We examine whether CEO gender, CEO overconfidence, and their interaction affect a firm’s likelihood of reporting a data security breach (DSB). Theory suggests that relative to male CEOs, female CEOs are more likely to allocate resources to managing IT-related risks, while overconfident CEOs are inclined toward risk-taking. Consistent with these arguments, we predict and find that firms led by female CEOs are significantly less likely to report a DSB, whereas those led by overconfident CEOs are significantly more likely to do so. Further, firms led by female CEOs that are also overconfident are incrementally less likely to report a DSB than firms led by overconfident male CEOs. Our findings offer new insights into how CEO characteristics impact the exposure of firms to cybersecurity risks.
Blocker et al. (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: