Understanding the Cost associated with Data Security Breaches
نویسندگان
چکیده
To estimate the cost of a data breach to the inflicted firm, this study examines the relationship between a breach incident and changes in the inflicted firm’s profitability, perceived risk, and the inflicted firms’ information environment transparency. Profitability is measured as reported earnings and analysts’ earnings forecasts. Perceived risk is measured as reported stock return volatility and dispersion among analysts’ forecasts. Although a number of studies have investigated the stock market reaction surrounding the disclosure of a breach incident to quantify the cost associated with breaches, we argue that there exists information uncertainty and deficiency in the disclosure of the breach incident and stock market reaction surrounding a security breach announcement date may not be the best measure for the cost of security breaches. And research using other complementary measures is warranted. Our preliminary finding suggests that data breaches negatively impact firm profitability, perceived risk and information transparency. Nevertheless, the damage of a breach most likely stems from direct costs such as compensation and litigation costs rather than indirect costs such as tarnished reputation and a decrease in market share and sales. More sophisticated analysts are also found to add value in estimating the real cost of a security breach.
منابع مشابه
The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers
Assessing the value of information technology (IT) security is challenging because of the difficulty of measuring the cost of security breaches. An event-study analysis, using market valuations, was used to assess the impact of security breaches on the market value of breached firms. The information-transfer effect of security breaches (i.e., their effect on the market value of firms that devel...
متن کاملIS THERE A COST TO PRIVACY BREACHES? AN EVENT STUDY Security and Assurance
While the literature on information security economics has begun to investigate the stock market impact of security breaches and vulnerability announcements, little more than anecdotal evidence exists on the effects of privacy breaches. In this paper we present the first comprehensive analysis of the impact of a company’s privacy incidents on its market value. We compile a broad data set of ins...
متن کاملThe Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market
This study examines the economic effect of information security breaches reported in newspapers on publicly traded US corporations. We find limited evidence of an overall negative stock market reaction to public announcements of information security breaches. However, further investigation reveals that the nature of the breach affects this result. We find a highly significant negative market re...
متن کاملIs There a Cost to Privacy Breaches? An Event Study
While the infosec economics literature has begun to investigate the stock market impact of security breaches and vulnerability announcements, little more than anecdotal evidence exists on effects of privacy breaches. In this paper we present the first comprehensive analysis of the impact of a company’s privacy incidents on its market value. We compile a broad data set of instances of exposure o...
متن کاملThe Market Effect of Healthcare Security: Do Patients Care about Data Breaches?
Data breach notification required by federal and state regulators has reduced information asymmetry on the effectiveness of information security programs. While pervasive media coverage of data breaches likely tarnishes an organization’s reputation, there is little empirical evidence that shows how consumers react to such organizational failures. Focusing on the healthcare sector as one of the ...
متن کامل