Gomes, Iivari, Ahokangas, Isotalo, Sahlin, and Melén
100
fundamental for many technological businesses, as even a mediocre technology can
succeed in the markets if it has a well‐designed business model, but perfectly designed
technology may fail because of a weak business model [11]. This is even more crucial for
the cyber security business where failing in business may cause serious risks beyond
economical risks. The business model as a concept in the literature has been defined as
an architectural [12] system of interdependent activities [13] and an interrelated set of
core logic and strategic decision variables [10,14], explaining transaction content, transaction governance and transaction relationship structures [15,16] for maximized value
creation and value capturing [13]. Therefore, in this chapter we aim to display the possible business impacts of cyber security in 5G, in order to increase awareness of how
and why business model thinking matters.
The rest of the chapter is structured as follows: first, we discuss the context of cyber
security business in 5G by explaining the types and costs of cyber threats. In the next
part, we delve deeper into the business aspect of cyber security by opening up theoretical discussions on business models. We elaborate on how the business model approach
helps to identify more tenable business opportunities through the 4C framework. We
also present an overview of the business case for cyber security in 5G. We display four
scenarios for 5G security provisioning for the future, which leads us to draw the technical landscape from service and user perspectives. Furthermore, as the main contribution of this chapter, we present a business model framework for identifying avenues for
cyber security business in 5G and the relevant business model options.
5.2 The Context of Cyber Security Businesses
Cyber security is usually delivered by specific third‐party providers as a service, as a
product or as a combination of a service and product, which helps organizations and
individuals to protect their digital assets. From this perspective, there are two distinct
types of organization whose business is dependent on security. First are the organizations who are directly or indirectly involved in the delivery of security solutions.
These companies either sell the security as a service or as a bundle with some other
service, product or infrastructure. Second, there are all the other business organizations who have remarkable digital footprints and face the potential threats of cyber‐
attacks. In the imperfect world we live in, any cyber‐attack will have a direct or
indirect impact on either or both of these types of organizations’ business. In this
chapter, we show different ways to organize security offerings in the 5G era and how
to monetize that.
In this section, we first provide the readers with a general perspective on the economic
impact of the cyber security phenomenon and present a brief discussion on the types of
cyber threat and the cost of cyber‐attacks. Cyber threats can be defined as events or the
deliberate exploitation of vulnerabilities by threat agents or attack vectors leading to the
disruption of an organization’s operations, or the loss or takeover of an organization’s
assets [17]. The threat to an organization’s assets (like information and IT infrastructure)
may arise from a natural occurrence such as an earthquake, equipment failure or the
unintentional actions of employees. However, a deliberate, planned attack – which poses
the highest risk and is able to wreak incalculable loss to organizations – is of interest
in this chapter.
100
fundamental for many technological businesses, as even a mediocre technology can
succeed in the markets if it has a well‐designed business model, but perfectly designed
technology may fail because of a weak business model [11]. This is even more crucial for
the cyber security business where failing in business may cause serious risks beyond
economical risks. The business model as a concept in the literature has been defined as
an architectural [12] system of interdependent activities [13] and an interrelated set of
core logic and strategic decision variables [10,14], explaining transaction content, transaction governance and transaction relationship structures [15,16] for maximized value
creation and value capturing [13]. Therefore, in this chapter we aim to display the possible business impacts of cyber security in 5G, in order to increase awareness of how
and why business model thinking matters.
The rest of the chapter is structured as follows: first, we discuss the context of cyber
security business in 5G by explaining the types and costs of cyber threats. In the next
part, we delve deeper into the business aspect of cyber security by opening up theoretical discussions on business models. We elaborate on how the business model approach
helps to identify more tenable business opportunities through the 4C framework. We
also present an overview of the business case for cyber security in 5G. We display four
scenarios for 5G security provisioning for the future, which leads us to draw the technical landscape from service and user perspectives. Furthermore, as the main contribution of this chapter, we present a business model framework for identifying avenues for
cyber security business in 5G and the relevant business model options.
5.2 The Context of Cyber Security Businesses
Cyber security is usually delivered by specific third‐party providers as a service, as a
product or as a combination of a service and product, which helps organizations and
individuals to protect their digital assets. From this perspective, there are two distinct
types of organization whose business is dependent on security. First are the organizations who are directly or indirectly involved in the delivery of security solutions.
These companies either sell the security as a service or as a bundle with some other
service, product or infrastructure. Second, there are all the other business organizations who have remarkable digital footprints and face the potential threats of cyber‐
attacks. In the imperfect world we live in, any cyber‐attack will have a direct or
indirect impact on either or both of these types of organizations’ business. In this
chapter, we show different ways to organize security offerings in the 5G era and how
to monetize that.
In this section, we first provide the readers with a general perspective on the economic
impact of the cyber security phenomenon and present a brief discussion on the types of
cyber threat and the cost of cyber‐attacks. Cyber threats can be defined as events or the
deliberate exploitation of vulnerabilities by threat agents or attack vectors leading to the
disruption of an organization’s operations, or the loss or takeover of an organization’s
assets [17]. The threat to an organization’s assets (like information and IT infrastructure)
may arise from a natural occurrence such as an earthquake, equipment failure or the
unintentional actions of employees. However, a deliberate, planned attack – which poses
the highest risk and is able to wreak incalculable loss to organizations – is of interest
in this chapter.
