2007
DOI: 10.1109/tse.2007.70712
|View full text |Cite
|
Sign up to set email alerts
|

An Empirical Analysis of the Impact of Software Vulnerability Announcements on Firm Stock Price

Abstract: Abstract-Security defects in software cost millions of dollars to firms in terms of downtime, disruptions, and confidentiality breaches. However, the economic implications of these defects for software vendors are not well understood. Lack of legal liability and the presence of switching costs and network externalities may protect software vendors from incurring significant costs in the event of a vulnerability announcement, unlike such industries as auto and pharmaceuticals, which have been known to suffer si… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

1
75
0
4

Year Published

2011
2011
2023
2023

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 186 publications
(80 citation statements)
references
References 43 publications
1
75
0
4
Order By: Relevance
“…The severity of the event would weaken the benefit of voluntary disclosure. Previous research shows that if the breach announcement suggests that the breach is severe, it could cause a significantly negative impact to the firm's CAR [25]. We believe the disclosure of a data breach event with larger data record loss could lead to more negative confidence on a firm's security controls.…”
Section: Theoretical Backgrounds and Hypotheses Developmentmentioning
confidence: 74%
See 3 more Smart Citations
“…The severity of the event would weaken the benefit of voluntary disclosure. Previous research shows that if the breach announcement suggests that the breach is severe, it could cause a significantly negative impact to the firm's CAR [25]. We believe the disclosure of a data breach event with larger data record loss could lead to more negative confidence on a firm's security controls.…”
Section: Theoretical Backgrounds and Hypotheses Developmentmentioning
confidence: 74%
“…But no literature considers the firm's decision to notify the data breach event to customers or the public as a factor to impact the market return. In our view, timely disclosure can be used to reduce the legal and reputation cost of bad news [25]. Firm's disclosure behavior also prevents competitors from unambiguously inferring that these firms are hiding information [8].…”
Section: Theoretical Backgrounds and Hypotheses Developmentmentioning
confidence: 99%
See 2 more Smart Citations
“…The poor password protection practises [3] are exploited by the attackers in order to recover the user passwords from the stolen data. These attacks lead to negative and significant loss in the vendor's market value [4]. collector attacks [10] can be countered by build-in memory safety techniques, specifically designed for embedded applications [18].…”
Section: Introductionmentioning
confidence: 99%