Paper Type
Complete
Abstract
Modern IT landscapes are defined by complex interdependencies that often translate into significant organizational liabilities. This study examines how structural IT complexity directly shapes data breach exposure, moving beyond prior work that infers complexity from organizational events (e.g., mergers and acquisitions) rather than measuring it in the firm’s technology footprint. Utilizing a firm-year panel from 2020 to 2022, we decompose IT structure into three observable dimensions that capture software complexity, hardware scale, and hardware heterogeneity. Results demonstrate that while software complexity and hardware scale are positively associated with breach likelihood, hardware heterogeneity reduces baseline risk by mitigating monoculture related failures. These effects are also interactive, with hardware heterogeneity strengthening the positive association between software complexity and breaches and pointing to a trade off in managing diverse environments. This research refines the conceptualization of attack surface and provides actionable implications for prioritizing governance and procurement strategies within complex IT portfolios.
Paper Number
1308
Recommended Citation
Zarfsazi, Arash and Parekh, Harsh, "When complexity Becomes Exposure: Software Complexity, Hardware Structure, and Data Breaches" (2026). AMCIS 2026 Proceedings. 4.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/4
When complexity Becomes Exposure: Software Complexity, Hardware Structure, and Data Breaches
Modern IT landscapes are defined by complex interdependencies that often translate into significant organizational liabilities. This study examines how structural IT complexity directly shapes data breach exposure, moving beyond prior work that infers complexity from organizational events (e.g., mergers and acquisitions) rather than measuring it in the firm’s technology footprint. Utilizing a firm-year panel from 2020 to 2022, we decompose IT structure into three observable dimensions that capture software complexity, hardware scale, and hardware heterogeneity. Results demonstrate that while software complexity and hardware scale are positively associated with breach likelihood, hardware heterogeneity reduces baseline risk by mitigating monoculture related failures. These effects are also interactive, with hardware heterogeneity strengthening the positive association between software complexity and breaches and pointing to a trade off in managing diverse environments. This research refines the conceptualization of attack surface and provides actionable implications for prioritizing governance and procurement strategies within complex IT portfolios.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC