Quantifying the financial impact of IT security breaches

Author:

Garg Ashish,Curtis Jeffrey,Halper Hilary

Abstract

Internet security is a pervasive concern for all companies. However, developing the business case to support investments in IT security has been particularly challenging because of difficulties in precisely quantifying the economic impact of a breach. Previous studies have attempted to quantify the magnitude of losses resulting from a breach in IT security, but reliance on self‐reported company data has resulted in widely varying estimates of limited credibility. Employing an event study methodology, this study offers an alternative approach and more rigorous evaluation of breaches in IT security. This attempt has revealed several new perspectives concerning the market reaction to IT security breaches. A final component of the study is the extension of the analysis to incorporate eSecurity vendors and a fuller exploration of market reactions before and after the denial of service attacks of February 2000. The key takeaway for corporate IT decision makers is that IT security breaches are extremely costly, and that the stock market has already factored in some level of optimal IT security investment by companies.

Publisher

Emerald

Subject

Library and Information Sciences,Management Science and Operations Research,Business and International Management,Management Information Systems

Reference11 articles.

1. Bosworth, S. and Kabay, M.E. (Eds) (2002), Computer Security Handbook, 4th ed., John Wiley, New York, NY.

2. Cavusoglu, H., Mishra, B. and Raghumathan, R. (2002), The Effect of Internet Security Breach Announcements on Market Value of Breached Firms and Internet Security Developers, Working Paper, The University of Texas at Dallas School of Management, Dallas, TX.

3. Ernst & Young, LLP (2002), Global Information Security Survey.

4. Ettredge, M. and Richardson, V. (2001), Assessing the Risk in E‐Commerce, October, working paper, University of Kansas, Lawrence, KS.

5. Fama, E.F., Fisher, L., Jensen, M. and Roll, R. (1969), “The adjustment of stock prices to new information”, International Economic Review, Vol. 10, pp. 1‐21.

Cited by 159 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Navigating through cyberattacks: The role of tax aggressiveness;Journal of Corporate Finance;2024-10

2. The impact of cryptocurrency-related cyberattacks on return, volatility, and trading volume of cryptocurrencies and traditional financial assets;International Review of Financial Analysis;2024-10

3. The impact of cyber enforcement actions on stock returns;Research in International Business and Finance;2024-08

4. Corporate communication and likelihood of data breaches;International Review of Economics & Finance;2024-07

5. The cybersecurity entrepreneur;The Review of Austrian Economics;2024-05-09

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3