{"title":"网络安全融资:投资决策和净现值的量化建模","authors":"Mazen Brho , Amer Jazairy , Aaron V. Glassburner","doi":"10.1016/j.ijpe.2024.109448","DOIUrl":null,"url":null,"abstract":"<div><div>Despite the growing literature on cybersecurity investment, significant gaps remain unaddressed. First, the existing literature does not differentiate between cybersecurity expenditures, namely investment versus spending, despite the differences in their financial treatments. Second, the literature predominantly employs economic and risk-based models, in which the incorporation of financial parameters is limited. Third, the literature focuses on quantifying market (stock) loss of cyberattacks or conducting a cost-benefit analysis of cybersecurity investments but has yet to bridge these two areas. Thus, our objective is to introduce a new financial model, the Alpha Model, that addresses these gaps. We first provide distinctions between cybersecurity investment (capital expenditure) and spending (operational expenditure). Grounded in Relative Valuation Models and Optimal Capital Structure Theory, we quantify the upper-bound of optimal cybersecurity investment by utilizing book and market values of equity and debt. We also demonstrate that the Net Present Values (NPV) of cybersecurity investment is considerably lower than its book value by incorporating financial parameters of equity and debt financing, inflation-adjusted capital cost, and tax credits of depreciation and interest. To validate our model, we conduct an empirical test using data from the S&P500 index during 2018–2023. We present practical implications to key stakeholders, including: (1) industry executives to financially quantify cybersecurity investments and ascertain their actual NPVs, individually and collaboratively with supply chain partners; (2) cybersecurity solution providers to promote business investments in cybersecurity; and (3) insurance providers to price premiums with higher NPVs than the corresponding investments. We also offer several avenues for further research.</div></div>","PeriodicalId":14287,"journal":{"name":"International Journal of Production Economics","volume":"279 ","pages":"Article 109448"},"PeriodicalIF":9.8000,"publicationDate":"2024-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"The finance of cybersecurity: Quantitative modeling of investment decisions and net present value\",\"authors\":\"Mazen Brho , Amer Jazairy , Aaron V. Glassburner\",\"doi\":\"10.1016/j.ijpe.2024.109448\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Despite the growing literature on cybersecurity investment, significant gaps remain unaddressed. First, the existing literature does not differentiate between cybersecurity expenditures, namely investment versus spending, despite the differences in their financial treatments. Second, the literature predominantly employs economic and risk-based models, in which the incorporation of financial parameters is limited. Third, the literature focuses on quantifying market (stock) loss of cyberattacks or conducting a cost-benefit analysis of cybersecurity investments but has yet to bridge these two areas. Thus, our objective is to introduce a new financial model, the Alpha Model, that addresses these gaps. We first provide distinctions between cybersecurity investment (capital expenditure) and spending (operational expenditure). Grounded in Relative Valuation Models and Optimal Capital Structure Theory, we quantify the upper-bound of optimal cybersecurity investment by utilizing book and market values of equity and debt. We also demonstrate that the Net Present Values (NPV) of cybersecurity investment is considerably lower than its book value by incorporating financial parameters of equity and debt financing, inflation-adjusted capital cost, and tax credits of depreciation and interest. To validate our model, we conduct an empirical test using data from the S&P500 index during 2018–2023. We present practical implications to key stakeholders, including: (1) industry executives to financially quantify cybersecurity investments and ascertain their actual NPVs, individually and collaboratively with supply chain partners; (2) cybersecurity solution providers to promote business investments in cybersecurity; and (3) insurance providers to price premiums with higher NPVs than the corresponding investments. We also offer several avenues for further research.</div></div>\",\"PeriodicalId\":14287,\"journal\":{\"name\":\"International Journal of Production Economics\",\"volume\":\"279 \",\"pages\":\"Article 109448\"},\"PeriodicalIF\":9.8000,\"publicationDate\":\"2024-10-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Production Economics\",\"FirstCategoryId\":\"5\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S0925527324003050\",\"RegionNum\":1,\"RegionCategory\":\"工程技术\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"ENGINEERING, INDUSTRIAL\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Production Economics","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0925527324003050","RegionNum":1,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, INDUSTRIAL","Score":null,"Total":0}
The finance of cybersecurity: Quantitative modeling of investment decisions and net present value
Despite the growing literature on cybersecurity investment, significant gaps remain unaddressed. First, the existing literature does not differentiate between cybersecurity expenditures, namely investment versus spending, despite the differences in their financial treatments. Second, the literature predominantly employs economic and risk-based models, in which the incorporation of financial parameters is limited. Third, the literature focuses on quantifying market (stock) loss of cyberattacks or conducting a cost-benefit analysis of cybersecurity investments but has yet to bridge these two areas. Thus, our objective is to introduce a new financial model, the Alpha Model, that addresses these gaps. We first provide distinctions between cybersecurity investment (capital expenditure) and spending (operational expenditure). Grounded in Relative Valuation Models and Optimal Capital Structure Theory, we quantify the upper-bound of optimal cybersecurity investment by utilizing book and market values of equity and debt. We also demonstrate that the Net Present Values (NPV) of cybersecurity investment is considerably lower than its book value by incorporating financial parameters of equity and debt financing, inflation-adjusted capital cost, and tax credits of depreciation and interest. To validate our model, we conduct an empirical test using data from the S&P500 index during 2018–2023. We present practical implications to key stakeholders, including: (1) industry executives to financially quantify cybersecurity investments and ascertain their actual NPVs, individually and collaboratively with supply chain partners; (2) cybersecurity solution providers to promote business investments in cybersecurity; and (3) insurance providers to price premiums with higher NPVs than the corresponding investments. We also offer several avenues for further research.
期刊介绍:
The International Journal of Production Economics focuses on the interface between engineering and management. It covers all aspects of manufacturing and process industries, as well as production in general. The journal is interdisciplinary, considering activities throughout the product life cycle and material flow cycle. It aims to disseminate knowledge for improving industrial practice and strengthening the theoretical base for decision making. The journal serves as a forum for exchanging ideas and presenting new developments in theory and application, combining academic standards with practical value for industrial applications.