Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer Products
Philipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling, Zinaida Benenson
Abstract
With the expansion of the Internet of Things (IoT), the number of security incidents due to insecure and misconfigured IoT devices is increasing. Especially on the consumer market, manufacturers focus on new features and early releases at the expense of a comprehensive security strategy. Hence, experts have started calling for regulation of the IoT consumer market, while policymakers are seeking for suitable regulatory approaches. We investigate how manufacturers can be incentivized to increase sustainable security efforts for IoT products. We propose mandatory security update labels that inform consumers during buying decisions about the willingness of the manufacturer to provide security updates in the future. Mandatory means that the labels explicitly state when security updates are not guaranteed. We conducted a user study with more than 1,400 participants to assess the importance of security update labels for the consumer choice by means of a conjoint analysis. The results show that the availability of security updates (until which date the updates are guaranteed) accounts for 8% to 35% impact on overall consumers’ choice, depending on the perceived security risk of the product category. For products with a high perceived security risk, this availability is twice as important as other high-ranked product attributes. Moreover, provisioning time for security updates (how quickly the product will be patched after a vulnerability is discovered) additionally accounts for 7% to 25% impact on consumers’ choices. The proposed labels are intuitively understood by consumers, do not require product assessments by third parties before release, and have a potential to incentivize manufacturers to provide sustainable security support.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- IoT Market Dynamics: An Analysis of Device Sales, Security and Privacy Signals, and their InteractionsSwaathi Vetrivel, Brennen Bouwmeester, Michel van Eeten, Carlos Hernandez GañánUSENIX Security 2024 · 2 citations
- Regulating Smart Device Support Periods: User Expectations and the European Cyber Resilience ActLorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten et al.USENIX Security 2025
- Are Consumers Willing to Pay for Security and Privacy of IoT Devices?Pardis Emami Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, Lorrie Faith CranorUSENIX Security 2023
- Missing, Present and Conflicting: A Large Scale Analysis of IoT Update Information in the EU MarketSwaathi Vetrivel, Michel van Eeten, Carlos H. GañánUSENIX Security 2026
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
Builds on3
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek et al.USENIX Security 2018 · 221 citations
Related papers
- Which Privacy and Security Attributes Most Impact Consumers' Risk Perception and Willingness to Purchase IoT Devices?Pardis Emami Naeini, Janarth Dheenadhayalan, Yuvraj Agarwal, Lorrie Faith CranorS&P 2021 · 80 citations
- Ask the Experts: What Should Be on an IoT Privacy and Security Label?Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan HibshiS&P 2020 · 195 citations
- Measuring Up to (Reasonable) Consumer Expectations: Providing an Empirical Basis for Holding IoT Manufacturers Legally ResponsibleLorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten et al.USENIX Security 2023
- "Belt and suspenders" or "just red tape"?: Investigating Early Artifacts and User Perceptions of IoT App Security CertificationPrianka Mandal, Amit Seal Ami, Victor Olaiya, Sayyed Hadi Razmjo et al.USENIX Security 2024 · 4 citations
- Examining Consumer Reviews to Understand Security and Privacy Issues in the Market of Smart Home DevicesSwaathi Vetrivel, Veerle van Harten, Carlos Hernandez Gañán, Michel van Eeten et al.USENIX Security 2023
