The Impact of Audit Office Cybersecurity Experience on Nonbreach Client’s Audit Fees and Cybersecurity Risks

1Citations
Citations of this article
21Readers
Mendeley users who have this article in their library.
Get full text

Abstract

This study investigates whether auditors’ experiences with their clients’ cybersecurity incidents affect their subsequent audits for nonbreach clients and help those clients reduce cybersecurity risks. We find that audit offices who have experience with cybersecurity-breached clients, ceteris paribus, charge higher audit fees from nonbreach clients. Additionally, the increased audit fees conditional on auditors’ cybersecurity experience are negatively associated with nonbreach clients’ future breach incidents. Such associations are found only in the Big 4 audit offices and offices with IT capability. This study offers timely insights for standard setters and important implications for both professionals and the academic literature by documenting the spillover effect of cybersecurity experience on subsequent risk assessments of nonbreach clients, while also confirming the effectiveness of engaging auditors in addressing cybersecurity matters.

Cite

CITATION STYLE

APA

Li, H., Sun, Z., & Huang, F. (2024). The Impact of Audit Office Cybersecurity Experience on Nonbreach Client’s Audit Fees and Cybersecurity Risks. Journal of Information Systems, 38(1), 177–206. https://doi.org/10.2308/ISYS-2023-014

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free