Author List: Wang, Tawei; Kannan, Karthik N.; Rees Ulmer, Jackie;
Information Systems Research, 2013, Volume 24, Issue 2, Page 201-218.
Firms often disclose information security risk factors in public filings such as 10-K reports. The internal information associated with disclosures may be positive or negative. In this paper, we evaluate how the nature of the disclosed security risk factors, believed to represent the firm's internal information regarding information security, is associated with future breach announcements reported in the media. For this purpose, we build a decision tree model, which classifies the occurrence of future security breaches based on the textual contents of the disclosed security risk factors. The model is able to accurately associate disclosure characteristics with breach announcements about 77% of the time. We further explore the contents of the security risk factors using text-mining techniques to provide a richer interpretation of the results. The results show that the disclosed security risk factors with risk-mitigation themes are less likely to be related to future breach announcements. We also investigate how the market interprets the nature of information security risk factors in annual reports. We find that the market reaction following the security breach announcement is different depending on the nature of the preceding disclosure. Thus, our paper contributes to the literature in information security and sheds light on how market participants can better interpret security risk factors disclosed in financial reports at the time when financial reports are released.
Keywords: information security; information security incident; risk factor; text mining
Algorithm:

List of Topics

#186 0.253 security information compliance policy organizations breach disclosure policies deterrence breaches incidents results study abuse managed isp violations based comply protection
#264 0.145 risk risks management associated managing financial appropriate losses expected future literature reduce loss approach alternative mitigate failures failure cause mitigation
#198 0.132 factors success information critical management implementation study factor successful systems support quality variables related results key model csf importance determinants
#176 0.122 e-commerce value returns initiatives market study announcements stock event abnormal companies significant growth positive using methodology investments period time initiative
#102 0.097 choice type functions nature paper literature particular implications function examine specific choices extent theoretical design discussion value widely finally adopted
#225 0.097 information environment provide analysis paper overall better relationships outcomes increasingly useful valuable available increasing greater regarding levels decisions viewed relative