Abstract
After a series of recent high-profile information security breach incidents, practitioners have engaged in heated debates about the role of the chief information officer (CIO), particularly his/her role in information security risk management. However, little is known in the academic literature about how a CIO's appetite for risk affects the effectiveness of information security management. We address this gap by examining how a CIO's risk appetite is associated with information security breach incidents. We show that the level of CIO risk aversion is negatively associated with the likelihood of breach incidents. Furthermore, we find that this association is stronger if the company's chief executive officer (CEO) is also risk averse. In additional analyses, we show that the relationship between CIO risk aversion and breach incidents varies depending on breach type and the strategic position of the company and is moderated by the CIO's power.
| Original language | English |
|---|---|
| Pages (from-to) | 59-75 |
| Number of pages | 17 |
| Journal | International Journal of Accounting Information Systems |
| Volume | 32 |
| DOIs | |
| State | Published - Mar 2019 |
Keywords
- Chief information officer
- Information security breach
- Information security risk management
Fingerprint
Dive into the research topics of 'Does CIO risk appetite matter? Evidence from information security breach incidents'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver