Paper Type

Complete

Abstract

Modern IT landscapes are defined by complex interdependencies that often translate into significant organizational liabilities. This study examines how structural IT complexity directly shapes data breach exposure, moving beyond prior work that infers complexity from organizational events (e.g., mergers and acquisitions) rather than measuring it in the firm’s technology footprint. Utilizing a firm-year panel from 2020 to 2022, we decompose IT structure into three observable dimensions that capture software complexity, hardware scale, and hardware heterogeneity. Results demonstrate that while software complexity and hardware scale are positively associated with breach likelihood, hardware heterogeneity reduces baseline risk by mitigating monoculture related failures. These effects are also interactive, with hardware heterogeneity strengthening the positive association between software complexity and breaches and pointing to a trade off in managing diverse environments. This research refines the conceptualization of attack surface and provides actionable implications for prioritizing governance and procurement strategies within complex IT portfolios.

Paper Number

1308

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

When complexity Becomes Exposure: Software Complexity, Hardware Structure, and Data Breaches

Modern IT landscapes are defined by complex interdependencies that often translate into significant organizational liabilities. This study examines how structural IT complexity directly shapes data breach exposure, moving beyond prior work that infers complexity from organizational events (e.g., mergers and acquisitions) rather than measuring it in the firm’s technology footprint. Utilizing a firm-year panel from 2020 to 2022, we decompose IT structure into three observable dimensions that capture software complexity, hardware scale, and hardware heterogeneity. Results demonstrate that while software complexity and hardware scale are positively associated with breach likelihood, hardware heterogeneity reduces baseline risk by mitigating monoculture related failures. These effects are also interactive, with hardware heterogeneity strengthening the positive association between software complexity and breaches and pointing to a trade off in managing diverse environments. This research refines the conceptualization of attack surface and provides actionable implications for prioritizing governance and procurement strategies within complex IT portfolios.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.