The impact of CIO characteristics on data breaches

Thomas Smith1, Amanuel F. Tadesse2, Nishani Edirisinghe Vincent3
1Associate Professor of Accounting, University of South Florida, 4202 E Fowler Avenue, Tampa, FL 33620, USA
2Associate Professor of Accounting, University of New Orleans, 2000 Lakeshore Drive, New Orleans, LA 70148, USA
3Associate Professor of Accounting, The University of Tennessee at Chattanooga, 615 McCallie Avenue, Chattanooga, TN 37403, USA

Tài liệu tham khảo

Al Shammari, 2018, CEO Incentive compensation and risk-taking behavior: The moderating role of CEO characteristics, Acad. Strateg. Manag. J., 17, 1 Ball, 2002, CIO on center stage: 9/11 changes everything, Inform. Syst. Manag., 19, 8, 10.1201/1078/43200.19.2.20020228/35136.2 Banker, 2019, The impact of information security breach incidents on CIO turnover, J. Inform. Syst., 33, 309 Banker, 2011, CIO reporting structure, strategic positioning, and firm performance, MIS Quart., 35, 487, 10.2307/23044053 Becker, 1993, Nobel lecture: the economic way of looking at behavior, J. Polit. Econ., 101, 385, 10.1086/261880 Benaroch, 2017, Operational IT failures, IT value destruction, and board-level IT governance changes, MIS Quart., 41, 729, 10.25300/MISQ/2017/41.3.04 Burke, 2006, Health care CIOs: Assessing their fit in the organizational hierarchy and their influence on information technology capability, Health Care Manager, 25, 167, 10.1097/00126450-200604000-00010 Chatterjee, 2001, Examining the shareholder wealth effects of announcements of newly created CIO positions, MIS Quart., 25, 43, 10.2307/3250958 Chen, 2010, Antecedents and effects of CIO supply-side and demand-side leadership: A staged maturity model, J. Manag Inform. Syst., 27, 231, 10.2753/MIS0742-1222270110 Chen, 2011, IT management capability and its impact on the performance of a CIO, Inform. Manag., 48, 145, 10.1016/j.im.2011.04.001 Cheng, 2017 Choobineh, 2007, Management of information security: Challenges and research directions, Commun. Assoc. Inform. Syst., 20, 958 Chun, 2009, CIO roles and responsibilities: Twenty-five years of evolution and change, Inform. Manag., 46, 323, 10.1016/j.im.2009.05.005 Clements, 2015, Multiple directorships, industry relatedness, and corporate governance effectiveness, Corpor. Gover., 15, 590, 10.1108/CG-05-2014-0060 Cohn, 1975, Individual investor risk aversion and investment portfolio composition, J. Finance, 30, 605, 10.1111/j.1540-6261.1975.tb01834.x Committee of Sponsoring Organizations of the Treadway Commission (COSO), 2004 Crossland, 2011, Differences in managerial discretion across countries: how nation-level institutions affect degree to which CEOs matter, Strateg. Manag. J., 32, 797, 10.1002/smj.913 Daboub, 1995, Top management team characteristics and corporate illegal activity, Acad. Manag. Rev., 20, 138, 10.2307/258890 Davenport, T. 2016. Why No One Wants to Be a Chief Information Officer Any More. Forbes. March 10, 2016. Available online from:http://fortune.com/2016/03/10/why-no-one-wants-to-be-a-chief-information-officer-any-more/?utm_source=emailshare&utm_medium=email&utm_campaign=email-share-article&utm_content=20190531. Davidson, 2006, Determinants of CEO age at succession, J. Manage. Govern., 10, 35, 10.1007/s10997-005-3548-5 Disterer, 2013, ISO/IEC 27000, 27001 and 27002 for information security management, J. Inform. Sec., 04, 92 Díaz-Fernández, 2015, Top management teams' demographic characteristics and their influence on strategic change, Qual. Quant., 49, 1305, 10.1007/s11135-014-0053-4 Dohmen, 2011, Individual risk attitudes: Measurement, determinants, and behavioral consequences, J. Euro. Econom. Assoc., 9, 522, 10.1111/j.1542-4774.2011.01015.x Donkers, 2001, Estimating risk attitudes using lotteries: A large sample approach, Journal of Risk and Uncertainty, 22, 165, 10.1023/A:1011109625844 Dunbar, 2008, CIO response: Bat demonstrates an effective “two-handed clap”, MIS Quart. Execut., 1 Engelbrecht, 2003, Human capital and economic growth: cross-section evidence for OECD countries, Econom. Record, 79, 40, 10.1111/1475-4932.00090 Ettredge, 2018, Trade secrets and cybersecurity breaches, J. Account. Public Policy, 37, 564, 10.1016/j.jaccpubpol.2018.10.006 Limited Feng, 2009, Internal control and management guidance, J. Account. Econom., 48, 190, 10.1016/j.jacceco.2009.09.004 Feng, 2015 Feng, 2019, Does CIO risk appetite matter? Evidence from information security breach incidents, Int. J. Account. Inform. Syst., 32, 59, 10.1016/j.accinf.2018.11.001 Faccio, 2016, CEO gender, corporate risk-taking, and the efficiency of capital allocation, J. Corp. Fin., 39, 193, 10.1016/j.jcorpfin.2016.02.008 Garcia-Alvarez, 2011, Structural capital management: A guide for indicators, Int. J. Manag. Inform. Syst., 15, 41 Gilbert, 1991, The trouble of thinking: Activation and application of stereotypic beliefs, J. Pers. Soc. Psychol., 60, 509, 10.1037/0022-3514.60.4.509 Gilbert, 1989, Thinking backward: Some curable and incurable consequences of cognitive busyness, J. Pers. Soc. Psychol., 57, 940, 10.1037/0022-3514.57.6.940 Gottschalk, 1999, Strategic management of IS/IT functions: The role of the CIO in Norwegian organizations, Int. J. Inf. Manage., 19, 389, 10.1016/S0268-4012(99)00034-1 Haislip, 2021, The impact of executives’ IT expertise on reported data security breaches, Inf. Syst. Res., articles in advance, 1 Haislip, 2016, Repairing organizational legitimacy following information technology (IT) material weaknesses: Executive turnover, IT expertise, and IT system upgrades, J. Inform. Syst., 30, 41 Haislip, 2015, External reputation penalties for CEOs following information technology material weaknesses, Int. J. Account. Inform. Syst., 17, 1, 10.1016/j.accinf.2015.01.002 Haislip, 2018, The effect of CEO IT expertise on the information environment: Evidence from earnings forecasts and announcements, J. Inform. Syst., 32, 71 Hamblen, M. 2018. CIOs’ evolving role: Think revenue and strategy. Information Week January, 9. Online. Available at https://www.informationweek.com/strategic-cio/cios-evolving-role-think-revenue-and-strategy/d/d-id/1330764. Hambrick, 1984, Upper echelons: The organization as a reflection of its top managers, Acad. Manag. Rev., 9, 193, 10.2307/258434 Heckman, 1979, Sample selection bias as a specification error, Econometrica, 47, 153, 10.2307/1912352 Henderson, 2006, How quickly do CEOs become obsolete? industry dynamism, CEO tenure and company performance, Strateg. Manag. J., 27, 447, 10.1002/smj.524 Hendricks, 2002, How important is human capital for development? Evidence from immigrant earnings, American Economic Review, 92, 198, 10.1257/000282802760015676 Higgs, 2016, The relationship between board-level technology committees and reported security breaches, J. Inform. Syst., 303, 79 Huang, 2012, CEO age and financial reporting quality, Account. Horizons, 26, 725, 10.2308/acch-50268 Huang, 2013, Gender and corporate finance: Are male executives overconfident relative to female executives?, J. Financ. Econ., 108, 822, 10.1016/j.jfineco.2012.12.005 Hütter, 2017, Chief Information Officer Role Effectiveness: Literature Review and Implications for Research and Practice, 1 ISACA. 2012. COBIT 5: A business framework for the governance and management of enterprise IT. Retrieved from www.isaca.org. Kayworth, 2010, Effective Information Security Requires a Balance of Social and Technology Factors, MIS Quart. Execut., 9, 163 Khallaf, 2012, Investigating the impact of CIO competencies on IT security performance of the U.S. federal government agencies, J. Manag. Inf. Syst., 291, 55, 10.1080/10580530.2012.634298 Kimberly, 1981, Organizational innovation: The influence of individual organizational and contextual factors on hospital adoption of technical and administrative innovations, Acad. Manag. J., 24, 689, 10.2307/256170 Knapp, 2006, Information security: management’s effect on culture and policy, Inform. Manag. Comput. Sec., 14, 24, 10.1108/09685220610648355 Kogut, 1996, What firms do? Coordination, identity, and learning, Organ. Sci., 7, 502, 10.1287/orsc.7.5.502 Kwon, 2013, The association between top management involvement and compensation and information security breaches, J. Inform. Syst., 27, 219 Lawrence, 2018, Is operational control risk informative of financial reporting deficiencies?, Audit. J. Pract. Theory, 37, 139, 10.2308/ajpt-51784 Lennox, 2012, Selection models in accounting research, Account. Rev., 87, 589, 10.2308/accr-10195 Li, 2013, Matching business strategy and CIO characteristics: The impact on organizational performance, J. Bus. Res., 66, 248, 10.1016/j.jbusres.2012.07.017 Li, 2020, Are external auditors concerned about cyber incidents? Evidence from audit fees, Audit. A J. Pract. Theory, 39, 151, 10.2308/ajpt-52593 Luftman, 2007, An update on business-it alignment: “A line” has been drawn, MIS Quart. Execut., 6, 165 MacCrimmon, 1990, Characteristics of risk taking executives, Manage. Sci., 36, 422, 10.1287/mnsc.36.4.422 Malmendier, 2011, Overconfidence and early-life experiences: the effect of managerial traits on corporate financial policies, J Finance, 66, 1687, 10.1111/j.1540-6261.2011.01685.x Miles, 1978 National Institute of Standards and Technology (NIST), 2002 Ng, 2010, Organizational Tenure and Job Performance, J. Manag., 36, 1220 Nielsen, 2013, Top management team nationality diversity and firm performance: a multilevel study, Strateg. Manag. J., 34, 373, 10.1002/smj.2021 Pettey, C. 2019. CIO Agenda 2019: Take a Hard and Soft Approach to Cybersecurity. Gartner. April 29, 2019. Available online at: https://www.gartner.com/smarterwithgartner/cio-agenda-2019-take-a-hard-and-soft-approach-to-cybersecurity/. Institute Preston, 2008, Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study, Decision Sci., 39, 605, 10.1111/j.1540-5915.2008.00206.x Raghunathan, 1989, Relationship of the rank of information systems executive to the organizational role and planning dimensions of information systems, J. Manag. Inform. Syst., 6, 111, 10.1080/07421222.1989.11517852 Rhodes, 1983, Age-related differences in work attitudes and behavior: A review and conceptual analysis, Psychol. Bull., 93, 328, 10.1037/0033-2909.93.2.328 Richardson, 2019, Much ado about nothing: The (lack of) economic impact of data privacy breaches, J. Inform. Syst., 33, 227 Rowsell-Jones, 2007, The emergence of enterprise dynamics, CIO Canada, 15, 1 Sanders, J. 2019. 25% of software vulnerabilities remain unpatched for more than a year. TechRepublic March 12, 2019. Online, available at: https://www.techrepublic.com/article/25-of-software-vulnerabilities-remain-unpatched-for-more-than-a-year/?ftag=CMG-01-10aaa1b. Securities and Exchange Commission. 2009. Securities and Exchange Commission Proxy Disclosure Enhancements, Release Nos. 33-9089; 34-61175; IC-29092; File No. S7-13-09. Retrieved from http://www.sec.gov/news/press/2009/2009-268.htm. Securities and Exchange Commission. 2011. CF Disclosure Guidance: Topic No. 2: Cybersecurity. Retrieved from https://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm. Sharma, 2015, Adopting IS process innovations in organizations: the role of IS leaders’ individual factors and technology perceptions in decision making, Eur. J. Inform. Syst., 24, 23, 10.1057/ejis.2013.24 Shao, 2016, Impact of chief information officer’s strategic knowledge and structural power on enterprise systems success, Ind. Manag. Data Syst., 116, 43, 10.1108/IMDS-05-2015-0186 Simsek, 2007, CEO tenure and organizational performance: An intervening model, Strateg. Manag. J., 28, 653, 10.1002/smj.599 Smaltz, 2006, The antecedents of CIO role effectiveness in organizations: An empirical study in the healthcare sector, IEEE Trans. Eng. Manage., 53, 207, 10.1109/TEM.2006.872248 Smith, 2019, Do auditors price breach risk in their audit fees?, J. Inform. Syst., 33, 177 Sobol, 2009, Relation of CIO background, IT infrastructure, and economic performance, Inform. Manag., 46, 271, 10.1016/j.im.2009.05.001 Soomro, 2016, Information security management needs more holistic approach: A literature review, Int. J. Inf. Manage., 36, 215, 10.1016/j.ijinfomgt.2015.11.009 Spanos, 2016, The impact of information security events to the stock market: A systematic literature review, Comput. Secur., 58, 216, 10.1016/j.cose.2015.12.006 Spitze, 2012, The renaissance CIO project: The invisible factors of extraordinary success, California Manag. Rev., 54, 72, 10.1525/cmr.2012.54.2.72 Statham, 1987, The gender model revisited: Differences in the management styles of men and women, Sex Roles, 16, 409, 10.1007/BF00289552 Stephens, 1992, Executive or functional manager? The nature of the CIO's job, MIS Quart., 16, 449, 10.2307/249731 Sturman, 2003, Searching for the inverted U-shaped relationship between time and performance: meta-analyses of the experience/performance, tenure/performance, and age/performance relationships, J. Manag., 29, 609 Thomas, 1994, Matching managers to strategy: An investigation of performance implications and boundary conditions, Australian J. Manag., 19, 73, 10.1177/031289629401900105 Thomas, 1996, Matching managers to strategy: Further tests of miles and snow topology, Br. J. Manag., 7, 247, 10.1111/j.1467-8551.1996.tb00118.x Tu, 2018, Strategic value alignment for information security management: A critical success factor analysis, Inform. Comput. Secur., 26, 150, 10.1108/ICS-06-2017-0042 Uppal, 2017, Uncovering curvilinearity in the organizational tenure-job performance relationship: A moderated mediation model of continuance commitment and motivational job characteristics, Personnel Rev., 46, 1552, 10.1108/PR-11-2015-0302 Varonis. 2019. Data gets personal: 2019 global data risk report from the Varonis data lab. Retrieved from https://info.varonis.com/hubfs/Varonis%202019%20Global%20Data%20Risk%20Report.pdf. Vincent, 2017, IT governance and the maturity of IT risk management practices, J. Inform. Syst., 31, 59 Vincent, 2019, Board and management level factors affecting the maturity of IT risk management practices, J. Inform. Syst., 33, 117 Vincent, 2020, IT risk management: Interrelationships based on strategy implementation, Int. J. Account. Inform. Manag., 28, 553, 10.1108/IJAIM-08-2019-0093 Wang, 2013, Board composition and operational risk events of financial institutions, J. Bank. Finance, 37, 2042, 10.1016/j.jbankfin.2013.01.027 Werlinger, 2009, An integrated view of human, organizational, and technological challenges of IT security management, Inform. Manag. Comput. Secur., 17, 4, 10.1108/09685220910944722 Yim, 2013, The acquisitiveness of youth: CEO age and acquisition behavior, J. Financ. Econ., 108, 250, 10.1016/j.jfineco.2012.11.003 Zafar, 2016, The value of the CIO in the top management team on performance in the case of information security breaches, Inform. Syst. Front., 18, 1205, 10.1007/s10796-015-9562-5 Zurkus, K. 2015. Why every CIO needs a cybersecurity attorney. CIO. August 4, 2015. Available online from: https://www.cio.com/article/2956374/why-every-cio-needs-a-cybersecurity-attorney.html.