网络安全是一种社会责任吗?

IF 6.9 3区 管理学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS
Waqas Nawaz Khan, Jae Kyu Lee, Shan Liu
{"title":"网络安全是一种社会责任吗?","authors":"Waqas Nawaz Khan, Jae Kyu Lee, Shan Liu","doi":"10.1007/s10796-024-10565-z","DOIUrl":null,"url":null,"abstract":"<p>Cybersecurity incidents damage not only the organizations attacked, but also society in general, harming customers and stakeholders. Through the text mining of the incident database, we observed that the impact of cybersecurity incident trends became more outward-oriented causing increased risks associated with social responsibility. Thus, this study aims to validate the potential effect of cybersecurity incidents on social responsibility risks and stock price drops. To derive meaningful factors from the description of incidents, we mined the texts to extract the features of the severity of incidents and their direction of impact whether inward or outward. The severity score is derived from sentiment analysis and the impact direction by topic modeling and machine learning models including SVM, LSTM, and BERT. The effects of these incident features are studied through regression models with social responsibility risk and stock price drops as dependent variables. To conduct this study, we collected incident texts from the Privacy Rights Clearinghouse database, and social responsibility risk indices from the Privacy and Data Security index and Cyber Risk Rating scores. The subsequent short-term stock price drops are measured by Cumulative Abnormal Returns and their variations. Our analysis revealed a profound impact of cybersecurity incidents on social responsibility risk indices and stock price drops with the moderating effect of outward impact in both models. However, we recognize the incompatibility between an annual index of social responsibility risk and short-term stock price drops. Therefore, we propose a short-term social responsibility risk index for cybersecurity which can be derived from the disclosed incidents. All these scenarios support the premise that cybersecurity incidents significantly impact the social responsibility risk and may lead to potential stock price drops.</p>","PeriodicalId":13610,"journal":{"name":"Information Systems Frontiers","volume":"4 1","pages":""},"PeriodicalIF":6.9000,"publicationDate":"2025-01-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Is Cybersecurity a Social Responsibility?\",\"authors\":\"Waqas Nawaz Khan, Jae Kyu Lee, Shan Liu\",\"doi\":\"10.1007/s10796-024-10565-z\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Cybersecurity incidents damage not only the organizations attacked, but also society in general, harming customers and stakeholders. Through the text mining of the incident database, we observed that the impact of cybersecurity incident trends became more outward-oriented causing increased risks associated with social responsibility. Thus, this study aims to validate the potential effect of cybersecurity incidents on social responsibility risks and stock price drops. To derive meaningful factors from the description of incidents, we mined the texts to extract the features of the severity of incidents and their direction of impact whether inward or outward. The severity score is derived from sentiment analysis and the impact direction by topic modeling and machine learning models including SVM, LSTM, and BERT. The effects of these incident features are studied through regression models with social responsibility risk and stock price drops as dependent variables. To conduct this study, we collected incident texts from the Privacy Rights Clearinghouse database, and social responsibility risk indices from the Privacy and Data Security index and Cyber Risk Rating scores. The subsequent short-term stock price drops are measured by Cumulative Abnormal Returns and their variations. Our analysis revealed a profound impact of cybersecurity incidents on social responsibility risk indices and stock price drops with the moderating effect of outward impact in both models. However, we recognize the incompatibility between an annual index of social responsibility risk and short-term stock price drops. Therefore, we propose a short-term social responsibility risk index for cybersecurity which can be derived from the disclosed incidents. All these scenarios support the premise that cybersecurity incidents significantly impact the social responsibility risk and may lead to potential stock price drops.</p>\",\"PeriodicalId\":13610,\"journal\":{\"name\":\"Information Systems Frontiers\",\"volume\":\"4 1\",\"pages\":\"\"},\"PeriodicalIF\":6.9000,\"publicationDate\":\"2025-01-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Information Systems Frontiers\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://doi.org/10.1007/s10796-024-10565-z\",\"RegionNum\":3,\"RegionCategory\":\"管理学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Systems Frontiers","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.1007/s10796-024-10565-z","RegionNum":3,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

网络安全事件不仅损害了受攻击的组织,也损害了整个社会,伤害了客户和利益相关者。通过对事件数据库的文本挖掘,我们发现网络安全事件的影响趋势变得更加外向,导致与社会责任相关的风险增加。因此,本研究旨在验证网络安全事件对社会责任风险和股价下跌的潜在影响。为了从事件描述中提取有意义的因素,我们对文本进行了挖掘,以提取事件严重性及其影响方向(内向或外向)的特征。严重性得分是通过情感分析得出的,影响方向则是通过主题建模和机器学习模型(包括 SVM、LSTM 和 BERT)得出的。以社会责任风险和股价下跌为因变量,通过回归模型研究这些事件特征的影响。为了开展这项研究,我们从隐私权信息交换所数据库中收集了事件文本,并从隐私与数据安全指数和网络风险评级分数中收集了社会责任风险指数。随后的短期股价下跌通过累计异常回报及其变化来衡量。我们的分析表明,网络安全事件对社会责任风险指数和股价下跌有深远影响,在这两个模型中,外向影响具有调节作用。然而,我们认识到年度社会责任风险指数与短期股价下跌之间的不一致性。因此,我们提出了网络安全的短期社会责任风险指数,该指数可从披露的事件中得出。所有这些情况都支持这样一个前提,即网络安全事件会对社会责任风险产生重大影响,并可能导致潜在的股价下跌。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Is Cybersecurity a Social Responsibility?

Cybersecurity incidents damage not only the organizations attacked, but also society in general, harming customers and stakeholders. Through the text mining of the incident database, we observed that the impact of cybersecurity incident trends became more outward-oriented causing increased risks associated with social responsibility. Thus, this study aims to validate the potential effect of cybersecurity incidents on social responsibility risks and stock price drops. To derive meaningful factors from the description of incidents, we mined the texts to extract the features of the severity of incidents and their direction of impact whether inward or outward. The severity score is derived from sentiment analysis and the impact direction by topic modeling and machine learning models including SVM, LSTM, and BERT. The effects of these incident features are studied through regression models with social responsibility risk and stock price drops as dependent variables. To conduct this study, we collected incident texts from the Privacy Rights Clearinghouse database, and social responsibility risk indices from the Privacy and Data Security index and Cyber Risk Rating scores. The subsequent short-term stock price drops are measured by Cumulative Abnormal Returns and their variations. Our analysis revealed a profound impact of cybersecurity incidents on social responsibility risk indices and stock price drops with the moderating effect of outward impact in both models. However, we recognize the incompatibility between an annual index of social responsibility risk and short-term stock price drops. Therefore, we propose a short-term social responsibility risk index for cybersecurity which can be derived from the disclosed incidents. All these scenarios support the premise that cybersecurity incidents significantly impact the social responsibility risk and may lead to potential stock price drops.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Information Systems Frontiers
Information Systems Frontiers 工程技术-计算机:理论方法
CiteScore
13.30
自引率
18.60%
发文量
127
审稿时长
9 months
期刊介绍: The interdisciplinary interfaces of Information Systems (IS) are fast emerging as defining areas of research and development in IS. These developments are largely due to the transformation of Information Technology (IT) towards networked worlds and its effects on global communications and economies. While these developments are shaping the way information is used in all forms of human enterprise, they are also setting the tone and pace of information systems of the future. The major advances in IT such as client/server systems, the Internet and the desktop/multimedia computing revolution, for example, have led to numerous important vistas of research and development with considerable practical impact and academic significance. While the industry seeks to develop high performance IS/IT solutions to a variety of contemporary information support needs, academia looks to extend the reach of IS technology into new application domains. Information Systems Frontiers (ISF) aims to provide a common forum of dissemination of frontline industrial developments of substantial academic value and pioneering academic research of significant practical impact.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信