Journal of Information Technology
Document Type
Research Article
Abstract
The stock market reactions to information technology (IT)-related events have often been used as proxies to the value or cost of these events in the information systems literature. In this paper, we study the stock market reactions to information-security-related events using the event analysis methodology with consideration of the effects of a number of contingency factors, including business type, industry, type of breach, event year, and length of event window. We found that pure e-commerce firms experienced higher negative market reactions than traditional bricks-and-mortar firms in the event of security breach. We also found that denial of service attacks had higher negative impact than other types of security breaches. Finally, security events occurred in recent years were found to have less significant impact than those occurred earlier, suggesting that investors may have become less sensitive to the security events. Most interestingly, our analyses showed that the magnitude and longevity of security breaches vary with time across sub-samples. This raises some serious questions regarding the validity of analyzing only short-term stock market reactions as an indicator of the cost of security breaches, and in general, an indicator of the value of IT-related events. The implications of these results are discussed and potential future research directions are proposed.
DOI
10.1057/jit.2010.4
Recommended Citation
Yayla, Ali Alper and Hu, Qing
(2011)
"The Impact of Information Security Events on the Stock Value of Firms: The Effect of Contingency Factors,"
Journal of Information Technology: Vol. 26:
Iss.
1, Article 5.
DOI: 10.1057/jit.2010.4
Available at:
https://aisel.aisnet.org/jit/vol26/iss1/5