Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cybersecurity Is A Market For Lemons.

by The Gurus
May 22, 2019
in Featured, Opinions & Analysis
Cybersecurity Is A Market For Lemons.
Share on FacebookShare on Twitter

Written by Bernard Parsons, founder and CEO of Becrypt

I recently attended CYBERUK which is the UK government’s flagship cybersecurity event hosted by the National Cyber Security Centre (NCSC). The event features world-class speakers, and opportunities for interaction between the public and private sectors. It was a fascinating couple of days, partly as Becrypt is working with government on projects featured at the event, but it was also a great opportunity for the Cyber Growth Partnership (CGP) Assurance Working Group, of which Becrypt is a member, to promote cross-industry and government collaboration towards common objectives.

One area in particular that CGP and the High Assurance UK industry association (HAUK) are focused on is around how to better articulate and differentiate quality of security of products and services. During the event I delivered a presentation entitled: ‘Cybersecurity is a Market for Lemons’ which was on this very topic and I’ve summarised the key points in this article.

A ‘Market for Lemons’ is a term used by economists to denote market failure, where a free market does not self-optimise output for social benefit. There has been a debate taking place for some time as to whether this applies to cybersecurity. A number of characteristics are typically associated with market failure and I believe that two of these are particularly relevant to cyber, as touched on below.

Information Asymmetry

The classic example of information asymmetry is buying a used car, where the buyer has less information than the seller. It is very difficult, if you are buying a used car, to know whether you are buying a car that is above average quality or one that is a real “lemon”. The market tends to price cars on the average quality of all cars in the market, which can disadvantage cars that are higher quality, whose sellers may lose out if they can’t evidence this quality. Such cars may therefore get withdrawn from the market, driving down the average quality of remaining cars, and therefore average market price into a potential spiral.

Arguably, Information Asymmetry applies widely within the Cyber Security market. Buyers often have significantly less information about complex products and services than the sellers. Furthermore, sellers themselves often have less information than is required to robustly defend some of the claims they make about their products or services.

Negative Externalities

The second characteristic is Negative Externalities, where bad effects of the market are felt by third parties, in other words it is a cost that is suffered by a third party as a result of an economic transaction.

For example, if I have a fridge that has been compromised because it is connected to the internet with poor security, the buyers and sellers do not automatically lose out. Indeed the buyer probably got the fridge cheaper than they would have if the manufacturer had invested in robust security controls. The real losers are those that may be subject to the botnet that the compromised fridge forms a part of.

Regulation may be necessary, but is not sufficient

Where market failure occurs regulation is often required. Many would argue that within the cyber sector regulation may be necessary but is not sufficient. The whole world of technology is far too diverse and fast-paced, whether that is mobile, cloud, big data or AI, for regulation to keep sufficient pace and relevance to be the entire answer – there is more that we need to do as an industry to better optimise our output.

One of the big challenges that the cyber security sector faces, is that it values volume over validity. There is much more emphasis on making a noise in the market and analyst influence than defining and validating products’ security controls. In fact, for many procurement processes security requirements are not explicitly defined, it is more about features and functionality, making it difficult for buyers to quantify what they are getting in terms of return on security investment.

Government as an exemplar

Today, a number of exemplar government IT projects that successfully balance the security requirements of ‘High Assurance’ environments with broader user needs, as discussed at CYBERUK, have relevance to the market failure debate. This relevance results in part as there has been significant convergence between government and private sector IT requirements. On the one hand, both sectors have been increasingly subjected to overlapping threat actor communities, whilst in parallel government has developed an increased need and desire to adopt new technologies that offer increased flexibility at pace – moving from government bespoke to commercial of the shelf. Within these projects, government has had the resource, expertise and need to address Information Asymmetry, through thorough product and service assurance, and by working closely with the vendor ecosystem to both understand and influence product security controls.

An important question that arises, is how elements of relevant government successes may scale and apply to the private sector. Both CGP industry members and HAUK are focused on providing an industry voice to support government’s review of product assurance. Aspiring to achieve more agile and scalable approaches to gaining confidence of the value and effectiveness of security investment, and nudging our market towards more optimided output.

Agree or disagree? We’d love to hear your views. #CyberSector #MarketforLemons.

ShareTweet
Previous Post

Verizon DBIR Reaffirms The Importance Of Privileged Account Management.

Next Post

KnowBe4 Acquires CLTRe; Shines Spotlight On Security Culture Measurement.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol