The sample breach notification letter from Glasswasherparts displays a company’s best efforts in informing its customers of a malicious attack that occurred on their systems. (Not exactly THEIR systems, but the systems they pay for) There are two economic and social theories that can be tied to the letter to best explain it, as well as expand on some of the potential ramifications. Firstly, the economic theories. I believe that rational choice and the Laissez-faire economic theories can best be used to explain the letter. The rational choice theory explains that the best option is usually taken by an individual or organization, choosing “pleasure over pain”. Rather than evade public/legal scrutiny, Glasswasherparts discloses the breach as soon as practicable. (One could argue that this could harm them and they’d get sued anyway. I’d agree, but it would most likely be worse if it was released they hid the breach, more reputational damage as well as legal troubles would be incurred if they kept the breach under wraps.) Laissez-faire economics can be seen in the handling of the situation. Rather than have the government in control of the entire situation, they are investigating the aftermath. Laissez-faire economics lines right up with the government’s actions in the letter, as Glasswasherparts explains that law enforcement was investigating the loss of personal liberty or inalienable rights, that being privacy.
Regarding social theories, I believe social exchange theory and social identity theory can be tied to the letter. Social exchange theory proposes the idea that there should be benefits between interactions, or “exchanges”. Be it goods, services, or monetary gain, there is a relationship through this exchange. Part of the relationship exchange between Glasswasherparts and its customer was not, however, the loss of PII, including credit card data. Reputational damage is definitely on the horizon, as customers feel robbed in a sense, as the private exchange relationship between them and the company has been breached. Social identity theory also relates to the letter. This theory posits that there are groups, and tribes that will be created through business or social relationships. (Sports teams being an example) Customers aligned themselves with Glasswasherparts as part of a group, and the letter harms the relationship where customers “identify” themselves with the company. Allegiance is a facet with all tribes and groups, and when trust is broken, as in the case of the cyber breach, some customers may leave for more reputable organizations.