Cyber Security Business Models in 5G 107
As previously mentioned, we observe cyber security as a phenomenon having
significant impact on two broad types of organization. The ones who directly or indirectly sell or provide security‐related solutions and all the other organizations that have
significant digital footprint, are thus vulnerable to cyber threats.
The companies providing different cyber security related products/services have two
broad customer groups. The more successful customer group so far has been that of
organizational entities, which are widely referred to as B2B (business‐to‐business)
customers or B2G (business‐to‐government) customers in business literature. This
group of customers has shown growing interest in investing in cyber security in recent
years for the purpose of their own business/organizational sustainability. Since business
organizations or government agencies are more cautious about the security of their
digital assets, there has been a steady business opportunity in this segment. However,
the second broad group of customers is individual consumers, who are referred to
as B2C (business‐to‐customer) customers. For security providers, penetrating this
customer group has been comparatively difficult up until now. The difficulty is triggered because until now the value of individual people’s private data/information on
the Internet and other networks was perhaps seen to be dispensable by individuals
themselves. Though, in the era of 5G, where trillions of Internet of Things (IoT) devices
are going to flood the home environment, this scene is likely to change.
The second type of companies whose business is affected by cyber security are those
who utilize cyberspace as a vital element for their businesses. This group can comprise
of almost all types of organization in the modern world. Among these, different organizations are exposed to different levels of cyber threat. Unfortunately, even in today’s
globalized world, we still have organizations who are unable to evaluate the value of the
digital information at their disposal and some fail to invest in it at all at times or do not
invest enough in security [39].
Traditionally, organizations invest in cyber security solutions based on the need for
security when improving cyber preparedness against potential attacks [39]. This strategy for investing in cyber security products/services has been beneficial for many
organizations, but failing to estimate the need for security has resulted in fatality many
times too. We believe that the lacking interest to invest an adequate amount in cyber
security solutions arises from the failure to generate new revenue.
In Figure 5.3, we plot our understanding of the relationship between the level of security
and new revenue generation. To make any digital solution (physical or virtual) with a
higher security level, organizations need to invest an additional sum. The main intent of
any business organization is to be profitable by creating new revenues against investment.
Hence, if organizations find ways to generate new revenue for the improved security level
of the solution, they would eventually be more interested in investing the required sum
(although we argue that additional investments in security may not always straightforwardly result in new revenue when there is no need for additional security). So, in practice,
organizations should analyze the level of their security need smartly and improve the
security level accordingly. In the case where the need for security and the level of security
is at an optimum balance, organizations can then push for new revenue generation.
Figure 5.3 thus reflects the case of new revenue generation and security level for
different technological eras. In this figure, we plot four different presumptive cases for
different technological eras as A, B, C and D. In the early days of the digital era, there
were many organizations who created handsome new revenues without having highly
As previously mentioned, we observe cyber security as a phenomenon having
significant impact on two broad types of organization. The ones who directly or indirectly sell or provide security‐related solutions and all the other organizations that have
significant digital footprint, are thus vulnerable to cyber threats.
The companies providing different cyber security related products/services have two
broad customer groups. The more successful customer group so far has been that of
organizational entities, which are widely referred to as B2B (business‐to‐business)
customers or B2G (business‐to‐government) customers in business literature. This
group of customers has shown growing interest in investing in cyber security in recent
years for the purpose of their own business/organizational sustainability. Since business
organizations or government agencies are more cautious about the security of their
digital assets, there has been a steady business opportunity in this segment. However,
the second broad group of customers is individual consumers, who are referred to
as B2C (business‐to‐customer) customers. For security providers, penetrating this
customer group has been comparatively difficult up until now. The difficulty is triggered because until now the value of individual people’s private data/information on
the Internet and other networks was perhaps seen to be dispensable by individuals
themselves. Though, in the era of 5G, where trillions of Internet of Things (IoT) devices
are going to flood the home environment, this scene is likely to change.
The second type of companies whose business is affected by cyber security are those
who utilize cyberspace as a vital element for their businesses. This group can comprise
of almost all types of organization in the modern world. Among these, different organizations are exposed to different levels of cyber threat. Unfortunately, even in today’s
globalized world, we still have organizations who are unable to evaluate the value of the
digital information at their disposal and some fail to invest in it at all at times or do not
invest enough in security [39].
Traditionally, organizations invest in cyber security solutions based on the need for
security when improving cyber preparedness against potential attacks [39]. This strategy for investing in cyber security products/services has been beneficial for many
organizations, but failing to estimate the need for security has resulted in fatality many
times too. We believe that the lacking interest to invest an adequate amount in cyber
security solutions arises from the failure to generate new revenue.
In Figure 5.3, we plot our understanding of the relationship between the level of security
and new revenue generation. To make any digital solution (physical or virtual) with a
higher security level, organizations need to invest an additional sum. The main intent of
any business organization is to be profitable by creating new revenues against investment.
Hence, if organizations find ways to generate new revenue for the improved security level
of the solution, they would eventually be more interested in investing the required sum
(although we argue that additional investments in security may not always straightforwardly result in new revenue when there is no need for additional security). So, in practice,
organizations should analyze the level of their security need smartly and improve the
security level accordingly. In the case where the need for security and the level of security
is at an optimum balance, organizations can then push for new revenue generation.
Figure 5.3 thus reflects the case of new revenue generation and security level for
different technological eras. In this figure, we plot four different presumptive cases for
different technological eras as A, B, C and D. In the early days of the digital era, there
were many organizations who created handsome new revenues without having highly
