IDEAS home Printed from https://ideas.repec.org/a/taf/euract/v31y2022i3p701-728.html

Cyber-Security Incidents and Audit Quality

Author

Listed:
  • Pierangelo Rosati
  • Fabian Gogolin
  • Theo Lynn

Abstract

As signals of internal control weaknesses, cyber security incidents can represent significant risk factors to the quality of financial reporting. We empirically assess the audit quality implications of data breaches for a large sample of US firms. Using a difference-in-difference approach based on a matched sample of breached and non-breached firms, we find no evidence that cyber-security incidents result in a decline in audit quality. Instead, we observe positive shifts in four widely-used proxies for audit quality. We document that breached firms (i) experience a decrease in abnormal accruals, (ii) are less likely to report small profits or small earnings increases, (iii) are more likely to be issued a going concern report, and (iv) are less likely to restate their financial statements in the two years following a breach. Our results indicate that auditors effectively offset increases in audit risk through additional substantive testing and audit effort. Our evidence supports the view that auditors have increased their audit risk awareness and put in place adequate procedures to deal with the consequences of cyber-security incidents.

Suggested Citation

  • Pierangelo Rosati & Fabian Gogolin & Theo Lynn, 2022. "Cyber-Security Incidents and Audit Quality," European Accounting Review, Taylor & Francis Journals, vol. 31(3), pages 701-728, May.
  • Handle: RePEc:taf:euract:v:31:y:2022:i:3:p:701-728
    DOI: 10.1080/09638180.2020.1856162
    as

    Download full text from publisher

    File URL: http://hdl.handle.net/10.1080/09638180.2020.1856162
    Download Restriction: Access to full text is restricted to subscribers.

    File URL: https://libkey.io/10.1080/09638180.2020.1856162?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to

    for a different version of it.

    Citations

    Citations are extracted by the CitEc Project, subscribe to its RSS feed for this item.
    as


    Cited by:

    1. Zhang, Yimei & Smith, Thomas, 2023. "The impact of customer firm data breaches on the audit fees of their suppliers," International Journal of Accounting Information Systems, Elsevier, vol. 50(C).
    2. Benaroch, Michel, 2025. "Measuring the pervasiveness of IT general controls: A model and empirical validation," International Journal of Accounting Information Systems, Elsevier, vol. 56(C).
    3. Trinh, Vu Quang & Elnahass, Marwa & Pasiouras, Fotios, 2025. "Personal traits of CEOs and cybersecurity-related disclosure," Journal of International Accounting, Auditing and Taxation, Elsevier, vol. 58(C).
    4. Khowanas Saeed Qader & Kemal Cek, 2023. "Analysis of the Impact of External Auditors’ Autonomy on Financial Accounting Information Quality Case Study Commercial Banks in Northern Iraq," Sustainability, MDPI, vol. 15(12), pages 1-21, June.
    5. Ahmad Yuosef Alodat & Yunhong Hao & Haitham Nobanee & Hazem Ali & Marwan Mansour & Hamzeh Al Amosh, 2025. "Board characteristics and cybersecurity disclosure: evidence from the UK," Electronic Commerce Research, Springer, vol. 25(6), pages 4717-4735, December.
    6. Lisa Yao Liu, 2025. "Financial Statement Audits and Data Breaches," Management Science, INFORMS, vol. 71(8), pages 6340-6366, August.
    7. Erkan-Barlow, Asligul & Nguyen, Trung, 2024. "Cybersecurity and executive compensation: Can inside debt-induced risk aversion improve cyber risk management effectiveness?," International Review of Financial Analysis, Elsevier, vol. 93(C).
    8. Wang, Fangjun & Wang, Hao & Li, Jiyuan, 2024. "The effect of cybersecurity legislation on firm cost behavior: Evidence from China," Pacific-Basin Finance Journal, Elsevier, vol. 86(C).
    9. He, Guanming & Li, Zhichao & Yu, Ling & Zhou, Zhanqiang, 2025. "Does commercial reform embracing digital technologies mitigate stock price crash risk?," Journal of Corporate Finance, Elsevier, vol. 91(C).
    10. Jin, Justin & Li, Na & Liu, Suyi & Khalid Nainar, S.M., 2023. "Cyber attacks, discretionary loan loss provisions, and banks’ earnings management," Finance Research Letters, Elsevier, vol. 54(C).
    11. Saeed Rabea Baatwah & Mohammed Asiri & Mohammed Saleh Bajaher & Ayoob Alyafai & Salem Baajajah, 2026. "Thriving post-cyberattacks: the power of control, disclosure, and IT maturity," Electronic Commerce Research, Springer, vol. 26(2), pages 1705-1743, April.
    12. Chelsea Liu & Muhammad Ali Babar, 2026. "Corporate cybersecurity risk and data breaches: A systematic review of empirical research," Australian Journal of Management, Australian School of Business, vol. 51(1), pages 62-92, February.
    13. Liu, Xiaohui & Luo, Juan & Yawson, Alfred, 2025. "Equity offering following cyberattacks," Journal of Corporate Finance, Elsevier, vol. 91(C).

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:taf:euract:v:31:y:2022:i:3:p:701-728. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Chris Longhurst (email available below). General contact details of provider: http://www.tandfonline.com/REAR20 .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.