课题基金 / 基金详情

Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events

Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events
金融
批准号:
1938246
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
My DPhil research project "Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events" at the University of Oxford sets out to explore hidden costs stemming from firms' cyber security events. I explore firm value implications of investments in cyber security, changes in cost of capital following security breaches, and corporate insiders' knowledge and exploitation of security breaches and vulnerabilities. Specifically, I analysed the stock market impact of information security investments focusing on security standards. Such investments do not only have the potential to reduce financial penalties and losses associated with data breaches, but may also help to enhance reputation, win new business, and improve business processes. I found that certifications according to the UK's Cyber Essentials scheme are systematically associated with significant and positive market reactions. Becoming ISO/IEC 27001 compliant, however, elicits significant negative abnormal stock returns.Furthermore, I established that security breaches are associated with a statistically and economically significant increase in cost of equity. Analysing a large US-focused sample of severe security breaches I found that capital market participants ascribe a higher risk, measured in terms of beta factors, to breached companies. Additionally, downside betas particularly increase following a security breach, which indicates that when markets yield negative returns, breached firms are particularly susceptible to increases costs of equity. The findings carry important implications for firms' cost of capital, that is, the costs of obtaining funding from external capital providers.My research has been published by highly regarded outlets such as the Workshop on the Economics of Information Security (WEIS). The research project is of high relevance to academia and practitioners as previous research has focused mainly on obvious costs associated with cyber security and thereby neglected non-obvious losses to firms and society at large. The aim of my research is to establish a more holistic view on losses stemming from cyber (in-)security. The outcomes of my analyses will inform academic frameworks and executive decision making regarding information security investments.The novelty of my research methodology stems from the novel (a) perspective on cyber security costs; (b) datasets used; and (c) financial methodologies applied to cyber security. First, I introduce new perspectives on accounting for benefits and losses associated with cyber security (breaches). By highlighting non-obvious economic implications associated with cyber security, academics and practitioners can form a more sophisticated view on cyber security costs and benefits. My research can inform novel frameworks to help guiding information security investment endeavours. Second, I analyse previously-unused (financial) datasets to inform information security decision making. Introducing novel empirical evidence to the nascent field of cyber security investments is of high relevance as data is a scarce economic resource in this area of research. Third, I use well-established analytical methods from the financial economics literature to analyse cyber security phenomena. For instance, establishing changes in dual-beta systematic risk models following security breaches is novel to the information security economics literature. This project falls within the EPSRC Digital Economy research area.One sub-research project involves using data provided by a London-based asset management firm. Furthermore, I am in frequent discussions with senior employees at an international risk management and insurance firm, who are interested in my research and apply findings to their business activities.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间:
期刊:
影响因子: --
作者: [Dennis D. Malliouris;A. Simpson]
通讯作者: Dennis D. Malliouris;A. Simpson
国内基金
海外基金
Cyber体系脆弱性仿真分析方法研究
  • 批准号:
    61403400
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2014
  • 负责人:
    许相莉
  • 依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
  • 批准号:
    61374179
  • 项目类别:
    面上项目
  • 资助金额:
    77.0万元
  • 批准年份:
    2013
  • 负责人:
    胡晓峰
  • 依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
  • 批准号:
    61300132
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    23.0万元
  • 批准年份:
    2013
  • 负责人:
    王竹晓
  • 依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
  • 批准号:
    61174035
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2011
  • 负责人:
    贺筱媛
  • 依托单位: