Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.

Due to the rapid evolution of technology, IT software has become incredibly complex. However the human factor still has a very important role on the application of it, since people are responsible to create software. Consequently, software vulnerabilities represent inevitable drawbacks, found to cos...

Full description

Bibliographic Details
Main Authors: Lioupras, Ioannis, Manthou, Eleni
Format: Others
Language:English
Published: Umeå universitet, Institutionen för informatik 2014
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-90126
id ndltd-UPSALLA1-oai-DiVA.org-umu-90126
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-umu-901262014-06-19T05:04:39ZDon’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.engLioupras, IoannisManthou, EleniUmeå universitet, Institutionen för informatikUmeå universitet, Institutionen för informatik2014software vulnerabilityIT risk managementdisclosure policiesevent study methodologyDue to the rapid evolution of technology, IT software has become incredibly complex. However the human factor still has a very important role on the application of it, since people are responsible to create software. Consequently, software vulnerabilities represent inevitable drawbacks, found to cost extremely large amounts of money to the companies. “Heartbleed” is a recently discovered vulnerability with no prior investigation that answers questions about the impact it has to the companies affected. This paper focuses on the impact of it on the market value of the companies who participated in the vulnerability disclosure process with the help of an event study methodology. Furthermore our analysis investigates if there is a different affection to the value of the company based on the roles those companies had in the process. Our results suggest that the market did not punish the companies about the existence of vulnerability. However the general negative reaction of the market to the incident reflects the importance of a strategic vulnerability disclosure plan for such cases. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-90126Informatik Student Paper Master (INFSPM) ; 2014.16application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic software vulnerability
IT risk management
disclosure policies
event study methodology
spellingShingle software vulnerability
IT risk management
disclosure policies
event study methodology
Lioupras, Ioannis
Manthou, Eleni
Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
description Due to the rapid evolution of technology, IT software has become incredibly complex. However the human factor still has a very important role on the application of it, since people are responsible to create software. Consequently, software vulnerabilities represent inevitable drawbacks, found to cost extremely large amounts of money to the companies. “Heartbleed” is a recently discovered vulnerability with no prior investigation that answers questions about the impact it has to the companies affected. This paper focuses on the impact of it on the market value of the companies who participated in the vulnerability disclosure process with the help of an event study methodology. Furthermore our analysis investigates if there is a different affection to the value of the company based on the roles those companies had in the process. Our results suggest that the market did not punish the companies about the existence of vulnerability. However the general negative reaction of the market to the incident reflects the importance of a strategic vulnerability disclosure plan for such cases.
author Lioupras, Ioannis
Manthou, Eleni
author_facet Lioupras, Ioannis
Manthou, Eleni
author_sort Lioupras, Ioannis
title Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
title_short Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
title_full Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
title_fullStr Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
title_full_unstemmed Don’t let my Heart bleed! : An event study methodology in Heartbleed vulnerability case.
title_sort don’t let my heart bleed! : an event study methodology in heartbleed vulnerability case.
publisher Umeå universitet, Institutionen för informatik
publishDate 2014
url http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-90126
work_keys_str_mv AT liouprasioannis dontletmyheartbleedaneventstudymethodologyinheartbleedvulnerabilitycase
AT manthoueleni dontletmyheartbleedaneventstudymethodologyinheartbleedvulnerabilitycase
_version_ 1716704569673646080