Investigating the influence of governance determinants on reporting cybersecurity incidents to police: Evidence from Canadian organizations' perspectives

被引:8
作者
Agbodoh-Falschau, Kouassi Raymond [1 ]
Ravaonorohanta, Bako Harinivo [1 ,2 ]
机构
[1] Univ Sherbrooke, Business Sch, Dept Accounting Sci, 2500 Blvd Univ, Sherbrooke, PQ J1K 2R1, Canada
[2] Univ Sherbrooke, Dept Accounting, Sherbrooke, PQ, Canada
关键词
Cyber security; Cyber security incidents; Cyber security incidents reported to police; Governance; SEM-PLS; WarpPLS; AWARENESS; DISCLOSURE; IMPACT;
D O I
10.1016/j.techsoc.2023.102309
中图分类号
D58 [社会生活与社会问题]; C913 [社会生活与社会问题];
学科分类号
摘要
Government agencies and standard setters require organizations operating in critical infrastructure sectors to disclose cybersecurity incidents, yet little is known about whether organizations report these incidents to law enforcement. This study examines this issue based on data from the 2017-2021 periods of the Canadian Survey of Cybersecurity and Cybercrime administered to Canadian organizations. We assessed the effects of governance determinants along with cyber incidents and their impacts using partial least squares equation modelling to identify the relationships between these factors and cybersecurity incidents reported to police services. To conceptualize these relationships, we developed a framework based on resource-dependence theory, protection motivation theory, and previous empirical evidence. The overall governance determinants as well as the impacts of the incidents explained 51% of the intention to report cybersecurity incidents to police, and the intensity of the impacts explained 30% of these intentions to signal incidents to law enforcement. The results also revealed that the intensity of cyber incident impacts dictates the attitudes of organizations towards reporting digital attacks. This study makes a significant theoretical contribution to the information security literature and has practical implications for standard setters and government agencies that aim to combat cybersecurity incidents.
引用
收藏
页数:14
相关论文
共 75 条
[51]  
Moturi Christopher A., 2021, International Journal of Business Continuity and Risk Management, P343, DOI [10.1504/ijbcrm.2021.119943, 10.1504/IJBCRM.2021.119943]
[52]  
National Institute of Standards and Technology, 2018, FRAM IMPR CRIT INFR
[53]   Board engagement with digital technologies: A resource dependence framework [J].
Oliveira, Fabio ;
Kakabadse, Nada ;
Khan, Nadeem .
JOURNAL OF BUSINESS RESEARCH, 2022, 139 :804-818
[54]   Strategic roles of IT modernization and cloud migration in reducing cybersecurity risks of organizations: The case of US federal government [J].
Pang, Min-Seok ;
Tanriverdi, Huseyin .
JOURNAL OF STRATEGIC INFORMATION SYSTEMS, 2022, 31 (01)
[55]   The Impact of Cybersecurity Risk Management Examinations and Cybersecurity Incidents on Investor Perceptions and Decisions [J].
Perols, Rebecca R. ;
Murthy, Uday S. .
AUDITING-A JOURNAL OF PRACTICE & THEORY, 2021, 40 (01) :73-89
[56]   Cyber security trends: What should keep CEOs awake at night [J].
Piggin, Richard .
INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2016, 13 :36-38
[57]   Board Gender Diversity and Corporate Response to Cyber Risk: Evidence from Cybersecurity Related Disclosure [J].
Radu, Camelia ;
Smaili, Nadia .
JOURNAL OF BUSINESS ETHICS, 2022, 177 (02) :351-374
[58]   Developing a modified total interpretive structural model (M-TISM) for organizational strategic cybersecurity management [J].
Rajan, Rishabh ;
Rana, Nripendra P. ;
Parameswar, Nakul ;
Dhir, Sanjay ;
Sushil ;
Dwivedi, Yogesh K. .
TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2021, 170
[59]   New challenges for risk analysis: systemic risks [J].
Renn, Ortwin .
JOURNAL OF RISK RESEARCH, 2021, 24 (01) :127-133
[60]  
Ruvin O, 2020, Journal of Security and Sustainability Issues, V10, P175, DOI [10.9770/jssi.2020.10.1(13), 10.9770/jssi.2020.10.1, DOI 10.9770/JSSI.2020.10.1, 10.9770/jssi.2020.10.113, DOI 10.9770/JSSI.2020.10.113]