Critical Analysis 3

profileJohn_matt
case_study_1.docx

Critical Analysis Case study 1

Introduction

            Cybersecurity is a relatively new field that is considered an industry by many reporters and market analysts. It appears that these reporters and analysts consider cybersecurity an industry due to the amount of investors that have flocked to this market, as well as the amount of revenue generated by cybersecurity startup companies. For instance, in an industry report generated by CB Insights (2014), they mention that the cybersecurity industry has received approximately five billion dollars in the past five years, with almost two billion invested in 2013 alone. Moreover, investors are not only investing in successful startups, but are investing in businesses that are at every stage of their development (CB Insights, 2014). In addition, in a first quarter market report created by Cybersecurity Ventures (2015), it is estimated that by the year 2019, the cybersecurity market will grow to over one-hundred and fifty-five billion dollars. It is also possible that analysts consider cybersecurity to be an industry because these companies are producing products that fulfill a specific need, such as offensive or defensive applications to protect against cybercrime (Jaber, 2011).

Despite the opinions of others, the North American Industry Classification System (NAICS) has yet to list cybersecurity as a unique industry (United States Census Bureau, 2013). One possible explanation for this is that the NAICS does not consider the products produced by the cybersecurity industry to be unique when compared to those of other markets within the same sector. For instance, the Bureau of Labor Statistics writes that the NAICS “uses a production-oriented conceptual framework to group establishments into industries based on the activity in which they are primarily engaged” (2014, p. 1). The primary activity of the cybersecurity industry is to provide products and services for defensive or offensive applications throughout multiple sectors (Jaber, 2011). Perhaps the NAICS is grouping this industry with other industries that are all identified under the “computer systems design services” industry (United States Census Bureau, 2013d, p. 1). One other possible explanation is the fact that the NAICS has not been updated since 2012, and will not be updated again until the year 2017. Due to the increasing market size of the cyber security industry, it may be possible that in 2017, cybersecurity will be described within its own industry under the NAICS.

            Although the cyber security industry is not specifically mentioned under the NAICS, it is important for the company to identify which classification code it falls under. Having standardized classification codes are important for examining economic statistics in an ever changing economy (Bureau of Labor Statistics, 2014). Furthermore, certain organizations use these codes for specific reasons. For instance, government agencies require that companies have an NAICS code before the company can be listed as an approved supplier (University of Maryland University College, 2015). Furthermore, many companies use the NAICS codes for marketing purposes (NAICS Association, 2013). Companies use these codes to identify certain industries that represent their ideal customer. In addition, investors also use NAICS codes to identify specific industries. Investors look at specific companies within those industries to determine which companies are the most “attractive” for investing purposes (Investopedia, 2016). If the company wants to prove that they are more “attractive” than other companies within their industry, it is important to select the applicable NAICS code so they can attract investors.

Industry Codes Used by Cybersecurity Companies

            There are multiple NAICS codes that are currently being utilized by the company’s direct competitors that could be used by the cybersecurity company. For instance, NAICS code 334, which is for computer and electronic product manufacturing, could potentially be utilized by the company (United States Census Bureau, 2013b). This sub-sector is for companies that manufacture computers, computer peripherals, and other computer hardware. Since the cybersecurity company develops network sensors, which are a type of hardware, it could potentially utilize this code. In addition, NAICS code 51, also known as the information industry, could be used by the cybersecurity company as this sub-sector specifically addresses companies that design, develop, or publish software (United States Census Bureau, 2013c). Since the cybersecurity company develops big data analytics, which is a form of software, they could potentially use this code. Furthermore, the NAICS code 54, which is the professional, scientific, and technical services industry, could be used by the cybersecurity company (United States Census Bureau, 2013d). This sub-sector includes industries that integrate computer hardware, software, and communication technologies. Since the cybersecurity company currently integrates network sensors (hardware) with big data analytics (software), they could potentially use this industry code. Lastly, the company could also use the NAICS code 44, which is the retail trade industry (United States Census Bureau, 2013e). This sub-sector includes industries that sell electronics, such as packaged software, computer equipment, cameras, and audio equipment. Although the cybersecurity company doesn’t specifically offer electronic devices, the company could argue that they are offering an electronic product that they are trying to sell to its customers.

NAICS Code Best Fit

            Although there are multiple NAICS codes that the cybersecurity company could use, it is important that the code that represents the company’s largest source of revenue be used (Investopedia, 2016). This being said, the NAICS code that best represents the cybersecurity company is code 54151, which is the computer systems design and related services industry (United States Census Bureau, 2013f). This industry code represents companies that provide among other things, IT expertise that includes “planning and designing computer systems that integrate computer hardware, software, and communication technologies” (United States Census Bureau, 2013f, p. 1). Since the cybersecurity company’s largest generator of revenue is its suite of cybersecurity products that integrate network sensors with big data analytics to provide advanced threat detection, this code provides the closest match. Moreover, to confirm that cybersecurity companies should be utilizing this code, it was discovered in a research study that there are cybersecurity companies that are currently using this code (BW Research, 2014). Although there are other possible options that the cybersecurity company could use as their NAICS code, this code provides the best fit for this company, and should be used on its website, business directory listings, and in financial reports.  

            Conclusions

            In a perfect world, there would be an NAICS code dedicated specifically to the cybersecurity industry. However, until that code is created, it is important for cybersecurity companies to identify a code that can be used to represent the products and services that the company offers. For this particular cybersecurity company, the best fit would be the computer systems design and related services industry code.

 

References

Bureau of Labor Statistics. (2014, May 22). North American industry classification system (NAICS) at BLS. Retrieved from

http://www.bls.gov/bls/naics.htm

BW Research, Inc. (2014, March). Cybersecurity in San Diego. Retrieved from

http://www.sandiegobusiness.org/sites/default/files/Cyber%20Security%20Final%20Report.pdf

CB Insights. (2014, September 8). Cybersecurity industry report - $5.2 billion invested across 807 deals over the past five years. Retrieved from

https://www.cbinsights.com

Cybersecurity Ventures. (2015). Cybersecurity market report. Retrieved from http://cybersecurityventures.com/cybersecurity-market-report-q1-2015/

Investopedia. (2016). Industry. Retrieved from http://www.investopedia.com/terms/i/industry.asp

Jaber, B. (2011, November). Cyber security M&A: Decoding deals in the global cyber security industry. Retrieved from

https://www.pwc.com/gx/en/aerospace-defence/pdf/cyber-security-mergers-acquisitions.pdf

NAICS Association. (2013). How to use NAICS & SIC codes for marketing. Retrieved from http://www.naics.com/naicswp2014/wp-

content/uploads/2014/10/How_to_Use_NAICS_SIC_Codes_for_Marketing_NAICSAssociation.pdf

United States Census Bureau. (2013, May 13a). North American industry classification system. Retrieved from http://www.census.gov/cgi-

bin/sssd/naics/naicsrch?code=541512&search=2012%20NAICS%20Search

United States Census Bureau. (2013, May 13b). 334 computer and electronic product manufacturing. Retrieved from http://www.census.gov/cgi-

bin/sssd/naics/naicsrch?code=334&search=2012%20NAICS%20Search

United States Census Bureau. (2013, May 13c). 511210 software publishers. Retrieved from http://www.census.gov/cgi-bin/sssd/naics/naicsrch?

code=511210&search=2012%20NAICS%20Search

United States Census Bureau. (2013, May 13d). 541512 computer systems design services. Retrieved from http://www.census.gov/cgi-

bin/sssd/naics/naicsrch?code=541512&search=2012%20NAICS%20Search

United States Census Bureau. (2013, May 13e). 443142 electronics stores. Retrieved from http://www.census.gov/cgi-bin/sssd/naics/naicsrch?

code=443142&search=2012%20NAICS%20Search

United States Census Bureau. (2013, May 13f). 54151 computer systems design and related services. Retrieved from http://www.census.gov/cgi-

bin/sssd/naics/naicsrch?code=54151&search=2012%20NAICS%20Search

University of Maryland University College. (2015). CSIA 350: Cybersecurity in business & industry. Retrieved from

https://learn.umuc.edu/d2l/lms/dropbox/user/folder_submit_files.d2l?db=291398&grpid=0&isprv=0&bp=0&ou=127200