{"id":{"repo_id":"minho-thes","oai_identifier":"oai:repositorium.uminho.pt:1822/98641"},"canonical_url":"https://search.dev.ndltd.org/etd/minho-thes/oai:repositorium.uminho.pt:1822/98641","repository":{"repo_id":"minho-thes","name":"Universidade do Minho","base_url":"http://repositorium.sdum.uminho.pt/oai/request"},"display":{"title":"Supply chain cyber risk management","abstract":"Cybersecurity incidents are a growing concern for businesses, their supply chains, and stakeholders. The incidents’ potential adverse effects and borderlessness emphasize the importance of information sharing through market agents. Disclosures convey private information to the market and are critical tools to rebuild trust after companies experience cybersecurity incidents. Nevertheless, a lack of confidence surrounds disclosures due to the complex trade-off managers face during the reporting process, namely transparency-protecting sensitive information. The US Securities and Exchange Commission (SEC) recently issued final rulings on cybersecurity incident disclosure, expecting to increase the informational levels of disclosures and incident comparability. This research investigates how can supply chain participants leverage cybersecurity disclosed information to 1) develop mitigation strategies, 2) analyze the informational quality of disclosures, and 3) examine factors impacting the disclosures’ characteristics. To address these points, this research designed a novel database combining information disclosed by publicly traded companies in the US market from 2011 to 2023. The dataset covers 346 incidents, condensing over 650 firm-years and almost 3,000 filings discussing cybersecurity incidents. This dataset selected variables have been thoroughly analyzed in the literature and represent a bottom-up solution to the problem of “what to share.” Aside from this novel dataset, this thesis 1) developed a new incident classification to help users select their defensive strategies. The classes also uncover hidden classes’ characteristics and expose the dynamic interplay of the cognitive appraisal processes defenders pass during this selection. 2) It found i) disclosure adherence to the new SEC guidelines, indicating that under the regulators’ perspective, disclosures would be considered of quality, ii) in-company, and topic isomorphism in cybersecurity disclosures, and iii) managers’ reporting preferences. Moreover, 3) it is unveiled that the target company’s external characteristics influence the elapsed time to the first report and that the incident’s features connect to how thorough the disclosures are. Our results offer theoretical advances to multiple bodies of literature (namely, protection motivation, proprietary costs, institutional, information systems, and corporate social (digital) responsibility). Regarding policy implications, our results favor the regulatory steps taken by the SEC. However, there is still space for improvements, such as a shift from the one-size-fits-all regulation and the definition of a metric for incident comparability.","abstract_html":"Cybersecurity incidents are a growing concern for businesses, their supply chains, and stakeholders. The incidents’ potential adverse effects and borderlessness emphasize the importance of information sharing through market agents. Disclosures convey private information to the market and are critical tools to rebuild trust after companies experience cybersecurity incidents. Nevertheless, a lack of confidence surrounds disclosures due to the complex trade-off managers face during the reporting process, namely transparency-protecting sensitive information. The US Securities and Exchange Commission (SEC) recently issued final rulings on cybersecurity incident disclosure, expecting to increase the informational levels of disclosures and incident comparability. This research investigates how can supply chain participants leverage cybersecurity disclosed information to 1) develop mitigation strategies, 2) analyze the informational quality of disclosures, and 3) examine factors impacting the disclosures’ characteristics. To address these points, this research designed a novel database combining information disclosed by publicly traded companies in the US market from 2011 to 2023. The dataset covers 346 incidents, condensing over 650 firm-years and almost 3,000 filings discussing cybersecurity incidents. This dataset selected variables have been thoroughly analyzed in the literature and represent a bottom-up solution to the problem of “what to share.” Aside from this novel dataset, this thesis 1) developed a new incident classification to help users select their defensive strategies. The classes also uncover hidden classes’ characteristics and expose the dynamic interplay of the cognitive appraisal processes defenders pass during this selection. 2) It found i) disclosure adherence to the new SEC guidelines, indicating that under the regulators’ perspective, disclosures would be considered of quality, ii) in-company, and topic isomorphism in cybersecurity disclosures, and iii) managers’ reporting preferences. Moreover, 3) it is unveiled that the target company’s external characteristics influence the elapsed time to the first report and that the incident’s features connect to how thorough the disclosures are. Our results offer theoretical advances to multiple bodies of literature (namely, protection motivation, proprietary costs, institutional, information systems, and corporate social (digital) responsibility). Regarding policy implications, our results favor the regulatory steps taken by the SEC. However, there is still space for improvements, such as a shift from the one-size-fits-all regulation and the definition of a metric for incident comparability.","abstract_has_math":false,"creators":["Gomes Filho, Núbio Vidal de Negreiros"],"institution":"Universidade do Minho","degree_name":"Tese de doutoramento em Business Administration","degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Rego, Nazaré Glória Gonçalves","Claro, João Alberto Vieira de Campos Pereira"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-11-08","date_published":"2024-11-08","updated_at":"2026-08-21T16:46:39Z","subjects":["Cybersecurity disclosure","Cybersecurity incidents","Incident database","Mitigation strategies","Regulation","Base de dados de incidentes","Estratégias de mitigação","Incidentes cibernéticos","Regulação","Reportes cibernéticos"],"languages":["eng"],"rights":["embargoedAccess (3 Years)"],"rights_urls":["http://creativecommons.org/licenses/by-nc-nd/4.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1822/98641","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"source_record":{"url":"http://repositorium.sdum.uminho.pt/oai/request?verb=GetRecord&metadataPrefix=dim&identifier=oai%3Arepositorium.uminho.pt%3A1822%2F98641","prefix":"dim"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Rego, Nazaré Glória Gonçalves","Claro, João Alberto Vieira de Campos Pereira"]},{"key":"dc:creator","label":"Author","values":["Gomes Filho, Núbio Vidal de Negreiros"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-12-18T16:30:35Z"]},{"key":"dc:date.issued","label":"Date","values":["2024-11-08"]},{"key":"dc:relation","label":"Dc Relation","values":["Supply Chain Cyber Risk Management [SFRH/BD/145941/2019]","SFRH/BD/145941/2019"]},{"key":"dc:type","label":"Dc Type","values":["doctoralThesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Tese de doutoramento em Business Administration"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Universidade do Minho"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Cybersecurity disclosure","Cybersecurity incidents","Incident database","Mitigation strategies","Regulation","Base de dados de incidentes","Estratégias de mitigação","Incidentes cibernéticos","Regulação","Reportes cibernéticos"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["embargoedAccess (3 Years)"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://creativecommons.org/licenses/by-nc-nd/4.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1822/98641"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Cybersecurity incidents are a growing concern for businesses, their supply chains, and stakeholders. The incidents’ potential adverse effects and borderlessness emphasize the importance of information sharing through market agents. Disclosures convey private information to the market and are critical tools to rebuild trust after companies experience cybersecurity incidents. Nevertheless, a lack of confidence surrounds disclosures due to the complex trade-off managers face during the reporting process, namely transparency-protecting sensitive information. The US Securities and Exchange Commission (SEC) recently issued final rulings on cybersecurity incident disclosure, expecting to increase the informational levels of disclosures and incident comparability. This research investigates how can supply chain participants leverage cybersecurity disclosed information to 1) develop mitigation strategies, 2) analyze the informational quality of disclosures, and 3) examine factors impacting the disclosures’ characteristics. To address these points, this research designed a novel database combining information disclosed by publicly traded companies in the US market from 2011 to 2023. The dataset covers 346 incidents, condensing over 650 firm-years and almost 3,000 filings discussing cybersecurity incidents. This dataset selected variables have been thoroughly analyzed in the literature and represent a bottom-up solution to the problem of “what to share.” Aside from this novel dataset, this thesis 1) developed a new incident classification to help users select their defensive strategies. The classes also uncover hidden classes’ characteristics and expose the dynamic interplay of the cognitive appraisal processes defenders pass during this selection. 2) It found i) disclosure adherence to the new SEC guidelines, indicating that under the regulators’ perspective, disclosures would be considered of quality, ii) in-company, and topic isomorphism in cybersecurity disclosures, and iii) managers’ reporting preferences. Moreover, 3) it is unveiled that the target company’s external characteristics influence the elapsed time to the first report and that the incident’s features connect to how thorough the disclosures are. Our results offer theoretical advances to multiple bodies of literature (namely, protection motivation, proprietary costs, institutional, information systems, and corporate social (digital) responsibility). Regarding policy implications, our results favor the regulatory steps taken by the SEC. However, there is still space for improvements, such as a shift from the one-size-fits-all regulation and the definition of a metric for incident comparability.","Incidentes de cibersegurança preocupam as empresas, suas cadeias de abastecimento e outros atores. Seus efeitos adversos e sua ausência de fronteiras enfatizam a importância do compartilhamento de informações entre agentes de mercado. Reportes transmitem informações privadas e são ferramentas vitais para reconstruir a confiança após estes incidentes. Entretanto, a falta de confiança em torno da qualidade destas informações remonta uma complexa escolha que os gestores enfrentam durante o reporte: transparência x proteção de informações sensíveis. A Securities and Exchange Commission (SEC) emitiu recentemente um regulamento sobre divulgação destes incidentes, esperando aumentar os níveis informacionais das divulgações e a comparabilidade dos incidentes. Esta pesquisa investiga como os membros das cadeias de abastecimento se beneficiam dos reportes de cibersegurança para 1) selecionar estratégias defensivas, 2) analisar a qualidade informacional das divulgações e 3) examinar fatores que impactam suas características. Esta pesquisa projetou uma nova base de dados combinando informações divulgadas por empresas de capital aberto no mercado dos EUA de 2011 a 2023. O conjunto de dados abrange 346 incidentes, condensando mais de 650 anos-empresa e quase 3.000 documentos sobre estes incidentes. As variáveis selecionadas deste conjunto de dados foram analisadas na literatura e representam uma solução bottom-up para o problema de \"o que compartilhar\". Além deste novo conjunto de dados, esta tese 1) desenvolveu uma nova classificação de incidentes que ajuda usuários a selecionar suas estratégias defensivas. As classes revelam características ocultas e expõem a interação dinâmica dos processos de avaliação cognitiva pelos quais os defensores passam durante a seleção de defesas. 2) Encontrou i) adesão das divulgações às novas diretrizes da SEC, indicando que sob a perspetiva dos reguladores, as divulgações seriam consideradas de qualidade, ii) isomorfismo interno da empresa e de tópicos divulgados e iii) preferências de reporte dos gestores. Além disso, 3) revelou que idiossincrasias empresariais influenciam o tempo decorrido até o primeiro relatório e que as características do incidente se relacionam com a minúcia das divulgações. Nossos resultados oferecem avanços teóricos para vários corpos da literatura. Em relação às implicações de políticas públicas, nossos resultados corroboram as medidas regulatórias tomadas pela SEC. No entanto, melhorias são possíveis, como a mudanças regulatórias ou a definição de uma métrica para comparação de incidentes."]},{"key":"dc:title","label":"Title","values":["Supply chain cyber risk management"]}]}],"canonical_facts":{"dc:contributor.advisor":["Rego, Nazaré Glória Gonçalves","Claro, João Alberto Vieira de Campos Pereira"],"dc:creator":["Gomes Filho, Núbio Vidal de Negreiros"],"dc:date.accessioned":["2025-12-18T16:30:35Z"],"dc:date.issued":["2024-11-08"],"dc:description.abstract":["Cybersecurity incidents are a growing concern for businesses, their supply chains, and stakeholders. The incidents’ potential adverse effects and borderlessness emphasize the importance of information sharing through market agents. Disclosures convey private information to the market and are critical tools to rebuild trust after companies experience cybersecurity incidents. Nevertheless, a lack of confidence surrounds disclosures due to the complex trade-off managers face during the reporting process, namely transparency-protecting sensitive information. The US Securities and Exchange Commission (SEC) recently issued final rulings on cybersecurity incident disclosure, expecting to increase the informational levels of disclosures and incident comparability. This research investigates how can supply chain participants leverage cybersecurity disclosed information to 1) develop mitigation strategies, 2) analyze the informational quality of disclosures, and 3) examine factors impacting the disclosures’ characteristics. To address these points, this research designed a novel database combining information disclosed by publicly traded companies in the US market from 2011 to 2023. The dataset covers 346 incidents, condensing over 650 firm-years and almost 3,000 filings discussing cybersecurity incidents. This dataset selected variables have been thoroughly analyzed in the literature and represent a bottom-up solution to the problem of “what to share.” Aside from this novel dataset, this thesis 1) developed a new incident classification to help users select their defensive strategies. The classes also uncover hidden classes’ characteristics and expose the dynamic interplay of the cognitive appraisal processes defenders pass during this selection. 2) It found i) disclosure adherence to the new SEC guidelines, indicating that under the regulators’ perspective, disclosures would be considered of quality, ii) in-company, and topic isomorphism in cybersecurity disclosures, and iii) managers’ reporting preferences. Moreover, 3) it is unveiled that the target company’s external characteristics influence the elapsed time to the first report and that the incident’s features connect to how thorough the disclosures are. Our results offer theoretical advances to multiple bodies of literature (namely, protection motivation, proprietary costs, institutional, information systems, and corporate social (digital) responsibility). Regarding policy implications, our results favor the regulatory steps taken by the SEC. However, there is still space for improvements, such as a shift from the one-size-fits-all regulation and the definition of a metric for incident comparability.","Incidentes de cibersegurança preocupam as empresas, suas cadeias de abastecimento e outros atores. Seus efeitos adversos e sua ausência de fronteiras enfatizam a importância do compartilhamento de informações entre agentes de mercado. Reportes transmitem informações privadas e são ferramentas vitais para reconstruir a confiança após estes incidentes. Entretanto, a falta de confiança em torno da qualidade destas informações remonta uma complexa escolha que os gestores enfrentam durante o reporte: transparência x proteção de informações sensíveis. A Securities and Exchange Commission (SEC) emitiu recentemente um regulamento sobre divulgação destes incidentes, esperando aumentar os níveis informacionais das divulgações e a comparabilidade dos incidentes. Esta pesquisa investiga como os membros das cadeias de abastecimento se beneficiam dos reportes de cibersegurança para 1) selecionar estratégias defensivas, 2) analisar a qualidade informacional das divulgações e 3) examinar fatores que impactam suas características. Esta pesquisa projetou uma nova base de dados combinando informações divulgadas por empresas de capital aberto no mercado dos EUA de 2011 a 2023. O conjunto de dados abrange 346 incidentes, condensando mais de 650 anos-empresa e quase 3.000 documentos sobre estes incidentes. As variáveis selecionadas deste conjunto de dados foram analisadas na literatura e representam uma solução bottom-up para o problema de \"o que compartilhar\". Além deste novo conjunto de dados, esta tese 1) desenvolveu uma nova classificação de incidentes que ajuda usuários a selecionar suas estratégias defensivas. As classes revelam características ocultas e expõem a interação dinâmica dos processos de avaliação cognitiva pelos quais os defensores passam durante a seleção de defesas. 2) Encontrou i) adesão das divulgações às novas diretrizes da SEC, indicando que sob a perspetiva dos reguladores, as divulgações seriam consideradas de qualidade, ii) isomorfismo interno da empresa e de tópicos divulgados e iii) preferências de reporte dos gestores. Além disso, 3) revelou que idiossincrasias empresariais influenciam o tempo decorrido até o primeiro relatório e que as características do incidente se relacionam com a minúcia das divulgações. Nossos resultados oferecem avanços teóricos para vários corpos da literatura. Em relação às implicações de políticas públicas, nossos resultados corroboram as medidas regulatórias tomadas pela SEC. No entanto, melhorias são possíveis, como a mudanças regulatórias ou a definição de uma métrica para comparação de incidentes."],"dc:identifier.uri":["https://hdl.handle.net/1822/98641"],"dc:language.iso":["eng"],"dc:relation":["Supply Chain Cyber Risk Management [SFRH/BD/145941/2019]","SFRH/BD/145941/2019"],"dc:rights":["embargoedAccess (3 Years)"],"dc:rights.uri":["http://creativecommons.org/licenses/by-nc-nd/4.0/"],"dc:subject":["Cybersecurity disclosure","Cybersecurity incidents","Incident database","Mitigation strategies","Regulation","Base de dados de incidentes","Estratégias de mitigação","Incidentes cibernéticos","Regulação","Reportes cibernéticos"],"dc:title":["Supply chain cyber risk management"],"dc:type":["doctoralThesis"],"thesis:degree_name":["Tese de doutoramento em Business Administration"],"thesis:institution_name":["Universidade do Minho"]},"updated_at":"2026-08-21T16:46:39Z"}