Investors’ Judgment and Decisions after a Cybersecurity Breach: Understanding the Value Relevance of Cybersecurity Risk Management Assurance

Patricia Navarro, S. Sutton
{"title":"Investors’ Judgment and Decisions after a Cybersecurity Breach: Understanding the Value Relevance of Cybersecurity Risk Management Assurance","authors":"Patricia Navarro, S. Sutton","doi":"10.2139/ssrn.3817763","DOIUrl":null,"url":null,"abstract":"This study investigates how voluntary cybersecurity risk management (CyRM) assurance affects non-professional investors’ judgments and decisions. The study also examines how the value relevance of CyRM assurance is altered when having such assurance is expected/unexpected. Employing an experimental approach, we find that after a cyber-breach occurs, companies previously engaging in voluntary CyRM assurance receive more favorable investor assessments of management credibility and, in turn, higher stock valuations. We also find that investors’ assessments of management credibility and stock valuations are more extreme for companies that engage (do not engage) in CyRM assurance in industries where such assurance is not (is) the norm. This study begins to address the question of whether there is a demand for CyRM assurance offered by audit firms, particularly given lingering concerns in research and practice as to the viability of IT-related assurance services. Our research reinforces the profession’s position that management and boards need to recognize that cyber risk will differ by industry and that investors will react to violations of implicit industry standards for cyber risk management. The results also demonstrate the value to management credibility of having prior CyRM assurance after a cyber-breach; the reputation and damage control is important for both management and the company.","PeriodicalId":352857,"journal":{"name":"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)","volume":"40 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/ssrn.3817763","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

This study investigates how voluntary cybersecurity risk management (CyRM) assurance affects non-professional investors’ judgments and decisions. The study also examines how the value relevance of CyRM assurance is altered when having such assurance is expected/unexpected. Employing an experimental approach, we find that after a cyber-breach occurs, companies previously engaging in voluntary CyRM assurance receive more favorable investor assessments of management credibility and, in turn, higher stock valuations. We also find that investors’ assessments of management credibility and stock valuations are more extreme for companies that engage (do not engage) in CyRM assurance in industries where such assurance is not (is) the norm. This study begins to address the question of whether there is a demand for CyRM assurance offered by audit firms, particularly given lingering concerns in research and practice as to the viability of IT-related assurance services. Our research reinforces the profession’s position that management and boards need to recognize that cyber risk will differ by industry and that investors will react to violations of implicit industry standards for cyber risk management. The results also demonstrate the value to management credibility of having prior CyRM assurance after a cyber-breach; the reputation and damage control is important for both management and the company.
网络安全漏洞后投资者的判断和决策:理解网络安全风险管理保障的价值相关性
本研究探讨自愿性网络安全风险管理(CyRM)保证如何影响非专业投资者的判断和决策。该研究还考察了在预期/非预期的情况下,CyRM保证的价值相关性是如何改变的。采用实验方法,我们发现,在网络入侵发生后,之前从事自愿CyRM保证的公司获得了更有利的投资者对管理可信度的评估,进而获得更高的股票估值。我们还发现,在从事(不从事)CyRM担保的行业中,投资者对管理层可信度和股票估值的评估更为极端,而这种担保不是(是)常态。本研究开始解决审计公司是否需要提供CyRM保证的问题,特别是考虑到研究和实践中对it相关保证服务可行性的挥之不去的担忧。我们的研究强化了业界的观点,即管理层和董事会需要认识到网络风险因行业而异,投资者会对违反网络风险管理隐含行业标准的行为做出反应。结果还表明,在网络泄露事件发生后,事先进行CyRM保证对管理可信度的价值;声誉和损害控制对管理层和公司都很重要。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信