{"title":"网络安全漏洞后投资者的判断和决策:理解网络安全风险管理保障的价值相关性","authors":"Patricia Navarro, S. Sutton","doi":"10.2139/ssrn.3817763","DOIUrl":null,"url":null,"abstract":"This study investigates how voluntary cybersecurity risk management (CyRM) assurance affects non-professional investors’ judgments and decisions. The study also examines how the value relevance of CyRM assurance is altered when having such assurance is expected/unexpected. Employing an experimental approach, we find that after a cyber-breach occurs, companies previously engaging in voluntary CyRM assurance receive more favorable investor assessments of management credibility and, in turn, higher stock valuations. We also find that investors’ assessments of management credibility and stock valuations are more extreme for companies that engage (do not engage) in CyRM assurance in industries where such assurance is not (is) the norm. This study begins to address the question of whether there is a demand for CyRM assurance offered by audit firms, particularly given lingering concerns in research and practice as to the viability of IT-related assurance services. Our research reinforces the profession’s position that management and boards need to recognize that cyber risk will differ by industry and that investors will react to violations of implicit industry standards for cyber risk management. The results also demonstrate the value to management credibility of having prior CyRM assurance after a cyber-breach; the reputation and damage control is important for both management and the company.","PeriodicalId":352857,"journal":{"name":"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)","volume":"40 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Investors’ Judgment and Decisions after a Cybersecurity Breach: Understanding the Value Relevance of Cybersecurity Risk Management Assurance\",\"authors\":\"Patricia Navarro, S. Sutton\",\"doi\":\"10.2139/ssrn.3817763\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This study investigates how voluntary cybersecurity risk management (CyRM) assurance affects non-professional investors’ judgments and decisions. The study also examines how the value relevance of CyRM assurance is altered when having such assurance is expected/unexpected. Employing an experimental approach, we find that after a cyber-breach occurs, companies previously engaging in voluntary CyRM assurance receive more favorable investor assessments of management credibility and, in turn, higher stock valuations. We also find that investors’ assessments of management credibility and stock valuations are more extreme for companies that engage (do not engage) in CyRM assurance in industries where such assurance is not (is) the norm. This study begins to address the question of whether there is a demand for CyRM assurance offered by audit firms, particularly given lingering concerns in research and practice as to the viability of IT-related assurance services. Our research reinforces the profession’s position that management and boards need to recognize that cyber risk will differ by industry and that investors will react to violations of implicit industry standards for cyber risk management. The results also demonstrate the value to management credibility of having prior CyRM assurance after a cyber-breach; the reputation and damage control is important for both management and the company.\",\"PeriodicalId\":352857,\"journal\":{\"name\":\"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)\",\"volume\":\"40 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-02-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.2139/ssrn.3817763\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"DecisionSciRN: Other Investment Decision-Making (Sub-Topic)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/ssrn.3817763","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Investors’ Judgment and Decisions after a Cybersecurity Breach: Understanding the Value Relevance of Cybersecurity Risk Management Assurance
This study investigates how voluntary cybersecurity risk management (CyRM) assurance affects non-professional investors’ judgments and decisions. The study also examines how the value relevance of CyRM assurance is altered when having such assurance is expected/unexpected. Employing an experimental approach, we find that after a cyber-breach occurs, companies previously engaging in voluntary CyRM assurance receive more favorable investor assessments of management credibility and, in turn, higher stock valuations. We also find that investors’ assessments of management credibility and stock valuations are more extreme for companies that engage (do not engage) in CyRM assurance in industries where such assurance is not (is) the norm. This study begins to address the question of whether there is a demand for CyRM assurance offered by audit firms, particularly given lingering concerns in research and practice as to the viability of IT-related assurance services. Our research reinforces the profession’s position that management and boards need to recognize that cyber risk will differ by industry and that investors will react to violations of implicit industry standards for cyber risk management. The results also demonstrate the value to management credibility of having prior CyRM assurance after a cyber-breach; the reputation and damage control is important for both management and the company.