IDEAS home Printed from https://ideas.repec.org/a/eee/jfinec/v139y2021i3p719-749.html
   My bibliography  Save this article

Risk management, firm reputation, and the impact of successful cyberattacks on target firms

Author

Listed:
  • Kamiya, Shinichi
  • Kang, Jun-Koo
  • Kim, Jungmin
  • Milidonis, Andreas
  • Stulz, René M.

Abstract

We develop a model where a firm has an optimal exposure to cyber risk. With rational, fully informed agents and with no hysteresis, a successful cyberattack should have no impact on a financially unconstrained target's reputation and post-attack policies. In contrast, when a successful attack involves the loss of personal financial information, there is a significant shareholder wealth loss, which is much larger than the attack's out-of-pocket costs. This excess loss is higher when the attack decreases sales growth more and lower when the board pays more attention to risk management before the attack. Further, an attack decreases a firm's risk appetite, as it beefs up its risk management and information technology and decreases the risk-taking incentives of management. Finally, successful cyberattacks adversely affect the stock price of firms in the target's industry. These results imply that successful attacks with personal financial information loss provide adverse information about cyber risk to target firms, their stakeholders, and their competitors.

Suggested Citation

  • Kamiya, Shinichi & Kang, Jun-Koo & Kim, Jungmin & Milidonis, Andreas & Stulz, René M., 2021. "Risk management, firm reputation, and the impact of successful cyberattacks on target firms," Journal of Financial Economics, Elsevier, vol. 139(3), pages 719-749.
  • Handle: RePEc:eee:jfinec:v:139:y:2021:i:3:p:719-749
    DOI: 10.1016/j.jfineco.2019.05.019
    as

    Download full text from publisher

    File URL: http://www.sciencedirect.com/science/article/pii/S0304405X20300143
    Download Restriction: Full text for ScienceDirect subscribers only

    File URL: https://libkey.io/10.1016/j.jfineco.2019.05.019?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to search for a different version of it.

    References listed on IDEAS

    as
    1. Graham, John R. & Li, Si & Qiu, Jiaping, 2008. "Corporate misreporting and bank loan contracting," Journal of Financial Economics, Elsevier, vol. 89(1), pages 44-61, July.
    2. Nicola Gennaioli & Andrei Shleifer & Robert Vishny, 2015. "Neglected Risks: The Psychology of Financial Crises," American Economic Review, American Economic Association, vol. 105(5), pages 310-314, May.
    3. Anat Hovav & John D'Arcy, 2003. "The Impact of Denial‐of‐Service Attack Announcements on the Market Value of Firms," Risk Management and Insurance Review, American Risk and Insurance Association, vol. 6(2), pages 97-121, September.
    4. Anat R. Admati & Peter M. Demarzo & Martin F. Hellwig & Paul Pfleiderer, 2018. "The Leverage Ratchet Effect," Journal of Finance, American Finance Association, vol. 73(1), pages 145-198, February.
    5. Bryan, Stephen & Hwang, LeeSeok & Lilien, Steven, 2000. "CEO Stock-Based Compensation: An Empirical Analysis of Incentive-Intensity, Relative Mix, and Economic Determinants," The Journal of Business, University of Chicago Press, vol. 73(4), pages 661-693, October.
    6. Bakke, Tor-Erik & Mahmudi, Hamed & Fernando, Chitru S. & Salas, Jesus M., 2016. "The causal effect of option pay on corporate risk management," Journal of Financial Economics, Elsevier, vol. 120(3), pages 623-643.
    7. Karpoff, Jonathan M. & Lee, D. Scott & Martin, Gerald S., 2008. "The Cost to Firms of Cooking the Books," Journal of Financial and Quantitative Analysis, Cambridge University Press, vol. 43(3), pages 581-611, September.
    8. Marco Caliendo & Sabine Kopeinig, 2008. "Some Practical Guidance For The Implementation Of Propensity Score Matching," Journal of Economic Surveys, Wiley Blackwell, vol. 22(1), pages 31-72, February.
    9. Toni M. Whited & Guojun Wu, 2006. "Financial Constraints Risk," The Review of Financial Studies, Society for Financial Studies, vol. 19(2), pages 531-559.
    10. Carhart, Mark M, 1997. "On Persistence in Mutual Fund Performance," Journal of Finance, American Finance Association, vol. 52(1), pages 57-82, March.
    11. Chernobai, Anna & Jorion, Philippe & Yu, Fan, 2011. "The Determinants of Operational Risk in U.S. Financial Institutions," Journal of Financial and Quantitative Analysis, Cambridge University Press, vol. 46(6), pages 1683-1725, December.
    12. Larcker, David F. & Reiss, Peter C. & Tayan, Brian, 2017. "Critical Update Needed: Cybersecurity Expertise in the Boardroom," Research Papers repec:ecl:stabus:3622, Stanford University, Graduate School of Business.
    13. repec:cup:jfinqa:v:46:y:2011:i:06:p:1683-1725_00 is not listed on IDEAS
    14. Myers, Stewart C., 1977. "Determinants of corporate borrowing," Journal of Financial Economics, Elsevier, vol. 5(2), pages 147-175, November.
    15. Chan, Lilian H. & Chen, Kevin C.W. & Chen, Tai-Yuan, 2013. "The effects of firm-initiated clawback provisions on bank loan contracting," Journal of Financial Economics, Elsevier, vol. 110(3), pages 659-679.
    16. repec:bla:jfinan:v:43:y:1988:i:1:p:1-19 is not listed on IDEAS
    17. Cummins, J. David & Lewis, Christopher M. & Wei, Ran, 2006. "The market value impact of operational loss events for US banks and insurers," Journal of Banking & Finance, Elsevier, vol. 30(10), pages 2605-2634, October.
    18. Fama, Eugene F. & French, Kenneth R., 1993. "Common risk factors in the returns on stocks and bonds," Journal of Financial Economics, Elsevier, vol. 33(1), pages 3-56, February.
    19. Murphy, Deborah L. & Shrieves, Ronald E. & Tibbs, Samuel L., 2009. "Understanding the Penalties Associated with Corporate Misconduct: An Empirical Examination of Earnings and Risk," Journal of Financial and Quantitative Analysis, Cambridge University Press, vol. 44(1), pages 55-83, February.
    20. Titman, Sheridan, 1984. "The effect of capital structure on a firm's liquidation decision," Journal of Financial Economics, Elsevier, vol. 13(1), pages 137-151, March.
    21. Karpoff, Jonathan M & Lott, John R, Jr, 1993. "The Reputational Penalty Firms Bear from Committing Criminal Fraud," Journal of Law and Economics, University of Chicago Press, vol. 36(2), pages 757-802, October.
    22. Coles, Jeffrey L. & Daniel, Naveen D. & Naveen, Lalitha, 2006. "Managerial incentives and risk-taking," Journal of Financial Economics, Elsevier, vol. 79(2), pages 431-468, February.
    23. Tyler Shumway & Vincent A. Warther, 1999. "The Delisting Bias in CRSP's Nasdaq Data and Its Implications for the Size Effect," Journal of Finance, American Finance Association, vol. 54(6), pages 2361-2379, December.
    24. Eli Amir & Shai Levi & Tsafrir Livne, 2018. "Do firms underreport information on cyber-attacks? Evidence from capital markets," Review of Accounting Studies, Springer, vol. 23(3), pages 1177-1206, September.
    25. Froot, Kenneth A & Scharfstein, David S & Stein, Jeremy C, 1993. "Risk Management: Coordinating Corporate Investment and Financing Policies," Journal of Finance, American Finance Association, vol. 48(5), pages 1629-1658, December.
    26. Jarrell, Gregg & Peltzman, Sam, 1985. "The Impact of Product Recalls on the Wealth of Sellers," Journal of Political Economy, University of Chicago Press, vol. 93(3), pages 512-536, June.
    27. Shumway, Tyler, 2001. "Forecasting Bankruptcy More Accurately: A Simple Hazard Model," The Journal of Business, University of Chicago Press, vol. 74(1), pages 101-124, January.
    28. Cass Sunstein & Richard Zeckhauser, 2011. "Overreaction to Fearsome Risks," Environmental & Resource Economics, Springer;European Association of Environmental and Resource Economists, vol. 48(3), pages 435-449, March.
    29. Claire Lending & Kristina Minnick & Patrick J. Schorno, 2018. "Corporate Governance, Social Responsibility, and Data Breaches," The Financial Review, Eastern Finance Association, vol. 53(2), pages 413-455, May.
    30. Steven N. Kaplan & Luigi Zingales, 1997. "Do Investment-Cash Flow Sensitivities Provide Useful Measures of Financing Constraints?," The Quarterly Journal of Economics, President and Fellows of Harvard College, vol. 112(1), pages 169-215.
    31. Kevin M. Gatzlaff & Kathleen A. McCullough, 2010. "The Effect of Data Breaches on Shareholder Wealth," Risk Management and Insurance Review, American Risk and Insurance Association, vol. 13(1), pages 61-83, March.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Shinichi Kamiya & Jun-Koo Kang & Jungmin Kim & Andreas Milidonis & René M. Stulz, 2018. "What is the Impact of Successful Cyberattacks on Target Firms?," NBER Working Papers 24409, National Bureau of Economic Research, Inc.
    2. Giau Bui, Dien & Chen, Yehning & Lin, Chih-Yung & Lin, Tse-Chun, 2021. "Risk-taking of bank CEOs and corporate innovation," Journal of International Money and Finance, Elsevier, vol. 115(C).
    3. Chen, Sheng-Syan & Wang, Yanzhi, 2012. "Financial constraints and share repurchases," Journal of Financial Economics, Elsevier, vol. 105(2), pages 311-331.
    4. Qin, Jiaqi & Yang, Xue & He, Qing & Sun, Lingxia, 2021. "Litigation risk and cost of capital: Evidence from China," Pacific-Basin Finance Journal, Elsevier, vol. 68(C).
    5. Johnson, William C. & Xie, Wenjuan & Yi, Sangho, 2014. "Corporate fraud and the value of reputations in the product market," Journal of Corporate Finance, Elsevier, vol. 25(C), pages 16-39.
    6. Akhtar, Shumi & Akhtar, Farida & John, Kose & Wong, Su-Wen, 2019. "Multinationals' tax evasion: A financial and governance perspective," Journal of Corporate Finance, Elsevier, vol. 57(C), pages 35-62.
    7. Tetyana Balyuk & Nagpurnanand R. Prabhala & Manju Puri, 2020. "Indirect Costs of Government Aid and Intermediary Supply Effects: Lessons From the Paycheck Protection Program," NBER Working Papers 28114, National Bureau of Economic Research, Inc.
    8. Winston Wei Dou & Yan Ji & David Reibstein & Wei Wu, 2021. "Inalienable Customer Capital, Corporate Liquidity, and Stock Returns," Journal of Finance, American Finance Association, vol. 76(1), pages 211-265, February.
    9. Samuel L. Tibbs & Deborah L. Harrell & Ronald E. Shrieves, 2011. "Do Shareholders Benefit from Corporate Misconduct? A Long‐Run Analysis," Journal of Empirical Legal Studies, John Wiley & Sons, vol. 8(3), pages 449-476, September.
    10. Çolak, Gönül & Korkeamäki, Timo, 2021. "CEO mobility and corporate policy risk," Journal of Corporate Finance, Elsevier, vol. 69(C).
    11. Pak Hung Au & Yuk‐Fai Fong & Jin Li, 2020. "Negotiated Block Trade And Rebuilding Of Trust," International Economic Review, Department of Economics, University of Pennsylvania and Osaka University Institute of Social and Economic Research Association, vol. 61(2), pages 901-939, May.
    12. Al-Amri, Khalid & Davydov, Yevgeniy, 2016. "Testing the effectiveness of ERM: Evidence from operational losses," Journal of Economics and Business, Elsevier, vol. 87(C), pages 70-82.
    13. Chris Florackis & Christodoulos Louca & Roni Michaely & Michael Weber, 2023. "Cybersecurity Risk," The Review of Financial Studies, Society for Financial Studies, vol. 36(1), pages 351-407.
    14. Liu, Siqi & Yin, Chao & Zeng, Yeqin, 2021. "Abnormal investment and firm performance," International Review of Financial Analysis, Elsevier, vol. 78(C).
    15. Wei, Xin & Liu, Xi & Zhang, Xueyong, 2022. "Shadow banking and the cross-section of stock returns," Journal of International Financial Markets, Institutions and Money, Elsevier, vol. 81(C).
    16. Chen, Anlin & Lu, Cheng-Shou, 2015. "The effect of managerial overconfidence on the market timing ability and post-buyback performance of open market repurchases," The North American Journal of Economics and Finance, Elsevier, vol. 33(C), pages 234-251.
    17. John Y. Campbell & Jens Hilscher & Jan Szilagyi, 2008. "In Search of Distress Risk," Journal of Finance, American Finance Association, vol. 63(6), pages 2899-2939, December.
    18. James Malm & Marcin Krolikowski, 2017. "Litigation risk and financial leverage," Journal of Economics and Finance, Springer;Academy of Economics and Finance, vol. 41(1), pages 180-194, January.
    19. Linnenluecke, Martina K. & Chen, Xiaoyan & Ling, Xin & Smith, Tom & Zhu, Yushu, 2017. "Research in finance: A review of influential publications and a research agenda," Pacific-Basin Finance Journal, Elsevier, vol. 43(C), pages 188-199.
    20. Surendranath R. Jory & Thanh N. Ngo & Daphne Wang & Amrita Saha, 2015. "The market response to corporate scandals involving CEOs," Applied Economics, Taylor & Francis Journals, vol. 47(17), pages 1723-1738, April.

    More about this item

    Keywords

    Cyber risk; Cyberattack; Risk management; Reputation; Firm value; Stakeholders;
    All these keywords.

    JEL classification:

    • G14 - Financial Economics - - General Financial Markets - - - Information and Market Efficiency; Event Studies; Insider Trading
    • G32 - Financial Economics - - Corporate Finance and Governance - - - Financing Policy; Financial Risk and Risk Management; Capital and Ownership Structure; Value of Firms; Goodwill
    • G34 - Financial Economics - - Corporate Finance and Governance - - - Mergers; Acquisitions; Restructuring; Corporate Governance
    • G35 - Financial Economics - - Corporate Finance and Governance - - - Payout Policy

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:eee:jfinec:v:139:y:2021:i:3:p:719-749. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catherine Liu (email available below). General contact details of provider: http://www.elsevier.com/locate/inca/505576 .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.