2019
DOI: 10.2308/isys-52374
|View full text |Cite
|
Sign up to set email alerts
|

How Disclosing a Prior Cyberattack Influences the Efficacy of Cybersecurity Risk Management Reporting and Independent Assurance

Abstract: This paper provides evidence that the efficacy of voluntary cybersecurity risk management reporting and independent assurance, in terms of enhancing investment attractiveness, depends on whether a company has disclosed a prior cyberattack. Based on the voluntary disclosure literature, we predict and find that issuing the management component of the AICPA's cybersecurity reporting framework absent assurance is more effective when a company has not (versus has) disclosed a prior cyberattack, as nonprofessional i… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

3
31
0
3

Year Published

2019
2019
2024
2024

Publication Types

Select...
7

Relationship

1
6

Authors

Journals

citations
Cited by 25 publications
(37 citation statements)
references
References 47 publications
3
31
0
3
Order By: Relevance
“…Thus, companies like Target, Home Depot, and the countless others that have experienced prior cybersecurity incidents should consider external cybersecurity reporting such as the AICPA Framework. In fact, Frank et al (2019) find that external cybersecurity reporting also promotes investor confidence for firms that have not experienced cybersecurity incidents. These results demonstrate the value of external cyberse-4 See SEC (2018) for recent interpretative guidance on required SEC disclosures regarding cybersecurity risk management.…”
Section: External Cybersecurity Reportingmentioning
confidence: 99%
See 3 more Smart Citations
“…Thus, companies like Target, Home Depot, and the countless others that have experienced prior cybersecurity incidents should consider external cybersecurity reporting such as the AICPA Framework. In fact, Frank et al (2019) find that external cybersecurity reporting also promotes investor confidence for firms that have not experienced cybersecurity incidents. These results demonstrate the value of external cyberse-4 See SEC (2018) for recent interpretative guidance on required SEC disclosures regarding cybersecurity risk management.…”
Section: External Cybersecurity Reportingmentioning
confidence: 99%
“…With respect to companies who have experienced cybersecurity incidents, recent research suggests that external cybersecurity reporting can help restore investor confidence when coupled with assurance (see next section; Frank et al 2019). Thus, companies like Target, Home Depot, and the countless others that have experienced prior cybersecurity incidents should consider external cybersecurity reporting such as the AICPA Framework.…”
Section: External Cybersecurity Reportingmentioning
confidence: 99%
See 2 more Smart Citations
“…Results indicate that, on average, the economic consequences of privacy breaches on firms' cumulative abnormal returns, future accounting measures of performance such as sale growth return on sales and operating expense, higher audit and other fees, and future SOX 404 reports of material internal control weaknesses are generally very small. Frank et al (2019) examine whether a prior cyberattack influences the efficacy of cybersecurity risk management reporting and independent assurance. The authors design an experiment to capture how disclosures proposed by AICPA may influence nonprofessional investors' perceptions.…”
Section: Theme Issue: Implications Of Cybersecuritymentioning
confidence: 99%