{"id":3664,"date":"2022-01-18T20:55:56","date_gmt":"2022-01-19T03:55:56","guid":{"rendered":"https:\/\/blogs.ubc.ca\/genemoolee\/?p=3664"},"modified":"2025-12-04T12:11:41","modified_gmt":"2025-12-04T19:11:41","slug":"is-papers-on-cybersecurity","status":"publish","type":"post","link":"https:\/\/blogs.ubc.ca\/genemoolee\/2022\/01\/18\/is-papers-on-cybersecurity\/","title":{"rendered":"IS papers on Cybersecurity"},"content":{"rendered":"<p><strong>I do not actively conduct research on cybersecurity. So I will stop updating this page (March 3, 2025).<\/strong><\/p>\n<p>First published Jan 18, 2022.<\/p>\n<p>In this post, I gathered recent IS publications (2010-current) on the topic of cybersecurity. It is by no means an exhaustive list of the topic. This does not cover other related topics such as privacy and ethics.<\/p>\n<ol>\n<li>Jacob Haislip, Jee-Hae Lim, Robert Pinsker (2021) The Impact of Executives\u2019 IT Expertise on Reported Data Security Breaches. <em>Information Systems Research<\/em> 32(2):318-334.<\/li>\n<li>Ahmed Abbasi, David Dobolyi, Anthony Vance, Fatemeh Mariam Zahedi (2021) The Phishing Funnel Model: A Design Artifact to Predict User Susceptibility to Phishing Websites. <em>Information Systems Research<\/em> 32(2):410-436.<\/li>\n<li><span class=\"authors\">Yunhui Zhuang, Yunsik Choi, Shu He, Alvin Chung Man Leung, Gene Moo Lee &amp; Andrew Whinston<\/span>\u00a0<span class=\"date\">(2020)<\/span>\u00a0<span class=\"art_title\">Understanding Security Vulnerability Awareness, Firm Incentives, and ICT Development in Pan-Asia,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">37:3,<\/span>\u00a0<span class=\"page_range\">668-693.<\/span><\/li>\n<li>Qian Tang &amp; Andrew B. Whinston (2020) Do Reputational Sanctions Deter Negligence in Information Security Management? A Field Quasi\u2010Experiment, <em>Production and Operations Management<\/em> 29(2):410-427.<\/li>\n<li>Yoo, Chul &amp; Goo, Jahyun &amp; Rao, Raghav. (2020). Is Cybersecurity a Team Sport? A Multilevel Examination of Workgroup Information Security Effectiveness. <em>MIS Quarterly<\/em>. 44. 907-931.<\/li>\n<li><span class=\"authors\">Mohammadreza Ebrahimi, Jay F. Nunamaker Jr. &amp; Hsinchun Chen<\/span>\u00a0<span class=\"date\">(2020)<\/span>\u00a0<span class=\"art_title\">Semi-Supervised Cyber Threat Identification in Dark Net Markets: A Transductive and Deep Learning Approach,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">37:3,<\/span>\u00a0<span class=\"page_range\">694-722<\/span><\/li>\n<li><span class=\"authors\">Sebastian W. Schuetz, Paul Benjamin Lowry, Daniel A. Pienta &amp; Jason Bennett Thatcher<\/span>\u00a0<span class=\"date\">(2020)<\/span>\u00a0<span class=\"art_title\">The Effectiveness of Abstract Versus Concrete Fear Appeals in Information Security,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">37:3,<\/span>\u00a0<span class=\"page_range\">723-757.<\/span><\/li>\n<li><span class=\"authors\">Che-Wei Liu, Peng Huang &amp; Henry C. Lucas Jr.<\/span>\u00a0<span class=\"date\">(2020)<\/span>\u00a0<span class=\"art_title\">Centralized IT Decision Making and Cybersecurity Breaches: Evidence from U.S. Higher Education Institutions,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">37:3,<\/span>\u00a0<span class=\"page_range\">758-787.<\/span><\/li>\n<li><span class=\"authors\">Ravi Sen, Ajay Verma &amp; Gregory R. Heim<\/span>\u00a0<span class=\"date\">(2020)<\/span>\u00a0<span class=\"art_title\">Impact of Cyberattacks by Malicious Hackers on the Competition in Software Markets,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">37:1,<\/span>\u00a0<span class=\"page_range\">191-216<\/span><\/li>\n<li>John D\u2019Arcy, Idris Adjerid, Corey M. Angst, Ante Glavas (2020) Too Good to Be True: Firm Social Performance and the Risk of Data Breach. <em>Information Systems Research<\/em> 31(4):1200-1223.<\/li>\n<li>Zan Zhang, Guofang Nan, Yong Tan (2020) Cloud Services vs. On-Premises Software: Competition Under Security Risk and Product Customization. <em>Information Systems Research<\/em> 31(3):848-864.<\/li>\n<li>Terrence August, Duy Dao, Kihoon Kim (2019) Market Segmentation and Software Security: Pricing Patching Rights. <em>Management Science<\/em> 65(10):4575-4597.<\/li>\n<li>Seung Hyun Kim, Juhee Kwon (2019) How Do EHRs and a Meaningful Use Initiative Affect Breaches of Patient Information?. <em>Information Systems Research<\/em> 30(4):1184-1202.<\/li>\n<li>Kai-Lung Hui, Ping Fan Ke, Yuxi Yao, Wei T. Yue (2019) Bilateral Liability-Based Contracts in Information Security Outsourcing. <em>Information Systems Research<\/em> 30(2):411-429.<\/li>\n<li>Victor Benjamin, Joseph S. Valacich, and Hsinchun Chen (2019) DICE-E: a framework for conducting darknet identification, collection, evaluation with ethics. <i>MIS Quarterly<\/i> 43(1):1\u201322.<\/li>\n<li>Indranil Bose and Alvin Chung Man Leung (2019) Adoption of identity theft countermeasures and its short- and long-term impact on firm value. <i>MIS Quarterly<\/i> 43(1):313\u2013328.<\/li>\n<li>Corey M. Angst, Emily S. Block, John D&#8217;Arcy, and Ken Kelley (2017) When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. <i>MIS Quarterly<\/i> 41(3):893\u2013916.<\/li>\n<li>Orcun Temizkan, Sungjune Park, Cem Saydam (2017) Software Diversity for Improved Network Security: Optimal Distribution of Software-Based Shared Vulnerabilities. <em>Information Systems Research<\/em> 28(4):828-849.<\/li>\n<li>Shu He, Gene Moo Lee, Sukjin Han, Andrew B. Whinston (2016) How Would Information Disclosure Influence Organizations\u2019 Outbound Spam Volume? Evidence from a Field Experiment. <em>Journal of Cybersecurity<\/em> 2(1), pp. 99-118.<\/li>\n<li>Yonghua Ji, Subodha Kumar, Vijay Mookerjee (2016) When Being Hot Is Not Cool: Monitoring Hot Lists for Information Security. <em>Information Systems Research<\/em> 27(4):897-918.<\/li>\n<li>Karthik Kannan, Mohammad S. Rahman, Mohit Tawarmalani (2016) Economic and Policy Implications of Restricted Patch Distribution. <em>Management Science<\/em> 62(11):3161-3182.<\/li>\n<li>Chul Ho Lee, Xianjun Geng, Srinivasan Raghunathan (2016) Mandatory Standards and Organizational Information Security. <em>Information Systems Research<\/em> 27(1):70-86.<\/li>\n<li>Jingguo Wang, Manish Gupta, and H. Raghav Rao (2015) Insider threats in a financial institution: Analysis of attack-proneness of information systems applications. <i>MIS Quarterly<\/i> 39(1):91\u2013112.<\/li>\n<li>Jingguo Wang, Nan Xiao, H. Raghav Rao (2015) Research Note\u2014An Exploration of Risk Characteristics of Information Security Threats and Related Public Information Search Behavior. <em>Information Systems Research<\/em> 26(3):619-633.<\/li>\n<li>Sabyasachi Mitra, Sam Ransbotham (2015) Information Disclosure and the Diffusion of Information Security Attacks. <em>Information Systems Research<\/em> 26(3):565-584.<\/li>\n<li>Debabrata Dey, Atanu Lahiri, and Guoying Zhang (2014) Quality competition and market segmentation in the security software market. <i>MIS Quarterly<\/i> 38(2):589\u2013606.<\/li>\n<li>Seung Hyun Kim and Byung Cho Kim (2014) Differential effects of prior experience on the malware resolution process. <i>MIS Quarterly<\/i> 38(3):655\u2013678.<\/li>\n<li>Ryan T. Wright, Matthew L. Jensen, Jason Bennett Thatcher, Michael Dinger, Kent Marett (2014) Research Note\u2014Influence Techniques in Phishing Attacks: An Examination of Vulnerability and Resistance. <em>Information Systems Research<\/em> 25(2):385-400.<\/li>\n<li>Asunur Cezar, Huseyin Cavusoglu, Srinivasan Raghunathan (2013) Outsourcing Information Security: Contracting Issues and Security Implications. <em>Management Science<\/em> 60(3):638-657.<\/li>\n<li><span class=\"authors\">Xia Zhao, Ling Xue &amp; Andrew B. Whinston<\/span>\u00a0<span class=\"date\">(2013)<\/span>\u00a0<span class=\"art_title\">Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">30:1,<\/span>\u00a0<span class=\"page_range\">123-152.<\/span><\/li>\n<li>Chul Ho Lee, Xianjun Geng, Srinivasan Raghunathan, (2012) Contracting Information Security in the Presence of Double Moral Hazard. <em>Information Systems Research<\/em> 24(2):295-311.<\/li>\n<li>Ransbotham, S., Mitra, S., &amp; Ramsey, J. (2012). Are Markets for Vulnerabilities Effective?\u00a0<i>MIS Quarterly<\/i>,\u00a0<i>36<\/i>(1), 43\u201364.<\/li>\n<li>Gupta, A., &amp; Zhdanov, D. (2012). Growth and Sustainability of Managed Security Services Networks: An Economic Perspective.\u00a0<i>MIS Quarterly<\/i>,\u00a0<i>36<\/i>(4), 1109\u20131130.<\/li>\n<li><span class=\"authors\">Kai-Lung Hui, Wendy Hui &amp; Wei T. Yue<\/span>\u00a0<span class=\"date\">(2012)<\/span>\u00a0<span class=\"art_title\">Information Security Outsourcing with System Interdependency and Mandatory Security Requirement,<\/span>\u00a0<span class=\"serial_title\"><em>Journal of Management Information Systems<\/em>,<\/span>\u00a0<span class=\"volume_issue\">29:3,<\/span>\u00a0<span class=\"page_range\">117-156.<\/span><\/li>\n<li>Caliendo, M., Clement, M., Papies, D., &amp; Scheel-Kopeinig, S. (2012). Research Note: The Cost Impact of Spam Filters: Measuring the Effect of Information System Technologies in Organizations.\u00a0<i>Information Systems Research<\/i>,\u00a0<i>23<\/i>(3), 1068\u20131080.<\/li>\n<li>August, T., &amp; Tunca, T. I. (2011). Who Should Be Responsible for Software Security? A Comparative Analysis of Liability Policies in Network Environments.\u00a0<i>Management Science<\/i>,\u00a0<i>57<\/i>(5), 934\u2013959.<\/li>\n<li>Chen, P., Kataria, G., &amp; Krishnan, R. (2011). Correlated Failures, Diversification, and Information Security Risk Management.\u00a0<i>MIS Quarterly<\/i>,\u00a0<i>35<\/i>(2), 397\u2013422.<\/li>\n<li>Mookerjee, V., Mookerjee, R., Bensoussan, A., &amp; Yue, W. T. (2011). When Hackers Talk: Managing Information Security Under Variable Attack Rates and Knowledge Dissemination.\u00a0<i>Information Systems Research<\/i>,\u00a0<i>22<\/i>(3), 606\u2013623.<\/li>\n<li>Galbreth, M. R., &amp; Shor, M. (2010). The Impact of Malicious Agents on the Enterprise Software Industry.\u00a0<i>MIS Quarterly<\/i>,\u00a0<i>34<\/i>(3), 595\u2013612.<\/li>\n<li>Mahmood, M. A., Siponen, M., Straub, D., Rao, H. R., &amp; Raghu, T. S. (2010). Moving Toward Black Hat Research in Information Systems Security: An Editorial Introduction to the Special Issue.\u00a0<i>MIS Quarterly<\/i>,\u00a0<i>34<\/i>(3), 431\u2013433.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>I do not actively conduct research on cybersecurity. So I will stop updating this page (March 3, 2025). First published Jan 18, 2022. In this post, I gathered recent IS publications (2010-current) on the topic of cybersecurity. It is by no means an exhaustive list of the topic. This does not cover other related topics [&hellip;]<\/p>\n","protected":false},"author":51140,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[822902],"tags":[2467065,45222,1998],"class_list":["post-3664","post","type-post","status-publish","format-standard","hentry","category-teaching-materials","tag-cybersecurity","tag-it-risk","tag-security"],"_links":{"self":[{"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/posts\/3664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/users\/51140"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/comments?post=3664"}],"version-history":[{"count":6,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/posts\/3664\/revisions"}],"predecessor-version":[{"id":4622,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/posts\/3664\/revisions\/4622"}],"wp:attachment":[{"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/media?parent=3664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/categories?post=3664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ubc.ca\/genemoolee\/wp-json\/wp\/v2\/tags?post=3664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}