簡易檢索 / 詳目顯示

研究生: 王若芸
Wang, Ruo-Yun
論文名稱: 資安事件、揭露回應與公司價值:來自文本相似度的證據
Cybersecurity Incidents, Disclosure Responses, and Firm Value: Evidence from Textual Similarity
指導教授: 劉梧柏
Liu, Wu-Po
學位類別: 碩士
Master
系所名稱: 管理學院 - 會計學系
Department of Accountancy
論文出版年: 2026
畢業學年度: 114
語文別: 中文
論文頁數: 48
中文關鍵詞: 資訊安全事件資訊揭露文字探勘向量空間模型公司價值
外文關鍵詞: Cybersecurity Incidents, Information Disclosure, Text Mining, Vector Space Model (VSM), Firm Value
相關次數: 點閱:35下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 本研究以 2021 年至 2024 年台灣上市櫃公司為研究樣本,透過公開資訊觀測站蒐集重大資安事件公告資料,並配對未發生資安事件之公司作為比較樣本,接著運用文字探勘(Text Mining)技術,結合TF-IDF與向量空間模型(Vector Space Model, VSM),分析企業年報與永續報告書中之資安相關揭露內容,以衡量企業於資安事件發生前後揭露內容之變動程度。此外,本研究以 Tobin’s Q 作為公司價值之代理變數,進一步檢驗資安事件、揭露差異程度與公司價值之關聯性。實證結果顯示,企業於發生重大資安事件後,其資安揭露內容差異程度呈現顯著提升,表示企業在面對資安事件時,會因應監理機關要求、市場壓力及投資人關注,調整其揭露內容與揭露策略,提供較具公司特定性與資訊價值之揭露資訊,而不再僅採用制式化或模板化之揭露方式。然而,揭露差異程度與公司價值雖呈現正向關係,但未達統計顯著水準,且資安事件與揭露差異程度之交乘效果亦未顯著,表示市場對揭露內容之文字差異程度尚未形成明確評價,投資人可能更重視企業實際資安治理能力與事件處理成效,而非揭露文字本身之變化程度。

    This study examines Taiwanese listed and OTC firms from 2021 to 2024. Major cybersecurity incident announcements were collected from the Market Observation Post System (MOPS), and non-breached firms were matched as a control sample. Using text mining techniques, together with TF-IDF and the Vector Space Model (VSM), this study analyzes cybersecurity-related disclosures in annual and sustainability reports to measure disclosure differences before and after cybersecurity incidents. Tobin’s Q is employed as a proxy for firm value to investigate the relationships among cybersecurity incidents, disclosure differences, and firm value.
    The results show that firms significantly increase the degree of difference in their cybersecurity disclosures following major cybersecurity incidents, suggesting that they adjust their disclosure strategies and provide more firm-specific information rather than relying on standardized disclosures. However, neither the degree of disclosure difference nor its interaction with cybersecurity incidents has a significant impact on firm value. These findings suggest that investors place greater emphasis on firms’ actual cybersecurity governance and incident response capabilities than on changes in disclosure wording.

    第一章、緒論 1 第二章、文獻探討與假說建立 3 第一節、資安事件揭露 3 第二節、資訊揭露相似度與資訊品質 4 第三節、資安事件與公司價值 5 第四節、假說建立 6 第三章、研究方法 6 第一節、資料來源與樣本選取 6 第二節、揭露相似度的衡量方法 7 第三節、迴歸模型 10 第四節、變數設計 11 第四章、研究結果 15 第一節、敘述性統計 15 第二節、相關係數矩陣 17 第三節、實證分析結果 19 第五章、額外測試 21 第一節、公司價值的替代衡量方式 21 第二節、針對資訊敏感產業分群 22 第六章、結論 27 第一節、研究發現與結論 27 第二節、研究貢獻及政策意涵 28 第三節、研究限制及研究建議 29 參考文獻 31 附錄一、變數定義與說明 33 附錄二、資安揭露內容變化範例 34

    劉福運、鍾惠民、余俊憲與莊秉義,2025,生技醫療產業致股東報告書相似度之研究,《會計審計論叢》,第15卷1期,頁119-148。 https://www.airitilibrary.com/Article/Detail/22219374-N202506140003-00004
    Amir, E., Levi, S. and Livne, T. 2018. Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies 23: 1177-1206. https://doi.org/10.1007/s11142-018-9452-4
    Berkman, H., Jona, J., Lee, G., and Soderstrom, N. 2018. Cybersecurity awareness and market valuations. Journal of Accounting and Public Policy 37(6). https://doi.org/10.1016/j.jaccpubpol.2018.10.003
    Bosworth, D., & Rogers, M. (2001). Market value, R&D and intellectual property: an empirical analysis of large Australian firms. Economic Record, 77(239), 323-337. https://doi.org/10.1111/1475-4932.t01-1-00026
    Brown, S. V. and Tucker, J. W. 2011. Large-sample evidence on firms' year-over-year MD&A modifications. Journal of Accounting Research 49(2): 309-346. https://doi.org/10.1111/j.1475-679x.2010.00396.x
    Cavusoglu, H.. Mishra, B., and Raghunathan, S. 2004. The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers. International Journal of Electronic Commerce 9(1):69-104. https://doi.org/10.1080/10864415.2004.11044320
    Gordon, L. A., Loeb, M. P., Lucyshyn, W., and Sohail, T. 2006. The impact of the Sarbanes-Oxley Act on the corporate disclosures of information security activities. Journal of Accounting and Public Policy 25(5):503–530. https://doi.org/10.1016/j.jaccpubpol.2006.07.005
    Havakhor, T., Rahman, M. S., and Zhang, T. 2021. Disclosure of cybersecurity investments and the cost of capital. SSRN 3553470. https://doi.org/10.1287/isre.2023.0260
    Jacob Peng and Chang-Wei Li. 2022. Security Breaches and Modifications on Cybersecurity Disclosures. Journal of Accounting and Management Information Systems 21(3): 452-470. https://doi.org/10.24818/jamis.2022.03007
    Li, He., No, W. G., and Wang, T. 2018. SEC’s cybersecurity disclosure guidance and disclosed cybersecurity risk factors. International Journal of Accounting Information Systems 30(C): 40–55. https://doi.org/10.1016/j.accinf.2018.06.003
    Renders, A., Gaeremynck, A., & Sercu, P. (2010). Corporate-governance ratings and company performance: A cross-European study. Corporate Governance, 18(2), 87-106. https://doi.org/10.1111/j.1467-8683.2010.00791.x
    Rosati, P., Gogolin, F., and Lynn, T. 2019. Audit firm assessments of cyber-security risk: Evidence from audit fees and SEC comment letters. The International Journal of Accounting 54(3): 1950013. https://doi.org/10.1142/s1094406019500136
    Singh, Harmandeep. 2025. Voluntary cybersecurity risk disclosures and firms’ characteristics: the moderating role of the knowledge-intensive industry. Asian. Journal of Accounting Research 10(2): 168-185 https://doi.org/10.1108/ajar-12-2023-0413
    Srivastava, Rajendra. 2023. A New Measure of Similarity in Textual Analysis: Vector Similarity Metric versus Cosine Similarity Metric. Journal of Emerging Technologies in Accounting. 20(10): 2308. https://doi.org/10.2308/jeta-2021-043

    QR CODE