Implications of Enhanced Cybersecurity Risk Management Reporting and Independent Assurance

被引:1
|
作者
Frank, Michele L. [1 ]
Grenier, Jonathan H. [1 ]
Pyzoha, Jonathan S. [1 ]
Cribl, Natalie B. Zielinski [2 ]
机构
[1] Miami Univ, Oxford, OH 45056 USA
[2] Cribl, Scottsdale, AZ USA
来源
CURRENT ISSUES IN AUDITING | 2023年 / 17卷 / 01期
关键词
cybersecurity; risk management; assurance; nonprofessional investors; INFORMATION; DISCLOSURE; MARKET; ASSOCIATION;
D O I
10.2308/CIIA-2022-018
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
According to the World Economic Forum (WEF) (2022), cybersecurity risk is the most immediate and financially material sustainability risk that organizations face. Companies experience significant financial and reputational losses in the market after a cyberattack. However, companies are only required to disclose a trivial amount of information about their cybersecurity risk management efforts (SEC 2014; Newman 2018). This paper summarizes Frank, Grenier, and Pyzoha (2019), which examines whether voluntarily providing additional disclosures regarding a company's cybersecurity efforts, with or without assurance, increases investment attractiveness. Absent assurance, voluntary disclosures about the nature and effectiveness of cybersecurity efforts are sufficient to increase investment attractiveness for companies that have not (versus have) disclosed a prior cyberattack, as investors are less likely to question the disclosure's reliability. Assurance provides a greater benefit to companies that have (versus have not) disclosed a prior cyberattack, as they benefit more from the reliability enhancement of assurance.
引用
收藏
页码:P11 / P18
页数:8
相关论文
共 50 条
  • [1] How Disclosing a Prior Cyberattack Influences the Efficacy of Cybersecurity Risk Management Reporting and Independent Assurance
    Frank, Michele L.
    Grenier, Jonathan H.
    Pyzoha, Jonathan S.
    JOURNAL OF INFORMATION SYSTEMS, 2019, 33 (03) : 183 - 200
  • [2] Mission assurance policy and risk management in cybersecurity
    Cam H.
    Mouallem P.
    Environment Systems and Decisions, 2013, 33 (4) : 500 - 507
  • [3] Investors' perceptions of the cybersecurity risk management reporting framework
    Yang, Ling
    Lau, Linda
    Gan, Huiqi
    INTERNATIONAL JOURNAL OF ACCOUNTING AND INFORMATION MANAGEMENT, 2020, 28 (01) : 167 - 183
  • [4] Does cybersecurity maturity level assurance improve cybersecurity risk management in supply chains?
    Song, Ju Myung
    Wang, Tawei
    Yen, Ju-Chun
    Chen, Yu-Hung
    INTERNATIONAL JOURNAL OF ACCOUNTING INFORMATION SYSTEMS, 2024, 54
  • [5] Cybersecurity Risk Management
    Katsumata, Peter
    Hemenway, Judy
    Gavins, Wes
    MILITARY COMMUNICATIONS CONFERENCE, 2010 (MILCOM 2010), 2010, : 890 - 895
  • [6] The assurance providers' role in improving the independent assurance statement quality on sustainability reporting
    Harindahyani, Senny
    Agustia, Dian
    ACCOUNTING RESEARCH JOURNAL, 2023, 36 (01) : 37 - 54
  • [7] Determinants of Sustainability Reporting and Independent Assurance Decisions br
    Temiz, Huseyin
    Seker, Yasin
    Ozdemir, Fevzi Serkan
    ESKISEHIR OSMANGAZI UNIVERSITESI IIBF DERGISI-ESKISEHIR OSMANGAZI UNIVERSITY JOURNAL OF ECONOMICS AND ADMINISTRATIVE SCIENCES, 2022, 17 (03): : 862 - 892
  • [8] Accounting and Cybersecurity Risk Management
    Eaton, Tim V.
    Grenier, Jonathan H.
    Layman, David
    CURRENT ISSUES IN AUDITING, 2019, 13 (02): : C1 - C9
  • [9] Cyber risk logics and their implications for cybersecurity
    Backman, Sarah
    Stevens, Tim
    INTERNATIONAL AFFAIRS, 2024, 100 (06) : 2441 - 2460
  • [10] Is corporate reputation associated with voluntary cybersecurity risk reporting?
    Singh, Harmandeep
    MEDITARI ACCOUNTANCY RESEARCH, 2025, 33 (01) : 198 - 219