2013
DOI: 10.1287/isre.1120.0437
|View full text |Cite
|
Sign up to set email alerts
|

The Association Between the Disclosure and the Realization of Information Security Risk Factors

Abstract: Firms often disclose information security risk factors in public filings such as 10-K reports.The internal information associated with disclosures may be positive or negative. In this paper, we are interested in evaluating how the nature of security risk factors disclosed, which is believed to represent the internal information regarding information security, is associated with future breach announcements. For this purpose, we build a decision tree model, which classifies the occurrence of future security brea… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

1
39
0

Year Published

2013
2013
2024
2024

Publication Types

Select...
7
3

Relationship

2
8

Authors

Journals

citations
Cited by 145 publications
(44 citation statements)
references
References 82 publications
1
39
0
Order By: Relevance
“…3. Unfortunately, at times there is a tendency to downplay security breaches in the corporate sector, despite evidence that openness and disclosure generally results in a lower likelihood of future breaches (Wang et al, 2013). While, to our knowledge, there has been no studies looking at disclosure (or lack of) of victimisation incidents in a social media context, there are good reasons to speculate -both from the extant literature and the research presented in this paper -that this would be detrimental to lowering risks.…”
Section: Implications For Policy and Practicementioning
confidence: 99%
“…3. Unfortunately, at times there is a tendency to downplay security breaches in the corporate sector, despite evidence that openness and disclosure generally results in a lower likelihood of future breaches (Wang et al, 2013). While, to our knowledge, there has been no studies looking at disclosure (or lack of) of victimisation incidents in a social media context, there are good reasons to speculate -both from the extant literature and the research presented in this paper -that this would be detrimental to lowering risks.…”
Section: Implications For Policy and Practicementioning
confidence: 99%
“…given that the disclosure of information security risk factors, governance policies, and information security breaches can significantly impact firm value (Gordon, Loeb, & Sohail, 2010;Higgs, Pinsker, Smith, & Young, 2016;Wang, Kannan, & Ulmer, 2013). In addition, cybercrime poses "a different focal point of concern [and] a different 'subject' of risk", (Power, 2013, p. 538), because perpetrators are often unknown agents outside the organization.…”
Section: Introductionmentioning
confidence: 99%
“…• Disincentives to Disclose -There have been many studies (Bodeau 1992, Cavusoglu et al 2004, Lambert 1993, Rees 2009, Sohail 2006, Wang et al 2008 showing that companies and individuals are reluctant to disclose information related to security breaches.…”
Section: Why Breach Impact Estimation Is Hardmentioning
confidence: 99%