EconPapers    
Economics at your fingertips  
 

When Your Thing Won’t Behave: Security Governance in the Internet of Things

Martin Brennecke (), Gilbert Fridgen (), Jan Jöhnk (), Sven Radszuwill () and Johannes Sedlmeir ()
Additional contact information
Martin Brennecke: University of Luxembourg
Gilbert Fridgen: University of Luxembourg
Jan Jöhnk: University of Bayreuth
Sven Radszuwill: University of Bayreuth
Johannes Sedlmeir: University of Luxembourg

Information Systems Frontiers, 2025, vol. 27, issue 4, No 8, 1490 pages

Abstract: Abstract In the Internet of Things (IoT), interconnected smart things enable new products and services in cyber-physical systems. Yet, smart things not only inherit information technology (IT) security risks from their digital components, but they may also aggravate them through the use of technology platforms (TPs). In the context of the IoT, TPs describe a tangible (e.g., hardware) or intangible (e.g., software and standards) general-purpose technology that is shared between different models of smart things. While TPs are evolving rapidly owing to their functional and economic benefits, this is partly to the detriment of security, as several recent IoT security incidents demonstrate. We address this problem by formalizing the situation’s dynamics with an established risk quantification approach from platforms in the automotive industry, namely a Bernoulli mixture model. We outline and discuss the implications of relevant parameters for security risks of TP use in the IoT, i.e., correlation and heterogeneity, vulnerability probability and conformity costs, exploit probability and non-conformity costs, as well as TP connectivity. We argue that these parameters should be considered in IoT governance decisions and delineate prescriptive governance implications, identifying potential counter-measures at the individual, organizational, and regulatory levels.

Keywords: Information Security; Internet of Things (IoT); IT Governance; IT Security; Risk Analysis; Security Breach (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:

Downloads: (external link)
http://link.springer.com/10.1007/s10796-024-10511-z Abstract (text/html)
Access to the full text of the articles in this series is restricted.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:spr:infosf:v:27:y:2025:i:4:d:10.1007_s10796-024-10511-z

Ordering information: This journal article can be ordered from
http://www.springer.com/journal/10796

DOI: 10.1007/s10796-024-10511-z

Access Statistics for this article

Information Systems Frontiers is currently edited by Ram Ramesh and Raghav Rao

More articles in Information Systems Frontiers from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().

 
Page updated 2025-10-01
Handle: RePEc:spr:infosf:v:27:y:2025:i:4:d:10.1007_s10796-024-10511-z