2005
DOI: 10.2139/ssrn.677427
|View full text |Cite
|
Sign up to set email alerts
|

Impact of Software Vulnerability Announcements on the Market Value of Software Vendors - An Empirical Investigation

Abstract: Researchers in the area of information security have mainly been concerned with tools, techniques and policies that firms can use to protect themselves against security breaches.However, information security is as much about security software as it is about secure software.Software is not secure when it has defects or flaws which can be exploited by hackers to cause attacks such as unauthorized intrusion or denial of service attacks. Any public announcement about a software defect is termed as 'vulnerability d… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
16
0

Year Published

2009
2009
2021
2021

Publication Types

Select...
5
2
2

Relationship

1
8

Authors

Journals

citations
Cited by 34 publications
(16 citation statements)
references
References 33 publications
0
16
0
Order By: Relevance
“…Arora et al (2008) use a dataset assembled from CERT/CC's vulnerability notes and SecurityFocus database to show that early disclosure leads to faster patch release times. Telang and Wattal (2007) use an event study methodology to show that vulnerability disclosure leads to a loss of market value. Li and Rao (2007) empirically examined the role of private intermediaries on the timing of patch release by vendors and found that the presence of private intermediaries decreases vendors' incentive to deliver timely patches.…”
Section: Related Literature and Contributionmentioning
confidence: 99%
“…Arora et al (2008) use a dataset assembled from CERT/CC's vulnerability notes and SecurityFocus database to show that early disclosure leads to faster patch release times. Telang and Wattal (2007) use an event study methodology to show that vulnerability disclosure leads to a loss of market value. Li and Rao (2007) empirically examined the role of private intermediaries on the timing of patch release by vendors and found that the presence of private intermediaries decreases vendors' incentive to deliver timely patches.…”
Section: Related Literature and Contributionmentioning
confidence: 99%
“…We contribute to a wide literature on financial market reactions to IT failure (Bharadwaj et al, 2009;Cavusoglu, Mishra, & Raghunathan, 2004;Gordon et al, 2010;Telang & Wattal, 2005). We bring an important innovation to this literature: an actionable solution that managers can pursue.…”
Section: Resultsmentioning
confidence: 99%
“…damage to an organization [3]. Whereas a software bug can cause a software artifact to fail, a security bug can allow a malicious user to alter the execution of the entire application for his or her own gain.…”
Section: Introductionmentioning
confidence: 99%