Skip to Main Content
HBS Home
  • About
  • Academic Programs
  • Alumni
  • Faculty & Research
  • Baker Library
  • Giving
  • Harvard Business Review
  • Initiatives
  • News
  • Recruit
  • Map / Directions
Faculty & Research
  • Faculty
  • Research
  • Featured Topics
  • Academic Units
  • …→
  • Harvard Business School→
  • Faculty & Research→
Publications
Publications
  • 2024
  • Working Paper

Navigating Software Vulnerabilities: Eighteen Years of Evidence from Medium and Large U.S. Organizations

By: Raviv Murciano-Goroff, Ran Zhuo and Shane Greenstein
  • Format:Print
  • | Language:English
  • | Pages:60
ShareBar

Abstract

How prevalent are severe software vulnerabilities, how fast do software users respond to the availability of secure versions, and what determines the variance in the installation distribution? Using the largest dataset ever assembled on user updates, tracking server software updates by over 150,000 medium and large U.S. organizations between 2000 and 2018, this study finds widespread usage of server software with known vulnerabilities, with 57% of organizations using software with severe security vulnerabilities even when secure versions were available. The study estimates several different reduced-form models to examine which organization characteristics correlate with higher vulnerability prevalence and which update characteristics causally explain higher responsiveness to the releases of secure versions. The disclosure of severe vulnerability fixes in software updates does not jolt all organizations into installing them. Factors related to the cost of updating, such as whether the software is hosted on a cloud-based platform and whether the update is an incremental change or a major overhaul, play an important role. Observables cannot easily explain much variation. These findings suggest that there could be high returns to incorporating organizations' relative (in)attentiveness to act on software update releases into the design of cybersecurity policies.

Keywords

Cybersecurity; Applications and Software; Technology Adoption; Consumer Behavior

Citation

Murciano-Goroff, Raviv, Ran Zhuo, and Shane Greenstein. "Navigating Software Vulnerabilities: Eighteen Years of Evidence from Medium and Large U.S. Organizations." NBER Working Paper Series, No. 32696, July 2024.
  • Find it at Harvard
  • Purchase

About The Author

Shane M. Greenstein

Technology and Operations Management
→More Publications

More from the Authors

    • February 2025
    • Faculty Research

    Intenseye: Powering Workplace Health and Safety with AI (B)

    By: Michael W. Toffel, Shane Greenstein and Sadika El Hariri
    • December 2024 (Revised January 2025)
    • Faculty Research

    A Guide to the Vocabulary, Evolution, and Impact of Artificial Intelligence (AI)

    By: Shane Greenstein, Nathaniel Lovin, Scott Wallsten, Kerry Herman and Susan Pinckney
    • November 2024 (Revised February 2025)
    • Faculty Research

    Hugging Face (A) and (B)

    By: Shane Greenstein, Nicole Zelazko and Kerry Herman
More from the Authors
  • Intenseye: Powering Workplace Health and Safety with AI (B) By: Michael W. Toffel, Shane Greenstein and Sadika El Hariri
  • A Guide to the Vocabulary, Evolution, and Impact of Artificial Intelligence (AI) By: Shane Greenstein, Nathaniel Lovin, Scott Wallsten, Kerry Herman and Susan Pinckney
  • Hugging Face (A) and (B) By: Shane Greenstein, Nicole Zelazko and Kerry Herman
ǁ
Campus Map
Harvard Business School
Soldiers Field
Boston, MA 02163
→Map & Directions
→More Contact Information
  • Make a Gift
  • Site Map
  • Jobs
  • Harvard University
  • Trademarks
  • Policies
  • Accessibility
  • Digital Accessibility
Copyright © President & Fellows of Harvard College.