Corporate Transparency and Cybersecurity Risks
Name
Kim-dskim-PhD-Management-2025_-thesis.pdf
Description
Thesis PDF
Size
6.32 MB
Format
Adobe PDF
Checksum (MD5)
4d5f8bd4cca16d4d6cec49800ee9bcd4
Author(s)
Kim, David Sunghyo
Advisor(s)
So, Eric
Verdi, Rodrigo
Date Issued
May 2025
Publisher
Massachusetts Institute of Technology
Abstract
I study whether disclosure mandates alter the equilibrium of cyberattacks by unintentionally informing cybercriminals. The California Consumer Privacy Act (CCPA) requires companies to disclose their personal information collection practices to consumers, inadvertently informing cybercriminals about the potential benefits of breaching each firm. Using a difference-in-differences design, I find that firms disclosing the collection of valuable personal data face an increased probability of data breaches. These firms also strengthen their cyberdefenses both in terms of cybersecurity software and cybersecurity specialists. Firms trade off cybersecurity costs against the risk of data breaches, with the increase in breach probabilities more pronounced among firms that invest less in cybersecurity. Finally, I find that firms adjust their data collection policies as additional defense strategies. Overall, this study highlights the trade-off between transparency and cybersecurity risks in today’s digital economy.
MIT Department
Sloan School of Management
Terms of Use
In Copyright - Educational Use Permitted
Copyright retained by author(s)
Persistent DSpace Link