The Impact of the Type of Cybersecurity Assurance Service and Cybersecurity Incidents on Investor Perceptions and Decisions

被引:1
作者
Perols, Rebecca R. [1 ]
机构
[1] San Diego State Univ, San Diego, CA 92182 USA
来源
AUDITING-A JOURNAL OF PRACTICE & THEORY | 2024年 / 43卷 / 03期
关键词
voluntary disclosure; risk management; system and organization controls; cybersecurity risk manage- ment program; assurance services; nonaudit services; audit quality; process mediation model; informa- tion security; data breach; SOURCE CREDIBILITY; JUDGMENT; INFORMATION; DISCLOSURE; BIAS;
D O I
10.2308/AJPT-19-022
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
Regulators, investors, and boards of directors are increasingly demanding information about organizations' cybersecurity risk management. I examine the effect of the AICPA's voluntary cybersecurity examination service on investor perceptions and decisions. Similar to a previous AICPA IT-related assurance service called WebTrust that failed in the marketplace, cybersecurity examinations face competition from less comprehensive and less costly assurance services in a nonstandardized assurance market, and it is unclear whether investors will recognize the value provided by the more comprehensive assurance service. I find that investors are more willing to invest when management disclosures describe a cybersecurity examination compared with a less comprehensive assurance service but only if the assurance is in response to a cybersecurity incident. I also find that this effect is mediated by investor perceptions of assurance quality. I, however, do not find support for these same effects when the assurance is disclosed in the absence of an incident.
引用
收藏
页码:187 / 202
页数:16
相关论文
共 65 条