Guest Editorial: “Complexity is the Worst Enemy of Security”: Studying Cybersecurity Through the Lens of Organizational Complexity

Bruce Schneier & Anthony Vance

MIS Quarterly2025https://doi.org/10.25300/misq/2025/49.1.075article
FT50UTD24AJG 4*ABDC A*
Weight
0.52

Abstract

Writing about computer systems twenty-five years ago, Schneier wrote that “the worst enemy of security is complexity” (Schneier, 1999), because complex systems are both easier to attack and harder to secure than simpler ones. In this essay, we provide an overview of Schneier’s complexity principle and provide our observations of how two articles in this issue, Liang et al. (2025) and Tanriverdi et al. (2025), employed this principle in their research. We also offer our ideas for why complexity and cybersecurity are especially amenable for study in the field of information systems and where future research can go from here.

7 citations

Open via your library →

Cite this paper

https://doi.org/https://doi.org/10.25300/misq/2025/49.1.075

Or copy a formatted citation

@article{bruce2025,
  title        = {{Guest Editorial: “Complexity is the Worst Enemy of Security”: Studying Cybersecurity Through the Lens of Organizational Complexity}},
  author       = {Bruce Schneier & Anthony Vance},
  journal      = {MIS Quarterly},
  year         = {2025},
  doi          = {https://doi.org/https://doi.org/10.25300/misq/2025/49.1.075},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Guest Editorial: “Complexity is the Worst Enemy of Security”: Studying Cybersecurity Through the Lens of Organizational Complexity

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.52

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.47 × 0.4 = 0.19
M · momentum0.68 × 0.15 = 0.10
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.