Thriving post-cyberattacks: the power of control, disclosure, and IT maturity
摘要
We examine the strategic utilization of internal controls and breach disclosures by firms to safeguard their survival, particularly within the unique context of cyberattacks, which challenge operational continuity, data integrity, and proprietary information security. Our investigation reveals that frequent cyberbreach disclosures bolster a firm’s economic resilience, whereas weaknesses in internal controls have an adverse effect. These pivotal findings are substantiated through a comprehensive battery of rigorous tests encompassing alternative metrics, econometric methodologies, and endogeneity assessments. Furthermore, our research highlights the conditional nature of the survival impact associated with cyberbreach disclosures and internal control weaknesses. This effect is moderated by the information technology committee and chief information officer, signifying a strategic response to mitigate cyber risks. Additionally, our supplementary analysis underlines that frequent cyberbreach disclosures drive firms to enhance their business innovation and competitive positioning, strategically mitigating the potential repercussions of such disclosures. Our study underscores the substantial threat posed by cyber risks to firm sustainability, and provides invaluable insights into proactive cybersecurity strategies for survival in the modern business landscape.