Cyber-Security Incidents and Audit Quality

被引:30
|
作者
Rosati, Pierangelo [1 ]
Gogolin, Fabian [2 ]
Lynn, Theo [1 ]
机构
[1] Dublin City Univ, DCU Business Sch, Irish Inst Digital Business, Collins Ave, Dublin 9, Ireland
[2] Univ Leeds, Business Sch, Leeds, W Yorkshire, England
关键词
Cyber Security; External Audit; Audit Quality; SEC Comment Letters; INTERNAL CONTROL; NONAUDIT SERVICES; INFORMATION-TECHNOLOGY; OPERATIONAL RISK; MARKET VALUE; BREACH ANNOUNCEMENTS; EARNINGS MANAGEMENT; IMPACT; FEES; RESTATEMENTS;
D O I
10.1080/09638180.2020.1856162
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
As signals of internal control weaknesses, cyber security incidents can represent significant risk factors to the quality of financial reporting. We empirically assess the audit quality implications of data breaches for a large sample of US firms. Using a difference-in-difference approach based on a matched sample of breached and non-breached firms, we find no evidence that cyber-security incidents result in a decline in audit quality. Instead, we observe positive shifts in four widely-used proxies for audit quality. We document that breached firms (i) experience a decrease in abnormal accruals, (ii) are less likely to report small profits or small earnings increases, (iii) are more likely to be issued a going concern report, and (iv) are less likely to restate their financial statements in the two years following a breach. Our results indicate that auditors effectively offset increases in audit risk through additional substantive testing and audit effort. Our evidence supports the view that auditors have increased their audit risk awareness and put in place adequate procedures to deal with the consequences of cyber-security incidents.
引用
收藏
页码:701 / 728
页数:28
相关论文
共 50 条
  • [31] Pennsylvania starts cyber-security initiative
    不详
    COMPUTERS & SECURITY, 2001, 20 (08) : 650 - 650
  • [32] Self-Healing for Cyber-Security
    Gijsen, Bart
    Montalto, Ruggero
    Panneman, Jeffrey
    Falconieri, Federico
    Wiper, Paul
    Zuraniewski, Piotr
    2021 SIXTH INTERNATIONAL CONFERENCE ON FOG AND MOBILE EDGE COMPUTING (FMEC), 2021, : 84 - 90
  • [33] Strategic Communication for Supporting Cyber-Security
    Kuusisto, Tuija
    Kuusisto, Rauno
    INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2013, 3 (03) : 72 - 79
  • [34] The cyber-security challenge at the connected industry
    Garcia-Bringas, Pablo
    Angulo, Ignacio
    Goti-Elordi, Aitor
    Pastor, Iker
    DYNA, 2019, 94 (03): : 258 - 261
  • [35] Physical Cyber-Security of SCADA Systems
    Bichmou, Ahmed
    Chiocca, Joseph
    Hernandez, Leonarndo
    Hoffmann, R. Wade
    Horsham, Brandon
    Huy Lam
    McKinsey, Vince
    Bibyk, Steven
    PROCEEDINGS OF THE 2019 IEEE NATIONAL AEROSPACE AND ELECTRONICS CONFERENCE (NAECON), 2019, : 243 - 248
  • [36] Cyber-Security Training Evaluation Metrics
    Koutsouris, Nikolaos
    Vassilakis, Costas
    Kolokotronis, Nicholas
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 192 - 197
  • [37] A genetic epidemiology approach to cyber-security
    Santiago Gil
    Alexander Kott
    Albert-László Barabási
    Scientific Reports, 4
  • [38] Data Analysis for Network Cyber-security
    Dietz, Sebastian
    JOURNAL OF THE ROYAL STATISTICAL SOCIETY SERIES A-STATISTICS IN SOCIETY, 2016, 179 (03) : 878 - 878
  • [39] Cyber-security initiative now underway
    Jevtic, N
    CHEMICAL PROCESSING, 2003, 66 (02): : 17 - 17
  • [40] Plugging the cyber-security skills gap
    Caldwell, Tracey
    Computer Fraud and Security, 2013, 2013 (07): : 5 - 10