Please use this identifier to cite or link to this item:
Title: Risk management, firm reputation, and the impact of successful cyberattacks on target firms
Authors: Kamiya, Shinichi
Kang, Jun-Koo
Kim, Jungmin
Milidonis, Andreas
Stulz, René M.
Keywords: Business::Information technology
Issue Date: 2020
Source: Kamiya, S., Kang, J., Kim, J., Milidonis, A. & Stulz, R. M. (2020). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719-749.
Journal: Journal of Financial Economics
Abstract: We develop a model where a firm has an optimal exposure to cyber risk. With rational, fully informed agents and with no hysteresis, a successful cyberattack should have no impact on a financially unconstrained target's reputation and post-attack policies. In contrast, when a successful attack involves the loss of personal financial information, there is a significant shareholder wealth loss, which is much larger than the attack's out-of-pocket costs. This excess loss is higher when the attack decreases sales growth more and lower when the board pays more attention to risk management before the attack. Further, an attack decreases a firm's risk appetite, as it beefs up its risk management and information technology and decreases the risk-taking incentives of management. Finally, successful cyberattacks adversely affect the stock price of firms in the target's industry. These results imply that successful attacks with personal financial information loss provide adverse information about cyber risk to target firms, their stakeholders, and their competitors.
ISSN: 0304-405X
DOI: 10.1016/j.jfineco.2019.05.019
Rights: © 2020 Elsevier B.V. All rights reserved. This paper was published in Journal of Financial Economics and is made available with permission of Elsevier B.V.
Fulltext Permission: embargo_20230407
Fulltext Availability: With Fulltext
Appears in Collections:NBS Journal Articles

Files in This Item:
File Description SizeFormat 
Microsoft Word - cyber risk July 27 Final_revised - cyber risk July 27 Final_revised.pdf
  Until 2023-04-07
3.95 MBAdobe PDFUnder embargo until Apr 07, 2023

Page view(s)

Updated on Dec 2, 2021

Google ScholarTM




Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.