{"id":"https://openalex.org/W1902264846","doi":"https://doi.org/10.3233/jcs-2009-0398","title":"The impact of information security breaches: Has there been a downward shift in costs?","display_name":"The impact of information security breaches: Has there been a downward shift in costs?","publication_year":2011,"publication_date":"2011-02-14","ids":{"openalex":"https://openalex.org/W1902264846","doi":"https://doi.org/10.3233/jcs-2009-0398","mag":"1902264846"},"language":"en","primary_location":{"id":"doi:10.3233/jcs-2009-0398","is_oa":false,"landing_page_url":"https://doi.org/10.3233/jcs-2009-0398","pdf_url":null,"source":{"id":"https://openalex.org/S106992369","display_name":"Journal of Computer Security","issn_l":"0926-227X","issn":["0926-227X","1875-8924"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310318577","host_organization_name":"IOS Press","host_organization_lineage":["https://openalex.org/P4310318577"],"host_organization_lineage_names":["IOS Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Computer Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5074308055","display_name":"Lawrence A. Gordon","orcid":null},"institutions":[{"id":"https://openalex.org/I143663144","display_name":"Research Institute for Advanced Computer Science","ror":"https://ror.org/022qmyy53","country_code":"US","type":"facility","lineage":["https://openalex.org/I1329765538","https://openalex.org/I143663144"]},{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Lawrence A. Gordon","raw_affiliation_strings":["Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","University of Maryland Institute for Advanced Computer Studies","Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","institution_ids":["https://openalex.org/I66946132"]},{"raw_affiliation_string":"University of Maryland Institute for Advanced Computer Studies","institution_ids":["https://openalex.org/I143663144"]},{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041963808","display_name":"Martin P. Loeb","orcid":"https://orcid.org/0000-0003-1175-6092"},"institutions":[{"id":"https://openalex.org/I143663144","display_name":"Research Institute for Advanced Computer Science","ror":"https://ror.org/022qmyy53","country_code":"US","type":"facility","lineage":["https://openalex.org/I1329765538","https://openalex.org/I143663144"]},{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Martin P. Loeb","raw_affiliation_strings":["Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","University of Maryland Institute for Advanced Computer Studies","Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","institution_ids":["https://openalex.org/I66946132"]},{"raw_affiliation_string":"University of Maryland Institute for Advanced Computer Studies","institution_ids":["https://openalex.org/I143663144"]},{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5000724685","display_name":"Lei Zhou","orcid":"https://orcid.org/0000-0002-0433-3991"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lei Zhou","raw_affiliation_strings":["Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: , ,","institution_ids":["https://openalex.org/I66946132"]},{"raw_affiliation_string":"Department of Accounting and Information Assurance, Robert H. Smith School of Business, University of Maryland, College Park, MD 20742, USA. E-mails: lgordon@rshmith.umd.edu, mloeb@rshmith.umd.edu, lzhou@rshmith.umd.edu","institution_ids":["https://openalex.org/I66946132"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5074308055"],"corresponding_institution_ids":["https://openalex.org/I143663144","https://openalex.org/I66946132"],"apc_list":null,"apc_paid":null,"fwci":10.6958,"has_fulltext":false,"cited_by_count":224,"citation_normalized_percentile":{"value":0.97814454,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":"19","issue":"1","first_page":"33","last_page":"56"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9897000193595886,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9747999906539917,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.6445496082305908},{"id":"https://openalex.org/keywords/data-breach","display_name":"Data breach","score":0.6387848854064941},{"id":"https://openalex.org/keywords/stock-market","display_name":"Stock market","score":0.5668848752975464},{"id":"https://openalex.org/keywords/confidentiality","display_name":"Confidentiality","score":0.5563428401947021},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.5531168580055237},{"id":"https://openalex.org/keywords/stock","display_name":"Stock (firearms)","score":0.45979923009872437},{"id":"https://openalex.org/keywords/business-continuity","display_name":"Business continuity","score":0.4419686496257782},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3187040090560913},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.07437604665756226}],"concepts":[{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.6445496082305908},{"id":"https://openalex.org/C165609540","wikidata":"https://www.wikidata.org/wiki/Q1172486","display_name":"Data breach","level":2,"score":0.6387848854064941},{"id":"https://openalex.org/C2780299701","wikidata":"https://www.wikidata.org/wiki/Q475000","display_name":"Stock market","level":3,"score":0.5668848752975464},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.5563428401947021},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.5531168580055237},{"id":"https://openalex.org/C204036174","wikidata":"https://www.wikidata.org/wiki/Q909380","display_name":"Stock (firearms)","level":2,"score":0.45979923009872437},{"id":"https://openalex.org/C2778143579","wikidata":"https://www.wikidata.org/wiki/Q831801","display_name":"Business continuity","level":2,"score":0.4419686496257782},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3187040090560913},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.07437604665756226},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C2780762169","wikidata":"https://www.wikidata.org/wiki/Q5905368","display_name":"Horse","level":2,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.3233/jcs-2009-0398","is_oa":false,"landing_page_url":"https://doi.org/10.3233/jcs-2009-0398","pdf_url":null,"source":{"id":"https://openalex.org/S106992369","display_name":"Journal of Computer Security","issn_l":"0926-227X","issn":["0926-227X","1875-8924"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310318577","host_organization_name":"IOS Press","host_organization_lineage":["https://openalex.org/P4310318577"],"host_organization_lineage_names":["IOS Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Computer Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","display_name":"Climate action","score":0.7099999785423279}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":37,"referenced_works":["https://openalex.org/W148329840","https://openalex.org/W1481915258","https://openalex.org/W1483280370","https://openalex.org/W1501321335","https://openalex.org/W1525451939","https://openalex.org/W1681743793","https://openalex.org/W1718158504","https://openalex.org/W1863670505","https://openalex.org/W1966875048","https://openalex.org/W1972544775","https://openalex.org/W1995834279","https://openalex.org/W1997862012","https://openalex.org/W1997892903","https://openalex.org/W2001566875","https://openalex.org/W2018085556","https://openalex.org/W2033400055","https://openalex.org/W2035763235","https://openalex.org/W2056075452","https://openalex.org/W2064067537","https://openalex.org/W2069396279","https://openalex.org/W2091722306","https://openalex.org/W2096274199","https://openalex.org/W2101718392","https://openalex.org/W2102415505","https://openalex.org/W2113305199","https://openalex.org/W2122224612","https://openalex.org/W2130162792","https://openalex.org/W2136120210","https://openalex.org/W2155547871","https://openalex.org/W2160258502","https://openalex.org/W2166215547","https://openalex.org/W2184884513","https://openalex.org/W2513969704","https://openalex.org/W2798349041","https://openalex.org/W3124243881","https://openalex.org/W3124244954","https://openalex.org/W3144627111"],"related_works":["https://openalex.org/W4387497383","https://openalex.org/W3183948672","https://openalex.org/W3173606202","https://openalex.org/W3110381201","https://openalex.org/W2948807893","https://openalex.org/W2778153218","https://openalex.org/W2758277628","https://openalex.org/W1531601525","https://openalex.org/W125620621","https://openalex.org/W626714893"],"abstract_inverted_index":{"By":[0],"analyzing":[1],"evidence":[2,28],"of":[3,35,42,53,57,65,80,92,117,140,155,158,184],"stock":[4,62,103],"returns":[5,41,64],"using":[6],"a":[7,12,110,178],"sophisticated":[8],"market":[9,40,63,104],"model":[10],"over":[11,16],"long":[13],"period":[14],"and":[15,19,173,176],"two":[17],"distinct":[18],"naturally":[20],"arising":[21],"sub-periods,":[22],"this":[23,165],"study":[24,45],"helps":[25],"resolve":[26],"conflicting":[27],"from":[29,188],"previous":[30],"studies":[31],"concerning":[32],"the":[33,51,54,98,115,118,122,125,129,132,156,182],"effect":[34,77,101],"information":[36,58,141,195],"security":[37,59,119,142,196],"breaches":[38,60,71,91,120,143],"on":[39,61,102,148],"firms.":[43],"This":[44],"has":[46,108],"three":[47],"major":[48],"findings.":[49],"First,":[50],"impact":[52,116,130],"broad":[55],"class":[56],"firms":[66,192],"is":[67],"significant.":[68],"Second,":[69],"when":[70],"are":[72,94,168],"classified":[73],"by":[74],"their":[75,153],"primary":[76],"in":[78,114,121,131,181],"terms":[79],"(i)":[81],"confidentiality,":[82],"(ii)":[83],"availability":[84,93],"or":[85],"(iii)":[86],"integrity,":[87],"attacks":[88,127],"associated":[89],"with":[90,136,191],"seen":[95],"to":[96,186],"have":[97],"greatest":[99],"negative":[100],"returns.":[105],"Third,":[106],"there":[107],"been":[109],"significant":[111],"downward":[112,166],"shift":[113,167],"sub-period":[123],"following":[124],"9/11/2001":[126],"versus":[128],"pre-9/11":[133],"period.":[134],"Apparently,":[135],"increased":[137],"media":[138],"reporting":[139],"without":[144],"apparent":[145],"devastating":[146],"effects":[147],"targeted":[149],"corporations,":[150],"investors":[151],"lowered":[152],"assessment":[154],"costs":[157],"such":[159],"breaches.":[160],"Two":[161],"possible":[162],"reasons":[163],"for":[164],"(1)":[169],"more":[170],"effective":[171],"remediation":[172],"disaster":[174],"recovery":[175],"(2)":[177],"perceived":[179],"decrease":[180],"tendency":[183],"customers":[185],"refrain":[187],"doing":[189],"business":[190],"experiencing":[193],"an":[194],"breach.":[197]},"counts_by_year":[{"year":2026,"cited_by_count":9},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":23},{"year":2023,"cited_by_count":19},{"year":2022,"cited_by_count":20},{"year":2021,"cited_by_count":24},{"year":2020,"cited_by_count":18},{"year":2019,"cited_by_count":17},{"year":2018,"cited_by_count":23},{"year":2017,"cited_by_count":14},{"year":2016,"cited_by_count":11},{"year":2015,"cited_by_count":12},{"year":2014,"cited_by_count":11},{"year":2012,"cited_by_count":3}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
