With deepening digitalization and reliance on technology, cyberattack incidents are a rising concern for regulators, market participants and companies. Previous and anecdotal evidence suggests that the detrimental effects of cyberattacks extend far beyond the targeted firms. This study examines the spillover effects of cyberattacks on the costs of going public by non-targeted industry peers.
The authors employ several analysis techniques, including ordinary least squares regressions, propensity score matching methodology, entropy balancing, impact threshold analysis and probit estimation. The sample consists of US firms for the 2005–2018 period.
The results indicate that firms going public within one year of a cyberattack on an industry peer experience, on average, 5.4% higher first-day returns than their counterparts with no cyberattacks on industry peers in the pre–initial public offering (IPO) period. The findings are robust to alternative industry definitions and cyberattack proxies, filtering on prominent cyberattacks and the inclusion of a battery of controls. Furthermore, a cyberattack on an industry peer after the IPO filing increases the probability that the firm will withdraw its offering by 17.5%. These findings suggest that cyberattacks on industry peers result in costly IPOs for non-targeted newcomers.
This study has important implications for mandating prompt disclosures by companies about cybersecurity risks and incidents to improve investor confidence and thereby facilitate capital formation.
This study presents private firms with an additional factor to consider (i.e. cyberattack activity in their industry) when assessing the marginal costs of going public.
