Organizational Learning from Cybersecurity Performance: Effects on Cybersecurity Investment Decisions

被引:0
|
作者
Faheem Ahmed Shaikh
Mikko Siponen
机构
[1] University of Jyväskylä,Faculty of Information Technology
[2] University of Jyväskylä,Faculty of Information Technology
来源
关键词
Cybersecurity investment; Cybersecurity breach; Cybersecurity performance; Breach identification; Breach cost; Organizational learning;
D O I
暂无
中图分类号
学科分类号
摘要
IS literature has identified various economic, performance, and environmental factors affecting cybersecurity investment decisions. However, economic modeling approaches dominate, and research on cybersecurity performance as an antecedent to investments has taken a backseat. Neglecting the role of performance indicators ignores real-world concerns driving actual cybersecurity investment decision-making. We investigate two critical aspects of cybersecurity performance: breach costs and breach identification source, as antecedents to cybersecurity investment decisions. We use organizational learning to theorize how performance feedback from these two aspects of cybersecurity breaches influences subsequent investment decisions. Using firm-level data on 722 firms in the UK, we find that higher breach costs are more likely to elicit increases in cybersecurity investments. This relationship is further strengthened if a third party identifies the breach instead of the focal firm. We contribute to the literature on cybersecurity investments and incident response. The findings stress the need for firms to analyze aspects of their cybersecurity performance and use them as feedback for investment decisions, making these decisions data-driven and based on firm-specific needs.
引用
收藏
页码:1109 / 1120
页数:11
相关论文
共 50 条
  • [1] Organizational Learning from Cybersecurity Performance: Effects on Cybersecurity Investment Decisions
    Shaikh, Faheem Ahmed
    Siponen, Mikko
    [J]. INFORMATION SYSTEMS FRONTIERS, 2024, 26 (03) : 1109 - 1120
  • [2] Learning from cybersecurity
    Iannotta, Ben
    [J]. AEROSPACE AMERICA, 2016, 54 (07) : 2 - 2
  • [3] Talk too much? The Impact of Cybersecurity Disclosures on Investment Decisions
    Cheng, Xu
    Hsu, Carol
    Wang, Tawei
    [J]. COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2022, 50 : 481 - +
  • [4] Evaluating the adoption of cybersecurity and its influence on organizational performance
    Tahereh Hasani
    Norman O’Reilly
    Ali Dehghantanha
    Davar Rezania
    Nadège Levallet
    [J]. SN Business & Economics, 3 (5):
  • [5] An Options Approach to Cybersecurity Investment
    Chronopoulos, Michail
    Panaousis, Emmanouil
    Grossklags, Jens
    [J]. IEEE ACCESS, 2018, 6 : 12175 - 12186
  • [6] Making a Strategic Investment in Cybersecurity
    Cote, Mike
    [J]. HARVARD BUSINESS REVIEW, 2015, 93 (11) : 144 - 144
  • [7] Socially optimal IT investment for cybersecurity
    Paul, Jomon A.
    Wang, Xinfang
    [J]. DECISION SUPPORT SYSTEMS, 2019, 122
  • [8] Exploration and Exploitation in Organizational Cybersecurity
    Jeyaraj, Anand
    Zadeh, Amir H.
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2022, 62 (04) : 680 - 693
  • [9] The Influence of Ethical Beliefs and Attitudes, Norms, and Prior Outcomes on Cybersecurity Investment Decisions
    Fleischman, Gary M.
    Valentine, Sean R.
    Curtis, Mary B.
    Mohapatra, Partha S.
    [J]. BUSINESS & SOCIETY, 2023, 62 (03) : 488 - 529
  • [10] The Impact of the Type of Cybersecurity Assurance Service and Cybersecurity Incidents on Investor Perceptions and Decisions
    Perols, Rebecca R.
    [J]. AUDITING-A JOURNAL OF PRACTICE & THEORY, 2024, 43 (03): : 187 - 202