz2

� � p2q2−z2:

ð12Þ

As seen in (12), the firm bears only the total cost of the incident ð1−θcÞ s1þkz2 p2q2 with its share being (1−θc), and it has no burden of proof cost. From the first-order condition of (12), we can find the optimal price and security investment that maximizes the firm's profits in equilibrium:

p�2 ¼ V 2 − θc þ ρβð Þ

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi s

k 1 þ ρβð Þ ; r

ð13Þ

z�2 ¼ V 2

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ ρβð Þs

k

r −

1 þ sθc þ ρβs k

; ð14Þ

Π�2 ¼ V2

4 þ 1 þ sθc þ sρβ

k −V

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi s 1 þ ρβð Þ

k

r : ð15Þ

From Eqs. (1), (13), and (14), consumer surplus at p=p2⁎ and z=z2⁎ is

CS�2 ¼ V2

8 ð16Þ

Then, social welfare at p2=p2⁎ and z2=z2⁎ is

SW�2 ¼ CS�2 þ Π�2 ¼ 3V2

8 þ 1 þ sθc þ sρβ

k −V

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi s 1 þ ρβð Þ

k

r : ð17Þ

4. Comparisons across alternate online transaction regulation regimes

In this section, we investigate the consequences of the two legal re- gimes. We compare results for the alternative regimes by analyzing its effects on firm profit, the optimal level of investment in online transac- tion security, consumer surplus, and social welfare.

4.1. The impact of regulations on firm profits

Profit is an important business performance indicator for a mer- chant, so we intend to identify conditions where firms have greater profitability depending on the locus of the burden of proof. Using the optimal prices and levels of investment in security, we can calculate the firms' profits as (9) and (15) to compare the two cases, which pro- vide implications for discussion. To compare the effects of the two reg- ulations, we assume that online merchants in a market face identical macro-level conditions in terms of k and s, leading to the following propositions.

95S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

Proposition 1. In a market where k is greater [smaller] than k̂, in equilib- rium, merchants in a regime imposing the burden of proof for fraudulent online transactions on them will have a higher [lower] profit than mer- chants in a regime imposing the burden of proof on the customer:

k̂ ¼ 1−θf −θc−ρβ � �2

s

v2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ ρβ

p −

ffiffiffiffiffiffiffiffiffiffiffiffi 1 þ β

p� �2

Proposition 1 indicates that the legal regime that imposes the bur- den of proof on the merchant will allow merchants to be more prof- itable than the regime imposes the burden of proof on the consumer, in equilibrium, if the effectiveness of an investment in security is high enough. Otherwise, the legal regime in Case 2 will provide more profitability than the regime in Case 1. An intuitive interpreta- tion would be that the legal regime that imposes the burden of proof on customers favors the merchant because the firm is more likely to limit financial losses from security breaches than in the alternative regime. However, we find that, by absorbing the burden of proof, the merchant's investment in security becomes effective enough to gain more in a setting (e.g., country) whose k is high enough (effect of a marginal investment in security improvement). For instance, in a country where the IT security infrastructure is mature enough for the country to have a high k, imposing the burden of proof on the mer- chant will increase its profits, likely because in such a regime, the merchant can more substantially reduce its financial losses from se- curity breaches and attract customers than otherwise. This implies that, even in a legal system where the liability lies with the mer- chant, the security investments can be effective enough to increase customer demand (by providing more secure systems) depending on the effectiveness of security investments, which can be supported by our mathematical analysis in Appendix C.

On the contrary, if k is small enough, increased investments in security technologies would not substantially reduce the vulnerabil- ity of online transactions, potentially implying that in a country where security investments have low efficacy, firms have to make an expensive investment in security that will lower their profits. In that business environment, sales would not increase significantly, even when the firm invests considerable amounts of money in secu- rity technologies because of the burden of proof, which may yield lower profits than a firm under the alternative regime. Fig. 1 shows the changes in firms' profits in Cases 1 and 2 with variation in k.

Fig. 1. Firm profits and effectiveness of investment in security.

4.2. The impact of regulations on a firm's optimal level of security investments

As noted earlier, the appropriate level of investments in security technologies is a vital decision for a merchant. When facing emerging information security risks, firms aim to make investment decisions that are the best for the business. However, since security risks have non-trivial impacts, decision-making related to security investments is a challenging task. Here, we investigate how the alternative regimes af- fect a firm's optimal investment in security. From the analysis, we pro- pose the following.

Proposition 2. In a market where the effectiveness of the merchant's in-

vestment in security is larger [smaller] than 4k̂, in equilibrium, merchants under a regime that imposes the burden of proof for fraudulent online transactions on the customer will invest in security to a greater [lesser] de- gree than will merchants in a regime where they bear the burden of proof.

Proposition 2 indicates that when the effectiveness of a merchant's

investment in security is higher than4k̂, merchants invest less in the se- curity of its online business under a legal regime where they bear the burden of proof than when the law imposes the burden of proof on cus- tomers in equilibrium. Worded differently, in a country where the secu- rity infrastructure is mature enough that it has a high k, the legal regime that imposes the burden of proof on the merchant would decrease the level of online transaction security compared to the alternative regime. This may be because in markets where security investments are effec- tive, a legal regime imposing the burden of proof on consumers incen- tivizes firms to use security investments to attract customers than in the alternative regime.

On the contrary, when the effectiveness of security investments is low enough, merchants in a regime imposing the burden of proof on the cus- tomer will make lower investments than if they were to bear the burden of proof themselves. One intuition is that the legal regime wherein the merchant holds the burden of proof will give the firm a stronger incentive to invest in security than in the other regime because security breaches are directly associated with the loss and legal charges. Fig. 2 shows the op- timal level of investment in security for firms in Cases 1 and 2.

4.3. The impact of regulation regimes on consumer surplus and social welfare

In this section, we intend to investigate how the two legal regimes would impact consumer surplus and social welfare differently, because consumer surplus and social welfare as well as firm profit are important considerations to lawmakers and policy makers. Consumer surplus is an

Fig. 2. Optimal Investment in Security and Effectiveness of Investment in Security.

96 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

economic measure of consumers' gain and, in our study, it is defined as the difference between the total amount of customers' value for a prod- uct and the total amount of the customers' payment plus disutility caused by possible fraudulent transactions. Using the results in the pre- vious section, we compare consumer surplus across the two cases (Cases 1 and 2, noted earlier) and propose the following.

Proposition 3. In equilibrium, consumers under the law that imposes the burden of proof on the firm for fraudulent online transactions will have a same consumer surplus, V2/8, as consumers under the law that imposes the burden of proof on them.

Interestingly, the two alternative legal regimes have an identical consumer surplus, which implies that changes in the liability do not in- fluence consumer surplus. According to this result, consumer surplus is influenced only by the maximum value of consumers for the product with the associated assumption that customers' valuation is uniformly distributed between zero and the maximum value. It can be explained by the fact that decisions on the investment in security are made by firms, not consumers. Though a regulatory framework imposing the lia- bility on the firm appears to be more favorable to consumers intuitively, we find that it does not increase consumer surplus, compared to the al- ternative regulatory regime. In other words, online consumers would have the same consumer surplus regardless of the locus of the liability for fraudulent online transactions. The legal regime that imposes the burden on customers would discount the consumer's net utility but the lower price of goods, in equilibrium, than the alternative regime is likely to make the consumer surplus equal in both regimes.

Social welfare is one of the main considerations to governments and policy makers since it represents the well-being of the entire society. In our model, social welfare is defined as the sum of firm profit and consum- er surplus, and we found that the consumer surplus of Cases 1 and 2 are equal. Thus, the condition that social welfare under a regulatory frame- work that imposes the burden of proof on the firm is higher than social welfare under the alternative regulatory framework will be same as the condition for firm profit, and we have the following proposition.

Proposition 4. In a market in which k is greater [smaller] than k̂, in equi- librium, the society under the law that imposes the burden of proof on the firm for fraudulent online transactions will have a higher [lower] social wel- fare than the society under the law that imposes the burden of proof on the customer.

Proposition 4 indicates that the government need to be aware of the macro-level factor, k, to select appropriate regulations regarding fraudu- lent online transactions to maximize social welfare. In a country or market where the investments in online transaction security are not effective, the legal regime that imposes the burden of proof on the consumer is likely to provide the society a greater value than the alternative regime. However, if investments in a country or market related to online transaction securi- ty are associated with higher effectiveness, the legal regime that imposes the burden of proof on the firm provides the society a greater value. Policy makers would need to understand the dynamics associated with the macro-level variable, since these dynamics would dictate the optimal legal regime for the market. In particular, if the trends indicate that invest- ments in online transaction security overall are positively associated with effectiveness, policy makers need to understand that imposing the bur- den of proof on firms will induce firms to invest more in online security, which will in turn drive higher social welfare.

4.4. Corollaries

Corollary 1 shows that as the initial vulnerability s increases, firms in Case 2 are likely to be more profitable than firms in Case 1. In this case, both merchants and customers will resist taking on the burden of proof. As the security conditions in a country improve with reduced s, the pol- icy makers of that country can increase firms' profitability by imposing

the burden of proof on merchants. For instance, when crime rates relat- ed to fraudulent online transactions decrease enough, laws imposing the burden of proof on the merchant will help them profit more, imply- ing that the negative effects of the burden of proof are tempered by the fact that the firm would bear a lower financial loss from security breaches as the initial vulnerability decreases. However, as customers' maximum reservation prices increase, firms in Case 1 will be more prof- itable than firms in Case 2, according to Corollary 1B. Thus, in markets for expensive items, laws that impose the burden of proof on merchants will likely be more profitable for them, implying that obtaining con- sumers' trust in online transaction is more effective as a means to in- crease profit in markets for luxury items.

Corollary 1A. The k̂ always increases in s, ∂k̂∂s N0 .

Corollary 1B. The k̂ always decreases in V; ∂k̂∂V b0.

We can define θ as a function of β because the amount of spending for the burden of proof would influence the probability of losing or winning in a lawsuit. As the cost of the burden of proof increases, the firm can pro- cure more evidence and is likely to reduce the probability of losing in a lawsuit. We intend to examine the effect of the relationship between θ

and β on k̂. For simplicity, we assume a linear relationship between θ and β, θf=b−aβ and θc=b−aρβ, where a and b are constants. we

find conditions when the relationship increase or decrease k̂ as follows.

Corollary 2A. The k̂ increases [decreases] in a if aN ρβþ2b−1βðρþ1Þ h a b ρβþ2b−1βðρþ1Þ

i :

Corollary 2B. The k̂ increases [decreases] in b, if b N aβðρ þ 1Þ − ρβ − 12h bb aβðρþ1Þ−ρβ−12

i :

The a indicates the efficiency of the burden of proof cost to win the lawsuit. Corollary 2A implies that, if the cost of the burden of proof is effi- cient enough, firms in Case 2 are likely to be more profitable than firms in Case 1. On the contrary, if the cost of the burden of proof is less efficient, firms in Case 1 are likely to be more profitable than firms in Case 2. The b is the initial probability of a party's losing a lawsuit when the party have the burden of proof without any cost of the burden of proof. Corollary 2B implies that, if the initial probability of losing is large enough, firms in Case 2 are likely to be more profitable than firms in Case 1.

We concurrently consider outcomes of the alternative legal regimes in terms of the optimal investment in security, firms' total profits, and social welfare. We find that legislators' choice between the two regimes would yield different results of profitability, social welfare, and security investments depending on the effectiveness of security-related invest- ments in that country. We compiled the findings in the Propositions 1, 2, and 3 for the following corollaries.

Corollary 3A. In a market where k is larger than 4k̂, in equilibrium, the legal regime that imposes the burden of proof for fraudulent online transac- tions on the merchant will allow firms to achieve higher profits and policy makers to improve social welfare, with a lower level of firm's investment in security than will the regime that imposes the burden of proof on the customer.

Corollary 3B. In a market where k is larger than k̂ but smaller than 4k̂, in equilibrium, the legal regime that imposes the burden of proof for fraudu- lent online transactions on the merchant will allow the firms to achieve higher profits and policy makers to improve social welfare, with a higher level of firm's investment in security, than will the regime that imposes the burden of proof on the customer.

Corollary 3C. In a market where k is smaller than k̂, in equilibrium, the legal regime that imposes the burden of proof for fraudulent online transac- tions on the customer will allow firms to achieve higher profits and policy makers to improve social welfare, with a lower level of firm's investment in security, than will the regime that imposes the burden of proof on the merchant.

97S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

Corollary 3A indicates that in a market in which k is sufficiently

high (greater than 4k̂), the legal regime in Case 1 will be more prof- itable for merchants spending less money on security than will the regime in Case 2. It is interesting that this result is consistent with Anderson [1] observation that U.S. banks suffer much less fraud than do banks in Europe, even though they spend less money on se- curity. Certainly, our findings should be applied to current online transaction security legislations in different countries with caution because lawmakers in these countries need to consider a multitude of factors and objectives when making legislation and our model fo- cuses only on the economic perspective.

According to Corollary 3B, in countries with a medium k (one that

falls betweenk̂and4k̂), firms need to spend more to achieve the optimal investment in security, but they can attain greater profitability when the law imposes the burden of proof on the merchant rather than on the customer. However, Corollary 3C states that in countries where k is suf-

ficiently low (smaller than k̂), merchants cannot attain greater profit- ability when they bear the burden of proof rather than the customer, even though these firms might be investing more in security. Fig. 3 shows the relationship between the level of investment in security and the level of profit based on the degree of effectiveness of the firm's investment in security.

Overall, for policy makers in a country in which k is large enough, the legal regime that imposes the burden of proof on firm is a more efficient choice than the alternative regime because the level of security level is lower but the social welfare is higher. On the contrary, when k is small enough, the legal regime that imposes the burden of proof on con- sumers would result in a more efficient outcome, because it helps them achieve a higher social welfare with lower level of security investment.

In addition, we consider three types of consumers' risk attitudes — risk neutral, risk averse, and risk seeker. From our numerical analysis (see Appendix D), we have some interesting findings though they are not generalizable findings from analytical solutions due to com- plexity of the solutions. According to the numerical experiment, when consumers are risk averse, it is more likely that the regime im- posing the burden of proof on consumers results in a greater firm profit with a lower level of investments in security than the alterna- tive regime at a given k, compared to when consumers are risk neu- tral. On the contrary, when consumers are risk seekers, it is more likely that the regime imposing the burden of proof on consumers

Fig. 3. Condition of Government Enforcement of the Firm's Investment in Security.

results in a lower firm profit with a higher level of investments in se- curity than the alternative regime, compared to when consumers are risk neutral. This observation can be explained as follows. Market de- mand under the legal regime that imposes the burden of proof on consumers will be more influenced by the risk attitudes of con- sumers because consumer utility under the regime is determined by the cost of the burden of proof but that under the alternative regime is not. Among the three types of consumers, the degree of dis- count in the consumer utility under the regime imposing the burden of proof on consumers, compared to the alternative legal regime, will be greatest to risk-seeking consumers, medium to risk-neutral con- sumers, and lowest to risk-averse consumers. Thus, compared to risk-neutral consumers, risk-averse consumers under the regime imposing the burden on consumers are likely to have a lower dis- count in their consumer utility, which could lead to a greater firm profit relatively.

In our basic model above, we assume online transactions where dig- ital goods that do not have any production cost. This assumption can be relaxed to be applied to more general online transactions and Eq. (2) can be modified as follows:

Π ¼ p−cð Þq−L z; s; kð Þ−z; ð18Þ

where c is the variable cost. Although analytical solutions of our model with Eq. (18) are too complex for us to find interesting findings, similar results to our findings in our basic model are found from numerical analysis (see Appendix E). As the effectiveness of security investments increases, it is more likely that the legal regime imposing the burden of proof on firms yield a greater firm profit and a lower level of invest- ments in security.

5. Extension: competition model

5.1. Basic model

We now present competition models by considering multiple on- line stores that sell a digital product to consumers. We extend the Salop circular city model [25] where a continuum of consumers is distributed uniformly on a circle of perimeter 1. N firms are located at an equal distance from one another on the circle, which yields the distance between any two firms, 1N. Without the loss of generality, let firm 1 offer a digital product at price pf1 with less vulnerable e- commerce system. Other firms (firm i; i = 2 . N) sell the product at a price p to online consumers who have a product's preserved value, v. The other firms are more vulnerable for fraudulent online transactions than firm 1. Each consumer purchases at most one unit of product. The distance between a consumer and his chosen firm represents psychological distance for choosing the e- commerce site when she or he buys the digital product. Let a consumer's psychological distance to an online store be linear in the distance between the location of a firm and that of a consumer at rate t. The psychological distance to an online store is influenced by various factors including brand loyalty (e.g., brand royalty of Amazon.com), system quality attributes (e.g., usability), and the rate t can be determined by internet accessibility, network speed, etc. Thus, a consumer located at x ∈½0; 1N� who purchases from firm 1 derives the utility u(x)=v−pf1−lf1−tx.

5.2. Burden of proof lies with the online merchant

When a firm has the burden of proof, consumers' utility is deter- mined by price, psychological distance to online store, and the aver- age loss caused by fraudulent transactions. Thus, a consumer who is indifferent to whether he buys firm 1 or firm 2 is located at x̂, which can be determined by the equation pf 1 þ δtx þ ð1−θf Þ s1þkz f1 pf 1 ¼

98 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

pf 2 þ tð1N −xÞ þ ð1−θf Þ s1þkz f2 pf 2 where δ represent heterogeneity of capability to attract customers between firm 1 and firm 2. Then, the demand function of firm 1 is:

qf 1 ¼ 2x̂ ¼ 2 pf 2−pf 1 t 1 þ δð Þ þ

1 1 þ δð ÞN þ

s 1−θð Þpf 2 t 1 þ δð Þ 1 þ kzf 2

� �− s 1−θð Þpf 1 t 1 þ δð Þ 1 þ kzf 1

� � !

ð19Þ

Firm 1 has a profit function as follows:

Πf 1 ¼ 1− θf þ β � � s

1 þ kzf 1

pf 12x̂−zf 1 ð20Þ

Firm 2 (or firm i) has a profit function:

¼ 1− θf þ β � � s

1 þ kzf 2

pf 22

1 N −x̂

−zf 2 ð21Þ

In the first period, firms determine the level of security investment and then prices. In the second period of game, the firm finds an optimal price given a security level. From above profit functions, optimal prices can be given by:

p�f 1 ¼ t 2 þ δð Þ 1 þ kzf 1ð Þ

3N s 1−θf � �

þ 1 þ kzf 1 � � ; p�f 2 ¼ t 1 þ 2δð Þ 1 þ kzf 2

� � 3N s 1−θf

� � þ 1kzf 2

� � ð22Þ With the optimal prices, firm 1 can determine the optimal security

investment level. Let zf1 ≥ zf 2=0, then zf1 represents relative amounts of security investment level between firms. Then, we obtained optimal investment level as follows:

Z�f 1 ¼ 2 þ δð Þ

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 2kst 1 þ δð Þ 1 þ βð Þ

p 3k 1 þ δð ÞN −

1 þ s 1−θf � � k

ð23Þ

5.3. Burden of proof lies with the online consumer

When the burden of proof lies with online consumers, consumers' utility is determined by price, the psychological distance, the average security loss, and the burden of proof cost. Thus, a consumer who is indifferent to whether he or she buys firm 1 or other firm (similarly, firm N) is located at x̂ determined by pc1 þ δtx þ ðθc þ βÞ s1þkzc1 pc1 ¼ pc2 þ tð1N −xÞ þ ðθc þ βÞ s1þkzc2 pc2. Thus, the demand function of firm 1 is:

qc2 ¼ 2x̂ ¼ 2 pc2−p1 t 1 þ δð Þ þ

1 1 þ δð ÞN þ

s θc þ βð Þpc2 t 1 þ δð Þ 1 þ kzc2ð Þ

− s θc þ βð Þpc1

t 1 þ δð Þ 1 þ kzc1ð Þ

ð24Þ

The firm 1 has a profit function as follows:

Πc1 ¼ 1− 1−θcð Þ s

1 þ kzc1

pc12x̂−zc1 ð25Þ

Firm 2 (or other firms)’s profit function is given by

Πc2 ¼ 1− 1−θcð Þ s

1 þ kzc2

pc22

1 N −x̂

−zc2 ð26Þ

From the profit functions above, we obtain optimal prices as follows:

p�c1 ¼ t 2 þ δð Þ 1 þ kzc1ð Þ

3N s θc þ ρβð Þ þ 1 þ kzc1ð Þ ; p�c2 ¼

t 1 þ 2δð Þ 1 þ kzc2ð Þ 3N s θc þ ρβð Þ þ 1 þ kzc2ð Þ

ð27Þ

We also obtained firm's optimal security investment level when consumers have the burden of proof. Let zc1 ≥ zc2=0, then zc1

represents a relative amount of security investment level between firms. Then we obtained optimal investment level as follows:

z�c1 ¼ 2 þ δð Þ

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 2kst 1 þ δð Þ 1 þ ρβ f

� �q 3k 1 þ δð ÞN −

1 þ s θc þ ρβ f � � k

ð28Þ

5.4. Analysis: the effect of the regulation regime on Investments in Security

We intend to investigate the effect of regulations on the security in- vestment of a firm in a competitive market. As mentioned earlier, firm 1 is characterized by a higher level of investment in security than the other firms. The gap in security investment between firm 1 and other firms is compared in this section. Our next proposition concerns the con- ditions under which the investment gap is greater or smaller in the legal regime where the burden of proof lies with firms than in the alternative regime.

Proposition 5. In a competitive market, the gap in security investment between firm 1 and other firms is greater [smaller] in the legal regime that imposes the burden of proof on firms than in the legal regime that imposes the burden of proof on consumers if θc−ð1−θfÞNĝ [ θc−ð1−θf Þb ĝ ] where ĝ ¼ ð2þδÞ

ffiffiffiffiffiffiffi 2kst

p ð ffiffiffiffiffiffiffiffiffiffiffi 1þρβ f

p − ffiffiffiffiffiffiffiffiffi 1þβ f

p Þ

3sN ffiffiffiffiffiffiffi 1þδ

p −βf .

θc is the probability of the firm's winning a lawsuit when consumers have the burden of proof and (1−θf) is the probability of the firm's win- ning a lawsuit when the firm have the burden of proof. Thus, θc−(1−θf) indicates the degree of the firm's advantage by not having the burden of proof. If that advantage is significant enough, in a compet- itive market where firm 1 wants to differentiate itself from competitors with higher security, the legal system that impose the burden of proof on firms drives the firm 1 to invest more in security than the legal sys- tem that imposes it on consumers.

We would expect certain further competitive influences. In the situation where the burden of proof for fraudulent activity is on the firm and the influence of having the burden in the court is large enough (θc−ð1−θf ÞNĝ), firms that have more proactively invested in security efforts, through initiatives such as comprehensively insti- tuting IT audit trails and additional safeguards, should have a signif- icant competitive differentiation over firms who have not taken such proactive measures. Since such technological capabilities are seldom firm-specific and are likely to be available to other firms as well, this should further intensify the competition eventually and simulta- neously improve overall consumer welfare. On the other hand, when the burden of proof rests on the consumer and advantage of exempting from the burden is significant (θc−ð1−θf ÞNĝ), firms that have inferior levels of investment in security (due to limited incen- tive to enhance security) are likely to be marginally more profitable. In this scenario, there might be two forces at play, which might not have a similar effect on the competition. This is because, while firms competing on profit margins through reductions in IT security efforts would increase other firms to follow in the same path, there is a second effect in this scenario, which is that consumer welfare would be considerably lower and there would be a clear discourage- ment for online consumer commerce, which should reduce profit- ability of the entire market.

Contrasting this expected effect with the monopoly setting where effectiveness of IT security efforts matters, we would expect that, in a setting where firms bear the burden of proof and the influ- ence of having the burden of proof in the court is large enough (θc− ð1−θf ÞNĝ), firms would still be better off with the status quo in so far as the burden of proof is concerned as the market becomes more competitive. However, in a setting where consumers bear the burden of proof, as the market becomes more competitive, firms with higher levels of investment in transaction security would

99S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

gradually and increasingly be preferred by remaining consumers in a shrinking overall market (suffering from lack of trust in online commerce).

6. Conclusions

As online and mobile payment platform options (such as Android Pay ™, Apple PayR, Alipay ™, Paypal™ etc.) grow, it is increasingly im- portant to understand the legal ramifications of security breaches and the burden of proof, among other related factors. This study contributes to the current understanding of the impact of online business legislation on company performance and merchants' decisions related to their in- vestments in security by investigating the central concern of burden of proof for fraudulent online transactions. Although laws and regulations should provide the most fundamental safeguards for markets, firms, and consumers, few studies in the information systems literature have investigated the impact of these regulations on firms' investment in se- curity, firm performance, and social welfare.

In practice, decisions about security investments are important because of the potential financial losses from security breaches, and because appropriate decisions on security investment might minimize higher than ex ante security investments. Our model pro- vides a guideline to help firms determine the most appropriate level of investment in security in terms of the legal regimes in which they operate.

Our findings might be of help to governments and policy makers developing online security laws. Many countries are still in the process of refining the regulatory frameworks that govern online marketplaces. This process is challenging due to rapid and unprece- dented growth of information technologies, which continuously change in scope, magnitude, and reach. A simple imitation of online business regulations in other countries without considering the local characteristics might result in suboptimal economic outcomes. Policy makers in each county often need to understand how different (online) business regulations affect the behavior of online firms, consumers, and economic growth. They will be in a better position to develop appropriate legal systems for internet businesses by iden- tifying their own traits and tendencies related to the security envi- ronment, such as the effectiveness of firms' investment in security and extent of online commerce in their region. Our research contrib- utes to the literature on online business regulations by illustrating the differential consequences of two forms of regulation. In particu- lar, we aim to provide guidelines for policy makers in countries that have established online business laws to govern security breaches and fraudulent online transactions because economic performance is one of the most important considerations for legislators when enacting new regulations.

This model has certain limitations. It is very difficult to capture all managerial phenomena related to security issues in online transac- tions in a single model, which is frequent for analytical models. First, we assume a linear relationship between security loss and the cost of proof in the cost function for proof in order to focus on the fi- nancial liability aspect of a firm's investment in security and do not consider other factors that may determine the cost of proof. Second, we assume a linear relationship between the security loss and sales in this model. Although the linear relationship may not apply to all cases of security incidents and potentially limits the model, we be- lieve the relationship captures the essence of security losses in on- line marketplaces, and expect that in future could develop and use functions that are more specific. Third, the disutility function in our model is simplified to focus on the impact of security threats, though do not consider other threats in the disutility function. In addition, our model considers only risk-neutral consumers. Future work should reflect a full scope of risk attitudes, including risk aversion and risk seeking.

Acknowledgement

This work was supported by the Ministry of Education of the Republic of Korea and the National Research Foundation of Korea (NRF-2015S1A5A2A01009911).

Appendix A. Proofs of propositions

Proof of Proposition 1. From (8) and (12), we can calculate Π1−Π2:

(i) If ρβ≤(1−θf)−θc,Π1−Π2≥0 for all k

(ii) If ρβNð1−θf Þ−θc; Π1−Π2 ≥ b 0 for k

≥ b k̂ where k̂ ¼

½ρβ−ð1−θ f −θcÞ�2s V2ð

ffiffiffiffiffiffiffiffiffi 1þρβ

p − ffiffiffiffiffiffiffi 1þβ

p Þ 2 :

Because (1−θf) can be viewed as the probability of a merchant's winning a lawsuit when the burden of proof lies with the merchant and θc as the probability of a merchant's winning a lawsuit when the burden of proof lies with the customer, (1−θf)−θc can be viewed as the difference in probabilities of a firm's winning a lawsuit between Cases 1 and 2. It appears reasonable to assume that (1−θf) is smaller than θc because having the burden of proof would decrease the proba- bility of winning a lawsuit but not increase it. Then, ρβ is always greater than (1−θf)−θc because (1−θf)−θcb0 and ρβN0. Thus, we consider only (ii) not (i). ■

Proof of Proposition 2. From (6) through (8) and (9) through (11), we can calculate z1−z2:

z1−z2 ≥ b 0 for k

≥ b 4k̂ where k̂ ¼

ρβ− 1−θf −θc � �� �2

s

V2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ ρβ

p −

ffiffiffiffiffiffiffiffiffiffiffiffi 1 þ β

p� �2 :

As in the proof for Proposition 1, we assume θc−(1−θf).■

Proof of Proposition 3. Consumers whose valuation of the product is greater than p + l will buy the product, since their net utility will be greater than zero, U(v)N0. Consumer surplus is the sum of the differences between a customer's valuation of the service and p + l for all customers.

Case 1½ �l1 ¼ 1−θf � � s

1 þ kz1 p1;

CS1 ¼ Z V pþl1

v−p1−l1ð Þdv ¼ Vkz1−kp1z1 þ p1sθf −p1s þ V−p1 � �2

2 kz1 þ 1ð Þ2

By inserting Eqs. (7) and (8) into CS1, we can obtain consumer surplus

in equilibrium: CS�1 ¼ V 2

8 .

Case 2½ �l2 ¼ θc þ ρβð Þ s

1 þ kz2 p2;

CS2 ¼ Z V pþl2

v−p2−l2ð Þdv ¼ Vkz2−ρβsp2−kp2z2−p2sθc þ V−p2ð Þ2

2 kz2 þ 1ð Þ2

By inserting Eqs. (13) and (14) into CS2, we can obtain consumer sur- plus in equilibrium:

CS�2 ¼ V2

8 :Thus; CS�1 ¼ CS�2 ¼

V2

8 :■

Proof of Proposition 4. From Eqs. (11) and (17), we can obtain SW1⁎− SW2⁎:

SW�1−SW � ≥ 2 b 0 for k

≥ b k̂ where k̂ ¼

ρβ− 1−θf −θc � �� �2

s

V2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ ρβ

p −

ffiffiffiffiffiffiffiffiffiffiffiffi 1 þ β

p� �2 :

As in the proof for Propositions 1 and 2, we assume θc−(1−θf)N0. ■

Fi Fi P C

Fi Fi P C

Fi

100 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

Proof of Proposition 5. From Eqs. (23) and (28), we can calculate z1f⁎−z1c⁎ and we found:

If θc− 1−θf � �≥

b ĝ; then z�1f−z

� 1c

≥ <0; where ĝ

¼ 2 þ δð Þ

ffiffiffiffiffiffiffiffiffi 2kst

p ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ ρβ f

q −

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi 1 þ β f

q� � 3sN

ffiffiffiffiffiffiffiffiffiffiffi 1 þ δ

p −β f :■

Proof of Corollary 1. From the partial differentiation of k̂

¼ ½ρβþðθc−ð1−θ f ÞÞ� 2s

V2ð ffiffiffiffiffiffiffiffiffi 1þρβ

p − ffiffiffiffiffiffiffi 1þβ

p Þ 2,

∂k̂ ∂s

¼ 1−θf −θc−ρβ � �2

V2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi ρβ þ 1

p −

ffiffiffiffiffiffiffiffiffiffiffiffi β þ 1

p� �2 N0; and ∂k̂∂V ¼ − 2s 1−θf −θc−ρβ

� �2 V3

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi ρβ þ 1

p −

ffiffiffiffiffiffiffiffiffiffiffiffi β þ 1

p� �2 b0 if ρN1 :■

Proof of Corollary 2. The partial derivatives of k̂ with respect of a and b are

∂k̂ ∂a

¼ 2s aρβ þ aβ−ρβ−2b þ 1ð Þ ρβ þ 2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi β þ 1ð Þ ρβ þ 1ð Þ

p þ β þ 2

� � ρ þ 1ð Þ

βV2 ρ−1ð Þ2 ;

∂k̂ ∂b

¼ 4s ρβ−aρβ−aβ þ 2b−1ð Þ ρβ þ 2 ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi β þ 1ð Þ ρβ þ 1ð Þ

p þ β þ 2

� � β2V2 ρ−1ð Þ2

:

If a ≥ b

ρβ þ 2b−1 β ρ þ 1ð Þ ; then

∂k̂ ∂a

≥ b 0; and If b

≥ b

aβ ρ þ 1ð Þ−ρβ−1 2

then ∂k̂ ∂b

≥ b 0 :■

Proof of Corollary 3. From the proofs for Propositions 1 and 2, we can de- rive the following conditions:

(i) If kN4k̂; Π1−Π2 ≥0 and z1−z2b0.

(ii) If k̂bk≤4k̂; Π1−Π2 ≥0 and z1−z2N0.

(iii) If kbk̂; Π1−Π2b0 and z1−z2N0. ■

Fi P C

Appendix B. Hypothetical scenario

Firm H, a monopolistic company, is selling digital products whose marginal production cost is negligible (e.g., software, movies, music, etc.) in country N. In that market, the customer's valuation of the dig- ital product ranges from $0 to $100 (V = 100). The market is charac- terized by s = 1, β = 0.1, θf = 0.4, θc = 0.7, ρ = 2, and k = 0.1. If a security breach occurs in online transactions, disputes between the two parties may go to court. A numerical example similar to the fol- lowing will help a country's regulator understand the result of im- posing the burden of proof for the online fraudulent loss on the firm or the customer.

Case 1. When the firm bears the burden of proof for the online fraudu- lent loss.

The demand will be q1 ¼ 100−p1−ð1−0:4Þ 11þ0:1�z1 p1 and the firm's profit will be Π ¼ ½1−ð0:4 þ 0:1Þ 11þ0:1�z1�p1q1−z1. Then, p1=48.1, z1= 149.8, and Π1=2184.3.

Case 2. When the customer bears the burden of proof for the online fraudulent loss.

The demand will be q2 ¼ 100−½1 þ ð0:7 þ 2 � 0:1Þ 11þ0:1�z2�p2 and the firm's profit will be Π2 ¼ p2q2−ð1−0:7Þ 11þ0:1�z2 p2q2−z2 . Then, p2=47.4, z2=154.2, and Π2=2172.6.

In country N, imposing the burden of proof on the firm will result in a higher profit for the firm, but a lower investment in security. Therefore,

between the two alternative legal frameworks, imposing the burden of proof on the firm appears to be a reasonable choice. Table B1 shows the consequences of adopting the two legal frameworks in a market with a higher k.

Next, we consider a market in a different country where the in- vestment in security is much less effective (k = 0.004). In this exam-

ple, we can calculate k̂ ¼ 0:00418 ( kbk̂Þ . Table B3 shows the consequences of adopting the two legal frameworks with a lower k.

We can also apply this model to a country with k = 0.01 ðk̂bkb4k̂Þ. Table B2 shows the consequences of adopting the two legal frame- works with a medium k. As the tables show, the regulator may need to choose a different legal framework in terms of the burden of proof for an online fraudulent loss depending on the effectiveness of a firm's investment in security.

Table B.1 Consequences of alternative legal frameworks in a market with a higher k (k = 0.1).

Variable

Case 1

Case 2

Comparison

rm's investment in security (z)

149.8

154.2

z1bz2

rm profit (Π)

2184.3

2172.6

Π1NΠ2

rice (p)

48.2

47.4

p1Np2

onsumer surplus (CS)

1250.0

1250.0

CS1=CS2

cial welfare (SW)

3434.2

3422.5

SW1NSW2

So

Table B.2 Consequences of alternative legal frameworks in a market with a medium k (k = 0.01).

Variable

Case 1

Case 2

Comparison

rm's investment in security (z)

364.4

357.7

z1Nz2

rm profit (Π)

1611.19

1594.6

Π1NΠ2

rice (p)

44.3

41.8

p1Np2

onsumer surplus (CS)

1250.0

1250.0

CS1=CS2

cial welfare (SW)

2861.19

2844.6

SW1NSW2

So

Table B.3 Consequences of alternative legal frameworks in a market with a lower k (k = 0.004).

Variable

Case 1

Case 2

Comparison

rm's investment in security (z)

429.2

391.0

z1Nz2

rm profit (Π)

1241.7

1242.9

Π1bΠ2

rice (p)

41.0

37.0

p1Np2

onsumer surplus (CS)

1250.0

1250.0

CS1=CS2

cial welfare (SW)

2491.7

2492.9

SW1bSW2

So

Appendix C. The effect of the effectiveness of security investment on consumer demand and firm's financial loss

By mathematical analysis of relationships between consumer de- mand (qi) and the effectiveness of security investment (k) and between firm's financial losses (l) and the effectiveness, we have the following results:

(1) The increase rate of consumer demand in k is greater in Case 2 than in Case 1

(2) The decrease rate of firm's financial loss in k is greater in Case 2 than in Case 1

Proof of (1). The partial derivative of q1 (Eq. (5)) and q2 (in a line above

Eq. (12)) with respect of k yields: ∂q1∂k ¼ ð1−θ f Þspz ðkzþ1Þ2 and

∂q2 ∂k ¼

ðρβþθcÞspz ðkzþ1Þ2 . Then,

we can compare the two derivatives:

∂q1 ∂k

− ∂q2 ∂k

¼ − θc− 1−θf � �

þ ρβ � �

spz

kz þ 1ð Þ2

z Π p C

z Π p C

101S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

As we shown in the proof of Proposition 1, we can reasonably as-

sume θcN(1−θf). Then, ∂q1 ∂k b

∂q2 ∂k .

Proof of (2). The partial derivative of l1 and l2 with respect of k yields:

l1 ¼ ð1−θf Þ s1þkz1 p1 and ∂l1 ∂k ¼ −

ð1−θ f Þspz ðkzþ1Þ2 b0, l2 ¼ ðθc þ ρβÞ

s 1þkz2 p2 and

∂l2 ∂k

¼ − ðρβþθcÞspzðkzþ1Þ2 b0. Then, we can compare the two derivatives: ∂l1 ∂k −

∂l2 ∂k ¼

ðθc−ð1−θ f ÞþρβÞspz ðkzþ1Þ2 . As we shown in the proof of Proposition 1, we can rea-

sonably assume θcN(1−θf). Then, ∂l1 ∂k N

∂l2 ∂k.

Appendix D. Numerical examples for three types of risk attitudes

Based on Arrow–Pratt's definition of risk attitudes, we use specific utility functions representing each risk attitude: U(v)=v−p−l for risk neutral, U(v)=(v−p−l)2 for risk seeker, and UðvÞ ¼

ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi v−p−l

p for risk averse. With the same setting of the market in Appendix B, we have the following results. The tables below can be compared to the re- sults in Table B, which is an instance of risk-neutral consumers.

Table D.1 Economic outcomes for risk-averse and risk-seeking consumers in a market with a higher k (k = 0.1).

z Π P C

z Π p C

z Π p C

With a utility function of risk-averse consumers,

UðvÞ ¼ ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi v−p−l

p

With a utility function of risk-seeking consumers, U(v)=(v−p−l)2

z Π

Variable

Case 1

Case 2

Case 1

Case 2

p

49.7

N

49.0

1260.0

b

1314.0

C

270.8

N

268.0

145,610.0

N

145,500.0

60.5

N

57.8

33.2

N

33.1

S

128.3

=

128.3

98,765.4

=

98,765.4

399.1

N

396.3

244,376

N

244,265.0

SW

Table D.2 Economic outcomes for risk-averse and risk-seeking consumers in a market with a medi- um k (k = 0.01).

With a utility function of risk-averse consumers,

UðvÞ ¼ ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi v−p−l

p

With a utility function of risk-seeking consumers, U(v)=(v−p−l)2

Variable

Case 1

Case 2

Case 1

Case 2

45.7

N

24.9

3876.9

b

4026.3

133.4

b

145.1

140,230.0

N

139,900.0

47.2

N

38.7

32.8

N

32.7

S

128.3

=

128.3

98,765.4

=

98,765.4

261.7

b

279.4

238,999.0

N

238,670.0

SW

Table D.3 Economic outcomes for risk-averse and risk-seeking consumers in a market with a lower k (k = 0.004).

With a utility function of risk-averse consumers,

UðvÞ ¼ ffiffiffiffiffiffiffiffiffiffiffiffiffiffiffiffi v−p−l

p

With a utility function of risk-seeking consumers, U(v)=(v−p−l)2

Variable

Case 1

Case 2

Case 1

Case 2

0.0

0.0

5982.8

b

6191.0

120.3

b

141.8

135,782.0

N

135,289.8

41.7

N

35.8

32.5

N

32.2

S

128.3

=

128.3

98,765.4

=

98,765.4

248.6

b

270.1

234,547.0

N

234,055.0

SW

Appendix E. Numerical examples for general goods

To extend our model to general goods of which production cost is positive, we use Eq. (18), instead of Eq. (2). Using the same setting of the market in Appendix B, we have the following results with a variation of the production cost, c.

Table E.1 Changes with a variation of the product cost in a market with a higher k (k = 0.1).

c (production cost) = 10

c = 20

c = 30

Variable

Case 1

Case 2

Case 1

Case 2

Case 1

Case 2

148.9

b

153.2

360.1

N

353.2

141.0

b

144.9

1711.1

N

1677.5

1142.9

b

1126.6

925.8

N

914.8

53.3

N

52.5

49.8

N

47.1

63.6

N

62.6

S

996.5

N

995.7

953.1

N

949.7

576.6

N

571.7

2707.6

N

2695.2

2095.9

N

2076.3

1499.4

N

1486.6

SW

Table E.2 Changes with a variation of the product cost in a Market with a Medium k (k = 0.01).

c = 10

c = 20

c = 30

Variable

Case 1

Case 2

Case 1

Case 2

Case 1

Case 2

360.1

b

353.2

347

N

339.1

323.2

N

313.4

1142.9

N

1126.6

738.3

b

723.2

399

N

386.1

49.8

N

47.1

55.3

N

52.2

60.8

N

57.2

S

953.1

N

949.7

693.0

N

687.0

467.5

N

459.2

2095.9

N

2076.3

1431.3

N

1410.2

866.5

N

845.3

SW

Table E.3 Changes with a variation of the product cost in a Market with a Lower k (k = 0.004).

c = 10

c = 20

c = 30

Variable

Case 1

Case 2

Case 1

Case 2

Case 1

Case 2

419.7

N

380.7

389.1

N

347

326.1

N

275.0

780.0

b

781.3

393.1

b

398.1

89.2

b

100.0

47.0

N

42.5

52.9

N

47.7

58.8

N

52.5

S

902.1

N

894.7

600.3

N

586.6

334.2

N

312.5

1681.3

N

1676.0

993.5

N

984.7

423.5

N

412.5

SW

References

[1] R. Anderson, Why Information Security Is Hard — An Economic Perspective, University of Cambridge, 2002 http://www.cl.cam.ac.uk/~rja14/Papers/econ. pdf.

[2] S. Ba, Establishing online trust through a community responsibility system, Decision Support Systems 31 (3) (2001) 323–336.

[3] F. Belanger, J.S. Hiller, W.J. Smith, Trustworthiness in electronic commerce: the role of privacy, security, and site attributes, The Journal of Strategic Information Systems 11 (3–4) (2002) 245–270.

[4] S. Bhattacharjee, R.D. Gopal, K. Lertwachara, J.R. Marsden, Impact of legal threats on online music sharing activity: an analysis of music industry legal actions, The Journal of Law & Economics 49 (1) (2006) 91–114.

[5] N. Bohm, I. Brown, E. Gladman, Electronic commerce: who carries the risk of fraud? Journal of Information, Law and Technology 3 (2000) 00–03.

[6] H. Cavusoglu, S. Raghunathan, W.T. Yue, Decision-theoretic and game-theoretic ap- proaches to IT security investment, Journal of Management Information Systems 25 (2) (2008) 281–304.

[7] CyberSource, 2012 Online Fraud Report, 2012 Retrieved from. [8] J. D'Arcy, A. Hovav, Towards a best fit between organizational security countermea-

sures and information systems misuse behaviors, Journal of Information System Security 3 (2) (2007) 3–32.

[9] J.S. Dempsey, Introduction to Privacy Security. Wadsworth, Cengage Learning, Belmont, CA, 2013.

[10] E. Gans, How to dispute a charge on your credit card bill, May 19 2014 Retrieved from http://www.thesimpledollar.com/disputing-credit-card-changes/.

[11] L.A. Gordon, M.P. Loeb, The economics of information security investment, ACM Transactions on Information and System Security 5 (4) (2002) 438–457, http://dx.doi.org/10.1145/581271.581274.

[12] M. Gupta, A. Chaturvedi, S. Mehta, Economic analysis of tradeoffs between security and disaster recovery, Communications of the Association for Information Systems 28 (1) (2011) 1–17.

[13] D. Hoffman, T.P. Novak, M. Peralta, Building consumer trust online, Communications of the ACM 42 (4) (1999) 80–85.

[14] L. Hosmer, Trust: the connecting link between organizational theory and philosoph- ical ethics, Academy of Management Review 20 (2) (1995) 379–403.

[15] K.L. Hui, K.Y. Tam, Software functionality: a game theoretic analysis, Journal of Man- agement Information Systems 19 (1) (2002) 151–184.

[16] S.L. Jarvenpaa, N. Tractinsky, M. Vitale, Consumer trust in an internet store, Informa- tion Technology and Management 1 (1) (2000) 45–71.

[17] D.J. Kim, D.L. Ferrin, H. Raghav Rao, Trust and satisfaction, two stepping stones for successful e-commerce relationships: a longitudinal exploration, Information Sys- tems Research 20 (2) (2009) 237–257.

102 S.-H. Chun et al. / Decision Support Systems 92 (2016) 91–102

[18] H. Kim, Y. Han, S. Kim, M. Choi, A curriculum design for e-commerce security, Jour- nal of Information Systems Education 16 (1) (2005) 55–64.

[19] K. Laudon, C.G. Traver, E-commerce 2013, 9th ed Prentice Hall, 2012. [20] M.K.O. Lee, E. Turban, A trust model for internet shopping, International Journal of

Electronic Commerce 6 (1) (2001) 75–91. [21] D. Moth, 89% of British internet users are worried about online privacy: report,

Jan. 28 2014 Retrieved from https://econsultancy.com/blog/64209-89-of-british- internet-users-are-worried-about-online-privacy-report#i.4n3nxp9yieya10.

[22] K. Muralidhar, R. Sarathy, R. Parsa, An improved security requirement for data perturbation with implications for E-commerce, Decision Sciences 32 (4) (2001) 683–698.

[23] N. Musgrove, Am I liable for credit card fraud? 2009 Retrieved from http:// www.business-lawfirm.co.uk/Blog/2009/07/Am-I-liable-for-Credit-Card- Fraud/.

[24] O. Papadimitriou, How to dispute a credit card charge, 2014 Retrieved from http:// www.cardhub.com/edu/credit-cards-disputed-charges/.

[25] S.C. Salop, Monopolistic competition with outside goods, Bell Journal of Economics 10 (Spring) (1979) 141–156.

[26] H. Shaughnessy, Solving the $190 billion Annual Fraud Problem: More on Jumio, Forbes, Mar. 24 2011.

[27] R. Steennot, Allocation of liability in case of fraudulent use of an electronic payment instrument: the new directive on payment services in the internal market, Comput- er Law Security Report 24 (2008) 555–561.

[28] B. Suh, I. Han, The impact of customer trust and perception of security control on the acceptance of electronic commerce, International Journal of Electronic Commerce 7 (3) (2003) 135–161.

[29] H. Tanaka, K. Matsuura, O. Sudoh, Vulnerability and information security invest- ment: an empirical analysis of e-local government in Japan, Journal of Accounting and Public Policy 24 (1) (2005) 37–59.

Se-Hak Chun is a Professor at Seoul National University of Science and Technology. He received his B.S. in Economics from Korea University in 1994. He completed both his M.E. (1997) and his Ph.D. (2002) in Management Engineering at KAIST. He was a visiting profes- sor at University of Illinois at Urbana Champaign and Indiana University. He has published articles in journals including Expert Systems, Expert Systems with Applications, Artificial Intelli- gence in Medicine, Decision Support Systems, International Journal of Forecasting, Information technology and management, Personal and ubiquitous computing, Journal of Cluster Computing and International Review of Economics and Finance, among others. His research interests cloud computing, economics of electronic commerce, economics of information security, complex- ity theory, include financial forecasting, data mining, telecommunication economics and policy, industrial organization and law and economics.

Wooje Cho is an Associate Professor at the University of Seoul, South Korea. He earned his Doctoral degree at the University of Illinois at Urbana-Champaign, Master degree at the Carnegie Mellon University, and Bachelor degree at Seoul National University. His research interests lie in the IT strategy, information security, and software engineering. His articles have appeared in journals such as Decision Support Systems, IEEE Transactions on Engi- neering Management, and Information Technology & Management.

Ramanath (Ram) Subramanyam is an Associate Professor of Business Administration, University of Illinois at Urbana-Champaign. He earned his Ph.D. from the University of Michigan in 2004. His research interests include IT Sourcing Governance, Management of IS design processes and project management, technology and sustainability, new prod- uct development, customer influences on technological product design, and IT-driven sus- tainability in products and processes. His teaching interests include IS Development and Management, IT Strategy and Innovations, Enterprise software management, Software project management, and Business Value of IT.

  • Transaction security investments in online marketplaces: An analytical examination of financial liabilities
    • 1. Introduction
    • 2. Research background
    • 3. The model
      • 3.1. Model setup
      • 3.2. Modeling alternative online transaction regulations
        • 3.2.1. Case 1: burden of proof lies with the online merchant
        • 3.2.2. Case 2: burden of proof lies with the online customer
    • 4. Comparisons across alternate online transaction regulation regimes
      • 4.1. The impact of regulations on firm profits
      • 4.2. The impact of regulations on a firm's optimal level of security investments
      • 4.3. The impact of regulation regimes on consumer surplus and social welfare
      • 4.4. Corollaries
    • 5. Extension: competition model
      • 5.1. Basic model
      • 5.2. Burden of proof lies with the online merchant
      • 5.3. Burden of proof lies with the online consumer
      • 5.4. Analysis: the effect of the regulation regime on Investments in Security
    • 6. Conclusions
    • Acknowledgement
    • Appendix A. Proofs of propositions
    • Appendix B. Hypothetical scenario
    • Appendix C. The effect of the effectiveness of security investment on consumer demand and firm's financial loss
    • Appendix D. Numerical examples for three types of risk attitudes
    • Appendix E. Numerical examples for general goods
    • References