The stock market impact of information security investments: The case of security standards

The stock market impact of information security investments: The case of security standards
复制标题

DOI:
--
复制
发表时间:
--
期刊:
--
影响因子:
--
通讯作者:
Dennis D. Malliouris;A. Simpson
Dennis D. Malliouris;A. Simpson
中科院分区:
其他
文献类型:
--
作者:
Dennis D. Malliouris;A. Simpson

文献摘要

相似文献

网络安全管理人员天生对开发、实施和审查具有成本效益的系统感兴趣,以保护其组织免受安全漏洞的严重影响。对于这些高管来说,决定投资哪些安全项目可能是一个复杂的问题。一种有助于为此类决策提供信息的方法是考虑股票市场对证券投资的反应。其中一种信息安全投资--遵守网络安全标准--尤其值得考虑,因为这些投资不仅有可能减少与数据泄露相关的财务处罚和损失,而且还有助于提高声誉、赢得新业务和改善业务流程。在本文中,我们报告了一项研究,分析了成功完成这种安全投资的公司价值的影响,通过探索两种情况下的网络安全证书:英国的网络基本计划和全球ISO/IEC 27001标准。分析了2014年至2018年期间的145个Cyber Essentials事件和2001年至2018年期间的76个ISO/IEC 27001认证。我们发现,授予Cyber Essentials(Plus)证书与重大和积极的市场反应系统相关。令人惊讶的是,我们的国际样本显示,成为ISO/IEC 27001兼容elands显着负异常股票收益。我们的研究结果的潜在解释和影响进行了讨论。
Cyber security executives are inherently interested in developing, implementing, and reviewing cost-effective systems to safeguard their organisations from severe impacts of security breaches. Deciding which security projects to invest in can be a complex issue for such executives. One method that can help inform such decision making involves giving consideration to how the stock market reacts to security investments. One type of information security investment — complying with cyber security standards — is particularly interesting to consider, as these investments may not only have the potential to reduce financial penalties and losses associated with data breaches, but may also help to enhance reputation, win new business, and improve business processes. In this paper, we report upon a study that analysed the firm value impact of successful completion of such security investments by exploring two cases of cyber security certificates: the UK’s Cyber Essentials scheme and the global ISO/IEC 27001 standard. 145 Cyber Essentials events between 2014 and 2018 and 76 ISO/IEC 27001 certifications between 2001 and 2018 were analysed. We find that the award of a Cyber Essentials (Plus) certificate is systematically associated with significant and positive market reactions. Surprisingly, our international sample reveals that becoming ISO/IEC 27001-compliant elicits significant negative abnormal stock returns. Potential explanations and implications of our findings are discussed.