Investigating the influence of governance determinants on reporting cybersecurity incidents to police: Evidence from Canadian organizations' perspectives

被引:8
作者
Agbodoh-Falschau, Kouassi Raymond [1 ]
Ravaonorohanta, Bako Harinivo [1 ,2 ]
机构
[1] Univ Sherbrooke, Business Sch, Dept Accounting Sci, 2500 Blvd Univ, Sherbrooke, PQ J1K 2R1, Canada
[2] Univ Sherbrooke, Dept Accounting, Sherbrooke, PQ, Canada
关键词
Cyber security; Cyber security incidents; Cyber security incidents reported to police; Governance; SEM-PLS; WarpPLS; AWARENESS; DISCLOSURE; IMPACT;
D O I
10.1016/j.techsoc.2023.102309
中图分类号
D58 [社会生活与社会问题]; C913 [社会生活与社会问题];
学科分类号
摘要
Government agencies and standard setters require organizations operating in critical infrastructure sectors to disclose cybersecurity incidents, yet little is known about whether organizations report these incidents to law enforcement. This study examines this issue based on data from the 2017-2021 periods of the Canadian Survey of Cybersecurity and Cybercrime administered to Canadian organizations. We assessed the effects of governance determinants along with cyber incidents and their impacts using partial least squares equation modelling to identify the relationships between these factors and cybersecurity incidents reported to police services. To conceptualize these relationships, we developed a framework based on resource-dependence theory, protection motivation theory, and previous empirical evidence. The overall governance determinants as well as the impacts of the incidents explained 51% of the intention to report cybersecurity incidents to police, and the intensity of the impacts explained 30% of these intentions to signal incidents to law enforcement. The results also revealed that the intensity of cyber incident impacts dictates the attitudes of organizations towards reporting digital attacks. This study makes a significant theoretical contribution to the information security literature and has practical implications for standard setters and government agencies that aim to combat cybersecurity incidents.
引用
收藏
页数:14
相关论文
共 75 条
[1]   Measuring attitude towards personal data for adaptive cybersecurity [J].
Addae, Joyce Hoese ;
Brown, Michael ;
Sun, Xu ;
Towey, Dave ;
Radenkovic, Milena .
Information and Computer Security, 2017, 25 (05) :560-579
[2]   A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate [J].
Agrafiotis, Ioannis ;
Nurse, Jason R. C. ;
Goldsmith, Michael ;
Creese, Sadie ;
Upton, David .
JOURNAL OF CYBERSECURITY, 2018, 4 (01)
[3]   Towards Cybersecurity Risk Management Investment: A Proposed Encouragement Factors Framework for SMEs [J].
Alahmari, Abdulmajeed Abdullah ;
Duncan, Robert Anderson .
2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING (ICOCO), 2021, :115-121
[4]  
[Anonymous], 2018, Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1
[5]  
[Anonymous], 2022, ISO/IEC 27002. 2022
[6]   A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs [J].
Armenia, Stefano ;
Angelini, Marco ;
Nonino, Fabio ;
Palombi, Giulia ;
Schlitzer, Mario Francesco .
DECISION SUPPORT SYSTEMS, 2021, 147
[7]  
Bejarano M.H., 2021, ANN ROMANIAN SOC CEL, V25, P7280
[8]   No Rose without a thorn: Board IT competence and market reactions to operational IT failures [J].
Benaroch, Michel ;
Fink, Lior .
INFORMATION & MANAGEMENT, 2021, 58 (08)
[9]   Cybersecurity awareness and market valuations [J].
Berkman, Henk ;
Jona, Jonathan ;
Lee, Gladys ;
Soderstrom, Naomi .
JOURNAL OF ACCOUNTING AND PUBLIC POLICY, 2018, 37 (06) :508-526
[10]  
Bidgoli M., 2019, 2019 APWG S ELECT CR