When Your Thing Won’t Behave: Security Governance in the Internet of Things
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Brennecke, Martin; Fridgen, Gilbert; Jöhnk, Jan; Radszuwill, Sven; Sedlmeir, Johannes Article — Published Version When Your Thing Won’t Behave: Security Governance in the Internet of Things Information Systems Frontiers Provided in Cooperation with: Springer Nature Suggested Citation: Brennecke, Martin; Fridgen, Gilbert; Jöhnk, Jan; Radszuwill, Sven; Sedlmeir, Johannes (2024) : When Your Thing Won’t Behave: Security Governance in the Internet of Things, Information Systems Frontiers, ISSN 1572-9419, Springer US, New York, NY, Vol. 27, Iss. 4, pp. 1471-1490, https://doi.org/10.1007/s10796-024-10511-z This Version is available at: https://hdl.handle.net/10419/330801 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/
Information Systems Frontiers (2025) 27:1471–1490 https://doi.org/10.1007/s10796-024-10511-z When Your Thing Won’t Behave: Security Governance in the Internet of Things Martin Brennecke1·Gilbert Fridgen1·Jan Jöhnk2·Sven Radszuwill2·Johannes Sedlmeir1 Accepted: 30 June 2024 / Published online: 22 August 2024 © The Author(s) 2024 Abstract In the Internet of Things (IoT), interconnected smart things enable new products and services in cyber-physical systems. Yet, smart things not only inherit information technology (IT) security risks from their digital components, but they may also aggravate them through the use of technology platforms (TPs). In the context of the IoT, TPs describe a tangible (e.g., hardware) or intangible (e.g., software and standards) general-purpose technology that is shared between different models of smart things. While TPs are evolving rapidly owing to their functional and economic benefits, this is partly to the detriment of security, as several recent IoT security incidents demonstrate. We address this problem by formalizing the situation’s dynamics with an established risk quantification approach from platforms in the automotive industry, namely a Bernoulli mixture model. We outline and discuss the implications of relevant parameters for security risks of TP use in the IoT, i.e., correlation and heterogeneity, vulnerability probability and conformity costs, exploit probability and non-conformity costs, as well as TP connectivity. We argue that these parameters should be considered in IoT governance decisions and delineate prescriptive governance implications, identifying potential counter-measures at the individual, organizational, and regulatory levels. Keywords Information Security ·Internet of Things (IoT) ·IT Governance ·IT Security ·Risk Analysis ·Security Breach Managerial Relevance Statement This paper provides prescriptive governance implications to cope with Internet of Things (IoT) security risks resulting from the use of technology platforms (TPs). In simple terms, we argue that while allowing for several different TPs increases the risk of a security incident, large-scale BJan Jöhnk [email protected] Martin Brennecke [email protected] Gilbert Fridgen [email protected] Sven Radszuwill [email protected] Johannes Sedlmeir [email protected] 1Interdisciplinary Centre for Security, Reliability and Trust, University of Luxembourg, 29 Av. J.F. Kennedy, Luxembourg L-1855, Luxembourg 2FIM Research Institute for Information Management, University of Bayreuth, Universitätsstraße 30, Bayreuth D-95447, Germany exploits are more likely for homogeneous TP use. Further, consideringthecorrelationbetweenTPsisimportantbecause diversification-related security governance measures may be lesseffectiveiftwoTPs’vulnerabilitiesarehighlycorrelated. Finally, as we currently observe in practice, an increasing number of connected smart things makes IoT security across TPs particularly prone to large-scale exploits. Our governance implications address individuals (i.e., professional or private end-users) using smart things, manufacturers that build anddistributesuchsmart things,and suppliersof TPsas critical component across different models of smart things. Wefurther considerpolicymakers, regulators,andauthorities that provide the guardrails for smart thing adoption and risk management. Summarizing, we provide practitioners with a better understanding of why and how TPs pose security risks to smart thing adoption in the IoT, help quantify and assess the associated risks, and stimulate discussions on appropriate measures to mitigate these risks. 1 Introduction “The spirits that I called” – In Disney’s 1940 classic Fantasia, a sorcerer’s apprentice is struggling with the acquired 123
1472 Information Systems Frontiers (2025) 27:1471–1490 power over a broom and its growing autonomy. Similar to the broom, webcams and other so-called smart things (Alter, 2019; Huber et al., 2024) were responsible for the worldwide distributed denial of service (DDoS) attack Mirai in 2016, executed by a botnet of more than 500,000 Internet of Things (IoT) devices and blocking the accessibility of popular web services such as AirBnB, Twitter, and Netflix (Dailymail, 2016; Walters & Jordan, 2016). Another example of the numerous recent security incidents is the ZigBee exploit, which could brick Philips Hue devices or use them for further DDoS attacks (Ronen et al., 2016). This exploit was able to spread to similar nearby devices via built-in wireless connectivity, causing cascade effects (Ronen et al., 2016). Further, the exploits Spectre and Meltdown used speculative execution in Intel, AMD, and ARM processors, potentially disclosing sensitive information on more than a billion devices (Kocher et al., 2018; Lipp et al., 2018). Also modern cars and their so-called controller area network (CAN) bus have also been prone to vulnerabilities (ICS-CERT., 2018a,b). This serial bus enables attackers to control safetycritical functionalities (e.g., braking) after gaining access via modern media and navigation systems or maintenance ports. Incidents like these have caused stricter regulatory demands on cybersecurity in general and of increasingly softwaredefined and autonomous vehicles in particular (ISO/SAE 21434:2021., 2021; Regulation EU 2018/858., 2018;Regulation EU 2019/2144., 2019). More recently, we further observed a backdoor in XZ Utils on Linux that was coincidentally caught in time before it could be exploited on a large scale (Lins et al., 2024), as well as the CrowdStrike Falcon update (CrowdStrike, 2024) on Microsoft Windows that impacted a wide variety of critical infrastructures and sectors, including but not limited to the financial services, health, and aviation industries (Financial Times, 2024). All these incidents also exhibit at least three commonalities: They are associated with smart things and IoT, they use built-in networking features to spread rapidly, and they exploit a technology platform (TP) that is used in many different devices. Thus, guidance for IoT TP governance is needed; otherwise, security incidents will likely threaten the value capture driven by the opportunities of IoT, thereby transforming this paradigm into a costly botnet of things. The IoT paradigm describes an increasing number of smart things, which enable new interaction types for individuals, machines, and companies (Borgia, 2014; Ransbotham et al., 2016; Hartwich et al., 2023). Devices like webcams, refrigerators, microwaves, and even toothbrushes have become part of the IoT as simple embedded systems with access to the Internet (Neville-Neil, 2017), though they may not yet be actually smart (Huber et al., 2024). This drive to connect things to the Internet naturally increases the number of connections between objects in the physical realm (Aftergood, 2018; Li et al., 2015). Smart things in the IoT are equipped with high levels of connectivity on multiple layers (Whitmore et al., 2015). Intra-network connectivity refers to connectivity within companies or households (e.g., inside the (HAN)), typically providing value to the network’s owner. For instance, household appliances (e.g., a refrigerator and a washingmachine)cansynchronizetheirenergyconsumption in a household to limit expensive peak loads (Waldo, 2002; Rieger et al., 2016). On the other hand, inter-network connectivity, i.e., interactions between smart things across companies or individual homes that form digital value networks, is typically based on communication over the Internet. Thus, a washing machine and solar cells of two different households could synchronize energy supply and energy demand via smart grids. In the course of the ongoing digital transformation,thenumberofphysicalobjectsequippedwithsensors or communication and network interfaces and the number of smart things are growing, with new communication methods being created, and intra-network as well as inter-network connectivity increasing (Püschel et al., 2016;Yoo,2010). Security risks in the IoT strongly relate to smart things’ quality and their underlying TPs. In contrast to considering a single entity, securing TPs in the IoT bears the risk of vulnerabilities shared across the platform with the potential to reinforce security incidents via the connectivity between many devices. Slaughter et al. (1998) differentiate between software quality costs for conformity, i.e., expenditures associated with the identification and prevention of defects that include corresponding opportunity costs (e.g., owing to longer development times), and costs of non-conformity, i.e., expenditures for rework, maintenance, liability damages, or litigation. We extend this distinction to TPs in IoT since the costs of conformity (e.g., during the TP design and the development of smart things) and non-conformity (e.g., in the event of an exploit owing to a platform vulnerability) equally apply to standardization, homogeneity, and “smartification” in IoT TPs. Thus, there is a trade-off between conformity costs and non-conformity costs considering the associated risks of corresponding TPs. This trade-off raises questions concerning adequate individual, organizational, and regulatory reactions, i.e., which countermeasures should be taken to prevent or at least mitigate the effects of security incidents in the IoT. We see a need for effective management and governance procedures to balance the trade-off between conformity costs and non-conformity costs. In particular, the management and governance issues connected to TPs in the IoT must be considered from an individual’s perspective (Almeida et al., 2015) as well as from the perspective of companies and regulators (Weber, 2010; Vermesan & Friess, 2022). Such a holistic approach is necessary to account for the high degree of interconnectivity and the blurring boundaries between actors in the IoT. These questions strongly relate to the standardization of IoT platforms and their governance. 123
Information Systems Frontiers (2025) 27:1471–1490 1473 Management and information systems (IS) research as well as policy-makers are paying increasing attention to (technology) platforms, including related governance questions and tensions(Thomasetal.,2014;Weigletal.,2023).Particularly in the field of IS, researchers have previously investigated platformand IoT-related challenges at the individual or behavioral level, at the organizational level, and at the regulatory or societal level. Based on this research – and at the intersection with emerging technologies – researchers also developednumerousalertsystemsandframeworkstoaddress related challenges (Syed, 2020; Biswas et al., 2022,2023). At the same time, and along similar lines, the European Union (EU has started addressing cybersecurity challenges posed by the IoT, e.g., via the revision of the Product Liability Directive (COM/2022/495 final, 2022) and the Cyber Resilience Act (COM/2022/454 final., 2022). These measures are likely to substantially increase security requirements for products with digital components, including smart devices. Despite the recent ubiquity of challenges and risks related to TPs and IoT, the implications of TP use in the IoT and its impacts on information technology (IT) governance remain unexplored (Weber, 2013; Mohamad Noor & Haslina Hassan, 2019). Thus, like the sorcerer’s apprentice, individuals, companies, and regulators are still struggling to achieve sufficient security governance in the IoT. Against this backdrop, we ask the following research question: What are the implications of technology platform in the IoT for security governance at the individual, company, and regulatory levels? We follow the research cycle proposed by Meredith et al. (1989)to address this question. “[A]llresearch investigations involve a continuous, repetitive cycle of description, explanation, and testing” (cf. Meredith et al., 1989, p. 301). First, we seek to contribute to the descriptive body of knowledge by describing TP use in the IoT as well as its associated risks (Section 2). Second, we adopt a risk quantification approach developed for the automotive industry (Kang et al., 2015) to shed light on risk-related dynamics by addressing “the underlying causal structure of the theory” (cf. Meredith et al., 1989, p. 303), i.e., the antecedents, interdependencies, and implications of TP use in the IoT (Section 3). We demonstrate how the use of platforms and their risk quantification can be transferred to TPs in the IoT, using the case of BusyBox (ICS-CERT., 2022) as an illustrative example of a software suite that is used across millions of IoT devices – from (PLCs) to remote terminal units (RTUs) – and where risks have materialized, as highlighted by vulnerabilities related to its dynamic host configuration protocol (DHCP) clients (CVE-2016-2148., 2016), heap buffers (CVE-20181000517., 2018), and code execution (CVE-2022-48174., 2022). Third, we delineate prescriptive governance implications resulting from the inherent risks of TPs in the IoT (Section 4). In doing so, we seek to develop guidance to deal withanurgentreal-worldproblem.Wediscussthelimitations of our research and conclude in Section 5. 2 Technology Platforms and Platform Security Risks in the IoT 2.1 Technology Platforms in the IoT Platforms are considered an important paradigm for product management, new product development, as well as innovation and technological strategy (Facin et al., 2016). The concept of a platform comprises a set of different interpretations (Thomas et al., 2014). The literature either regards platforms from a technological perspective (Porch et al., 2015), with examples including IT platforms (Fichman, 2014), or as two-sided markets from a primarily economic perspective (Dibia & Wagner, 2015;Gawer,2014). We follow the perspective of Fichman (2014), who define an IT platform as “a general-purpose technology that enables a family of applications and related business opportunities” (cf. Fichman, 2014, p. 132). In the IoT, such TPs can take different forms (Arnold et al., 2022). One may think of software platforms as operating systems or hardware platforms as processor families. Also, a TP is not necessarily tangible, butcanalso“beasetofstandards”(cf.Geppetal.,2016,p.2). For instance, standards such as programming languages, protocols, or security guidelines can also represent TPs. Regardless of whether they are tangible or intangible, TPs are typically used to achieve economies of scale via cost reductions over a set of components (Baldwin & Woodard, 2008). As the marginal costs of software are considered to be close to zero from a seller’s perspective, the re-use of software components wherever possible is a logical consequence. Further, standards and standardized components enable cooperation in networks, because “firms with similar technological capabilities are likely to form strategic alliances and interact in a cooperative and competitive manner” (cf. hyu Kim et al., 2017, p. 2). In the automotive industry, efficient production is now inconceivable without platforms such as Volkswagen’s modular transverse toolkit (Kang et al., 2015). With the rapidlyincreasing number of manufactured and deployed IoT devices, TPs receive growing relevance in the IoT. Indeed, the IoT sector is experiencing a development towards TP use, such as in the increasingly sensorand software-defined automotive industry. 2.2 Technology Platform-related Risks, Vulnerabilities, and Exploits We draw on Kang et al. (2015) for the concept of TP risk, the associated terms, the necessary adaptations to the specifics 123
1474 Information Systems Frontiers (2025) 27:1471–1490 of TPs in the IoT, as well as the differentiation between them. Kang et al. (2015) differentiate between platforms, models, units, defects, and failures. They define a platform as “a set of design components (i.e., software modules or physical parts) that are commonly shared by a range of different products” (Kang et al., 2015, p. 372and 37), using Toyota as an application example. The products under consideration are the brakes based on the same platform, i.e., an identical underlying design. A model describes an individual use case that is based on the common platform. In the Toyota case, the brake platformmodels correspondtothe different car models,since each car model comes with its specific brake system that is based on the platform but adjusted to the specific car model. Units are entities of an instance of a model, e.g., the brake system in one manufactured Toyota Corolla. To model TP risk, Kang et al. (2015) further introduce the notion of defect and failure. They define a design defect as a “design flaw that can potentially cause a failure in the course of a product’s use” (cf. Kang et al., 2015, p. 373). Importantly, this is not to be confused with a unit’s failure caused by a defectively manufactured product (Kang et al., 2015). For instance, the reliance of a Boeing 737 Max on a single sensor for its Maneuvering Characteristics Augmentation System (MCAS) can be considered a defect, whereas accidents caused by a malfunction of the sensor would represent a failure (Travis, 2019). This definition already implies that afailure refers to the manifestation of a defect. Failures can thus be modeled as random events, with the underlying probability distribution described by defects (Kang et al., 2015). Notably, security risks in the IoT can further materialize not solely in relation to the hardware but also in the software being used. The resulting software security risks may not always be caused by the TP provider but can also be caused by third-party libraries the TP provider uses or adapts. One example of an IoT risk that materialized came in the form of three Apache log4j vulnerabilities, namely CVE-2021-44228, CVE-2021-45046, and CVE-2021-44832 (Microsoft Threat Intelligence., 2021). As log4j is a frequently used logging library, it affected a significant share of Java libraries used in both commercial and non-commercial settings. Consequently, many IoT TPs that comprise Java-based components, likely underlying billions (often interconnected) of smart devices, were affected. According to Microsoft, “the vulnerabilities presented a new attack vector and gained broad attention due to its severity and potential for widespread exploitation” (Microsoft Threat Intelligence., 2021). The Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly, at the time, further published a statement indicating that “this vulnerability poses a severe risk” (CISA., 2021). Similar risks can materialize in other digital infrastructures, including security and communication protocols. We transfer these concepts to the specifics of TPs underlying IoT devices to model the risk of large-scale exploits – as for our application example, BusyBox. The Unix-based BusyBox is an open-source toolkit designed for mobile and embedded systems, as often found in IoT applications (ICSCERT., 2022). The toolkit is widely used in products such as webcams (e.g., the D-Link Wi-Fi camera), routers and modems (e.g., AVM-Fritz!Box, Belkin, Linksys, and NetGear), smartphones (e.g., Nokia N900), television receivers (e.g., Dreambox), navigation systems (e.g., TomTom GO), and drones (e.g., AR Drone 2.0) (ICS-CERT., 2022; Arentz, 2005;TomTom,2005; Labs, 2016). We use it as illustrative example for the definitions of the aforementioned concepts. We apply Kang et al.’s (2015) definition of platforms to TPs in IoT, defining an IoT platform as any component type (hardware, software, or standard) that is shared between smart things. We regard a smart thing as a product – a “previously non-digital physical artifact” (cf. Yoo et al., 2012, p. 1399) that has been equipped with digital technology (Yoo et al., 2012). In our illustrative example, BusyBox represents the platform. Further, we consider an IoT model to be a type of smart thing that is based on a specific TP. This intails that different IoT models’ physical shapes can vary substantially, as illustrated by the various models based on BusyBox, for instance, a Parrot AR Drone 2.0 and a D-Link web camera. The concept of an IoT unit is straightforward; we regard one physical, manufactured instance of a smart thing as one IoT unit. While we also adopt the underlying definitions of defect and failure from Kang et al. (2015), their application and implications differ substantially between the automotive industry and the IoT field. Thus, following a classification by Howard & Longstaff (1998), we use the terms of vulnerability and exploit instead to account for additional, information systems-related specifics. A vulnerability is “a weakness [in the design, implementation, or configuration] of a system allowing unauthorized action” (cf. Howard & Longstaff, 1998, p. 14). This understanding is in line with other definitions that consider the concept of vulnerability to be directly related to the upper-level concept of thing (Syed, 2020). An exploit, on the other hand, represents a successful “group of attacks that can be distinguished from other attacksbecauseofthedistinctivenessoftheattackers,attacks, objectives, sites, and timing” (cf. Howard & Longstaff, 1998, p. 15). An attack is specified by corresponding vulnerabilities, tools, actions, targets, and unauthorized results (Howard & Longstaff, 1998). Analogous to Kang et al.’s (2015) definition of a defect, a vulnerability refers to a flawed design, for instance, the possibility for malicious code injection in BusyBox via the netstat tool (Cybersecurityhelp., 2022). Thus, an exploit constitutes a manifestation of a vulnerability of the IoT platform, e.g., a successfully planted backdoor in 123
Information Systems Frontiers (2025) 27:1471–1490 1475 a D-Link DCS-930L webcam utilizing the vulnerability of BusyBox. 2.3 Platform Security Risks In the context of IoT TPs, we understand security as an extension of the common CIA triad (confidentiality, integrity, and availability) that also considers access level and functional level security requirements (Meneghello et al., 2019). This interpretation demandscontrol both over information processed by an individual smart thing as well as the impact of such processing onothercomponents(e.g., individualsor other devices). In line with this understanding, platform security is concerned with “tangible and intangible assets relating to the wellbeing of either the individual or society at large” (cf. von Solms & van Niekerk, 2013,p.101).FollowingvonSolms&vanNiekerk’s (2013) definition of cybersecurity, we further include the entirety of all IoT devices in this assessment and do not solely refer to an individual’s information and communication using a specific IoT device as the asset at risk. Exploits such as the Mirai IoT botnet, which was based on the BusyBox TP vulnerability, illustrate that security breaches may not only affect a single smart thing according to the CIA triad, but rather risk the overall wellbeing of other smart things built on other TPs owing to DDoS attacks. As such, we argue that this holistic perspective is necessary. The overall security goals of the CIA triad (confidentiality, integrity, and availability) and its extensions (accountability, authenticity, non-repudiation, and reliability) remain unchanged in this interpretation in the context of the IoT (von Solms & van Niekerk, 2013; Siponen & OinasKukkonen, 2007). Yet, considering the connectivity of smart things in the IoT, related work suggests increasing resilience to attacks as an additional cybersecurity goal, i.e., “[avoiding] single points of failure and [adjusting] to node failures” (Faber & Günther 2007,p.3). Rainer Jr et al. (1991, p. 130) define risk as the condition “when an asset is vulnerable to a threat” and distinguish between physical threats (e.g., weather or fire) and unauthorized or authorized access as major threats to IT. Although unauthorized access is the most obvious security threat, authorized access can even be more influential because the access usually goes unnoticed. Further, Rainer Jr et al. (1991) note that threats can originate from internal or external sources. Security risks may occur at various levels, i.e., the application level, the organizational level, and the interorganizational level (Bandyopadhyay et al., 1999). Applied to the IoT, these definitions and distinctions remain valid, but the characteristics of the IoT imply potential risks at all three levels owing to its physical components, human-machine interaction, and cross-organizational interactions (Sadeghi et al., 2015). The IoT not only inherits classic IT security risks but also creates new security risks due to IoT-specific features (Zhou et al., 2019). According to Atzori et al. (2010), three IoT-specific vulnerabilities increase security risks for smart things: Unattended components that facilitate physical attacks, accessibility via wireless communication, and reduced security measures owing to limited energy and computing resources. We argue that the use of TPs in the IoT amplifies these vulnerabilities for two reasons. First, smart things built on a common TP are characterized by shared technical components as well as increased intra-network and inter-network connectivity in the IoT. Thus, although “platform sharing is considered an effective means of cost saving [...] it also runs the risk of propagating a particular failure” (Kang et al., 2015, p. 372) among smart things building on the same TP. This can lead to cascading effects even if only a single component is exploited. Second, although smart things share a common TP, they can still have distinct features that may prohibit or impede a simple platform-wide rollout of security countermeasures (e.g., patches). Thus, the degree of connectivity and the extent of variations across models may contribute to the risk of cascading TP-specific vulnerabilities. As a result, smart things in the IoT are attractive targets owing to their vulnerabilities and their frequent uses in critical infrastructures such as the internet of medical things (IoMT) (Wang et al., 2022) or environments of sensitive information such as the industrial IoT (IIoT) (Sadeghi et al., 2015; Eden et al., 2017; Miller & Rowe, 2012). We consider an IoT-specific analysis of platform security risks and the implications for appropriate governance measures to be a valuable addition to the existing body of knowledge. In light of the aforementioned definitions and examples, the specific risk of a TP in the IoT can be summarized as follows: Owing tothesharingof identicaltechnologicalcomponents across a platform, a vulnerability’s effect (i.e., the overall number of exploited units) can be substantial. Vulnerabilities of one smart thing model are likely to occur in a similar way (if not identically) in many other smart thing models that share the same TP. This is crucial because the key to successful platform strategies is to attract third-party vendors developing applications on the platform (Kim & Altmann, 2020). In this context, it does not matter if hardware, software, or a standard constitutes the TP. We want to point out that there are also other models for quantifying the risk or impact of IT security incidents, e.g. the IoT MicroMort model (Radanliev et al., 2018). In contrast, our focus lies on the risk of exploits of vulnerabilities that are correlated through the joint use of an IoT-specific TPs and an assessment of corresponding, potentially widespread, implications for security and resilience. Therefore, we will now elaborate on the modeling of such risks in TPs, based on the concepts of vulnerabilities and exploits. 123
1476 Information Systems Frontiers (2025) 27:1471–1490 3 Modeling Technology Platform Risks in the IoT To model TP risk in the IoT, we use a Bernoulli mixture model, an established approach to model credit default risk in the financial sector (Bluhm et al., 2010; Giesecke, 2004; Giesecke & Weber, 2004). To outline the specifics of IoT TPs, we follow the modeling procedure of Kang et al. (2015) and transfer it to IoT TPs. To understand the modeling procedure, it is important to distinguish between the ex-ante and ex-post probability (or density) of an incident, i.e., respectively, before any observation and after having observed a certain event (Rausand et al., 2020) – in our case, an exploit. Platforms are usually designed with care, and a platform provider can be assumed to not purposefully design a vulnerable platform. However, vulnerabilities empirically cannot be avoided entirely. Further, some security issues only emerge with new technological developments. For instance, certain cryptographic libraries can become insecure because an attacker’s computational power can increase or an attacker may get access to a capable quantum computer (Bhat & Giri, 2021). Thus, a vulnerability often only becomes apparent expost. For instance, when the BusyBox TP was first designed in 1995, the currently prevailing security incidents were not foreseeable, partly owing to the lack of technical possibilities at that time as well as the later arising use of the IoT. Thus, ex-ante, a platform design may be assumed to be free of vulnerabilities, yet after having observed exploits, ex-post, vulnerabilities become apparent. We will now transfer Kang et al.’s (2015) model to TP in the IoT and contribute to the descriptive body of knowledge by describing TP use in the IoT as well as the associated security risks. Also, we derive governance implications for TPs in the IoT from this model. To not exceed this paper’s scope, we refer to Bluhm et al. (2010) for a more detailed overview of Bernoulli mixture models. We use the notations in Table 1to describe the mathematical model. We inherit the following assumptions from Kang et al. (2015): Let Ii,kdenote the random variable representing wheTable 1 Mathematical Notations to Model TP Risks in the IoT Notation Description rNumber of models based on the TP i∈{1, ..., r}Index of a model within the TP miModel i NiTotal number of deployed units of model i pgVulnerability probability of the TP giExploit probability for model i ρi,jCorrelation coefficient between model iand j YiNumber of exploited units for model i X=r i=1YiNumber of exploited units for entire TP ther or not unit kamong model iis exploited, where i∈ {1,...,r}and k∈{1,...,Ni}.Letidenote the random variable representing the exploit probability for model i. Then: A0: For each pair of units k1in model i1and k2in model i2, the random variables Ii1,k1and Ii2,k2are independent and follow Bernoulli(i1)and Bernoulli(i2), respectively, for both i1=i2and i1= i2(conditional independence). A1: P(i1=gi1, i2=gi2∨i1=0, i2=0)=1 (perfect correlation). A2: i1and i2independently take one of two values, gi and0(independence). Our model can be thought of as describing two sequential incidents. Initially, to obtain a nonzero probability of exploited units of any model, a TP must contain a vulnerability.Subsequently,giventhattheTPisvulnerable,aspecific exploit for this vulnerability is possible for each model mi based on the TP. Thus, a TP has a vulnerability probability pg, and each model mihas an exploit probability gi.Again, in case a vulnerability would have been known ex-ante, the platform would have been designed differently. In our view, any IT-related TP has a vulnerability probability pg>0 because perfect security by design is virtually impossible, as steady reports on the most recent IT security incidents emphasize. This is due to the heavy use of IT components, their fairly short lifecycles, complex system environments, and economic incentives for attackers, to name just a few reasons (Nicolescu et al., 2018). Further, exploits in most cases require a conscious action, implying knowledge of the vulnerability and the development of a suitable counterattack. Both require time and effort. Thus, a perfect TP security level is hard to achieve, and pg>0. On the other hand, most vulnerabilities can be fixed and are fixed after exploits emerge or responsible disclosure occurs (Arora et al., 2010), i.e., before a large number of units are exploited. Thus, in our view, the exploit probability can generally be assumed to be small. Vulnerabilities that become public and remain unfixed for a long time are prone to exploits. In such cases, TPs in the IoT bear the subsequent risk of cascading an exploit through the network that connects individual devices. Thus, the risk of an exploit caused by a vulnerable TP can be amplified owing to the units’ connectivity. A key question is whether the contagion becomes an epidemic and spreads rapidly, or whether it dies out. The threshold between these two cases is called the epidemic threshold (Prakash et al., 2012). There is evidence that the epidemic threshold can be very low for homogeneous networks (Prakash et al., 2012). On the other hand, connectivity also provides the possibility to rapidly spread countermeasures, even before cascade effects occur. The explicit modeling of such cascades (with both positive 123
Information Systems Frontiers (2025) 27:1471–1490 1477 and negative effects) has been the subject of research in other disciplines (Buldyrev et al., 2010; Watts, 2002;Helbing, 2013), and should also be subject to future research in the IoT. Although we do not look into cascade effects in particular, we connect our findings to the notion of cascade effects. For single units of each model, we distinguish the two states exploit and no exploit, which can be modeled as a Bernoulli trial (Kang et al., 2015). Thus, the exploit of a single unit is a random event occurring with probability gifor model iof the TP, given the vulnerability in the TP. For instance, consider the aforementioned BusyBox as TP. Model m1could then denote the D-Link DCS-930L Home Network Webcam, model m2the D-Link DCS-932L Home Network Webcam, and model m3the TomTom GO 4 navigation system, since they all are based on BusyBox. The exploit probability gican vary for different models of the same platform, i.e., it may be more likely for model m1(D-Link DCS-930L webcam) to be exploited than for model m2(D-Link DCS-932L webcam), or for model m3 (TomTom GO 4). With this denomination, a risk measure for exploitsof aTPisgivenby the tailprobability P(X>x)(see Fig. 1), where X=r i=1Yi, and xis an arbitrary threshold that determines a large-scale exploit (Kang et al., 2015; Fabozzi et al., 2007;Roy,1952). In other words, P(X>x) denotes the probability that more than xunits across all models of a TP in the IoT are exploited. Although we do not focus oncascadeeffects inthis paper, considering xasthe epidemic threshold is intriguing. Since more than xexploited units will possibly lead to subsequent cascade effects that spread through the network, this strongly amplifies an exploit’s impacts. For instance, 3,000 D-Link DCS-930L webcams, 2,000 D-Link DCS-932L, and 5,000 TomTom GO 4 navigation systems exploited add up to 10,000 exploited units of theBusyBoxTP.If x=9,000,theepidemicthresholdwould have been surpassed, and cascade effects likely propagate the Fig. 1 The Number of Exploited Units as a Measure of Technology Platform Risk exploit throughout the network. A low probability of facing many exploited units is desirable for all involved parties, i.e., the TP supplier (e.g., BusyBox’s developers), manufacturers using the TP (e.g., D-Link and TomTom), individuals using the corresponding smart thing, as well as regulators. Figure 1 illustrates the denominations. We use a binomial distribution to model the number of exploited units for each model mi. Using the Bernoulli mixture approach, we can calculate the unconditional, marginal distribution of Yibased on Kang et al. (2015): P(Yi=x)=pgNi xgx i(1−gi)Ni−x. Beyond assuming that giis sufficiently small (see above), we also assume that the number of units of an IoT model Niis large. To allow for better computability, we thus use the Poisson approximation for a Bernoulli distribution and derive (1) (Kang et al., 2015):1 P(Yi=x)≈pg (λi)x x!e−λi,where λi=Ni·gi.(1) From (1), we obtain the probability that the number of exploited units Yifor model miequals x. For instance, we obtain the probability that x=3,000 units of the D-Link DCS-930L webcam are exploited. The overall designs of two models can be quite similar, for instance, for the D-Link DCS-930L webcam (m1) and the D-Link DCS-932L webcam (m2). For these two models, we assume a (high) correlation in case of a TP vulnerability because exploits in one model may indicate the presence of vulnerabilities or corresponding exploits in the other. In contrast, TomTom GO navigation systems (m3) use the same BusyBox TP, but the exploits between the navigation system and the webcams may only be weakly correlated. A high number of webcams being exploited does not necessarily correlate to a high number of navigation systems being exploited. Further, we interpret two uncorrelated models as using individually designed (i.e., different) TPs. ThiswouldbeasituationinwhichtheD-Link DCS-930Land D-Link DCS-932Lwebcams usesimilar functionalunits, but on different TPs, i.e., D-Link DCS-930L would use BusyBox, and D-Link DCS-932L would build on another entirely differentTP.WecanmodelthesecorrelationsintheBernoulli mixture model between random variables (Bluhm et al., 2010), i.e., in our case, we can model the correlation of dif1Note that the number of IoT devices can be assumed to be very large. However, to allow for a good approximation of the underlying Bernoulli model by the Poisson distribution, we keep λi=giNiat a reasonable size. This does not affect our subsequent discussion of governance implications for TP use in IoT because we focus on generalizable insights for fundamentally different scenarios rather than on specific numbers. 123
1478 Information Systems Frontiers (2025) 27:1471–1490 ferent models miof a platform using a correlation coefficient ρi,j. We consider a TP with only two models m1and m2in the following, and we set the exploit probabilities g1=g2. This allows us to illustrate the basic connections between the model parameters. Since we focus on deriving governance implications from our model, we point out that the assumptions do not restrict our subsequent insights to a two-model situation. A more general modeling of Bernoulli mixtures can, for instance, be found in Bluhm et al. (2010). Following Bluhm et al. (2010) and Kang et al. (2015), we obtain three cases that depict different correlation levels: the two models can be partially correlated,perfectly correlated,oruncorrelated. To improve readability, we set ˜ρ=pg+ρ1,2(1−pg). Partially correlated (0 <ρ 1,2<1): P(Xpartially =x)=˜ρpg (λ1+λ2)x x!e−(λ1+λ2) +pg(1−˜ρ)λx 1e−λ1+λx 2e−λ2 x!.(2) From this general formula, we directly get the two special cases for perfectly correlated (ρ1,2=1, i.e., ˜ρ=1) and uncorrelated models (ρ1,2=0, i.e., ˜ρ=pg): Perfectly correlated (ρ1,2=1): P(Xperfect =x)=pg (λ1+λ2)x x!e−(λ1+λ2).(2a) Uncorrelated (ρ1,2=0): P(Xuncorrelated =x)=p2 g (λ1+λ2)x x!e−(λ1+λ2) +pg(1−pg)λx 1e−λ1+λx 2e−λ2 x!.(2b) Distinguishing these three cases allows us to discuss TP governance choices more distinctly. We will now illustrate the insights from our TP risk model, looking into the different input parameters’ effects regarding their impacts on the overall risk for TPs in the IoT. We will further relate our findings to current literature and derive governance implications for the IoT. 4 Application Scenario and Governance Implications for the IoT From (2)–(2b), we conclude that four distinct parameters impact the risk of exploits for TPs in the IoT. An analysis of these parameters thus allows for a detailed discussion of appropriate IoT governance aspects. We outline how the correlation coefficient ρ1,2,thevulnerability probability pg,the exploit probability gi, and the model size Ni(and, thus, the overall platform size consisting of all models), determine the risk of large-scale exploits in the IoT. We use the example of BusyBox (ICS-CERT., 2022) to illustrate and analyze these parameters’ impacts based on an application example and analytical insights. We further derive and discuss implications for IoT security governance as a first research step in this direction. In particular, we outline how the use of TPs affectsconformityandnon-conformitycosts(Slaughteretal., 1998) and derive implications for IoT security governance. We thus distinguish between the individual,company, and regulatory levels of IoT governance measures. At the individual level, we locate the individual end-user that makes use of a smart thing built on a specific TP. At the company level, we see both suppliers who develop and distribute TPs and manufacturers that make use of these TPs when developing their smart things. Finally, the regulatory level involves policymakers, regulators, and authorities who are responsible for setting the rules for TPs use, development, and distribution in the IoT. 4.1 Correlation, Homogeneity, and Heterogeneity 4.1.1 Application Example and Model Implications We follow a two-step approach when analyzing and discussing our model. First, we provide an application example to illustrate the fundamental properties and outline the differences between correlated and uncorrelated TPs. Note that the expected number of exploits is independent of the degree of correlation and only depends on the other parameters. Second, we look into analytical results to gain deeper insights into the model’s parameters and various governance implications. We see that a key question is whether to use a single TP or more than one TP for different models, i.e., deciding for homogeneity or for a specific heterogeneity level. As outlined, we model this by using different correlation levels. We begin with an application example, for which we assume a vulnerability probability pg=10 %. We consider twomodelsm1andm2with N1=25,000and N2=25,000, i.e., a platform size of 50,000 units, with exploit probabilities g1=g2=0.1%. We compare three distinct scenarios: Scenario A (homogeneity) – model m1(D-Link DCS-930L) and m2(D-Link DCS-932L) are perfectly correlated since they both use the BusyBox TP. Scenario B (partially correlated) – model m1(D-Link DCS-930L) and m2(TomTom GO navigation system) use the BusyBox TP but enact in a different environment, such that a partial correlation can be assumed (we use ρ1,2=0.5 for this scenario). Scenario C (heterogeneity) – model m1(D-Link DCS-930L) and m2 123
Information Systems Frontiers (2025) 27:1471–1490 1485 non-conformity costs to derive governance implications for TP use in the IoT. We found that companies should carefully consider their TP heterogeneity level since experiencing at least one exploit is more likely for two uncorrelated models (TPC I), whereas large-scale exploits are more likely for homogeneous TPs (TCP II). Vulnerability probability is influential since it directly translates to an increased or decreased risk (TPC V). Further, for x→∞, the ratio between TP homogeneity and heterogeneity depends on the vulnerability probability (TPC III) alone, and homogeneous TPs become riskier compared to heterogeneous ones settings when decreasing the vulnerability probability (TPC IV). The exploit probability and model size mainly affect large-scale exploits (TPC VI). We also identified several potential governance measures at the individual, company, and regulatory levels relating to the TPCs. From the individual perspective, IoT TPs are often not apparent, limiting the potential governance measures to increased awareness for security, for instance, by ensuring regular updates. Supplier companies may limit the level of conformity costs, trading it for potential non-conformity costs, partially owing to the absence of effective regulation, since it has no inherent value until a (relatively unlikely) exploit occurs. Since manufacturers can hardly avoid using TPs owing to their functional and economic benefits, they should establish good governance practices such as structured TP selection, timely patches, or audits. Thus, we argue for a deliberate, strategic decision-making process by manufacturers on the interfaces and connectivity levels of their smart things (Thielmann, 2017), considering the appropriate – or, rather, necessary – platform security level. Yet, it is hard to engage in the IoT governance field from companies’ perspectives if regulation provides no effective framework or responsibilities for regulation are even denied (Thielmann, 2017). Thus, we see a need for increased collaboration at the company and regulatory levels to find an appropriate balance between regulation and open interfaces of IoT, i.e., conformity and non-conformity costs. This is especially challenging considering the requirement for international regulation frameworks owing to the global nature of the IoT (Weber, 2010; Nicolescu et al., 2018). Combining our model interpretation with the notion of epidemic thresholds, we Table 2 Technology Platform Characteristics and Security-Related Governance Measures TPC Description Governance Implications I-II It is most likely for the uncorrelated case (scenario C – heterogeneity) and least likely for the perfectly correlated case (scenario A – homogeneity) to experience an exploit at all, i.e., an exploit in at least one unit. Large-scale exploits are most likely for the perfectly correlated case (scenario A – homogeneity) and least likely for the uncorrelated case (scenario C – heterogeneity). Attheindividual level,itappearslargelyimpossibletoinfluence the correlation of models. Companies may have to make a strategicdecision to resolve tensions between model homogeneity and heterogeneity. Suppliers will have to identify how many models are based ontheir TP.Manufacturers willfaceacontinuumofchoices. At the regulatory level, a decision may have to be made to which extent TP homogeneity and heterogeneity would be desired and enforced. III–V For x→∞, the relationship between scenarios A and C solely depends on the vulnerability probability pg. For x→∞, the lowering of vulnerability probability pg makes the use of one TP relatively riskier compared to two uncorrelated TPs. Anincreased vulnerabilityprobability directlyincreases the risk of large-scale exploits of TPs in IoT. Attheindividual level,itappearslargelyimpossibletoinfluence the correlation of models. Individuals should be aware of the TPs used and their vulnerabilities. Companies and regulators may thus have to step in to protect end-users. Suppliers should be incentivized to provide TPs with low vulnerability probabilities to manage the risks caused by TPC V. They may also rely on the use of established security standards, audits, security by design, and code testing. As manufacturers apply previously designed and supplied TPs, they have limited control over vulnerabilities. Nevertheless, they are incentivized to do their best when it comes to the selection of TPs and the related security audits. At the regulatory level, legal requirements and norms could be developed to avoid situations in which companies aim to achieve excessive conformity cost savings at the expense of higher levels of vulnerability. VI Increasing the exploit probability or the model size increases the probability P(X>x), especially for largescale exploits (x>x). For individuals and manufacturers, it is advisable to keep all smart things regularly updated. Most of the responsibility to limit exploits lies with the TP supplier. At the regulatory level, legal requirements and standards could be formulated, particularly in relation to critical infrastructures. 123
1486 Information Systems Frontiers (2025) 27:1471–1490 emphasize the impacts resulting from widespread IoT TP use and potential cascade effects within a highly interconnected IoT. We summarize the different potential governance measures relating to their respective TPCs in Table 2. Our research has several limitations, which may also stimulate further research on IoT TPs in at least five key areas. First, we focus on generic TP risks, so our governance implications require further elaboration for specific application fields or geographical regions. Future research could focus on a detailed IoT platform governance framework, taking the cause-and-effect-relationships from our paper as a theoretical foundation. Second, our model of TP risks in the IoT represents only an abstract image of complex realities, neglecting additional influencing factors. For instance, we have simplified interfaces, connectivity, model-specific platform adaptations, or inter-temporal facets. This opens promising avenues concerning the validation of our insights with extensive real-world datasets and making them more case-specific; for instance, assessing the severity of vulnerabilities/exploits and adjusting countermeasures accordingly (Cavusoglu et al., 2008). Third, we used a Poisson approximation for the binomial distribution, which limits our model’s applicability; other approximations may allow for a betterapplicabilityfor real-worldnumbers infutureresearch. Fourth, the explicit analysis of cascade effects in the IoT, for which the Bernoulli mixture model and our notion of correlation may be too simplistic, should be subject to future research. Fifth, our illustrative example focuses on two TPs in the IoT. Future research could thus expand on the model by including more than two TPs and conduct sensitivity analyses for cases in which the Poisson approximation does not hold. Whileit remainstobe seenwhowill tamesmartthings and prove to be the sorcerer in ‘IoT Fantasia’, we provide initial evidence on promising governance measures. Thus, we contribute to the descriptive body of knowledge by describing TP use in the IoT as well as the associated risks. By transferring a risk quantification approach from the automotive industry, we shed light on the implications on governance choices related to (non-) conformity on security threats in the IoT and thereby explore “the underlying causal structure of the theory” (cf. Meredith et al., 1989, p. 303). We outline which parameters of TPs affect the risks of TP use in the IoT, using the case of BusyBox as an example. Further, we delineate prescriptive governance implications resulting from the parametersofTPsintheIoT.Thus,wehelprevealtherelevant cause-and-effect relationships that individuals, companies, and regulators can incorporate for sound risk assessments. Acknowledgements This research was funded in part by the Luxembourg National Research Fund (FNR) and PayPal, PEARL grant reference 13342933/Gilbert Fridgen, as well as grant reference 16326754/ PABLO. Supported by Banque et Caisse d’Épargne de l’État, Luxembourg (Spuerkeess). For the purpose of open access, and in fulfillment of the obligations arising from the grant agreement, the authors have applied a Creative Commons Attribution 4.0 International (CC BY 4.0) license to any Author Accepted Manuscript version arising from this submission. Author Contributions Martin Brennecke: Conceptualization, validation, data curation, writing – original draft, writing – review and editing, project administration. Gilbert Fridgen: Conceptualization, resources, writing – review and editing, supervision, funding acquisition. Jan Jöhnk: Conceptualization, methodology, validation, formal analysis, data curation, writing – original draft, writing – review and editing, visualization, project administration. Sven Radszuwill: Conceptualization, methodology, validation, formal analysis, data curation, writing – original draft, writing – review and editing, visualization. Johannes Sedlmeir: Conceptualization, validation, data curation, writing – original draft, writing – review and editing, supervision. Funding Open Access funding enabled and organized by Projekt DEAL. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitteduse,youwillneedtoobtainpermissiondirectlyfromthecopyright holder. To view a copy of this licence, visit http://creativecomm ons.org/licenses/by/4.0/. References Aftergood, S. (2018). Governments want your smart devices to have stupidsecurity flaws.Nature, 560(7720), 550–551. https://doi.org/ 10.1038/d41586-018-06033-9 Almeida, V. A., Doneda, D., & Monteiro, M. (2015). Governance Challenges for the Internet of Things. IEEE Internet Computing, 19(4), 56–59. https://doi.org/10.1109/MIC.2015.86 Alter, S. (2019). Making sense of smartness in the context of smart devices and smart systems. Information Systems Frontiers, 9(4), 381–393. https://doi.org/10.1007/s10796-019-09919-9 Arentz, S. (2005). Hacking Linux-powered devices. Retrieved March 25, 2024, from http://bofh.nikhef.nl/events/CCC/congress/21c3/ papers/136%20Hacking%20Linux-Powered%20Devices.pdf Arnold, L., Jöhnk, J., Vogt, F., & Urbach, N. (2022). IIoT platforms’ architectural features - a taxonomy and five prevalent archetypes. Electronic Markets, 32(2), 927–944. https://doi.org/ 10.1007/s12525-021-00520-0 Arora, A., Krishnan, R., Telang, R., & Yang, Y. (2010). An empirical analysis of software vendors’ patch release behavior: impact of vulnerability disclosure. Information Systems Research, 21(1), 115–132. https://doi.org/10.1287/isre.1080.0226 Atzori, L., Iera, A., & Morabito, G. (2010). The Internet of Things: A survey. Computer Networks, 54(15), 2787–2805. https://doi.org/ 10.1016/j.comnet.2010.05.010 Axelrod, C.W. (2015). Enforcing security, safety and privacy for the InternetofThings.In:Long Island Systems, Applications and Technologyhttps://doi.org/10.1109/LISAT.2015.7160214 123
Information Systems Frontiers (2025) 27:1471–1490 1487 Baldwin, C.Y., & Woodard, C.J. (2008). The architecture of platforms: a unified view. Harvard Business School Finance Working Paper, (09-034) https://doi.org/10.2139/ssrn.1265155 Bandyopadhyay, K., Mykytyn, P. P., & Mykytyn, K. (1999). A framework for integrated risk management in information technology. Management Decision, 37(5), 437–445. https://doi.org/10.1108/ 00251749910274216 Bhat, M.I., & Giri, K.J. (2021). Impact of computational power on cryptography. In: K. J. Giri, S. A. Parah, R. Bashir, & K. Muhammad(Eds.),Multimediasecurity:Algorithmdevelopment,analysis and applications (pp. 45–88). https://doi.org/10.1007/978-98115-8711-5_4 Biswas, B., Mukhopadhyay, A., Bhattacharjee, S., Kumar, A., & Delen, D. (2022). A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums. Decision Support Systems, 152, 113651. https://doi.org/10.1016/ j.dss.2021.113651 Biswas, B., Mukhopadhyay, A., Kumar, A., & Delen, D. (2023). A hybrid framework using explainable AI (XAI) in cyber-risk management for defence and recovery against phishing attacks. Decision Support Systems., 177, 114102. https://doi.org/10.1016/ j.dss.2023.114102 Bluhm,C.,Overbeck,L.,& Wagner, C. (2010).An introduction to credit risk modeling. Chapman Borgia, E. (2014). The Internet of Things vision: Key features, applications and open issues. Computer Communications,54,. https://doi. org/10.1016/j.comcom.2014.09.008 Boulanger, A. (2005). Open-source versus proprietary software: Is one more reliable and secure than the other? IBM Systems Journal, 44(2), 239–248. https://doi.org/10.1147/sj.442.0239 Buck, C., Olenberger, C., Schweizer, A., Völter, F., & Eymann, T. (2021). Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust. Computers & Security, 110, 102436. https://doi.org/10.1016/j.cose.2021. 102436 Buldyrev, S. V., Parshani, R., Paul, G., Stanley, H. E., & Havlin, S. (2010). Catastrophic cascade of failures in interdependent networks. Nature, 464, 1025–1028. https://doi.org/10.1038/ nature08932 BusyBox. (2022). The swiss army knife of embedded Linux: Products. Retrieved March 25, 2024, from https://www.busybox.net/about. html Cavusoglu, H., Cavusoglu, H., & Zhang, J. (2008). Security patch management: Share the burden or share the damage? Management Science, 54(4),657–670.https://doi.org/10.1287/mnsc.1070.0794 CISA. (2021). Statement from CISA Director Easterly on Log4j Vulnerability. Retrieved March 25, 2024, from https://www.cisa. gov/news-events/news/statement-cisa-director-easterly-log4jvulnerability Chen, P.-Y., Kataria, G., & Krishnan, R. (2011). Correlated failures, diversification, and information security risk management. MIS Quarterly, 35(2), 397–422. https://doi.org/10.2307/23044049 Colwill, C. (2009). Human factors in information security: The insider threatwho can you trust these days? Information Security Technical Report, 14(4), 186–196. https://doi.org/10.1016/j.istr.2010. 04.004 COM/2022/454 final. (2022). Proposal for a Directive of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 (Cyber Resilience Act). Retrieved March 25, 2024, from https://eur-lex.europa.eu/legal-content/EN/ TXT/?uri=celex:52022PC0454 COM/2022/495 final. (2022). Proposal for a Directive of the European Parliament and of the Council on liability for defective products (New Product Liability Directive). Retrieved March 25, 2024, from https://eur-lex.europa.eu/legal-content/EN/TXT/? uri=CELEX:52022PC0495 Preliminary post incident review (pir): Content configuration update impacting the falcon sensor and the windows operating system (bsod). Retrieved July 24, 2024, from https://www.crowdstrike. com/falcon-contentupdate-remediation-and-guidance-hub/ CVE-2016-2148. (2016) Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. Retrieved March 25, 2024, from https://www.cvedetails. com/cve/CVE-2016-2148/ CVE-2018-1000517. (2018). BusyBox project BusyBox wget version prior to commit 8e... contains a buffer overflow vulnerability. Retrieved March 25, 2024, from https://www.cvedetails.com/cve/ CVE-2018-1000517/ CVE-2022-48174. (2022). There is a stack overflow vulnerability in ash.c:6030 in BusyBox before 1.35. Retrieved March 25, 2024, from https://www.cvedetails.com/cve/CVE-2022-48174/ Cybersecurity & Infrastructure Security Agency. (2024). Industrial Control Systems. Retrieved March 25, 2024, from https://www. cisa.gov/topics/industrial-control-systems Cybersecurityhelp. (2022). #U65004 OS command injection in BusyBox. Retrieved from https://www.cybersecurity-help.cz/ vulnerabilities/65004/ Dailymail, (2016). Cyber attacks cripple Twitter, Netflix, other websites. Retrieved March 25, 2024, from http://www.dailymail. co.uk/wires/afp/article-3859624/Twitter-Spotify-websites-shutDDOS-attack.html Dibia, V., & Wagner, C. (2015). Success within app distribution platforms: the contribution of app diversity and app cohesivity. (4304–4313) https://doi.org/10.1109/HICSS.2015.515 Directive (EU) 2022/2555. (2022). Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Retrieved March 25, 2024, from http://data.europa. eu/eli/dir/2022/2555/oj Economides, N., & Katsamakas, E. (2006). Two-sided competition of proprietary vs. open source technology platforms and the implications for the software industry. Management Science,52(7), 1057–1071 https://doi.org/10.1287/mnsc.1060.0549 Eden, P., Blyth, A., Jones, K., Soulsby, H., Burnap, P., Cherdantseva, Y., & Stoddart, K. (2017). SCADA System Forensic Analysis Within IIoT. In: Advanced Manufacturing, Cybersecurity for Industry 4.0: Analysis for Design and Manufacturing (pp. 73–101). Springer. Eltayeb, M.A. (2017). Internet of Things: Privacy and security implications. International Journal of Hyperconnectivity and the Internet of Things,1(1), https://doi.org/10.4018/IJHIoT.2017010101 Faber, B., & Günther, O. (2007). Distributed ONS and its impact on privacy. IEEE International Conference on Communications, (1223–1228) https://doi.org/10.1109/ICC.2007.207 Fabozzi, F. J., Kolm, P. N., Pachamanova, D. A., & Focardi, S. M. (2007). Robust portfolio optimization and management. John Wiley. Facin, A. L. F., de Vasconcelos Gomes, L. A., de Mesquita Spinola, M., & Salerno, M. S. (2016). The evolution of the platform concept: a systematic review. IEEE Transactions on Engineering Management, 63(4), 475–488. https://doi.org/10.1109/TEM. 2016.2593604 Federal Trade Commission. (2017). FTC charges D-Link put consumers’ privacy at risk due to the inadequate security of its computer routers and cameras: Device-maker’s alleged failures to reasonably secure software created malware risks and other vulnerabilities. Retrieved March 25, 2024, from https://www. ftc.gov/news-events/news/press-releases/2017/01/ftc-charges123
1488 Information Systems Frontiers (2025) 27:1471–1490 d-link-put-consumers-privacy-risk-due-inadequate-security-itscomputer-routers-cameras Fichman, R. G. (2014). Real options and IT platform adoption: implicationsfor theory andpractice.Information Systems Research, 15(2), 132–154. https://doi.org/10.1287/isre.1040.0021 Financial Times (2024). Companies around the world hit by Microsoft outage. Retrieved July 19, 2024, fromhttps://www.ft.com/content/ fba9b61d-efcf-4348-b640-ccb1f9d18ced Frank, M., Jaeger, L., & Ranft, L. M. (2022). Contextual drivers of employees’ phishing susceptibility: Insights from a field study. Decision Support Systems, 160, 113818. https://doi.org/10.1016/ j.dss.2022.113818 Gawer,A.(2014).Bridging differingperspectivesontechnologicalplatforms: toward an integrative framework. Research Policy, 43(7), 1239–1249. https://doi.org/10.1016/j.respol.2014.03.006 Gepp, M., Foehr, M., & Vollmar, J. (2016). Standardization, modularization and platform approaches in the engineer-to-order business – review and outlook. In: Proceedings of the Annual IEEE Systems Conference. https://doi.org/10.1109/SYSCON.2016.7490549 Giesecke, K. (2004). Credit risk modeling and valuation: an introduction. Credit Risk: Models and Management,2,. https://doi.org/10. 2139/ssrn.479323 Giesecke, K., & Weber, S. (2004). Cyclical correlations, credit contagion,andportfoliolosses.Journal of Banking and Finance, 28(12), 3009–3036. https://doi.org/10.1016/j.jbankfin.2003.11.002 Hampson, M. (2019) IoT security risks: drones, vibrators, and kids’ toys are still vulnerable to hacking. Retrieved March 25, 2024, from https://spectrum.ieee.org/iot-security-risks-dronesvibrators-iot-devices-kids-toys-vulnerable-to-hacking Hartwich, E., Rieger, A., Sedlmeir, J., Jurek, D., & Fridgen, G. (2023). Machine economies. Electronic Markets,33,. https://doi.org/10. 1007/s12525-023-00649-0 Helbing, D. (2013). Globally networked risks and how to respond. Nature, 497(7447), 51–59. https://doi.org/10.1038/nature12047 Howard, J.D., & Longstaff, T.A. (1998). A common language for computer security incidents. Sandia National Laboratories Huber, R.X.R., Lockl, J., Röglinger, M., & Weidlich, R., (2024). The Concept of a Smart Action–Results from Analyzing Information Systems Literature. Communications of the Association for Information Systems,54(1), 6 https://doi.org/10.17705/1CAIS.05408 ICS-CERT. (2018a). ICSA-15-260-01: Harman-Kardon Uconnect vulnerability. Retrieved March 25, 2024, from https://ics-cert.us-cert. gov/advisories/ICSA-15-260-01 ICS-CERT. (2018b). ICSA-17-208-01: Continental AG Infineon SGold 2 (PMB 8876). Retrieved March 25, 2024, from https://icscert.us-cert.gov/advisories/ICSA-17-208-01 ISO/SAE 21434:2021. (2021). Road vehicles: Cybersecurity engineering standard of the International Organization for Standardization. Retrieved March 25, 2024, https://www.iso.org/standard/70918. html Kang, C. M., Hong, Y. S., Huh, W. T., & Kang, W. (2015). Risk propagation through a platform: the failure risk perspective on platform sharing. IEEE Transactions on Engineering Management, 62(3), 372–383. https://doi.org/10.1109/TEM.2015.2427844 Karale, A. (2021). The Challenges of IoT Addressing Security, Ethics, Privacy, and Laws. Internet of Things,15,. https://doi.org/10.1016/ j.iot.2021.100420 Keoh, S. L., Kumar, S. S., & Tschofenig, H. (2014). Securing the Internet of Things: A standardization perspective. IEEE Internet of Things Journal, 1(3), 265–275. https://doi.org/10.1109/JIOT. 2014.2323395 Kim, K., & Altmann, J. (2020). Platform provider roles in innovation in software service ecosystems. IEEE Transactions on Engineering Management, 69(4), 930–939. https://doi.org/10.1109/TEM. 2019.2949023 Kocher, P., Horn, J., Fogh, A., Genkin, D., Gruss, D., Haas, W.,..., Yarom, Y. (2018). Spectre attacks: Exploiting speculative execution. Retrieved March 25, 2024, https://spectreattack.com/spectre. pdf Kim, D.-h., Lee, H., Kwak, J. (2017). Standards as a driving force that influences emerging technological trajectories in the converging world of the internet and things: An investigation of the M2M/IoT patent network. Research Policy, 46(7), 1234–1254. https://doi. org/10.1016/j.respol.2017.05.008 Lee, C. H., Geng, X., & Raghunathan, S. (2016). Mandatory standards and organizational information security. Information Systems Research., 27(1), 70–86. https://doi.org/10.1287/isre.2015.0607 Lemos, R. (2024). SAST, DAST, IAST, and RASP: Pros, cons and how to choose. Techbeacon. Retrieved March 25, 2024, from https:// techbeacon.com/sast-dast-iast-rasp-pros-cons-how-choose Li, S., Xu, L. D., & Zhao, S. (2015). The Internet of Things: A survey. Information Systems Frontiers, 17(2),243–259.https://doi.org/10. 1007/s10796-014-9492-7 Lins, M., Mayrhofer, R., Roland, M., Hofer, D., & Schwaighofer, M. (2024). On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from xz. https://doi.org/10.48550/arXiv.2404 08987 Linton, M., & Parseghian, P. (2018). Today’s CPU vulnerability: What you need to know. Retrieved March 25, 2024, from https://security.googleblog.com/2018/01/todays-cpuvulnerability-what-you-need.html Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Fogh, A., ..., Hamburg, M. (2018). Meltdown. Retrieved March 25, 2024, from https://meltdownattack.com/meltdown.pdf Medeiros, J. (2017). WannaCry laid bare the NHS’ outdated IT network – and it’s still causing problems: The effects of the WannaCry attack are still being felt at NHS hospitals. Retrieved July 25, 2024, from http://www.wired.co.uk/article/nhs-cyberattackit-ransomware Meneghello, F., Calore, M., Zucchetto, D., Polese, M., & Zanella, A. (2019). IoT: Internet of threats? A survey of practical security vulnerabilitiesinrealIoTdevices.IEEE Internet of Things Journal, 6(5), 8182–8201. https://doi.org/10.1109/JIOT.2019.2935189 Meredith, J. R., Raturi, A., Amoako-Gympah, K., & Kaplan, B. (1989). Alternative research paradigms in operations. Journal of Operations Management, 8(4), 297–326. https://doi.org/10.1016/02726963(89)90033-8 Microsoft Threat Intelligence. (2021). Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability. Retrieved March 25, 2024, from https://www.microsoft.com/enus/security/blog/2021/12/11/guidance-for-preventing-detectingand-hunting-for-cve-2021-44228-log4j-2-exploitation/#attacks Miller, B., & Rowe, D. (2012). A survey SCADA of and critical infrastructure incidents. 1st Annual Conference on Research in Information Technology, 51–56 https://doi.org/10.1145/2380790. 2380805 Ministry of Internal Affairs and Communications, National Institute of Information and Communications Technology. (2019). The “NOTICE” project to survey IoT devices and to alert users. Retrieved March 25, 2024, from https://www.nict.go.jp/en/press/ 2019/02/01-1.html Mohamad Noor, M., & Haslina Hassan, W. (2019). Current research on Internet of Things (IoT) security: a survey. Computer Networks, 148(15), 283–294. https://doi.org/10.1016/j.comnet.2018.11.025 Neville-Neil, G. V. (2017). IoT: The Internet of Terror. Communications of the ACM, 60(10), 46–37. https://doi.org/10.1145/3132728 Nicolescu, R., Huth, M., Radanliev, P., & Roure, D. D. (2018). Mapping the values of IoT. Journal of Information Technology, 33(4), 345– 360. https://doi.org/10.1057/s41265-018-0054-1 123
Information Systems Frontiers (2025) 27:1471–1490 1489 Porch, C., Timbrell, G., & Rosemann, M. (2015). Platforms: a systematic review of the literature using algorithmic histography. https:// doi.org/10.18151/7217443 Prakash, B. A., Chakrabarti, D., Valler, N. C., Faloutsos, M., & Faloutsos, C. (2012). Threshold conditions for arbitrary cascade models onarbitrary networks.Knowledge and Information Systems, 33(3), 549–575. https://doi.org/10.1007/s10115-012-0520-y Püschel, L., Schlott, H., & Röglinger, M. (2016). What’s in a smart thing? Development of a multi-layer taxonomy. Proceedings of the 37th International Conference on Information Systems. Retrieved March 25, 2024, from https://aisel.aisnet.org/icis2016/ DigitalInnovation/Presentations/6 Radanliev, P., Roure, D. C. D., Nicolescu, R., Huth, M., Montalvo, R. M., Cannady, S., & Burnap, P. (2018). Future developments in cyber risk assessment for the Internet of Things. Computers in Industry, 102, 14–22. https://doi.org/10.1016/j.compind.2018.08. 002 Rainer, R. K., Jr., Snyder, C. A., & Carr, H. H. (1991). Risk analysis for information technology. Journal of Management Information Systems, 8(1), 129–147. https://doi.org/10.1080/07421222.1991. 11517914 Ransbotham, S., Fichman, R. G., Gopal, R., & Gupta, A. (2016). Special section introduction - ubiquitous IT and digital vulnerabilities. Information System Research, 27(4), 834–847. https://doi.org/10. 1287/isre.2016.0683 Rausand,M.,Barros,A.,&Hoyland,A.(2020).SystemReliabilityTheory: Models, Statistical Methods, and Applications. John Wiley & Sons. https://doi.org/10.1002/9781119373940 Regulation (EU) 2016/679. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Retrieved March 25, 2024, from http://data.europa.eu/eli/ reg/2016/679/oj Regulation (EU) 2018/858. (2018). Regulation (EU) 2018/858 of the European Parliament and of the Council of 30 May 2018 on the approval and market surveillance of motor vehicles and their trailers, and of systems, components and separate technical units intended for such vehicles, amending Regulations (EC) No 715/2007 and (EC) No 595/2009 and repealing Directive 2007/46/EC. Retrieved March 25, 2024, from http://data.europa. eu/eli/reg/2018/858/oj Regulation (EU) 2019/2144. (2019). Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users, amending Regulation (EU) 2018/858 of the European Parliament and of the Council and repealing Regulations (EC) No 78/2009, (EC) No 79/2009 and (EC) No 661/2009 of the European Parliament and of the Council and Commission Regulations (EC) No 631/2009, (EU) No 406/2010, (EU) No 672/2010, (EU) No 1003/2010, (EU) No 1005/2010, (EU) No 1008/2010, (EU) No 1009/2010, (EU) No 19/2011,(EU)No109/2011,(EU)No458/2011,(EU)No65/2012, (EU) No 130/2012, (EU) No 347/2012, (EU) No 351/2012, (EU) No 1230/2012 and (EU) 2015/166. Retrieved March 25, 2024, from http://data.europa.eu/eli/reg/2019/2144/oj Rieger,A., Thummert,R., Fridgen,G., Kahlen, M.,& Ketter,W. (2016). Estimating the benefits of cooperation in a residential microgrid: A data-driven approach. Applied Energy, 180, 130–141. https:// doi.org/10.1016/j.apenergy.2016.07.105 Ronen, E., O’Flynn, C., Shamir, A., & Weingarten, A.O. (2016). IoT goes nuclear: creating a ZigBee chain reaction. Retrieved March 25, 2024, from https://eprint.iacr.org/2016/1047.pdf Roy, A. D. (1952). Safety first and the holding of assets. Econometrica, 20(3), 431. https://doi.org/10.2307/1907413 Sadeghi, A.R., Wachsmann, C., & Waidner, M. (2015). Security and privacy challenges in industrial Internet of Things. Proceedings of the 52nd Annual Design Automation Conference.https://doi.org/ 10.1145/2744769.2747942 Sicari, S., Cappiello, C., Pellegrini, F. D., Miorandi, D., & CoenPorisini, A. (2016). A security-and quality-aware system architecture for Internet of Things. Information Systems Research, 18(4), 665–677. https://doi.org/10.1007/s10796-014-9538-x Siponen, M. T., & Oinas-Kukkonen, H. (2007). A review of information security issues and respective research contributions. ACM SIGMIS Database, 38(1), 60–80. https://doi.org/10.1145/1216218. 1216224 Slaughter, S. A., Harter, D. E., & Krishnan, M. S. (1998). Evaluating the cost of software quality. Communications of the ACM, 41(8), 67–73. https://doi.org/10.1145/280324.280335 Smartfrog Ltd. (2012). Open source terms. Retrieved March 25, 2024, from https://www.smartfrog.com/en-us/open-source-terms Syed, R. (2020). Cybersecurity vulnerability management: A conceptual ontology and cyber intelligence alert system. Information & Management, 57(6), 103334. https://doi.org/10.1016/j.im.2020. 103334 Temizkan, O., Park, S., & Saydam, C. (2017). Software diversity for improvednetworksecurity:Optimaldistributionofsoftware-based shared vulnerabilities. Information Systems Research, 28(4), 828– 849. https://doi.org/10.1287/isre.2017.0722 Thielmann, S. (2017). Acting federal trade commission head: Internet of Things should self-regulate. Retrieved March 25, 2024, from https://www.theguardian.com/technology/2017/mar/ 14/federal-trade-commission-internet-things-regulation Thomas, L. D. W., Autio, E., & Gann, D. M. (2014). Architectural leverage: Putting platforms in context. Academy of Management Perspectives, 28(2), 198–219. https://doi.org/10.5465/amp.2011. 0105 TomTom, T. (2005). Open source software: TomTom GO 4. Retrieved March 25, 2024, from https://www.tomtom.com/de_at/ opensource/go-version-4 Travis, G. (2019). How the Boeing 737 Max disaster looks to a software developer. IEEE Spectrum,18. Retrieved from https:// spectrum.ieee.org/how-the-boeing-737-max-disaster-looks-toa-software-developer Vermesan, O., & Friess, P. (Eds.) (2022). Digitising the industry Internet of Things connecting the physical, digital and VirtualWorlds. Taylor & Francis Violino, B. (2017). FTC vs D-Link: The legal risks of IoT insecurity: Vulnerabilities in connected devices spell potential trouble for product manufacturers. Retrieved March 25, 2024, from https://www.zdnet.com/article/ftc-vs-d-link-thelegal-risks-of-iot-insecurity/ Vectra AI Security Research Team. (2016). How a webcam Can Be exploited as a backdoor, 2024-07-25. https://www.vectra.ai/blog/ turning-a-webcam-into-a-backdoor von Solms, R., & van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97–102. https://doi.org/ 10.1016/j.cose.2013.04.004 Waldo, J. (2002). Virtual organizations, pervasive computing, and an infrastructure for networking at the edge. Information Systems Frontiers, 4(1), 9–18. https://doi.org/10.1023/A:1015322219248 Walters, R., & Jordan, J. (2016). US must remain vigilant to counter cyberattacks. Retrieved March 25, 2024, from http://dailysignal. com/2016/10/26/how-a-cyberattack-took-down-twitter-netflixand-the-new-york-times/ Wang, H., He, H., Zhang, W., Liu, W., Liu, P., & Javadpour, A. (2022). Using honeypots to model botnet attacks on the Internet of Medi123
1490 Information Systems Frontiers (2025) 27:1471–1490 cal Things. Computers and Electrical Engineering, 102, 108212. https://doi.org/10.1016/j.compeleceng.2022.108212 Watts, D.J. (2002). In A simple model of global cascades on random networks (Vol. 99, 5766–5771). https://doi.org/10.1073/pnas. 082090499 Weber, R. H. (2010). Internet of Things - new security and privacy challenges. Computer Law & Security Review, 26(1), 23–30. https:// doi.org/10.1016/j.clsr.2009.11.008 Weber, R. H. (2013). Internet of Things - governance quo vadis? Computer Law & Security Review, 29(4), 341–347. https://doi.org/10. 1016/j.clsr.2013.05.010 Weigl, L., Barberea, T., Sedlmeir, J., & Zavolokina, L. (2023). Mediating the tension between data sharing and privacy: The case of DMA and GDPR. In: Proceedings of the 31st European Conference on Information Systems, AIS. Retrieved from https://aisel. aisnet.org/ecis2023_rip/49/ West, J. (2003). How open is open enough? Melding proprietary and open source platform strategies. Research Policy, 32(7), 1259– 1285. https://doi.org/10.1016/S0048-7333(03)00052-0 Whitmore, A., Agarwal, A., & Xu, L. D. (2015). The Internet of Things - a survey of topics and trends. Information Systems Frontiers, 17(2), 261–274. https://doi.org/10.1007/s10796-014-9489-2 Yoo, Y. (2010). Computing in every day life: A call for research on experiential computing. MIS Quarterly, 34(2), 213–231. https:// doi.org/10.2307/20721425 Yoo, Y., Jr., R. J. B., Lyytinen, K., & Majchrzak, A. (2012). Organizing for innovation in the digitized world. Organization Science, 23(5), 1398–1408. https://doi.org/10.1287/orsc.1120.0771 York, D. (2018). Meltdown and Spectre: Why we need vigilance, upgradeability, and collaborative security. Retrieved March 25, 2024, from https://www.internetsociety.org/blog/2018/01/ meltdown-spectre-need-vigilance-upgradeability-collaborativesecurity/ Zhou,W., Jia, Y., Peng, A.,Zhang, Y., &Liu, P. (2019). Theeffectof IoT new features on security and privacy: new threats, existing solutions, and challenges yet to be solved. Internet of Things Journal, 6(2), 1606–1616. https://doi.org/10.1109/JIOT.2018.2847733 Publisher’s Note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. Martin Brennecke is a doctoral researcher at the Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg. In his research, he investigates the impact of digital infrastructure decentralization on individuals, organizations, and society. He holds a master’s degree in international economics and governance, as well as a bachelor’s degree in philosophy and economics. Gilbert Fridgen is a full professor and PayPal FNR PEARL Chair in Digital Financial Services at the Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg, and coordinator of the National Centre of Excellence in Research on Financial Technologies (NCER-FT). In his research, he analyzes the transformative effects of digital technologies on individual organizations and on the relationship between organizations. He addresses especially emerging technologies like distributed ledgers, digital identities, machine learning, and the internet of things. Jan Jöhnk is a product owner at the commercial insurance company HDI Global SE in Hanover, Germany, and an affiliated researcher at the FIM Research Institute for Information Management. He received his doctorate in Information Systems and Strategic IT Management from the University of Bayreuth and visited the Department of Digitalization at Copenhagen Business School for a research stay. In his research, Jan is especially interested in questions of digital transformation at the interface of IT organization, IT management, and emerging technologies. Sven Radszuwill is a department head for new products and services at a health-tech software company, former researcher at the University of Bayreuth and Fraunhofer FIT in the area of digital networks, project management, and distributed ledger technologies. Johannes Sedlmeir is a postdoctoral researcher at the Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg. In his research, he focuses on the effective use of emerging digital technologies in organizations by designing and evaluating innovative IT artifacts based on, e.g., distributed ledgers, digital identity attestations, and zero-knowledge proofs. 123