Schneier
Complexity and Cybersecurity: An Editorial Perspective
Pages
6
Time to read
21 mins
Publication
Language
English
Pages
6
Time to read
21 mins
Publication
Language
English
This editorial is published in MIS Quarterly and discusses the principle of complexity in relation to cybersecurity, as articulated by Bruce Schneier. The text outlines how complexity can negatively impact security, making systems easier to attack and harder to defend. It references two articles in the same issue that apply this principle to their research on mergers and acquisitions (M&As) and multihospital systems. The editorial explains that complex systems have larger attack surfaces, which increases vulnerability. It also details how M&As can lead to increased data breach risks due to structural complexity. The authors present observations on how organizational complexity affects cybersecurity, emphasizing that as organizations grow more complex, the challenges of securing IT systems also increase. The editorial concludes by noting that while complexity poses significant challenges, there have been improvements in cybersecurity practices over time, though the struggle against complexity continues.