• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

没有“I-S”就拼不出“风险”:《财富》1000强企业对信息系统风险的披露。

You cannot spell risk without "I-S": The disclosure of information systems risks by Fortune 1000 firms.

作者信息

Whitaker Jonathan, Thekdi Shital

机构信息

Robins School of Business, University of Richmond, Richmond, Virginia, USA.

出版信息

Risk Anal. 2024 Sep 7;45(5):1027-43. doi: 10.1111/risa.17644.

DOI:10.1111/risa.17644
PMID:39244512
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC12087742/
Abstract

Cybersecurity events can cause business disruptions, health and safety repercussions, financial costs, and negative publicity for large firms, and executives rank cybersecurity as a top operational concern. Although cybersecurity may be the most publicized information systems (IS) risk, large firms face a range of IS risks. Over the past three decades, researchers developed frameworks to categorize and evaluate IS risks. However, there have been few updates to these frameworks despite numerous technological advances, and we are not aware of any research that uses empirical data to map actual IS risks cited by large firms to these frameworks. To address this gap, we coded and analyzed text data from Item 1A (Risk Factors) of the fiscal year 2020 Securities and Exchange Commission Forms 10-K for all Fortune 1000 firms. We build on prior research to develop a framework that places 25 IS risks into four quadrants and 10 categories, and we record the number and type of IS risks cited by each firm. The risk of cyberattack is cited by virtually all Fortune 1000 firms, and the risk of software/hardware failure is cited by 90% of Fortune 1000 firms. Risks associated with data privacy law compliance are cited by 70% of Fortune 1000 firms, and risks associated with internet/telecommunications/power outage, human error, and natural disasters/terrorism are cited by 60% of Fortune 1000 firms. We perform additional analysis to identify differences in risk citation based on industry and financial measures.

摘要

网络安全事件可能导致业务中断、对健康与安全产生影响、造成财务成本,并给大公司带来负面宣传,企业高管将网络安全列为首要运营关注点。尽管网络安全可能是最受关注的信息系统(IS)风险,但大公司还面临一系列其他的IS风险。在过去三十年里,研究人员开发了一些框架来对IS风险进行分类和评估。然而,尽管有众多技术进步,这些框架却鲜有更新,而且我们也不知道有任何研究使用实证数据将大公司提及的实际IS风险映射到这些框架中。为了填补这一空白,我们对所有《财富》1000强公司2020财年美国证券交易委员会10-K表格中项目1A(风险因素)的文本数据进行了编码和分析。我们在先前研究的基础上,开发了一个框架,将25种IS风险分为四个象限和10个类别,并记录每家公司提及的IS风险的数量和类型。几乎所有《财富》1000强公司都提到了网络攻击风险,90%的《财富》1000强公司提到了软件/硬件故障风险。70%的《财富》1000强公司提到了与数据隐私法合规相关的风险,60%的《财富》1000强公司提到了与互联网/电信/停电、人为错误以及自然灾害/恐怖主义相关的风险。我们进行了额外的分析,以确定基于行业和财务指标的风险引用差异。

相似文献

1
You cannot spell risk without "I-S": The disclosure of information systems risks by Fortune 1000 firms.没有“I-S”就拼不出“风险”:《财富》1000强企业对信息系统风险的披露。
Risk Anal. 2024 Sep 7;45(5):1027-43. doi: 10.1111/risa.17644.
2
The relationship between cybersecurity ratings and the risk of hospital data breaches.网络安全评级与医院数据泄露风险之间的关系。
J Am Med Inform Assoc. 2021 Sep 18;28(10):2085-2092. doi: 10.1093/jamia/ocab142.
3
Interventions to promote technology adoption in firms: A systematic review.促进企业技术采用的干预措施:一项系统综述。
Campbell Syst Rev. 2021 Nov 3;17(4):e1181. doi: 10.1002/cl2.1181. eCollection 2021 Dec.
4
Benefits in behavioral health carve-out plans of Fortune 500 firms.
Psychiatr Serv. 2001 Jul;52(7):943-8. doi: 10.1176/appi.ps.52.7.943.
5
Business Strategy and Environmental Information Disclosure Quality: Empirical Evidence from Chinese Heavy Pollution Listed Firms.企业战略与环境信息披露质量:来自中国重污染上市公司的经验证据。
Int J Environ Res Public Health. 2022 Jul 7;19(14):8325. doi: 10.3390/ijerph19148325.
6
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study.网络卫生方法在提高医疗机构网络安全和数据隐私意识中的应用:概念研究。
J Med Internet Res. 2023 Jul 27;25:e41294. doi: 10.2196/41294.
7
Economic Impact of a Hospital Cyberattack in a National Health System: Descriptive Case Study.国家卫生系统中医院网络攻击的经济影响:描述性案例研究
JMIR Form Res. 2023 Jun 30;7:e41738. doi: 10.2196/41738.
8
Greenwashing and financial performance in public health firms: the mechanism of organizational legitimacy erosion.公共卫生公司的漂绿行为与财务绩效:组织合法性侵蚀机制
Front Public Health. 2025 Mar 25;13:1565703. doi: 10.3389/fpubh.2025.1565703. eCollection 2025.
9
Pilot Medical Certification飞行员医学认证
10
Universal fluctuations in growth dynamics of economic systems.经济系统增长动态的普遍波动。
Sci Rep. 2019 Jan 24;9(1):713. doi: 10.1038/s41598-018-38088-z.

本文引用的文献

1
Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016-2021.2016-2021 年美国医院、诊所和其他医疗保健提供组织遭受勒索软件攻击的趋势。
JAMA Health Forum. 2022 Dec 2;3(12):e224873. doi: 10.1001/jamahealthforum.2022.4873.
2
The Role of Fairness in Early Characterization of New Technologies: Effects on Selective Exposure and Risk Perception.公平性在新技术早期特征描述中的作用:对选择性接触和风险感知的影响。
Risk Anal. 2021 Sep;41(9):1614-1629. doi: 10.1111/risa.13633. Epub 2020 Nov 10.
3
Summarizing risk using risk measures and risk indices.
使用风险度量和风险指数总结风险。
Risk Anal. 2014 Dec;34(12):2143-62. doi: 10.1111/risa.12220. Epub 2014 Jun 10.
4
Interrater reliability: the kappa statistic.组内一致性:kappa 统计量。
Biochem Med (Zagreb). 2012;22(3):276-82.
5
Catastrophic cascade of failures in interdependent networks.相互依存网络中的灾难性故障级联。
Nature. 2010 Apr 15;464(7291):1025-8. doi: 10.1038/nature08932.
6
A flexible count data regression model for risk analysis.一种用于风险分析的灵活计数数据回归模型。
Risk Anal. 2008 Feb;28(1):213-23. doi: 10.1111/j.1539-6924.2008.01014.x.
7
A psychometric study of information technology risks in the workplace.工作场所信息技术风险的心理测量学研究。
Risk Anal. 2008 Feb;28(1):81-93. doi: 10.1111/j.1539-6924.2007.00963.x.
8
Measurement and pricing of risk in insurance markets.保险市场中风险的度量与定价。
Risk Anal. 2005 Dec;25(6):1653-68. doi: 10.1111/j.1539-6924.2005.00684.x.