The impact of information sharing legislation on cybersecurity industry. Issue 9 (13th August 2020)
- Record Type:
- Journal Article
- Title:
- The impact of information sharing legislation on cybersecurity industry. Issue 9 (13th August 2020)
- Main Title:
- The impact of information sharing legislation on cybersecurity industry
- Authors:
- Yang, Agnes
Kwon, Young Jin
Lee, Sang-Yong Tom - Abstract:
- Abstract : Purpose: The objective of this paper is to investigate how firms react to cybersecurity information sharing environment where government organizations disseminate cybersecurity threat information gathered by individual firms to the private entities. The overall impact of information sharing on firms' cybersecurity investment decision has only been game-theoretically explored, not giving practical implication. The authors therefore leverage the Cybersecurity Information Sharing Act of 2015 (CISA) to observe firms' attitudinal changes toward investing in cybersecurity. Design/methodology/approach: The authors design a quasi-experiment where they set US cybersecurity firms as an experimental group (a proxy for total investment in cybersecurity) and nonsecurity firms as a control group to measure the net effect of CISA on overall cybersecurity investment. To enhance the robustness of the authors' difference-in-difference estimation, the authors employed propensity score matched sample test and reduced sample test as well. Findings: For the full sample, the authors' empirical findings suggest that US security firms' overall performance (i.e. Tobin's Q) improved following the legislation, which indicates that more investment in cybersecurity was followed by the formation of information sharing environment. Interestingly, big cybersecurity firms are beneficiaries of the CISA when the full samples are divided into small and large group. Both Tobin's Q and sales growthAbstract : Purpose: The objective of this paper is to investigate how firms react to cybersecurity information sharing environment where government organizations disseminate cybersecurity threat information gathered by individual firms to the private entities. The overall impact of information sharing on firms' cybersecurity investment decision has only been game-theoretically explored, not giving practical implication. The authors therefore leverage the Cybersecurity Information Sharing Act of 2015 (CISA) to observe firms' attitudinal changes toward investing in cybersecurity. Design/methodology/approach: The authors design a quasi-experiment where they set US cybersecurity firms as an experimental group (a proxy for total investment in cybersecurity) and nonsecurity firms as a control group to measure the net effect of CISA on overall cybersecurity investment. To enhance the robustness of the authors' difference-in-difference estimation, the authors employed propensity score matched sample test and reduced sample test as well. Findings: For the full sample, the authors' empirical findings suggest that US security firms' overall performance (i.e. Tobin's Q) improved following the legislation, which indicates that more investment in cybersecurity was followed by the formation of information sharing environment. Interestingly, big cybersecurity firms are beneficiaries of the CISA when the full samples are divided into small and large group. Both Tobin's Q and sales growth rate increased for big firms after CISA. Research limitations/implications: The authors' findings shed more light on the research stream of cybersecurity and information sharing, a research area only explored by game-theoretical approaches. Given that the US government has tried to enforce cybersecurity defensive measures by building cooperative architecture such as CISA 2015, the policy implication of this study is far-reaching. Originality/value: The authors' study contributes to the research on the economic benefits of sharing cybersecurity information by finding the missing link (i.e. empirical evidence) between "sharing" and "economic impact." This paper confirms that CISA affects the cybersecurity industry unevenly by firm size, a previously unidentified relationship. … (more)
- Is Part Of:
- Industrial management & data systems. Volume 120:Issue 9(2020)
- Journal:
- Industrial management & data systems
- Issue:
- Volume 120:Issue 9(2020)
- Issue Display:
- Volume 120, Issue 9 (2020)
- Year:
- 2020
- Volume:
- 120
- Issue:
- 9
- Issue Sort Value:
- 2020-0120-0009-0000
- Page Start:
- 1777
- Page End:
- 1794
- Publication Date:
- 2020-08-13
- Subjects:
- Cybersecurity information sharing -- Cybersecurity industry -- Economic impact -- Real option theory -- Quasi-experiment -- Difference-in-difference
Industrial management -- Periodicals
Electronic data processing -- Periodicals
Business -- Periodicals
Industrial management -- Great Britain -- Periodicals
658.05 - Journal URLs:
- http://www.emeraldinsight.com/0263-5577.htm ↗
http://www.emeraldinsight.com/ ↗ - DOI:
- 10.1108/IMDS-10-2019-0536 ↗
- Languages:
- English
- ISSNs:
- 0263-5577
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4457.715000
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 22178.xml