Whitaker Jonathan, Thekdi Shital
Robins School of Business, University of Richmond, Richmond, Virginia, USA.
Risk Anal. 2024 Sep 7;45(5):1027-43. doi: 10.1111/risa.17644.
Cybersecurity events can cause business disruptions, health and safety repercussions, financial costs, and negative publicity for large firms, and executives rank cybersecurity as a top operational concern. Although cybersecurity may be the most publicized information systems (IS) risk, large firms face a range of IS risks. Over the past three decades, researchers developed frameworks to categorize and evaluate IS risks. However, there have been few updates to these frameworks despite numerous technological advances, and we are not aware of any research that uses empirical data to map actual IS risks cited by large firms to these frameworks. To address this gap, we coded and analyzed text data from Item 1A (Risk Factors) of the fiscal year 2020 Securities and Exchange Commission Forms 10-K for all Fortune 1000 firms. We build on prior research to develop a framework that places 25 IS risks into four quadrants and 10 categories, and we record the number and type of IS risks cited by each firm. The risk of cyberattack is cited by virtually all Fortune 1000 firms, and the risk of software/hardware failure is cited by 90% of Fortune 1000 firms. Risks associated with data privacy law compliance are cited by 70% of Fortune 1000 firms, and risks associated with internet/telecommunications/power outage, human error, and natural disasters/terrorism are cited by 60% of Fortune 1000 firms. We perform additional analysis to identify differences in risk citation based on industry and financial measures.
网络安全事件可能导致业务中断、对健康与安全产生影响、造成财务成本,并给大公司带来负面宣传,企业高管将网络安全列为首要运营关注点。尽管网络安全可能是最受关注的信息系统(IS)风险,但大公司还面临一系列其他的IS风险。在过去三十年里,研究人员开发了一些框架来对IS风险进行分类和评估。然而,尽管有众多技术进步,这些框架却鲜有更新,而且我们也不知道有任何研究使用实证数据将大公司提及的实际IS风险映射到这些框架中。为了填补这一空白,我们对所有《财富》1000强公司2020财年美国证券交易委员会10-K表格中项目1A(风险因素)的文本数据进行了编码和分析。我们在先前研究的基础上,开发了一个框架,将25种IS风险分为四个象限和10个类别,并记录每家公司提及的IS风险的数量和类型。几乎所有《财富》1000强公司都提到了网络攻击风险,90%的《财富》1000强公司提到了软件/硬件故障风险。70%的《财富》1000强公司提到了与数据隐私法合规相关的风险,60%的《财富》1000强公司提到了与互联网/电信/停电、人为错误以及自然灾害/恐怖主义相关的风险。我们进行了额外的分析,以确定基于行业和财务指标的风险引用差异。