Where is IT in Information Security? The Interrelationship among IT Investment, Security Awareness, and Data Breaches

Wilson Weixun Li, Alvin Chung Man Leung and Wei T. Yue. "Where Is IT in Information Security? The Interrelationship of IT Investment, Security Awareness and Data Breaches" Management Information Systems Quarterly 47, no. 1 (2023): 317-342

Posted: 18 Jun 2020 Last revised: 2 Mar 2023

See all articles by Wilson LI

Wilson LI

Deakin University - Deakin Business School

Alvin Leung

City University of Hong Kong (CityU) - Department of Information Systems

Wei Thoo Yue

City University of Hong Kong (CityU)

Date Written: April 16, 2020

Abstract

Data breaches can severely damage a firm’s reputation and its customers’ confidence. Firms must therefore continuously invest in security measures to prevent such breaches. However, the effectiveness of security investment has been questioned by both practitioners and academics. We illustrate the bidirectional dynamic relationship between information technologies (IT) investment and data breaches using an 8-year panel of 260 U.S.-listed firms, moderated by threat and countermeasure security awareness. Drawing on Straub and Welke’s security planning model, we provide empirical evidence that investing solely in security measures may not effectively prevent data breaches. IT investment must instead be combined with heightened security awareness. Our results suggest that firms should reconsider whether security performance is a direct outcome of security measures and take a broader perspective when addressing information security concerns.

Keywords: security investment, IT investment, security awareness, data breach, IT planning, panel vector autoregression model

JEL Classification: M15

Suggested Citation

LI, Wilson and Leung, Alvin and Yue, Wei Thoo, Where is IT in Information Security? The Interrelationship among IT Investment, Security Awareness, and Data Breaches (April 16, 2020). Wilson Weixun Li, Alvin Chung Man Leung and Wei T. Yue. "Where Is IT in Information Security? The Interrelationship of IT Investment, Security Awareness and Data Breaches" Management Information Systems Quarterly 47, no. 1 (2023): 317-342, Available at SSRN: https://ssrn.com/abstract=3581594 or http://dx.doi.org/10.2139/ssrn.3581594

Wilson LI (Contact Author)

Deakin University - Deakin Business School ( email )

Australia

Alvin Leung

City University of Hong Kong (CityU) - Department of Information Systems ( email )

83 Tat Chee Avenue
Kowloon
Hong Kong

Wei Thoo Yue

City University of Hong Kong (CityU) ( email )

Hong Kong
Hong Kong

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Abstract Views
1,744
PlumX Metrics