This paper wants to analyse the cyber-risk impact on economy in particular on the returns of the companies suffering information braches. The problem has become very interesting in recent years in the literature for the large dependence of the business with cyber world. The analysis focuses on event study in which the impact of cyber-attacks on stock prices of selected companies is investigated. Cyber-risk phenomenon is processed considering a portfolio of targeted assets, in order to analyse their correlation. Risk measures, such as VaR, will be evaluated and backtested using different methods to monitor which one is able to better capture this type of riskiness.
Garg, A., Curtis, J. and Halper, H. (2003) Quantifying the Financial Impact of IT Security Breaches. Information Management and Computer Security, 11, 74-83. https://doi.org/10.1108/09685220310468646
Ko, M. and Dorantes, C. (2006) The Impact of Information Security Breaches on Financial Performance of the Breached Firms: An Empirical Investigation. Journal of Information Technology Management, 17, 13-22.
Andoh-Badoo, F.K. and Osei-Bryson, K.M. (2007) Exploring the Characteristics of Internet Security Breaches that Impact the Market Value of Breached Firms. Expert Systems with Applications, 32, 703-725. https://doi.org/10.1016/j.eswa.2006.01.020
Ishiguro, M., Tanaka, H., Matsuura, I. and Murase, I. (2007) The Effect of Information Security Incidents on Corporate Values in the Japanese Stock Market. Workshop on the Economics of Securing Information Infrastructure (Arlington), 1-12.
Oates, B. (2001) Cyber-Crime: How Technology Makes It Easy and What To Do about It. Information Systems Security, 9, 1-6. https://doi.org/10.1201/1086/43298.9.6.20010102/30989.8
Kannan, A., Rees, J. and Sridhar, S. (2007) Market Reaction to Information Security Breach Announcements: An Empirical Analysis. International Journal of Electronic Commerce, 12, 69-91. https://doi.org/10.2753/JEC1086-4415120103
Odulaja, G.O. and Wada, F. (2012) Assessing Cyber-Crime and Its Impact on e-Banking in Nigeria Using Social Theories. African Journal of Computing & ICTs, 4, 69-82.
Ettredge, M.L. and Richardson, V.J. (2003) Information Transfer among Internet Firms: The Case of Hacker Attacks. Journal of Information Systems, 17, 71-82. https://doi.org/10.2139/ssrn.334460
Hovav, A. and D’arcy, J. (2003) The Impact of Denial-of-Service Attack Announcements on the Market Value of Firm. Risk Management and Insurance Review, 6, 97-121. https://doi.org/10.1046/J.1098-1616.2003.026.x
Kundur, D., Feng, X., Mashayekh, S., Liu, S., Zourntos, T. and Butler-Purry, K.L. (2011) Towards Modelling the Impact of Cyber-Attacks on a Smart Grid. International Journal of Security and Networks, 6, 2-13. https://doi.org/10.1504/IJSN.2011.039629
Eisenstein, E.M. (2008) Identity Theft: An Exploratory Study with Implications for Marketers. Journal of Business Research, 61, 1160-1172. https://doi.org/10.1016/j.jbusres.2007.11.012
Winn, J. and Govern, K. (2009) Identity Theft: Risks and Challenges to Business of Data Compromise. Journal of Science Technology & Environmental Law, 28, 49.
Geers, K. (2010) The Challenge of Cyber-Attack Deterrence. Computer Law & Security Review, 26, 298-303. https://doi.org/10.1016/j.clsr.2010.03.003
Lilienthal, G. and Ahmad, N. (2015) Cyber-Attack as Inevitable Kinetic War. Computer Law & Security Review, 31, 390-400. https://doi.org/10.1016/j.clsr.2015.03.002
Gordon, L.A., Loeb, M.P. and Lucyshyn, W. (2003a) Sharing Information on Computer Systems Security: An Economic Analysis. Journal of Accounting and Public Policy, 22, 461-485. https://doi.org/10.1016/j.jaccpubpol.2003.09.001
Gordon, L.A. and Loeb, M.P. (2002) The Economics of Information Security Investment. ACM Transactions on Information and System Security, 5, 438-457. https://doi.org/10.1145/581271.581274
Dos Santos, B.L., Peffers, K. and Mauer, D.C. (1993) The Impact of Information Technology Investment Announcements on the Market Value of the Firm. Information Systems Research, 4, 1-108. https://doi.org/10.1287/isre.4.1.1
Brockett, P.L., Golden, L.L. and Wolman, W. (2012) Enterprise Cyber Risk Management. In: Emblemsvag, J., Ed., Risk Management for the Future: Theory and Cases, IntechOpen, London.
Shackelford, S.J. (2012) Should Your Firm Invest in Cyber Risk Insurance? Business Horizons, 55, 349-356. https://doi.org/10.1016/j.bushor.2012.02.004
Gordon, L.A., Loeb, M.P. and Lucyshyn, W. (2003) Information Security Expenditures and Real Options: A Wait-and-See Approach. Computer Security Journal, 19.
Uma, M. and Padmavathi, G. (2013) A Survey on Various Cyber Attacks and Their Classification. International Journal of Network Security, 15, 390-396. https://pdfs.semanticscholar.org/ba7b/234738e80b027240e9bfd837bfba61c13e17.pdf
Campbell, K., Gordon, L., Loeb, M. and Zhou, L. (2003) The Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market. Journal of Computer Security, 11, 431-448. https://doi.org/10.3233/JCS-2003-11308
Pettit, R.R. (1972) Dividend Announcements, Security Performance, and Capital Market Efficiency. The Journal of Finance, 27, 993-1007. https://doi.org/10.2307/2978844
Bener, A.B. (2000) Risk Perception, Trust and Credibility: A Case in Internet Banking. University College of London, London.
Cavusoglu, H., Mishra, B. and Raghunathan, S. (2004) The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers. International Journal of Electronic Commerce, 9, 70-104. https://doi.org/10.1080/10864415.2004.11044320
Arcuri, M.C., Brogi, M. and Gandolfi, G. (2018) The Effect of Cyber-Attacks on Stock Returns. Corporate Ownership & Control, 15, 70-83. https://doi.org/10.22495/cocv15i2art6
Acquisti, A., Friedman, A. and Telang, R. (2006) Is There a Cost to Privacy Breaches? An Event Study. AIS Electronic Library. https://www.semanticscholar.org/paper/Is-There-a-Cost-to-Privacy-Breaches-An- Event-Study-Acquisti-Friedman/05c60011f0b375b45daf422a67ce205f09f9d82b
Gordon, L.A., Loeb, M.P. and Zhou, L. (2011) The Impact of Information Security Breaches: Has There Been a Downward Shift in Costs. Journal of Computer Security, 19, 33-56. https://doi.org/10.3233/JCS-2009-0398
Cohen, F. (1997) Information System Defences: A Preliminary Classification Scheme. Computer and Security, 16, 94-114. https://doi.org/10.1016/S0167-4048(97)88289-2
Cohen, F. (1997) Information Systems Attacks: A Preliminary Classification Scheme. Computer and Security, 16, 29-46. https://doi.org/10.1016/S0167-4048(97)85785-9
Cohen, F., Phillips, C., Swiler, L.P., Gaylor, T., Leary, P., Rupley, F. and Isler, R. (1998) A Cause and Effect Model of Attacks on Information Systems. Computer and Security, 17, 211-221. https://doi.org/10.1016/S0167-4048(98)80312-X
Gandhi, R., Sharma, A., Mahoney, W., Sousan, W., Zhu, Q. and Laplante, P. (2011) Dimensions of Cyber-Attacks: Cultural, Social, Economic, and Political. IEEE Technology and Society Magazine, 30, 28-38. https://doi.org/10.1109/MTS.2011.940293
Gupta, M., Chaturvedi, A.R., Metha, S. and Valeri, L. (2000) The Experimental Analysis of Information Security Management Issue for online Financial Services. In: Proceedings of the Twenty First International Conference on Information Systems, Association for Information Systems, Atlanta, GA, 667-675.
Young, D., Lopez, J., Rice, M., Ramsey, B. and McTasney, R. (2016) A Framework for Incorporating Insurance in Critical Infrastructure Cyber Risk Strategies. International Journal of Critical Infrastructure Protection, 14, 43-57. https://doi.org/10.1016/j.ijcip.2016.04.001
Eling, M. and Schnell, W. (2016) What Do We Know about Cyber Risk and Cyber Risk Insurance? The Journal of Risk Finance, 17, 474-491. https://doi.org/10.1108/JRF-09-2016-0122
Taplin, R. (2016) Managing Cyber Risk in the Financial Sector. Lessons from Asia, Europe and the USA. Routledge, London. https://doi.org/10.4324/9781315675930
Bhattachrya, S. and Thakor, A.V. (1993) Contemporary Banking Theory. Journal of Financial Intermediation, 3, 2-50. https://doi.org/10.1006/jfin.1993.1001
Allen, F. and Santomero, A.M. (1997) The Theory of Financial Intermediation. Journal of Banking and Finance, 21, 1461-1485. https://doi.org/10.1016/S0378-4266(97)00032-0
Cummins, J.D., Lewis, C.M. and Wei, R. (2006) The Market Value Impact of Operational Risk Events for U.S. Banks and Insurers. Journal of Banking and Finance, 30, 2605-2634. https://doi.org/10.1016/j.jbankfin.2005.09.015
Gillet, R., Hubner, G. and Plunus, S. (2010) Operational Risk and Reputation in the Financial Industry. Journal of Banking and Finance, 34, 224-235. https://doi.org/10.1016/j.jbankfin.2009.07.020
Pennathur, A.K. (2001) Clicks and Bricks: E-Risk Management for Banks in the Age of the Internet. Journal of Banking and Finance, 25, 2103-2123. https://doi.org/10.1016/S0378-4266(01)00197-2
Cont, R. (2001) Empirical Properties of Asset Returns: Stylized Facts and Statistical Issues. Quantitative Finance, 1, 223-236. https://doi.org/10.1088/1469-7688/1/2/304
Engle, R.F. and Sheppard, K. (2001) Theoretical and Empirical Properties of Dynamic Conditional Correlation Multivariate GARCH. Economics Working Paper Series, University of California at San Diego, San Diego, CA. https://doi.org/10.3386/w8554
Colacito, R., Engle, R.F. and Ghysels, E. (2013) A Component Model for Dynamic Correlations. Journal of Econometrics, 164, 45-59. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1354526
Christoffersen, P.F. (2012) Elements of Financial Risk Management. Elsevier, Amsterdam.
Meulbroek, L.K. (1992) An Empirical Analysis of Illegal Insider Trading. The Journal of Finance, 47, 1661-1699. https://doi.org/10.2307/2328992
Frino, A., Satchell, S., Wong, B. and Zheng, H. (2013) How Much Does an Illegal Insider Trade. International Review of Finance, 13, 241-263. https://doi.org/10.1111/irfi.12006
Brown S.J. and Warner, J.B. (1980) Measuring Security Price Performance. Journal of Financial Economics, 8, 205-258. https://doi.org/10.1016/0304-405X(80)90002-1
Iheagwara, C., Blyth, A. and Singhal, M. (2004) Cost Effective Management Frameworks for Intrusion Detection Systems. Journal of Computer Security, 12, 777-798. https://doi.org/10.3233/JCS-2004-12506
McConnell, J.J. and Muscarella, C.J. (1985) Corporate Capital Expenditure Decisions and the Market Value of the Firm. Journal of Financial Economics, 14, 399-422. https://doi.org/10.1016/0304-405X(85)90006-6
Fama, E.F., Fischer, L., Jensen, M.C. and Roll, R. (1969) The Adjustment of Stock Prices to New Information. International Economic Review, 10, 1-21. https://doi.org/10.2307/2525569
MacKinlay, A.C. (1997) Event Studies in Economics and Finance. Journal of Economic Literature, 55, 13-39. https://pdfs.semanticscholar.org/aac6/83a678a12a3dcd73389aac7289868847ea73.pdf
Boehmer, E., Musumeci, J. and Poulsen, A. (1991) Event-Study Methodology under Conditions of Event-Induced Variance. Journal of Financial Economics, 30, 253-272. https://doi.org/10.1016/0304-405X(91)90032-F
Mikkelson, W.H. and Partch, M.M. (1988) Withdrawn Security Offerings. Journal of Financial and Quantitative Analysis, 23, 119-133. https://doi.org/10.2307/2330876
Elliott, J., Morse, D. and Richardson, G. (1984) The Association between Insider trading and Information Announcements. The RAND Journal of Economics, 15, 521-536.