课题基金 / 基金详情

Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events

Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events
金融
批准号:
1938246
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
我在牛津大学(University of Oxford)的博士研究项目“金融与网络安全:揭示与企业网络安全事件相关的重大非明显财务损益”,旨在探索企业网络安全事件带来的隐性成本。我探讨了网络安全投资对公司价值的影响,安全漏洞后资本成本的变化,以及企业内部人员对安全漏洞和漏洞的了解和利用。具体来说,我分析了以安全标准为重点的信息安全投资对股票市场的影响。这样的投资不仅有可能减少与数据泄露相关的经济处罚和损失,而且还可能有助于提高声誉、赢得新业务和改进业务流程。我发现,根据英国“网络必需品”(Cyber Essentials)计划获得的认证与显著而积极的市场反应有系统的联系。然而,符合ISO/IEC 27001标准会导致显著的负异常股票回报。此外,我确定了安全漏洞与统计上和经济上显著的股权成本增加有关。在分析了一个以美国为重点的严重安全漏洞的大型样本后,我发现,资本市场参与者将更高的风险(以贝塔系数衡量)归咎于被入侵的公司。此外,在发生安全漏洞后,下行贝塔系数尤其会增加,这表明当市场产生负回报时,被入侵的公司特别容易受到股权成本增加的影响。这些发现对企业的资本成本(即从外部资本提供者获得资金的成本)具有重要意义。我的研究成果已在诸如信息安全经济学研讨会(WEIS)等知名机构发表。由于以往的研究主要集中在与网络安全相关的明显成本上,从而忽略了对企业和整个社会的非明显损失,因此该研究项目与学术界和实践者具有高度相关性。我的研究目的是对网络(非)安全造成的损失建立一个更全面的看法。我的分析结果将为有关信息安全投资的学术框架和行政决策提供信息。我的研究方法的新颖性源于(1)对网络安全成本的新颖视角;(b)使用的数据集;(c)应用于网络安全的财务方法。首先,我介绍了与网络安全(漏洞)相关的损益核算的新视角。通过强调与网络安全相关的不明显的经济影响,学者和从业者可以对网络安全的成本和收益形成更复杂的观点。我的研究可以为帮助指导信息安全投资努力的新框架提供信息。其次,我分析以前未使用的(财务)数据集,为信息安全决策提供信息。将新的经验证据引入网络安全投资这一新兴领域具有重要意义,因为在这一研究领域,数据是一种稀缺的经济资源。第三,运用金融经济学文献中成熟的分析方法对网络安全现象进行分析。例如,在信息安全经济学文献中,在安全漏洞之后建立双beta系统风险模型的变化是新颖的。该项目属于EPSRC数字经济研究领域。其中一个子研究项目涉及使用伦敦一家资产管理公司提供的数据。此外,我经常与一家国际风险管理和保险公司的高级员工进行讨论,他们对我的研究感兴趣,并将研究结果应用于他们的业务活动。
英文摘要
My DPhil research project "Finance & Cyber Security: Uncovering major non-obvious financial gains and losses associated with corporate cyber security events" at the University of Oxford sets out to explore hidden costs stemming from firms' cyber security events. I explore firm value implications of investments in cyber security, changes in cost of capital following security breaches, and corporate insiders' knowledge and exploitation of security breaches and vulnerabilities. Specifically, I analysed the stock market impact of information security investments focusing on security standards. Such investments do not only have the potential to reduce financial penalties and losses associated with data breaches, but may also help to enhance reputation, win new business, and improve business processes. I found that certifications according to the UK's Cyber Essentials scheme are systematically associated with significant and positive market reactions. Becoming ISO/IEC 27001 compliant, however, elicits significant negative abnormal stock returns.Furthermore, I established that security breaches are associated with a statistically and economically significant increase in cost of equity. Analysing a large US-focused sample of severe security breaches I found that capital market participants ascribe a higher risk, measured in terms of beta factors, to breached companies. Additionally, downside betas particularly increase following a security breach, which indicates that when markets yield negative returns, breached firms are particularly susceptible to increases costs of equity. The findings carry important implications for firms' cost of capital, that is, the costs of obtaining funding from external capital providers.My research has been published by highly regarded outlets such as the Workshop on the Economics of Information Security (WEIS). The research project is of high relevance to academia and practitioners as previous research has focused mainly on obvious costs associated with cyber security and thereby neglected non-obvious losses to firms and society at large. The aim of my research is to establish a more holistic view on losses stemming from cyber (in-)security. The outcomes of my analyses will inform academic frameworks and executive decision making regarding information security investments.The novelty of my research methodology stems from the novel (a) perspective on cyber security costs; (b) datasets used; and (c) financial methodologies applied to cyber security. First, I introduce new perspectives on accounting for benefits and losses associated with cyber security (breaches). By highlighting non-obvious economic implications associated with cyber security, academics and practitioners can form a more sophisticated view on cyber security costs and benefits. My research can inform novel frameworks to help guiding information security investment endeavours. Second, I analyse previously-unused (financial) datasets to inform information security decision making. Introducing novel empirical evidence to the nascent field of cyber security investments is of high relevance as data is a scarce economic resource in this area of research. Third, I use well-established analytical methods from the financial economics literature to analyse cyber security phenomena. For instance, establishing changes in dual-beta systematic risk models following security breaches is novel to the information security economics literature. This project falls within the EPSRC Digital Economy research area.One sub-research project involves using data provided by a London-based asset management firm. Furthermore, I am in frequent discussions with senior employees at an international risk management and insurance firm, who are interested in my research and apply findings to their business activities.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间:
期刊:
影响因子: --
作者: [Dennis D. Malliouris;A. Simpson]
通讯作者: Dennis D. Malliouris;A. Simpson
国内基金
海外基金
Cyber体系脆弱性仿真分析方法研究
  • 批准号:
    61403400
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2014
  • 负责人:
    许相莉
  • 依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
  • 批准号:
    61374179
  • 项目类别:
    面上项目
  • 资助金额:
    77.0万元
  • 批准年份:
    2013
  • 负责人:
    胡晓峰
  • 依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
  • 批准号:
    61300132
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    23.0万元
  • 批准年份:
    2013
  • 负责人:
    王竹晓
  • 依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
  • 批准号:
    61174035
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2011
  • 负责人:
    贺筱媛
  • 依托单位: