Financial Impact of Information Security Breaches on Breached Firms and their Non-Breached Competitors

被引:22
作者
Zafar, Humayun [1 ]
Ko, Myung S. [2 ]
Osei-Bryson, Kweku-Muata [3 ]
机构
[1] Kennesaw State Univ, Informat Secur & Assurance, Kennesaw, GA 30144 USA
[2] Univ Texas San Antonio, Informat Syst & Technol Management, San Antonio, TX 78249 USA
[3] Virginia Commonwealth Univ, Informat Syst, Richmond, VA 23284 USA
关键词
Competition Effect; Contagion Effect; Financial Impact; Information Security Breach; Information Transfer; Organizational Impact;
D O I
10.4018/irmj.2012010102
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information security breaches pose a growing threat to organizations and individuals, particularly those that are heavily involved in e-business/e-commerce. An information security breach can have wide-ranging impacts, including influencing the behaviors of competitors and vice versa within the context of a competitive marketplace. Therefore, there is a need for further exploration of implications of information security breaches beyond the focus of the breached firm. This study investigates the financial impact of publicly announced information security breaches on breached firms and their non-breached competitors. While controlling for size and the industry the firm operates in, the authors focus on specific types of information security breaches (Denial of Service, Website Defacement, Data Theft, and Data Corruption). Unlike previous studies that have used event study methodology, the authors investigate information transfer effects that result from information security breaches using the matched sampling method. The study reveals statistically significant evidence of the presence of intra-industry information transfer for some types of security breaches. The authors also found evidence of contagion effects, but no similar evidence concerning competition effect.
引用
收藏
页码:21 / 37
页数:17
相关论文
共 45 条
[1]  
Acquisti Alessandro, 2006, 27 INT C INF SYST MI
[2]   CONTAGION EFFECTS OF BANK FAILURES - EVIDENCE FROM CAPITAL-MARKETS [J].
AHARONY, J ;
SWARY, I .
JOURNAL OF BUSINESS, 1983, 56 (03) :305-322
[3]   FINANCIAL RATIOS, DISCRIMINANT ANALYSIS AND PREDICTION OF CORPORATE BANKRUPTCY [J].
ALTMAN, EI .
JOURNAL OF FINANCE, 1968, 23 (04) :589-609
[4]   Exploring the characteristics of Internet security breaches that impact the market value of breached firms [J].
Andoh-Baidoo, Francis K. ;
Osei-Bryson, Kweku-Muata .
EXPERT SYSTEMS WITH APPLICATIONS, 2007, 32 (03) :703-725
[5]  
Bagchi K, 2003, COMMUNICATIONS ASS I, V12, P684, DOI DOI 10.17705/1CAIS.01246
[6]   Detecting abnormal operating performance: The empirical power and specification of test statistics [J].
Barber, BM ;
Lyon, JD .
JOURNAL OF FINANCIAL ECONOMICS, 1996, 41 (03) :359-399
[7]  
Bardram J. E., 2003, WORKSH UB COMP PERV
[8]   INFORMATION-SYSTEMS SECURITY DESIGN METHODS - IMPLICATIONS FOR INFORMATION-SYSTEMS DEVELOPMENT [J].
BASKERVILLE, R .
COMPUTING SURVEYS, 1993, 25 (04) :375-414
[9]   Intrusion detection systems and multisensor data fusion [J].
Bass, T .
COMMUNICATIONS OF THE ACM, 2000, 43 (04) :99-105
[10]   The financial rewards of new product introductions in the personal computer industry [J].
Bayus, BL ;
Erickson, G ;
Jacobson, R .
MANAGEMENT SCIENCE, 2003, 49 (02) :197-210