Reading the Disclosures with New Eyes: Bridging the Gap between Information Security Disclosures and Incidents †

Tawei Wang, Jackie Rees, Karthik Kannan · 2007

This paper investigates the relationship between information security related disclosures in financial reports and the impacts of information security incidents. First, by drawing upon the theories in accounting literature, we regress stock price reactions to a number of information security incidents from 1997 to 2006 on the number of disclosures along with control variables. Our findings demonstrate that new information security risk factor disclosures can mitigate the effect of information security incidents in terms of cumulative abnormal return (CAR). Second, a clustering analysis is performed on the disclosures in financial reports before and after the incidents. The results demonstrate that companies react to information security incidents by disclosing more emerging risk factors in financial reports. A prediction model is also built based on disclosures. The model can correctly classify a firm as either breached or non-breached twothirds of the time. This paper not only contributes to the literature in information security and accounting but also sheds light on how managers can evaluate their information security policies and convey information security practices more effectively to the investors.

Read the paper · More papers on PaperTik