“…given that the disclosure of information security risk factors, governance policies, and information security breaches can significantly impact firm value (Gordon, Loeb, & Sohail, 2010;Higgs, Pinsker, Smith, & Young, 2016;Wang, Kannan, & Ulmer, 2013). In addition, cybercrime poses "a different focal point of concern [and] a different 'subject' of risk", (Power, 2013, p. 538), because perpetrators are often unknown agents outside the organization.…”