The worst cyberattack so far
In this commentary, Crosignani et al. describe the NotPetya attack in 2017 which targeted Ukrainian organizations in an effort by Russian military intelligence to cripple critical Ukrainian infrastructure. NotPetya’s aim was not the financial gains from ransom payments, instead, it was a cyberattack designed to encrypt and paralyze the computer networks of Ukrainian banks, firms, and government. The damage of NotPetya was estimated at $10 billion in damages as it affected a few large global firms through their Ukrainian subsidiaries. For example: the shipping company Maersk had its operations grind to a halt, creating chaos at ports around the globe. A FedEx subsidiary was also affected. Manufacturing, research, and sales were halted at the pharmaceutical giant Merck, making it unable to supply vaccines to the Center for Disease Control and Prevention (CDC). Several other large companies had their servers taken down and could not carry out essential activities.


Cyberattacks and Supply Chain Disruptions
By: Matteo Crosignani, Marco Macchiavelli, André F. Silva – Federal Reserve Bank of New York
Who are the targets of cyberattacks
In this paper, Kamiyaa et al. use a comprehensive sample of disclosed cyberattacks on public corporations involving data breaches from 2005 to 2017, to investigate the impact on corporations of successful cyberattacks. They find that:
- The firms experiencing cyberattacks are larger, older, more profitable, less risky, have higher future growth opportunities, higher leverage, and higher asset intangibility. Most importantly, few targets are financially constrained.
- It is cyberattacks involving the loss of customers’ financial information that mostly lead to the company’s shareholder loss. In particular, these firms experience a drop in sales growth mostly due to reputational damage.
- Interestingly, competitors of firms that have experienced cyberattacks involving the loss of clients’ financial information, also incur wealth losses as the vulnerability index of the industry increases.
Risk management, firm reputation, and the impact of successful cyberattacks on target firms
Authors: Shinichi Kamiyaa, Jun-Koo Kanga, Jungmin Kimb, Andreas Milidonis, René M. Stulz
From: Nanyang Technological University, Hong Kong Polytechnic University, University of Cyprus, The Ohio State University
A global issue
From a global perspective, regulatory agencies must ensure that proper compliance frameworks and regulations are in place to support local companies. For example, in Latin America the absence of legislation enforcing the use of well-stablished standards such as the NIST or ISO frameworks means that companies based in these regions are not required to implement such controls that would prevent further incidents – except when the organization itself takes the initiative to apply such frameworks on their own. […] In an increasingly connected world that breaks down continental barriers, a weaker security standard tends to be compromised and will, therefore, contribute to the compromise of other organizations even if such organizations follow stronger standards. In other words, a local failure can impact everyone in the industry, which is the reason why we need a global policy for data protection.
A Case Study of the Capital One Data Breach
Authors: Nelson Novaes Neto, Stuart Madnick, Anchises Moraes G. de Paula, Natasha Malara Borges
From: MIT, C6 Bank