Three essays on cyber risk management

dc.contributor.advisor George, Joey F
dc.contributor.advisor Ulmer, Jacquelyn R
dc.contributor.advisor Cao, Chengxin
dc.contributor.advisor Sapp, Travis
dc.contributor.advisor Parsa, Rahul
dc.contributor.author Lin, Zhaoxin
dc.contributor.department Supply Chain Management
dc.date.accessioned 2022-11-09T02:26:51Z
dc.date.available 2022-11-09T02:26:51Z
dc.date.issued 2021-08
dc.date.updated 2022-11-09T02:26:51Z
dc.description.abstract With rapid advancements in technology, cybersecurity risks impose greater threats on enterprise’s operation and business objectives. Thus, it is imperative for organizations to manage these risks effectively. A massive part of this endeavor is to understand the organizational risks, either from internal or external, and implement different strategies to handle the risks in an optimal way. My dissertation addresses these issues by applying business analytics tools to data breach data and firm transactional data to help companies better understand cybersecurity risks and protect business values efficiently and effectively. My dissertation is comprised of three essays. The first essay uses stock trading data to classify opportunistic insiders who sell stocks ahead of cyber breach announcements and examine their trading patterns and reporting relationship roles. In the second essay, I apply a Difference in Difference method to explore the breached firm’s internal IT capital allocation strategy and investigate the tradeoff between IT capital investment efficiency and cybersecurity risk mitigation during the post-event era. In the third essay, a copula-based model is proposed for pricing cybersecurity insurance premiums for the focal firm under a correlated network. In these essays, I apply financial, econometric, and statistical methods. These essays contribute to the finance and management information systems literature and help policy makers and firms implement and maintain administrative actions and comprehensive solutions to make sure the business is adequately protected.
dc.format.mimetype PDF
dc.identifier.doi https://doi.org/10.31274/td-20240329-800
dc.identifier.orcid https://orcid.org/0000-0003-0436-420X
dc.identifier.uri https://dr.lib.iastate.edu/handle/20.500.12876/WwPg1yEz
dc.language.iso en
dc.language.rfc3066 en
dc.subject.disciplines Information technology en_US
dc.subject.disciplines Business administration en_US
dc.subject.keywords Business Analytics en_US
dc.subject.keywords Cybersecurity en_US
dc.subject.keywords Information Security en_US
dc.subject.keywords Risk Management en_US
dc.title Three essays on cyber risk management
dc.type dissertation en_US
dc.type.genre dissertation en_US
dspace.entity.type Publication
relation.isOrgUnitOfPublication ef3ab1b0-d571-4148-84dd-470ef1cdb17a
thesis.degree.discipline Information technology en_US
thesis.degree.discipline Business administration en_US
thesis.degree.grantor Iowa State University en_US
thesis.degree.level dissertation $
thesis.degree.name Doctor of Philosophy en_US
File
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Lin_iastate_0097E_19629.pdf
Size:
1.24 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
0 B
Format:
Item-specific license agreed upon to submission
Description: