A Quantitative Study Assessing the Impact of Financial Sector Saf-11-85.pdf

Is there anything else you׳d like to ask?
Our top-rated tutors can help you.

Click here to post a question
Related Documents
1 / 75100%
1
CHAPTER I: INTRODUCTION
Cybersecurity failure in the private sector is a national problem and a growing federal policy
priority. Diminishing the frequency and severity of successful cybersecurity breaches has
emerged as a “national security and economic security imperative” (The White House, 2022, 2nd
paragraph). Nevertheless, US policy makers continue to struggle with which policy tools are
most effective to address this policy problem. The federal government is now embracing a
regulation heavy approach. President Biden’s 2023 National Cybersecurity Strategy states “new
authorities will be required to set regulations that can drive better cybersecurity practices at
scale” (The White House, 2023, p. 7).
In public policy, tool selection, also known as instrumentation, focuses on which tools policy
makers should select to best enable their policy objectives (Howlett, 1991). Behavioral public
policy forwards that to achieve desired objectives, policy tool section and policy target
“behavioural expectations” must be linked (Howlett & Fraser, 2018, p. 101). In other words, an
association and correlational relationship exists between alignment of policy target behavioral
attributes and policy tool selection to policy outcome achievement. Howlett & Fraser (2018) and
Barak - Corren & Kariv – Teitelbaum (2020), and Jing & Graham (2008) assert key policy target
behavioral attributes that align with regulation policy tools are a culture of deference to
government regulatory activities, a culture shaped by regulatory activity, and regulator / regulate
interaction during regulation development.
The financial sector is one of the most essential critical infrastructure sectors, and
cybersecurity failures in the financial sector can have great cascading societal impacts (Atkins &
Lawson, 2020). Diminishing breach frequency and severity in the financial sector is nationally
important. Current behavioral public policy theory suggests that an appropriate tool selection for
2
achieving cybersecurity policy outcomes in the financial sector are regulatory authority tools.
This is because the financial sector has key behavioral attributes as noted by Howlett & Fraser
(2018) and Barak - Corren & Kariv – Teitelbaum (2020) and (Jing & Graham, 2008). Financial
companies have a long- established culture of willingness to respond to “government invoked
penalties and proscriptions” (Howlett & Fraser, 2018, p. 111) and financial sector regulators
have often “interacted with regulates” (Howlett & Fraser, 2018, p. 5169) in the development of
regulation (Barak – Corren & Kariv – Teitelbaum, 2020). In 2000, The Gramm - Leach Bliley
Act (1999) allowed financial regulators to adopt management based regulation to compel
financial sector companies to adopt “administrative, technical, and physical safeguards for the
protection of customer records and information” by reducing the frequency and severity of
breaches. (Taft et al., 2019, p. 2). From 2003 – 2005, financial regulators implemented
Safeguards regulations to protect the confidentiality and limit the availability of consumer
personal information to unauthorized parties by requiring financial companies to employ
administrative, technical, and physical safeguards. These rules become the foundational
financial sector cybersecurity regulations to diminish breach frequency and severity.
Although cybersecurity public policy scholars have investigated the impact of regulation on
government sector breach reduction (Curti et. al, 2023) and private company proclivity to invest
in cybersecurity (Lam and Seifert, 2023) as a result of breach notification regulations, little
empirical study exists that tests the relationship of Safeguards rules on reducing actual breach
frequency and severity for private companies in the financial sector.
The purpose of this study is to quantitatively test behavioral public policy theory in the
cybersecurity policy domain by assessing if Safeguards rules have served as an effective tool for
3
achieving cybersecurity policy outcomes in the financial sector – reduction of breach severity
and frequency through implementation of administrative, technical, and physical safeguards.
For policy practitioners, the study sheds light on the effectiveness of policy instrumentation that
heavily focuses on regulation as a tool for facilitating private sector cybersecurity. The United
States government’s use of federal cybersecurity regulation is primed for growth. Empirical
study illuminating the effectiveness of cybersecurity regulation in the financial sector can help
shape the impending regulatory evolution for other industry sectors that are not currently subject
to cybersecurity regulation. When discussing the state of behavioral public policy theory,
Michael Howlett and Simon Fraser (2018) contend that much more empirical study in this area is
needed to validate the linkages between policy tools and behavioral attributes. For public policy
theorists, this work helps validate linkages between behavioral attributes and authority regulatory
tools.
Research Question and Hypothesis
The current behavioral public policy research offers that a regulation tool heavy cybersecurity
policy instrumentation should be effective in reducing breach severity and frequency in financial
sector companies. This work poses the question - have safeguards regulatory rules reduced data
breach frequency and severity on private sector US financial institutions from 2005 - 2020?
This study hypothesizes that these regulations have significantly helped reduce successful breach
severity and frequency during this time period. The study’s indictor variable is the presence of
Safeguards regulations. The study’s outcome variables are successful breach severity and
frequency which are measured with a mixture of numerical and dichotomous categorical
variables. Breach frequency is measured as the percentage of the total number of breaches that
4
occur on financial sector companies each year. A successful breach is characterized as a cyber
enabled intrusion into a company’s network enabling expose of consumer records. Breach
severity is measured as the number of consumer records exposed during the breach and the
sensitivity of the information exposed.
The Dissertation Structure
The remainder of this chapter provides necessary background context by outlining the
financial sector regulatory environment and the evolution of financial sector cybersecurity
regulation. Chapter two provides a literature review. This literature review chapter critically
examines theoretical and empirical works focusing on policy instrumentation, behavioral public
policy, and existing works at the nexus of regulation and private sector cybersecurity. The
primary goals of this chapter are to discuss what has been done in these areas of focus, to center
the current research in the existing literature, and to develop a theoretical framework to link
theory and analysis. Chapter III delves into the proposed research method. The chapter begins
with a discussion of the work’s philosophical approach. It subsequently enumerates the study’s
key variables, data collection procedures, and data analysis technique. In this part of the chapter,
variable operational measurement and statistical analysis procedures are explained. The chapter
concludes with a discussion of measurement reliability and study validity. Chapter IV revisits
the research question and hypothesis, reports the results of analysis, and provides commentary on
the result’s statistical and practical significance. Finally, Chapter V, discusses analysis results
and provides implications for both behavioral public policy theory and practice in the
cybersecurity policy domain.
5
The Financial Sector Cybersecurity Regulatory Landscape
Because the research focuses on US financial sector cybersecurity regulations, prior to
delving into the literature review of theoretical and empirical works, it is helpful to provide
background context for the US financial sector cybersecurity regulatory environment. The US
financial sector does not have a single regulator. Its regulatory environment has been shaped by
“responses to various financial crises” and is composed of “multiple overlapping regulators”
(Congressional Research Office, 2020, p. Summary). The table below provides a crosswalk of
financial regulators to their covered entities. The regulator column is the regulatory agency. The
broad area of regulation illustrates the major category of regulatory grouping for the regulator,
and the covered entity column depicts the type of financial business that falls under the purview
of the associated regulator.
6
Regulator Broad Area of Regulation Covered Entities for Standards
Federal Trade Commission Corporate & Depository
All finanical enties not covered by other regulators
Office of Comptroller of the Currency Depository National Banks
Federal Deposit Insurance Corporation Depository
State Banks that are not members of the Federal Reserve
System
National Credit Administration Depository Federally Chartered Credit Unions
Securities & Exchange Commission Securities Markets
Broker - Dealers, Clearing & Settlement Agencies,
Investment Funds, Invetsment Advisors, Investment
Compnies
Commodity Futures Trading Commission Securities Markets
Futures Commission Merchants, Commodity Trading
Advisors, Derivative Clearing Houses,
Federal Housing Finance Agency Government Sponsored Enterprise
Fannie Mae, Fredie Mac, Federal Home Loan Banks
Farm Credit Administration Government Sponsored Enterprise
Farmer Mac
Consumer Financial Protection Bureau Consumer Protection
Nonbank mortgage firms, private student lenders
Table 1: The Federal Financial Regulators
7
The Laws, the Rules, and the Guidances
A prerequisite to any federal regulatory discussion is a delineation of regulatory laws, rules,
and guidances. There are significant differences between federal laws, rules, and guidance.
Laws are pieces of legislation that are passed by both houses of Congress and signed by the
President. Regulations (also referred to as rules) are a set of requirements issued by a federal
government agency to implement laws passed by Congress. Regulations are published through a
rule – making process that is made available for public comment through the Federal Register.
Once a final rule is issued, it has the force of law because it is implementing a law. Safeguards
regulations fall in this category. Guidance is supplemental information published by an agency
that helps clarify existing rules and agency expectations. Guidances are not subject to rule-
making procedures and as a result are not legally binding.
The Gramm – Leach – Bliley Act provides the launch point for all discussions about
cybersecurity regulation in the US financial sector. It was passed in 1999 with the intent of
modernizing the regulation of financial services. Specifically, sections 501, 504, and 505
addresses the safeguarding of consumer information confidentiality through prevention of
unauthorized access and unauthorized use of consumer personal information.
Gramm – Leach – Bliley (1999) asserts that financial institutions must “protect the security
and confidentiality of its customers’ nonpublic personal information” (p. 15 USC 6801) and that
regulatory agencies must establish standards for financial institutions relating to “administrative,
technical, and physical safeguards” to protect confidentiality, integrity, and unauthorized access
of personal information (p. 15 USC 6801). From 2003 – 2005, the various financial regulators
imposed Safeguards rules on their financial sector regulated entities.
8
Safeguards Rules
The Safeguards regulations are a goals – based regulatory regime enacted from 2003 – 2005
by financial regulators initiating implementation of GLBA stipulations. Goals - based
regulations establish regulatory aims, but do not specify the exact means to achieve these aims;
whereas, rules – based regimes establish specific standards, protocols, and tool (Decker, 2018).
Safeguards regulations established a regulatory environment that compelled financial sector
companies to aim for the outcome of “protection of customer records and information” by
“adopt[ing] written policies and procedures that address administrative, technical, and physical
safeguards (Taft et al., 2019, p. 2). These regulatory aims become known as the Safeguards
regulations. While the regulations proscribed development of policies and procedures, they
allowed financial firms’ flexibility by not specifying what should be included in the policies and
what should be the procedures. The name Safeguards regulations adopted a plural context
because multiple financial regulators implemented GLBA stipulations. However, the financial
regulators ubiquitously directed that company’s policies and procedures address administrative,
technical, and physical safeguards for the protection of customer records and information by: (1)
Ensuring security, confidentiality, and integrity of customer records and defend against (2)
Mitigating unauthorized access to records and information that could result in “substantial harm
or inconvenience to any customer” (Taft et al., 2019, p. 2). Although at the time of adoption, the
primary focus of these Safeguards rules were administrative and physical protections from loss,
the growing maturity of the digital ecosystem in the 2000s ushered in an increased focus on the
technical aspect of the regulation – what we now refer to as cybersecurity.
9
Intensifying Covered Entity Regulation Enforcement
Financial regulators issued Safeguards rules in the early 2000s, but enforcement actions
remained sparse for the better part of the next decade. From 2000 - 2010, the SEC infrequently
brought cybersecurity focused enforcement actions. Although in the early 2000s financial
regulators remained a bit shy in wading in the cybersecurity enforcement waters, toward the
2014 - 2015 time frame, financial regulators intensified emphasis on cybersecurity regulation
audit and enforcement. This period marks a dramatic elevation in SEC, FTC, and CFTC
cybersecurity focus. In April 2014, the SEC heralded its first cybersecurity sweep examination
initiative. The sweep consisted of a canvas of registered investment advisor (RIA) and broker -
dealers which consisted of examination of written cybersecurity policies and procedures. The
sweep was not a formal audit and results were not linked to specific institutions. Instead, the goal
was to gain a better understanding of how covered entities "address legal, regulatory, and
compliance issues associated with cybersecurity" (Taft et al., 2019, p. 6). This sweep ultimately
folded into a risk alert that provided areas that cybersecurity oversight can be enhanced, as well
as offering six key take - aways that entities could contemplate when executing Safeguards
requirements.
Financial regulators were becoming much more aggressive in enforcing Safeguards rule
requirements. From 2015 - 2018, the SEC brought forth three enforcement actions against R.T.
Jones Capital Equities, Craig Scott Capital, and Morgan Stanley. The Morgan Stanley action is
particularly noteworthy. In this action the SEC stated that "despite having written policies and
procedures, Morgan Stanley had breached the Safeguards rule. The safeguards were not
reasonably designed to protect customers" (Pierotti, 2018, p. 413). With this action, the SEC sent
a message to the financial sector that both the quality of cybersecurity planning and the
10
execution of the planning were under regulatory scrutiny. Doubling down on the message that
the SEC conveyed in the Morgan Stanley case, in 2020, the SEC announced enforcement action
against eight firms that included Cetera Advisor Networks LLC, Cetera Investment Services
LLC, Cetera Financial Specialists LLC, Cetera Advisors LLC, and Cetera Investment Advisers
LLC (collectively, the Cetera Entities); Cambridge Investment Research Inc. and Cambridge
Investment Research Advisors Inc. (collectively, Cambridge); and KMS Financial Services Inc.
(KMS). In its press release, the SEC proclaimed that "It is not enough to write a policy requiring
enhanced security measures if those requirements are not implemented or are only partially
implemented, especially in the face of known attacks" (Securities and Exchange Commission,
2020, 5th paragraph).
It is important to note that the SEC has issued additional cybersecurity related guidance to all
publically traded companies that became a formal rule in 2023. In 2010, the SEC issued CF
Disclosure guidance which informed all publically traded companies they should report material
breaches in the same vein as traditional investor risk. In 2023, the SEC codified this guidance as
a formal regulation. However, unlike the Safeguards rules which apply to financial sector
covered companies, CF Disclosure rules do not mandate implementation of cybersecurity
administrative, technical and physical controls.
11
CHAPTER II: LITERATURE REVIEW
Literature review is an essential component of the research process. It enables research
question context, development of theoretical underpinnings, mitigation of duplicative research,
and identification of gaps in the existing body of work (Creswell & Creswell, 2018). This
chapter provides theoretical context to guide the research and a review of existing empirical
work at the nexus of financial sector regulation and cybersecurity.
The Literature Review Protocol
The literature review’s protocol is based on the PRISMA 2022 protocol. (PRISMA, 2023).
PRISMA is methodology for executing systematic reviews and meta-analyses. PRISMA
provides a procedure to guide identification of relevant studies, screening of these studies to
assess acceptability, and inclusion of acceptable studies. The protocol provides 27 checklist
items to help create a taxonomy for examined literature. A critical component of the PRISMA
identification step is establishing literature inclusion and exclusion criteria. Originally proposed
by Harold Lasswell and later modified by Michael Howlett (Howlett, et. al, 2020), the policy
lifecycle provides a useful framework for scoping literature review inclusion and exclusion
criteria. The framework, depicted in figure 1 below, provides a sequence of events that
characterize policy genesis through policy implementation through policy evaluation.
12
This research focuses on the policy formation and policy evaluation phases of the lifecycle.
Harkening back to the introduction chapter, the purpose of this study is to quantitatively test
behavioral public policy theory in the cybersecurity policy domain by assessing if Safeguards
regulations have served as an effective tool for achieving cybersecurity policy outcomes in the
financial sector – reduction of breach frequency and severity through implementation of
administrative, technical, and physical safeguards. To that end, the literature review’s inclusion
criteria are behavioral public policy theoretical works and existing empirical studies delving into
policy instrumentation during policy formulation and impact evaluation of the cybersecurity
regulatory tools in the financial sector. Agenda setting, policy decision making, and policy
Figure 1: The Policy Lifecycle
13
implementation phases are all necessary for describing a policy lifecycle in totality, but these
phases are out of scope for this work. As a result, literature gravitating around these phases are
excluded. The primary outcomes of this literature review are twofold. One, establish a
behavioral public policy theoretical foundation for the proposed causal relationship between the
financial sector Safeguards cybersecurity regulations on the frequency and severity of breaches
in financial sector private companies. Two, engage the existing empirical literature that focuses
on financial sector regulation cybersecurity. This is necessary to both understand the state of the
field and to validate that the proposed research question fills a gap in the scholarly work. The
most heavily relied upon databases include EBSCOhost, Web of Science, and Google Scholar.
Policy Formation Tools
In the policy lifecycle, the formation phase accounts for the activities to craft policy options.
The substance of this phase is policy tool selection, otherwise known as policy instrumentation
(Howlett, et. al, 2020). When instrumenting, policy makers select the tools that are most capable
of facilitating desired policy outcomes. Financial sector regulators instrumented cybersecurity
policy with a heavy emphasis on authority tools – Safeguards regulations. The remainder of this
section outlines the array of tools at policy makers’ disposal and explores why behavioral public
policy theory suggests that financial sector regulators policy instrumentation approach should
facilitate their cybersecurity policy goals.
14
The Policy Tools
A necessary starting point is Christopher Hood’s tools of government. Hood is one of the
most influential policy scientists in the last 50 years. His tools of government theory was
originally introduced in the book The Tools of Government (Hood, 1983). Hood and Margetts
(2007) later revisited his theory in authoring The Tools of Government in the Digital Age. In
this publication, they discuss the original theory in context of a modern digital world and
conclude that the theory is still applicable to the modern public policy environment. The theory
provides a taxonomy of policy tools that government can tap into during instrumentation. Over
the last 50 years, this taxonomy has become the driving scaffolding for visualizing policy tools.
As a result, a deep – dive into the tools of government theory is necessary.
Hood and Margetts (2007) assert the same tools allow the government to execute two
functions – detect or take in information from the public, and effect or conduct actions to impact
its citizenry. The four tools used to both detect and effect are nodality which is implemented with
informational resources, authority which is implemented with legislative or regulatory resources,
treasure which is implemented with financial resources, and organization which is implemented
with human capacity resources. They use the acronym NATO when referring to these tools.
Nodality
The primary resource that government leverages when employing the nodality tool is
information. When government is detecting with nodality, government attempts to absorb
information through informational channels to help shape policy administration. Put another
way, the government uses information platforms to absorb information that informs policy.
When effecting, government attempts to shape the policy environment through proactive use of
15
information to shape citizens’ behaviors. Nodality effect tools are designed to "shape individuals
behavior" (Hood & Margetts, 2007, p. 28). These tools attempt to provide information or
suppress information.
Authority
Authority is the government’s “ability to command and prohibit, commend and permit”
through official procedures (Hood & Margetts, 2007, p. 50). Use of this tool has long standing by
US regulators and legislators and demonstrated success in achieving desired policy ends. A well
discussed example of a successful implementation of the authority tool to shape the policy
environment is the Federal Motor Vehicle Safety Standard 208 that required automakers to
include seatbelts in automobiles and subsequent state level laws mandating use of seatbelts
(Shapiro, 1991).
The tools of government theory notes that seminal to authoritarian capacity is the
government's token of authority (Hood & Margetts, 2007, p. 50) Tokens of authority may be
thought of as the structural and legal basis of power for executing the authority tool. When
detecting through authority, government uses its token of authority to obtain information from
the public with "the threat of sanction for non - compliance" procedures (Hood & Margetts,
2007, p. 51). When discussing the effect function and the authoritarian tool, the foundation
remains the token of authority. Through power associated with the token, government shapes
public behavior by making demands or creating prohibitions. Hood discusses a spectrum
government assertiveness when making demands or creating prohibitions. A lower level of
assertiveness occurs with use of "conditional tokens" or a "promised threat that government
[will] do x if y happens” (Hood & Margetts, 2007, p. 59). A higher level of authoritarian
16
assertiveness is exemplified by financial sector cybersecurity regulation with the actual demand
of actions. Describing the authoritarian tool, Hood introduces the term “constraints” (Hood &
Margetts, 2007, p. 62). The term constraint usually implies prohibition of an activity, but Hood
discusses both positive and negative constraints. Positive constraints are when government
requires and action. Negative constraints are when government prohibits an action. Financial
sector cybersecurity regulations (and presumably expanded regulation that will impact other
sectors) are effect based positive constraints because they direct a specific action through their
regulatory token of authority to shape the behavior of a specific population.
Treasure
As the name implies, the primary resource of the treasure tool is financial and the
government’s ability to distribute funds. But Hood characterizes the treasure tool by stating that
there are "positive incentives or inducements government can use to secure information or
change behavior" (Hood & Margetts, 2007, p. 78). He also extends the aperture of the treasure
tool past financial incentives to "more subtle applications" such as establishment of
organizational connections (Hood & Margetts, 2007, p. 78). In fulfilling detection functions,
government may use rewards or government purchases for information. When using treasure to
effect public behavior, government can execute a quid pro quo for a specific population or it can
execute without requiring an affirmative exchange. Some examples of quid pro quo are
government tax breaks or loans for specific endeavors, grants, loans, and tax breaks. A common
form of non quid pro quo use of treasure to effect policy outcomes is through public money
transfers. It is not uncommon for government to try and bind policy outcomes to public money
17
transfer mechanisms such as pensions or welfare programs to shape opinions or actions (Hood &
Margetts, 2007).
Organization
Organization is the last tool Hood discusses in his tools of government theory. When
employing the organization tool, the government acts with its organic capability. Hood &
Margetts (2007) characterize organization “as stock of land, buildings, and equipment, and a
collection of individuals” (p. 102). Like the other tools, organization serves both detecting and
effecting purposes. Equipment such as integrated camera surveillance systems or personal such
as TSA agents greeting in country arrivals are examples of organizational detection. In the
modern digital age, technologies such as AI enabled facial recognition are changing
organizational detection capabilities like never before.
When effecting policy with the organizational level, government uses its organic capacities to
effect desired policy outcomes. Perhaps the most notable of the US government’s use of
organization for cybersecurity is the creation of the Cybersecurity and Infrastructure Security
Agency (CISA). Over the past five years, CISA has grown into one of the most influential
federal agencies. With a project 2024 budget of $3.1 billion, it sways considerable influence
shaping both government and US private sector cybersecurity endeavors.
18
Behavioral Public Policy Based Tool Selection
With the publication of Hood’s taxonomy, the table was well set for a ubiquitous visualization
of the most prominent policy instruments. However, how policy makers should conduct
instrumentation was not obvious. Although, in broad strokes, Hood alluded to some use cases for
specific instruments, his position was largely that the instrumentation process “cannot be
systemically appraised” (Howlett, 1991, p. 10) and that instrumentation is largely an iterative
learning process based on “past presents and experiences” (Howlett, 1991, p. 11).
Nevertheless, policy scientist continued to seek systematic approaches to explain and guide
policy instrumentation. Throughout the early part of the 21st century, efforts to determine how to
select policy tools largely focused on direct resource based instrumentation. In this era,
instrumentation was often mechanical and an exercise of aligning the perceived right instruments
for the job. Van Duen et., al (2018) note that during this era, policy makers assumed a rationality
of thought by policy targets and that policy targets would make decisions that “maximize
welfare” (p. 3). However, toward the second decade of the 21st century, policy instrumentation
studies began to perceive that policy targets may not be rational actors; that policy targets were
“subject to systemic bias” and used “cognitive shortcuts or rules of thumb” when reacting to
policy instruments (Van Duen et al., 2018, p. 3). This paradigm led to an integration of concepts
from the behavioral decision making discipline and behavioral economics; this new policy
approach became known as behavioral public policy (Starassheim, 2019). At the highest level of
abstraction, behavior decision making science is the study of human cognitive processes used to
choose alternatives. Behavioral public policy moved beyond exclusively considering the
feasibility and acceptability of policy instruments, but included considerations of how certain
instruments might cognitively shape the policy targets decision.
19
Nudging, made famous by Richard Thaler and Cass Sunstein, was one of the first attempts to
operationalize behavioral public policy. Nudging attempts to “change the choice architecture of
citizens, i.e, the informational or physical structure of the [policy] environment” (Van Deun, et.,
al, 2018, p. 6) and “change individual behavior with coercion (Martin & Mikolajczak, 2023, p.
363). Nudging frequently aligns with use of Hood’s nodal and organizational instruments.
There are two critical premises behind nudging: (1) Policy targets’ desires are aligned with the
policy ends and (2) The government uses policy instruments to set the conditions to make it
easier for policy targets to make decisions that are aligned with policy ends (Lawlor & Hopkins,
2022). Over the last decade, nudging has emerged as an important field of study and policy
instrument with great potential. But, debate exists as to the degree to which nudging can
facilitate significant policy target behavioral shifts. A common view is that nudging is
particularly effective in helping policy targets make choices that they may otherwise make, but
less effective in pushing policy targets to adopt behaviors that they are not otherwise inclined
(Van Deun, et. al, 2018).
As the policy science discipline progressively integrated more thoughts from behavioral
scientists, a view that an understanding of why policy targets may respond to one instrument or
set of instruments versus another was severely lacking. To address this, policy scholars began to
aggressively revisit the likes of Schneider and Ingram. An early vanguard in forging connections
between policy instrumentation and behavioral science, Anne Schneider and Helen Ingram
(1990) argued that "existing concepts had not been helpful in understanding choices among
policy instruments" (p. 511). While they didn't disagree with resource - based taxonomies, they
argued that these approaches were limited because they did not account for behavioral
characteristics that would shape policy target adoption. To that end, Schneider and Ingram
20
(1990) introduced a framework to "capture the behavioral attributes of policy content" (p. 511).
The policy instruments included in their framework were: authority tools, incentive tools,
capacity tools, symbolic / hortatory tools, and learning tools. Interesting to the current cyber
policy domain, they offered that authority tools could be helpful when incentives are lacking and
that policy targets are indoctrinated in a culture of regulation adherence. When bemoaning the
lack of effectiveness of PPPs and information distribution in facilitating private sector critical
infrastructure cybersecurity, Madeline Carr (2018) referred to the challenge of lack of incentives.
In these areas, Carr's insights align with some existing behavioral policy based study that
indicates that informational and nodality based policy designs can be helpful when the target
shares a utilitarian view of the policy outcome, but less effective when policy targets do not
perceive utilitarian value to the policy.
Much of the current state of policy science and instrumentation research assumes that "policy
tool use and behavioral expectations" (Howlett & Fraser, 2018, p. 101) are connected and
continues to move past nudging to focus on more pronounced target shaping through behavior
based "calibration of policy tools" (Howlett & Fraser, 2018, p. 101). Hood's resource-based
taxonomy continues to provide a widely used scaffolding for understanding and discussing
various policy instruments, but policy scholars are integrating behavior concepts as discussed by
Schneider and Ingram in instrumentation design. Howlett and Fraser (2018) discuss the concept
of the supply and demand side of policy tools. Tool instruments such as Hood's NATO constitute
the supply side whereas, the policy target constitutes the demand side. The behavioral bridge
between the supply and demand sides is that the effectiveness of instrumentation and instrument
selection is "linked not just to resource availability", but to an ability of policy instrumentation to
shape behavioral "receptors on the part of policy targets which make them respond in predictable
21
ways" (Howlett & Fraser, 2018, p. 110). Howlett further enumerated policy target behavioral
perquisites for consideration for each of Hood's policy instruments. Table 2 below (Howlett &
Fraser, 2018, p. 111).
Table 2: Behavioral Attributes For Policy Tools
Tool Type
Government Resource
Applied
Policy Target Behavioral /
Cultural Attributes
Nodality
Information
Credibility & Trust –
Willingness to believe and act
upon information provided by
the government
Authority
Coercive Power / Force
Legitimacy – Willingness to
be manipulated by the
government through invoked
penalties and proscriptions
Treasure
Financial
Cupidity – Willingness to be
manipulated by the
government through financial
gains and losses
Organization
Human Capacity
/Organizational Capacity
Competency – Willingness to
receive goods and services
from the government and enter
into partnership agreements
22
Connected to these concepts, scholars in the economics and legal disciplines have devoted
time to specific focus on the authority tools and the types of regulation that is most conducive to
target population compliance. Because this research focuses on the authority tool in the form of
regulation, it is helpful to introduce a distinction between command and control direct regulation
and incentive based regulation. When employing direct regulation, government creates policy
requirements and frequently relies on penalties for regulatory compliance; when relying on
incentive based regulation, government seeks to create opportunities to entice compliance
through things such as reduced costs (Malloy, 2002). Both of these approaches leverage what
Hood & Margetts (2007) referred to as the government tokens of authority, but they differ in the
way the regulation seeks to gain compliance. There is not a consensus regarding which
regulatory approach is more effective. The scholarly regulatory landscape is flooded with studies
arguing the benefits for either approach. However, there are two insights that seem to surface.
One, direct regulation can compel compliance faster than incentive based regulation (Harrington,
& Morgenstern, 2007). Two, direct regulation can be encumbered with an undesirable byproduct
– policy targets will seek the least expensive way to meet regulatory compliance (Malloy, 2002).
In order to mitigate this byproduct, it may be better crafted as management – based regulation or
performance – based regulation versus directive requirement regulations. In the next section of
this literature review, this distinction is highlighted in a work by David Thaw (2014).
It is important to remember that although behavior based policy instrumentation offers great
promise, it is not a policy science panacea. Governance is full of failed policies because of an
inability of policy makers to account for key obstacles to behavior based policy design. Holger
Strassheim (2019) argue that prominent obstacles that we should note are that: One, behavioral
based policy design is often ill - shaped because policy makers misinterpret or misapply target
23
feedback. The misinterpretation can pollute the policy instrumentation learning environment and
result in a failed contamination; Two, behavioral based policy design approaches can be very
culturally contextual. As discussed by Howlett and Fraser (2018), there may be specific set of
target behavioral prerequisites that enable the effectiveness of instrumentation. A lack of
consideration for the cultural differences between one target group and another can instrument
success for one group and failure for another.
Existing Financial Sector Cybersecurity Literature
Activities that occur during the policy evaluation phase of the policy lifecycle seek to assess
the degree to which the formulated policy achieves desired outcomes (Howlett, et. al, 2020).
The previous section focused on the policy formation phase. It outlined the various tools at
policy maker’s disposal and explored why behavioral public policy theory suggest that a
regulation heavy instrumentation should facilitate cybersecurity policy outcomes in the financial
sector. This section canvases existing financial sector regulation focused cybersecurity empirical
works to gauge what the literature says about the effectiveness of regulation in the financial
sector as a policy tool. Reviewing this body of literature will illuminate the current state of
research and validate the usefulness of the current study.
There is a healthy body of published literature discussing the impacts of regulation on
cybersecurity. The bulk of existing study focuses on one of the following subject areas: (1)
Evaluating the most effective form of regulation – directive versus management based, (2) The
efficacy and impact of breach notification regulation, (3) The impact of regulation incentivizing
private company cybersecurity investment. Addressing the most effective form of regulation,
David Thaw (2014) executed a mixed methods project that assessed the “efficacy” of
24
cybersecurity regulation comparing the impact of directive regulations akin to state breach
reporting laws vs federal management – based regulations (p. 294). He characterizes directive
regulations as “laying out express performance standards and / or means of achieving
performance” (Thaw, 2014, p. 310) whereas he characterizes management – based regulations as
“modes of regulation under which administrative agencies, through legislatives mandated
collaboration with regulatory stakeholders, promulgate regulations requiring regulated entities to
develop plans designed to achieve certain aspirational goals” (Thaw, 2014, p. 324). His period
of study is from 2000 – 2010. His key findings were that regulatory tools can be effective in
diminishing cybersecurity risk and that: (1) The combination of both regulatory models are
superior to either exclusively and (2) If having to choose between the two regulatory models, the
Federal regulatory management – based models offer better efficacy at preventing breaches, but
may also incur a sunk cost of incentivizing covered organizations to “race to the bottom” and
settle with compliance minimums (Thaw, 2014, p. 371). Of note, financial sector Safeguards
regulations are a management – based model.
Another interesting perspective along this topic area is a study by Massacci et al. (2016).
Their work does not seek to evaluate the effectiveness of regulation vs other policy tools but
provides interesting insights as to which regulatory models may be more effective. Rules - based
regulation applies mandated security provisions and is the dominant form for the US bulk energy
sector. Risk - based regulation applies mandates for regulatory outcomes. For example, rules -
based regulation may dictate specific cybersecurity controls, whereas risk - based regulation may
dictate thresholds of impact to the electric grid. Leveraging the Institutional Analysis and
Development (IAD) framework, Massacci et al. found that: (1) The effectiveness of rules - based
regulation is predicated upon the regulators knowledge of the security architectures, (2) A clear
25
understanding of the regulator's desired outcome from regulation is essential, and (3) Culture
matters and that the appropriate regulatory approach may hinge on the cultural dynamics of the
regulated ecosystem (Massacci et al., 2016).
Loren Selznick and Carolyn LaMacchia (2016) investigate if SEC cybersecurity actions are
leading to desired outcomes. However, their focus is SEC CF disclosure guidance and not
financial sector Safeguard rules. They ultimately assert that SEC disclosure guidance has done
little to impact the likelihood of cybersecurity breaches and efforts to incentivize breach
deterrence through investor awareness have failed because most company disclosures are little
more than “boilerplate language that fails to provide meaningful information” (Selznick &
LaMacchia, 2016, p. 52). Substantiating this claim, they refer to several examples of company
breaches and disclosures. One of these examples is Yahoo Inc. In both 2012 and 2014, Yahoo
experienced separate material cybersecurity breaches. In neither disclosure did Yahoo illuminate
pertinent information for investors and the 10-K reports from 2012, 2013, and 2014 “contain
almost identical language” (Selznick & LaMacchia, 2016, p. 53). While informative, this study
contributes little to this study’s research question. CF Disclosure guidance is expressly focused
on reporting breaches as part of traditional investor risk notifications. Unlike Safeguards Rule
that are applicable to financial sector companies, CF Disclosure guidance does not institute
cybersecurity control activities. Their findings align with conclusions by Michael Ferraro (2013)
who contends that CF Disclosure guidance “substantially underachieves” (p. 297).
As opposed to measuring reductions in breach frequency and severity, Lam and Seifert (2023)
use financial investment as a proxy for cybersecurity regulation effectiveness. Lam and Seifert
(2023) highlight "important market failures" because companies under-invest in cybersecurity (p.
146). They offer that a contributing factor to this dynamic is that the private sector overly
26
focuses on damage control versus cybersecurity risk prevention and that regulation is needed to
account for this market failure. The sentiment that companies under invest in cybersecurity is
echoed by Gordon et al. (2015). Leveraging economic production theory, these researchers
evaluated the impact of federal regulation on private sector companies' cybersecurity investment.
However with a couple of exceptions, rarely does analysis attempt to assess the effectiveness
of diminishing actual breach frequency and severity in the financial sector using Safeguards rules
as an indicator variable. Additionally, most of these studies tend to disregard theoretical
bridging to the current state of policy instrumentation theory. In these works, often there is little
reference to policy science hallmarks such as Hood’s tools of government or Howlett’s work in
behavioral public policy. This leaves much of the current body of financial sector cybersecurity
study without public policy theoretical grounding. One of these exceptions is by Curti et al.
(2023) who investigated the impact of state and local government cybersecurity regulations at
the public sector municipality level. Their study provided empirical evidence that state and local
cybersecurity regulations had little impact on strengthening cybersecurity for local and state level
governmental organizations.
The current literature does substantiate that cybersecurity breach is a problem with significant
financial sector impacts. Freed and Hackney (2022) found that data breaches significantly
impact the financial sector as they lead to a lack of confidence in essential and underpinning
technological architectures. Goglin et al. (2020) highlight that cyberattacks reduce deposit
growth at affected bank branches and have considerable financial impact because of diminished
customer trust. Discussing the potential for cyberattack instigating financial systemic failure,
Atkins and Lawson (2020) state that “the world’s financial system could collapse” if “growing
fears of cyber-security hack are released” (p. 1).
27
Centering This Research
Cybersecurity in the private sector is a now a prominent US policy domain. US policy makers
are increasingly drifting to a more regulatory heavy tool approach. However, behavioral public
policy theory asserts that to achieve desired objectives, policy tool section and policy target
“behavioural expectations” must be linked (Howlett & Fraser, 2018, 101). The US financial
sector has both a long history of using regulation as a tool to facilitate cybersecurity and the
behavioral attributes that should make cybersecurity regulation effective. However, this review
reveals that there is little behavioral public policy theory based study evaluating the effectiveness
of the financial sector’s cybersecurity Safeguards regulations on diminishing actual financial
sector company breach frequency and severity. These insights validate that this study fills
existing theoretical and policy practitioner gaps. This study addresses the need that Howlett and
Fraser (2018) articulated and forwards the current body of empirical behavior public policy
research into a new policy domain – national cybersecurity.
Additionally, this study provides valuable insights for the national cybersecurity policy
practitioner community. The federal government is now embracing an authority tool regulation
heavy approach to national cyber policy instrumentation. However, it seems that this pivot has
not been grounded in consequential consideration of the behavioral attributes of policy targets.
The US financial sector has a rich history of using regulation as a cybersecurity policy tool. It
also has many of the behavioral attributes that theoretically contribute to authority tool based
policy success. First, regulation in the financial sector has great legitimacy. A number of
behavioral policy works note that regulatory tools are challenged in policy domains that lacking
a cultured deference to government regulatory activities (Jing & Graham, 2008). Financial
companies have a long – established culture of willingness to respond to “government invoked
28
penalties and proscriptions” (Howlett & Fraser, 2018, p. 111). Second, financial sector
regulators have often “interacted with regulates” (p. 5169) in the development of regulation;
Barak – Corren and Kariv – Teitelbaum (2020) contend that this is a critical behavioral attribute
to effective use of authority tools. Atkins and Lawson (2020) offer that financial regulators have
worked together closely with covered entities to draft consistent harmonized regulation. In the
Journal of Internet Banking, Derek Mohammed (2015) notes that the Financial Sector
Coordinating Council “fully supported cybersecurity regulation” (p. 3). Three, financial sector
regulations are management – based and direct. This combination should both provide
unequivocal regulatory direction for cybersecurity requirements that diminish successful breach
frequency and severity, while providing compliance flexibility and adaptability to changing
environmental conditions. The financial sector provides an idyllic testbed for both validating
theoretical behavioral policy contentions and gaining insights about the effectiveness of a
regulation heavy policy instrumentation for national cybersecurity policy. These insights can
provide an indicator of whether greater reliance on regulation will stem successful breach
frequency and severity in other US private industry sectors. A primary output for the literature
review is the development of theoretical framework that links theory with the concepts
associated with the research question. This chapter wove together this tapestry and crafted a
theoretical base for subsequent analysis. Figure 2 below provides a visualization of this
framework.
29
The primary goals of this literature review were to critically illuminate what has been done
in the field, place the current research in the broader scholarly literature, develop a theoretical
framework, and demonstrate how the current research forwards the current body of theoretical
and practitioner works. The next chapter articulates the research method. Topics included in
Chapter III are philosophical leanings, research design, data collection, and data analysis.
Figure 2: Theoretical Framework
30
CHAPTER III: RESEARCH METHOD
Chapter II provided a review of the current state of behavioral public policy theory and
discussed existing scholarly works that address the impacts of financial sector cybersecurity
regulation. Two key insights gleaned from that review are: (1) Behavioral public policy theory
suggests that Safeguards regulations should serve as an effective tool for achieving cybersecurity
policy outcomes in the financial sector – reduction of breach frequency and severity through
implementation of administrative, technical, and physical safeguards; and (2) The bulk of
existing work focuses on the ability of regulation to stimulate private sector breach reporting and
cybersecurity investment. These studies use CF Disclosure guidance or state breach reporting
laws as indicator variables, but little analysis exists that tests the effectiveness of diminishing
actual breach frequency and severity using existing Safeguards rule regulations as indicator
variables.
This study quantitatively tests behavioral public policy theory in the cybersecurity policy
domain by assessing if Safeguards regulations have served as an effective tool for achieving
desired cybersecurity policy outcomes in the financial sector – reduction of breach severity and
frequency. Because the financial sector maintains key behavioral traits that behavioral public
policy theory asserts are conducive to authority tool policy instrumentation, this research expects
a significant correlative relationship between Safeguards and regulations and reduction of breach
severity and frequency. We cannot validate pure deterministic relationships between indicator
and outcomes variables in nonexperimental statistical research. Without an ability to control the
experimental environment and manage administration of the intervention, validation of
statistically significant correlational relationships are more feasible. Nonexperimental research
is able to achieve high levels of correlation and examine the degree to which indicator variables
31
are “associated” with changes to outcome variables (Leedy & Ormrod, 2016, p. 148) Figure 3
below depicts this relationship.
Figure 3: Tested Relationship
Necessary for analyzing this relationship is that outcomes accurately reflect the impact of
regulation. This requires an assumption that regulations are resulting in reductions in breach
frequency and severity versus resulting in companies hiding breaches from the public light and
seeking ways to not report them. Michael Jensen & William Meckling’s (1976) theory of the
firm asserts that companies place costs and profits at the center of decision making. Their theory
could substantiate a suspicion that financial sector companies are hiding breaches from both
regulators and the public eye for fear that breach releases would harm profits. Sandra Cerola and
Joanna Dynowska’s (2019) work examining company breach reporting noted that companies can
32
be reluctant to report breaches in SEC risk disclosures. However, much empirical research
argues that companies are actually incentivized not to hide breaches from the public. Jumah and
Alasour (2020) discovered that there is not a significant negative effect of breach notification on
company value. Liune and Eli’s (2018) study discovered that withholding breach information is
associated with a “decline of approximately 3.6% in equity values in the month the attack is
discovered” (p. 1177). This insight is echoed by Gordon and Loeb (2010) who reported that
there is “strong evidence” that breach disclosure results in an increase in company market value
because public disclosure facilitates public trust and mitigates potential litigation costs (p. 568).
This is not to say that companies never engage in breach hiding; it is impossible to know if every
financial sector breach is made public, but these study’s suggests that data collected will
illustrate the correlations between cybersecurity regulations and reduction in breach frequency
and severity.
The remainder of this chapter introduces the research design and methodology by restating
the research question, outlining the research design, elaborating on key variables, and flushing
out data collection and analysis techniques.
33
Philosophical Approach
The work’s philosophical world view flows from a positivist and empirical perspective. A
positivist approach is characterized with objectivism, impartiality, and a worldview of theory
based deductive analysis. When discussing the positivist research philosophy, James Scotland
states that “the researcher and the researched are independent entities” (Scotland, 2012, p. 10).
John and J. David Creswell note that hallmarks of positivist research world views are
determination, reductionism, empirical observation, and theory verification (Creswell &
Creswell, 2018). In this condition, outcome variables can be inferred from indicator variables
and correlations between these variables can be measured quantitatively. This study fits the
positivist and empirical mold. A theoretical framework drives development of research questions
and hypothesis, and the work tests a statistical correlation between indicator and outcome
variables.
Research Question
The question is - have safeguards regulatory rules reduced data breach severity and frequency
on private sector US financial institutions from 2005 - 2020? Further explanation of breach
frequency and severity is provided in the subsequent key variable subsection. This study
hypothesizes that Safeguards rules have significantly helped reduce successful breach frequency
and severity.
34
Research Design
Research design is based upon selection of methods that provide direction and azimuth for the
research study protocol (Creswell & Creswell, 2019). Well considered design enables
researchers to effectively operationalize the theoretical framework. My theoretical framework
derives from behavioral public policy theory which contends that when there is alignment of
policy target behavioral attributes and selected policy tools, desired policy outcomes are more
likely. The financial sector maintains many of the behavioral attributes that behavioral public
policy theory asserts are conducive for use of regulatory tools to achieve desired policy
outcomes. The financial sector has a culture of deference to government regulatory activities,
and Safeguards regulations were crafted through regulator / regulate interaction. As a result,
there should be a relationship between, Safeguards regulations, which require companies to
implement cybersecurity controls to protect consumer information, and a reduction of breach
frequency and severity.
To operationalize the theoretical framework and test the relationship between Safeguards
regulations on breach frequency and severity, there is engagement with policy evaluation phase
activities. In his book Studying Public Policy: Principles and Processes, Howlett et. al (2020)
provides key concepts for policy outcome evaluation design. The first of these concepts is a
distinction between efficiency based output assessment and impact based outcome assessment.
Efficiency and outputs are tied to products, whereas, impacts and outcomes are tied to changes in
the environment. This study focuses on desired regulatory outcomes – protection of consumer
information through reduction of frequency and severity of breach in financial sector companies.
As a result, selected outcome variables should measure frequency and severity of breach. The
second concept regards selection of the type of experiment. Howlett et al (2020) note that an
35
advantage of quasi – experiments is that “they occur in the real world which makes the findings
more robust and generalizable” (p. 261). I adopt this form of experiment, but instead of using
the term quasi – experiment, I use the term nonexperimental. The key hallmarks of
nonexperimental research are a lack of manipulation of the independent or indicator variable, and
a lack of participant random assignment. Nonexperimental design is appropriate when the
researcher’s hypothesis includes a “relationship between two variables” and it is not “feasible
[or] ethical to manipulate the independent variable” (University of Minnesota Libraries, no date,
1st and 2nd paragraph). Such is the case in this study. It is not feasible to manipulate the indicator
variables. US financial sector cybersecurity regulations are introduced by US government
financial regulators and are subject to rules making processes codified in law. A final key
concept is that the research design should assess a counterfactual (Howlett et. al, 2020). The
research should draw a comparison between what would happen if the indicator did not exist.
Financial sector regulators established Safeguards and regulations which require implementation
of cybersecurity controls. Companies in other sectors are not subject to this type of regulation.
Unit of Analysis & Key Variables
In the most basic terms, a study’s unit of analysis is the entity that the analysis is focused and
the main parameter of investigation (Columbia University Libraries, no date). Tying this
concept to the theoretical framework, this work’s unit of analysis is successful breaches on
private sector companies from 2005 – 2020 and delineation if the victim was a member of the
financial sector. STATA SE 18 allows time effect included difference in difference analysis of
pooled cross section data of individual breach events to assess the impact of the financial sector’s
Safeguards regulations as a treatment to breach severity and frequency.
36
Indicator Variables
In positivist studies, indictor variables are derived from theoretical suppositions and provide a
predictor of outcome variables. In this study, the indicator variable is a policy treatment –
whether a breached company was subject to financial sector Safeguards regulations. This is
categorically measured for each successful breach attempts from 2005 – 2020, indicating
whether the breached company was a member of the financial sector and subject to financial
sector cybersecurity regulations or not a member of the financial sector. A determination of
whether a breached company is a member of the US financial sector is based on the original
guidance from the Gramm-Leach-Bliley Act (1999). As discussed, this act set the conditions for
financial regulators to establish Safeguards rules for financial firms. Financial firms participating
in financial activities or incidental to financial activities were considered financial firms (Federal
Trade Commission, 2022). Section 505 of Gramm-Leach-Bliley (1999) specifically calls – out
banks, investment companies, investment advisors, and insurance companies. When coding
whether the breached company was a member of the financial sector, I pair this guidance with
the company’s four digit North American Industrial Classification System (NAICS) code. Refer
to Appendix A for a NAICS code decomposition table extracted from the NAICS association (no
date).
37
Outcome Variables
Because this is a positivist study, an assumption is that there is an impact of indicator
variables on outcome variables. As previously discussed, behavioral public policy theory
suggests that authority tools should be effective means to achieve policy outcomes in the
financial sector. Assessing the impact of Safeguards regulations on breach frequency and
successful breach severity is an effective way to evaluate whether these regulations facilitated
desired cybersecurity policy outcomes. Safeguards rules were implemented as management -
based regulation to compel financial sector companies to adopt “administrative, technical, and
physical safeguards for the protection of customer records and information” (Taft et al., 2019, p.
2). Capturing successful frequency breach numbers and severity of breaches when they occur, is
an appropriate measure of protection of customer records and information.
Breach frequency is measured as the percentage of the total number of private sector
breaches that occur on financial sector companies each year from 2005 - 2020. A breach is
characterized as unauthorized access into company networks or databases via cyberspace. In this
study incidents that involve stolen computers, accidental emails, lost network recovery tapes, or
accidental postings of information on a public webpage are not characterized as breach incidents.
Another important note is that because this study focuses on the impact of regulation heavy
policy instrumentation on the private sector, victim entities such as governmental organizations
and not for profit organizations are excluded. Additionally, the health care and bulk energy
sectors are excluded because these sectors are subject to other sets of cybersecurity regulations as
per the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the North
American Electric Reliability Corporate Corporation Critical Infrastructure Protection (NERC
CIP).
38
Breach severity is measured using two elements – number of records exposed during a
successful cybersecurity breach and the sensitivity of the information contained in exposed
records. Both of these elements were prominently included in IT – Harvest and SafeNet’s Breach
Level Index (BLI). In 2013, IT-Harvest and SafeNet released its BLI in a presentation at the
globally influential RSA Cyber conference. They stated that breaches are not "binary
proposition[s] where an organization either has or has not been breached" (Stiennon, 2013, p. 1).
Instead, breaches are "wildly variable in their severity and ramifications" (Stiennon, 2013, p. 1).
To help organizations better measure the impact of their cybersecurity breaches, IT - Harvest and
SafeNet published an index that measures breach severity. Both the number of records exposed
and sensitivity of data were included in their BLI.
The number of records exposed per breach is a numerical variable that is the actual number of
consumer records extracted in each breach. The sensitivity of the records extracted is
categorically measured using qualitative categories. The Department of Labor defines personally
identifiable information (PII) as “any representation of information that permits the identity of an
individual to whom the information applies to be reasonably inferred by either direct or indirect
means” (Department of Labor, nd., first paragraph). However, this definition is not helpful in
delineating sensitivity of extracted information because it lumps social security numbers in the
same characterization as names. This study adopt two categories of sensitivity: nonsensitive and
sensitive. A nonsensitive record is characterized with attributes such as names, email address,
addresses. A nonsensitive record does not offer account authentication and access information to
on – line accounts or any financial information. Sensitive records are characterized as records
that allow account authentication and access information, provide financial information, provide
39
social security numbers or other data that could be expected to cause significant consumer
impact.
Covariates
In this study, covariates are variables other than the examined policy treatment variable that
could impact breach severity and frequency outside of Safeguards rules. The variables are
helpful in isolating the impact of Safeguards by controlling for the impacts of other deployed
governmental policy tools. The federal government has, and continues, to leverage policy tools
other than regulation to stimulate cybersecurity in the private sector. This is expected, often
policy makers deploy policy tools in bundles to achieve desired ends. Hood’s nodality and
organization tools offer the primary resources in these endeavors. In attempt to isolate the impact
of financial sector Safeguards regulations, this study integrates two government approaches as
covariates. The first of these is sector participation in cybersecurity Information Sharing and
Analysis Centers (ISAC). ISACs are non-profit organizations that organize and distribute
cybersecurity threat information. The federal government has a long standing view that
information sharing is foundational to private sector cybersecurity (GAO 04 – 780, 2004). To
that end, the federal government has “emphasized the importance of ISACs” and have worked
closely with ISACs to provide cyber threat information to industry sectors. (GAO 04 – 780,
2004, p. intro). Industry sectors with an ISAC may be more apt to address emerging
cybersecurity risks. Over the last 25 years, ISACs have emerged independently in various
industry sectors. Appendix B provides a listing of the year each ISAC was established. Another
covariate is whether a breached company was in a critical infrastructure sector with an assigned
sector risk management agency (SRMA). In 2013, Presidential Directive – 21, assigned the 16
40
designated critical infrastructure sectors a federal SRMA to coordinate cybersecurity defense.
SRMAs often recommend cybersecurity standards, proliferate threat information, and partner
with ISACs. It is reasonable to assume that both of these covariates could impact breach
frequency and severity absent of federal regulations. For each breach from 2005 – 2020, an
assessment is made as to whether the breached company was in a sector with an active ISAC and
whether the company was aligned to a SRMA.
Statistical Methods
Data Collection
All data used to measure variables and conduct statistical analysis is cross – sectional,
secondary in nature, and spans 2005 – 2020. A primary challenge in all studies examining
cybersecurity breach events is that there is not a single authoritarian source capturing all breach
incidents. Some databases leverage SEC filings exclusively, some databases leverage state
breach reporting requirements, and some databases compile news reporting. To comprehensively
capture breach events and build a reliable dataset, this study fuses information from two
respected sources: The Audit Analytics database and Privacy Right’s Data Breach Chronology.
The company Audit Analytics maintains comprehensive databases that are tailored for a
range of financial sector investigations. The company’s databases are used to support research by
many R1 universities such as Cornell, University of Florida, Duke, and the University of Kansas
and are cited in over 1500 academic papers (Audit Analytics for Academia, no date). One of its
databases is the cybersecurity database which contains information about cybersecurity incidents
impacting all SEC registered companies. The company builds the database through a
combination of both SEC filings and open-source reporting of cybersecurity breaches.
41
PrivacyRights.org is a not-for-profit organization (privacyrights.org, 2023) largely funded by
The Rose Foundation for Communities and the Environment Consumer Products Fund. Drawing
data from the U.S. Department of Health and Human Services, public press breach reporting and
US states with breach reporting requirement laws, it assembled a database titled The Privacy
Right’s Data Breach Chronology that captures cybersecurity breach information for the majority
of the last twenty years. The database is a well-regarded source of data and was prominently
featured in the Journal of Accountancy (Collins, September 1 2019).
Statistical Analysis
Collected data is secondary and pooled cross sectional, but we should expect that time will
affect the impact of regulations on financial sector companies. There are many statistical models
that leverage pooled cross sectional data. The difference in difference technique is exceedingly
useful for this study.
Often when assessing the impact of public policy decisions randomized controlled trials are
not feasible. Such is the case with the current research. In these circumstances, difference in
difference analysis is very constructive in estimating the effect of policy intervention (Wing, et.
al, 2018). Difference in difference allows an evaluation of the “effect of a specific intervention
or treatment (such as a passage of law, enactment of policy, or large-scale program
implementation)” by contrasting the “changes in outcomes over time” between a control and
subject group after the intervention. (Columbia University Mailman School of Public Heath, no
date, description paragraph). Difference in difference methods allow a focus on the policy effect
outcomes prevalent at the unit of analysis over time under the alternative levels of treatment
(Wing et al. 2018). It aligns well with the policy evaluation requirement of a counterfactual
42
assessment and integrates nicely into nonexperimental research. Curti et al. (2023) leveraged a
difference in difference technique when using secondary cross – sectional data to evaluate the
impact of state – level cybersecurity laws on state and local government governments.
Michael Lechner (2010) discuss several key assumptions that are necessary for the difference
in difference model. The first of these is the stable unit treatment value assumption which
requires that there is no cross impact from the treatment and control groups. The second
assumption is exogeneity. To meet the exogeneity assumption the covariates may not be
influenced by the treatment. While not an assumption, a common practice is to execute the
regression using robust standard errors to allow for heteroscedasticity. Finally, and the most
frequently discussed difference in difference assumption is parallel trends. Parallel trends states
that absent the policy intervention, over time there will be no difference between the treatment
and control populations. Without the intervention, the treatment group follows the same trend as
the control group. Figure 4 depicts this dynamic (Columbia University Mailman School of Public
Health, no date, parallel trend assumption). In the figure 4, the treatment and control populations
share a parallel trend prior to policy intervention and this trend continues absent the policy
intervention effect. The policy intervention shifts the outcome for the treatment population which
results in an outcome difference.
43
Figure 4: Difference in Difference Parallel Assumption
In Designing Difference in Difference Studies: Best Practices for Public Health Policy
Research, Wing et al. (2018) offer when there is a single treatment and a single control group (g
= 1, 2) that are evaluated in two time periods (t = 1, 2); the difference in difference can be
“represented by a 2 × 2 box” (p. 455). In T1, neither group is exposed to the intervention.
However, in T2, the treatment group is subject to the intervention, but the control group is not.
Wing et al. (2018) continue to state
Let Tg = 1[g = 2] be a dummy variable identifying observations on group 2. Tg has no time
subscript because group membership is time invariant. Pt = 1[t = 2] indicates observations
from period 2, and Pt has no group subscript because the time period does not vary across
the groups. In the simple DID, the treatment variable is the product of these two dummy
variables: Dgt = Tg × Pt. It is easy to see the connection between the description of the
design and the notation. For example, Dgt = 0 for both groups in the first period because
Pt = 0; and Dgt = 1 only for group 2 in period 2 because that is the only way that both Tg
and Pt are equal to 1. (p. 455)
44
Such is the case in this study. The current work’s treatment population is financial sector
companies. The policy treatment is implementation of Safeguards cybersecurity regulations that
sought to protect consumer information by reducing breach frequency and severity. The control
population is companies in all other sectors that were not subject to cybersecurity control
implementation regulations. According to the parallel trends assumption, we must assume a
similar breach frequency and severity between financial sector and all other companies prior to
Safeguards implementation. However, the assumption does not require an exact parallel between
populations, only a similar one (Waldinger, no date). Parallel trends is a reasonable assumption
for this study. Based on a limited number of cybersecurity breaches from 2000 – 2007, an
inference of similar trend for both companies in and outside of the financial sector is possible.
Below is the tailored difference in difference regression equation used in this study. Table 3
paired with figure 5 provides an equation coefficient explanation (Columbia University Mailman
School of Public Health, no date, regression model).
45
Y= β0 + β1*[Time] + β2*[Intervention Group] + β3*[Time*Intervention Group] + β*[Covariates]+ε
Table 3: Difference in Difference Equation Explanation
Coefficient
Interpretation
Β0
Baseline Average
Β1
Equal effect of time on both
financial and non-financial sector
breached companies absent policy
intervention from 2005 – 2020
Β2
Difference between financial
sector and non-financial sector
prior to Safeguards regulations
implementation (the study uses
2007)
Β3
Difference in financial sector
versus non-financial sector
breached companies changes over
time including the effects of
Safeguards regulations from 2005
– 2020
Figure 5: Difference in Difference Model Depiction
46
Dataset Curation and Building the Dataset
A prerequisite for the difference in difference analysis is normalization of the data in the
Audit Analytics and Privacy Right’s Data Breach Chronology database into a single dataset.
Each database’s information is displayed in a mixture of structured and unstructured data.
Numbers of records exposed per breach are displayed as structured numerical values in both, but
company industry sector and type of record exposed are captured in unstructured prose.
Additionally, the two databases do not display these pieces of information homogenously. For
example the Audit Analytics Database crosswalks a breached company to its NAICS code, the
Breach Chronology database notes that a breached company may be in the financial sector based
on its name. When referencing the type of record exposed, the Audit Analytics database
provides a prose description such as ‘Credit Card or social security’, the Breach Chronology
database provides a prose description such as ‘The breach involved unauthorized access to
sensitive tax-related information.’ Creating a single merged dataset for this study requires a
uniform transformation of both databases into a consistently structured dataset. This is
accomplished by merging the databases in their raw form, deleting entries that do not match a
breach event, and then manually transforming each breach event into a common structured data
format.
Data Analysis Execution
Data analysis execution begins with a series of data diagnostic tests. All diagnostic and
statistical analysis is conducted using STATA SE18. These diagnostics include: normality
testing and multicollinearity testing. Heteroscedasticity testing is not necessary as the study
employs robust standard errors. A Jarque Bera test will help validate the normality of the data.
47
The null hypothesis for Jarque Bera is that the data is normally distributed. An important note, is
that while I test for normality, the study’s population is large enough to account for potential
normality issues. A Variance Inflation Factor (VIF) will test for multicollinearity; the influence
of one indicator variable on others. This study assumes that a VIF value above 10 indicates
extremely high and not tolerable multicollinearity between indicator variables.
When executing the analysis, attention is given to both descriptive and inferential statistics.
Although descriptive statistics do not offer predictive insights, they do offer insights that can
help visualize statistical characteristics. For example, the mean and the standard deviation can
help us to understand the average values and the distribution of values for each outcome variable.
The primary inferential statistical measure for Safeguards impact is the B3 coefficient. The study
executes a regression on both frequency and severity and adopts a (P ≤ 0.10) significance value.
It is important to note that in a statement regarding statistical significance and p – values, the
ASA stated that researchers should not base statistical significant conclusions on whether a p –
value exceeds a specific value and that significance must be considered in greater context
(Bentensky, 2019). To this end, although this research adopts a (P ≤ 0.10) significance value,
assertions regarding the significance of findings is based on a variety of contextual measures that
include coefficient values and whether the difference between the treatment and control group is
significant prior to treatment implementation.
48
CHAPTER IV: RESULTS
The purpose of this chapter is to report the results of the statistical analysis. Discussions
regarding the result’s implications for practitioners and theory, recommendations, and
conclusions are in Chapter V. After conducting three regressions, the analysis does substantiate
the hypothesis that the financial sector Safeguards regulations have significantly impacted
cybersecurity breach severity and frequency in financial sector private companies relative to
companies that are not subject to federal cybersecurity regulations. The remainder of this
chapter will revisit the research question and key variables, discuss descriptive statistics, report
the results from the statistical analysis, and reflect upon the usability of Howlett’s policy
evaluation concepts for this work’s research design.
As discussed in Chapter III, the research question posed is - have Safeguards regulations
reduced data breach severity and frequency on private sector US financial institutions from 2005
- 2020? The unit of analysis is each successful breach conducted on US private sector companies
from 2005 – 2020. The indicator variable is whether a breached company is a member of the
financial sector and subject to Safeguards regulations. The outcome variables are breach severity,
measured as the numbers of records extracted in each breach and whether these records contain
sensitive PII, and breach frequency, measured as the total number of breaches in a given year
divided by the number of breaches that occur on financial sector companies. Two covariates are
whether the breached company’s industry sector has an active ISAC, and whether the breached
company has an assigned SRMA. Both of these covariates represent government policy tools,
other than regulation, that could affect private sector breach frequency and severity outside
enactment of Safeguards regulations. Inclusion of these covariates provides an ability to control
for government employed nodality and organization tools and isolate the impact of Safeguards
49
regulations. Please refer back to Chapter III for a more detailed discussion regarding key
variables.
After considering the American Statistical Association’s (ASA) statement about p – value
significance which contends that researchers should not base statistical significant conclusions
on whether a p – value exceeds a specific value and that significance must be considered in
greater context (Bentensky, 2019), this research adopts a (P ≤ 0.10) significance value; but,
assertions regarding the significance of findings is based on a variety of measures that include
coefficient values and whether the difference between the treatment and control group is
significant prior to treatment implementation
Descriptive Statistics
Descriptive statistics describe key features of data but do not provide inferential conclusions.
As a result, the information in this section does not offer insights into the effectiveness of
Safeguards regulations, but it does provide an “understanding of the characteristics” of the
population of breach events (Fulk, 2023, p. 1). The study’s population is the total number of
successful breaches from 2005 – 2020; this number is 746 (N = 746). Because the research
focuses on cybersecurity regulatory impacts on the private sector, entities such as government
organizations, not for profits, and universities are omitted from the population. Additionally,
private sector companies that are subject to cybersecurity regulations other than Safeguards rules
are also omitted. Entities of this type include companies subject to medical HIPAA and bulk
energy NERC CIP regulations. Finally, recorded breaches without an associated number of
records extracted or clearly defined sensitivity of records extracted are omitted from the study.
Table four provides some key descriptive statistics.
50
Total Population (N) = 746
Sector
Population
(N)
Mean
Number of
Breaches
per Year
From 2005
- 2020
Total Mean
Number of
Records
Extracted
From 2005
- 2020
Standard
Deviation of
Mean
Records
Extracted
Total
Median
Number of
Records
Extracted
From 2005
- 2020
Percent of
Breaches
from 2005
– 2020
Exposing
Sensitive
Information
Financial
Sector
Company
Breaches
185
12
7,468,763
49,628,376
1300
74%
Non-
Financial
Sector
Company
Breaches
561
38
5,708,063
161,869,489
3657
69%
Within the total population, the number of breaches of financial sector companies subject to
Safeguards regulations is 185. Whereas, the number of breaches of companies in all other sectors
that are not subject to Safeguards regulations is 561. The breached population consists of an
approximately a 3:1 ratio of non-financial sector breached companies to financial sector
breached companies. This is consistent with data presented by private sector cybersecurity
researchers. In Kroll Cybersecurity Risk Management firm’s annual Data Breach Outlook, David
White (2024) reports that in 2023 the financial sector accounted for 27% of breaches.
Additionally, this ratio is very similar to the ratio of mean number of breaches per year between
these groups in this study’s descriptive statistics. The mean number of breaches per year for
financial sector companies is 12, and the mean number of breaches per year for non-financial
sector companies is 38. Interestingly however, is that this ratio does not hold when examining
the median number of records extracted per breach in each group; the ratio of median number of
Table 4: Descriptive Statistics
51
records extracted per breach closes considerably between the two groups. The median number of
extracted record per breach in financial sector companies is 1,300, whereas, the median number
of extracted records per breach in non-financial sector companies is 3,657. Furthermore, when
examining the percentage of breaches that exposed sensitive records, the ratio reverses with
financial sector company breaches exposing sensitive records 74% of the time and mon-financial
sector company breaches exposing sensitive records 69% of the time.
Regression Analysis
The primary statistical method used in this study is difference in difference. Chapter III
provided a comprehensive difference in difference discussion and the reasons why difference in
difference is appropriate for this research. As a recap, difference in difference allows an
evaluation of the “effect of a specific intervention or treatment (such as a passage of law,
enactment of policy, or large-scale program implementation)” by contrasting the “changes in
outcomes over time” between a control and subject group after the intervention (Columbia
University Mailman School of Public Heath, no date, description paragraph). It provides an
ability to integrate both the effects of a specific policy intervention and the effects of time on
outcome variables. I execute two difference in difference regressions that address severity of
breaches. The first regression evaluates the impact of Safeguards regulations on the number of
records extracted in breaches on financial versus non-financial sector companies from 2005 –
2020. The second regression evaluates the impact of the Safeguards regulations on the sensitivity
of the records extracted in breaches on financial versus non-financial sector companies from
2005 – 2020. For a third regression, I employ a linear model to evaluate the likelihood of a
52
breach being a financial sector company by examining the annual percentage of total breach in
the financial sector from 2005 – 2020.
For all three regressions, the indicator variable is whether a breached company was a member
of the financial sector and subject to Safeguards regulations. The outcome variables are breach
severity and likelihood. In regression one and two, severity is measured as the numbers of
records extracted in each breach and the sensitivity of these records - whether these records
contained sensitive PII. In regression three, frequency is measured as the total number of
breaches in a given year divided by the number of breaches that occur in financial sector
companies. The treatment group is breached companies in the financial sector that are subject to
Safeguards cybersecurity regulations; the control group is breached companies in nonfinancial
sectors that are not subject to any federal cybersecurity regulations. The table below provides a
legend for the regression variables. The columns in the table provide the STATA variable names
and what the variables means in the regression. Note, for ease of reading, I assign a dissertation
prose variable name to each STATA variable. In discussing the regressions, I will reference the
dissertation prose variable name.
53
Table 5: Difference in Difference Regression Variable Legend
STATA Regression
Variable Name
Dissertation
Prose Variable
Name
Variable Role in Regression
preorpostsafeguardstreatment
Equal Effect of
Time
This variable is the assumed equal effect of
time from 2005 – 2020 without the effect of
Safeguards regulations on the treatment and
control group
FinancialIndustry
Difference Prior
to Safeguards
This variable is the difference between the
treatment and control group prior to
implementation of Safeguards regulations in
2007
Treatmentpost
Difference
After
Safeguards
This variable is the difference between the
treatment and control group after
implementation of Safeguards regulations in
2007. It includes the effect of the regulation
and the effect of time.
Number of Records Extracted Regression
The first regression uses the outcome variable the number of records extracted per breach.
This regression includes the following variables: (1) The Equal Effect of Time (2) Differences
Prior to Safeguards and (3) Difference After Safeguards. While, financial sector regulators
formalized Safeguards in formal regulatory rule – making from 2000 – 2005, this study marks
2007 as the post treatment variable because we would expect a several year lag in regulation
enactment and implementation by private sector companies. The graph below shows a
correlation exists between implementation of Safeguards regulations and a relative reduction of
records extracted in the financial sector vs the non-financial sector. Please note the divergent
trajectories between financial sector companies and non – financial sector companies. As
discussed previously, we would expect that the number of records extracted increase for both the
treatment and control groups, but the rate of increase for the financial sector was appreciably
blunted.
54
Figure 6: Records Extracted Difference in Difference Graph
The difference in difference regression output reveals a statistically and practically significant
impact on the number of records extracted correlated to the implementation of Safeguards
cybersecurity regulations. In terms of statistical significance, the regression meets the
established p – value significance threshold F (3, 742) = 4.27, p = .065, there is also a non-
significant difference between the financial sector and non-financial sector prior to
implementation of Safeguards regulation p = .308. In terms of practical significance, the
Difference After Safeguards variable coefficient indicates that companies in the financial sector
only experienced an increase of records extracted by approximately 3 million, compared to
roughly an increase of 20 million records extracted in the non – financial sector. The Equal
Effect of Time coefficient shows us that from 2005 – 2020, 19.9 million records were extracted
55
in non – financial sector company breaches. The Difference Prior to Safeguards coefficient
shows us that prior to implementation of Safeguards regulations the difference in records
extracted from financial sector companies versus non – financial sector companies was 4.2
million records. The Difference After Safeguards coefficient shows us that from 2005 – 2020,
16.7 million less records were extracted from financial sector versus non – financial sector
companies during cybersecurity breaches.
Table 6: Number of Records Extracted Regression
Coefficient
Robust
Standard
Errors
T
P>T
Equal Effect
of Time
19.9409
7.0528
2.83
.005
Difference
Prior to
Safeguards
4.2828
4.202
1.02
.308
Difference
After
Safeguards
-16.7662
9.0626
-1.85
.065
Although the initial regression proved statistically and practically significant, it does not
account for omitted variable bias because the two covariates were not included. To validate these
findings and mitigate the potential of omitted variable bias, I regressed the number of records
extracted two more times – first, including the covariate active ISAC and second, including the
covariate assigned SRMA. Finally, I executed a Joint F – Test regressing with both covariates to
validate a lack of significance for the combined effect of both covariates.
When regressing with the covariate active ISAC, the impact of Safeguards regulations,
represented as, Treatment Post remained significant F (4, 741) = 3.27, p = .076. Of additional
56
note, the covariate Active ISAC proved not significant F (4, 741) = 3.27, p = .108. The
Treatment Post’s coefficient increased from -16.7662 to -17.1560 and robust standard errors only
slightly increased from 9.0626 to 9.6657. When regressing with the covariate assigned SRMA,
the impacts of Safeguards regulations also remained significant F (4, 740) = 3.51, p = 0.095. Of
additional note, the covariate assigned SRMA also proved not significant F (4, 740) = 3.51, p =
0.285. The magnitude of the Treatment Post’s coefficient increased from -16.7662 to -27.6123.
However, robust standard errors notably increased from 9.0626 to 16.5316. This increase is
likely because SRMAs did not exist until 2013. When regressing with this covariate, all breaches
were coded with a ‘0’ from 2005 – 2012. My final validation of the significant impact of
Safeguards regulations on number of records extracted was to conduct a Joint F – Test to validate
a lack of significance for the combined effect of both covariates. Previously, I demonstrated that
each covariate independently did not significantly impact the number of records extracted.
However, while this is necessary it is not sufficient. The Joint F – Test validates that the
combination of both covariates did not significantly impact the number of records extracted, and
combined impact of both covariates was not significant F (2, 739) = 1.30, p = 0.2726.
Sensitivity of Records Extracted Regression
The second regression uses the outcome variable the sensitivity of information in the records
extracted per breach. This regression includes the following variables: (1) The Equal Effect of
Time. (2) Differences Prior to Safeguards (3) Difference After Safeguards. In the graph below
note the parallel trajectory of the financial and non – financial sectors after the implementation of
Safeguards regulations in 2007. This demonstrates that implementation of the Safeguards
57
regulation does not create a significant difference of the sensitivity of records extracted between
financial sector companies breached and non – financial sector companies breached.
Figure 7: Sensitivity of Records Extracted Graph
The difference in difference regression output substantiates the graph and reveals there is not a
statistically significant impact on the sensitivity of records extracted stemming from
implementation of the Safeguards cybersecurity regulation. The regression does not meet the
established p – value significance threshold F (3, 676) = 4.27, p = .785, there is not a significant
difference between the financial sector and non-financial sector prior to implementation of
Safeguards regulation p = .303, nor does the treatment post coefficient indicate a difference in
the sensitivity of records extract between financial companies and non-financial companies.
58
Table 7: Sensitivity of Records Extracted
Total Population (N) = 680
Coefficient
Robust
Standard
Errors
T
P>T
Equal Effect
of Time
-0.1935
0.0637
-3.03
.003
Difference
Prior to
Safeguards
0.0625
0.0606
1.03
.303
Difference
After
Safeguards
0.0193
0.0797
.27
.785
Of additional note, regressions including the two covariates reveal not significant results also.
A regression integrating whether a breached company’s sector had an active ISAC was not
significant F (3, 675) p = .848 and a regression integrating whether a breached company was
partnered with an SRMA was not significant F (3, 674) p = .880.
Financial Sector Likelihood Regression
The previous two regressions illuminated the impact of Safeguards regulations on breach
severity by regressing the number of records extracted per breach and the sensitivity of the
records extracted in each breach. This regression sheds light on the impact of Safeguards
regulations on the likelihood a successful breach was on the financial sector from 2007 – 2020.
For this, I employ a linear model with the independent variable being implementation of
Safeguards regulations and the dependent variable being the annual percentage of total breaches
that were from the financial sector. I deviated from the difference in difference model for this
regression because I now only have one observation per year capturing what percent of breaches
59
were from the financial sector, and could not reliably establish the pre – treatment environment.
As a result, the regression only regresses financial sector breaches.
Because Safeguards regulations were not implemented until the 21st century and data is only
available starting in 2005, the regression has a small number of annual observations. However,
the regression results do indicate a significant statistical and practical impact on the annual
percentage of total breaches in the financial sector F (1, 14) p = .014. This indicates that
Safeguards regulations can be correlated to a reduction in the likelihood of a successful breach
being in the financial sector post 2007. The Implementation of Safeguards coefficient shows a
10 percentage point reduction which translates to approximately 80 breaches from 2007 – 2020.
The table below provides the regression output.
Total Population (N) = 16
Coefficient
Robust
Standard
Errors
T
P>T
Implementation
of Safeguards
-0.1001
0.0358
-2.79
.014
Table 8: Financial Sector Percent of Annual Breaches Regression
60
Reflecting on Key Research Design Tenants
Three of Howlett et al’s (2020) concepts for policy outcome evaluation provided the
scaffolding for research design, guided statistical model selection, and shaped data collection
approaches. These concepts are: (1) There is a distinction between policy output evaluation and
policy efficiency evaluation; (2) Quasi experiments (nonexperimental) are valuable for policy
evaluation studies; (3) Policy evaluation must integrate a counterfactual. Prior to reflecting upon
the statistical analysis results, it is worthwhile to pause and reflect on if Howlett et al.’s concepts
provided a feasible design approach.
Howlett’s concepts were a useful scaffolding for guiding research design development. The
distinction between policy output evaluation and policy efficiency evaluation is important and
provided a helpful azimuth to ensure that variable identification and data collection set the
conditions for assessing the impact of the Safeguards regulation. As discussed in the literature
review chapter, the focus of the work was the impacts of the Safeguards regulation not the
efficiency of policy development or execution. By centering the work in policy output
evaluation, the research remained true to the policy evaluation phase of the policy lifecycle and
kept the research from drifting into the policy formulation phase or the policy implementation
phase of the policy lifecycle.
It was not feasible to execute a random experiment and to manipulate the indicator variable.
US financial sector cybersecurity regulations are introduced by US government financial
regulators and are subject to rules making processes codified in law. However, a
nonexperimental design executing statistical analysis was not the only option. Another design
option was to execute case study analysis. Once again, Howlett’s concept for policy evaluation
proved useful. In keeping with Howlett’s view that nonexperimental design is conducive to
61
policy evaluation, this this work benefitted from opting away from other approaches such as case
studies. By engaging in nonexperimental research, the research was both able to benefit from
data from the entire US private sector and the impact of over a decade of time after Safeguards
implementation. The breadth and longevity of data collection and statistical analysis adds
generalizability. Finally, Howlett’s contention that policy evaluation should include a
counterfactual shaped statistical model selection. Once again, his assertion was a valuable and
key driver to the research design. The need to integrate a counterfactual naturally led to
difference in difference model and an ability to assess the potential impact of Safeguard
regulation policy outcomes by examining cybersecurity outcomes in a control and treatment
group.
Reflecting on Statistical Analysis Results
The analysis’s goal was to evaluate the hypothesis that the financial sector Safeguard
regulation have significantly impacted cybersecurity breach severity and frequency in financial
sector private companies relative to companies that are not subject to federal cybersecurity
regulations. Armed with three regressions that evaluated breach severity and frequency for
financial sector companies versus nonfinancial sector companies from 2005 – 2020, we can point
to evidence that supports the hypothesis and reject the null.
The difference in difference regression demonstrated a statistically and practically significant
impact on the number of records extracted correlated to the implementation of Safeguards
cybersecurity regulations (3, 742) = 4.27, p = .065. As importantly, there is also a non-
significant difference between the financial sector and non-financial sector prior to
implementation of Safeguards regulation p = .308 and a non – significant joint impact from the
62
role of ISACs and SRMAs F (2, 739) = 1.30, p = 0.2726. These non – significant outputs allow
for disentanglement of potential impacts from nodal and organization policy tools, isolate the
impact of the Safeguard regulation, and confidently assert a significant correlation exists
between the Safeguards regulation and a diminished number of personal records extracted during
breach in the financial sector versus the private sector. As discussed previously, the finding does
not offer that number of records extracted during breaches from 2005 – 2020 went down in the
financial sector, but it does confirm a significant difference in the numbers of records extracted
in the financial sector versus the non – financial sector by roughly 16 million records. This is a
notable number of records as the median number of records extracted per breach in the financial
sector is 1,300 and 3,657 in the non-financial sector.
Whereas the difference in difference regression demonstrated a statistically significant impact
on the number of records extracted, it demonstrated a non – significant difference in the financial
sector versus the non – financial sector regarding if records extracted during breach events
contained sensitive information, F (3, 676) = 4.27, p = .785. This is not surprising and it should
not cast an overage of doubt on rejection of the null hypothesis. The descriptive statistics
highlighted that a very high percentage of all breaches included sensitive information loss. The
government’s, the private sector’s, and this study’s characterization of sensitive information
includes information such as account password and log – in information, regardless of whether
the breach exposes information such as financial, health, social security numbers. The vast
majority of breaches will expose at least local account information. For example, a breach of the
ResearchGate database might expose an individual researcher’s username and password;
although a ReaserchGate account breach may not yield a social security number or bank account
number. Without an ability to meaningfully distinguish sensitive information such as social
63
security numbers and back account number from truly less sensitive information such as a
ResearchGate username and password, it will continue to be difficult to draw meaningful
conclusions with this outcome variable.
This dissertation began by offering a research question and hypothesis regarding the impact of
the financial sector’s Safeguard regulation on private sector companies’ breach severity and
frequency. Additionally, the dissertation promised a discussion regarding implications for cyber
public policy practitioners and behavioral public policy theory. Chapter IV provided
substantiation that we should not reject the hypothesis that this regulation has resulted in a
significant difference between financial sector and non – financial sector companies in terms of
breach severity and frequency. The next chapter, Chapter V, will provide commentary regarding
these findings implications.
64
CHAPTER V: IMPLICATIONS AND CONCLUSIONS
The previous chapter provided the analysis’s findings and assessed the validity of the
hypothesis that the financial sector Safeguards regulations have significantly reduced cyber
breach severity and frequency in financial firms in comparison to other industries not subject to
cyber security focused regulations. Leveraging difference in difference and linear model
regressions, Chapter III substantiated this hypothesis. This chapter operationalizes the findings
from Chapter IV into implications for behavioral public policy theory and national policy
practice in the cyber domain. Additionally, this chapter will offer recommendations for further
related research.
When discussing implications, it is important not to fall into the trap of thinking that simply
presenting quantitative results that support a hypothesis is beneficial to policy – makers. As
noted by Botterill and Hindmoor (2012), policy – makers are subject to bounded rationality and
often evidence – based research is problematic in how it is communicated. Specially, they
contend that evidence is subject to policy maker’s “constraints of summary and interpretation”
and, as a result, it is incumbent on researchers to convey the research’s caveats (Botterill &
Hindmoor, 2012, p. 370). To that end, key caveats are addressed in discussions regarding
implications.
The terms research caveats and research limitations are often used interchangeably. This
study views them differently. This chapter provides separate discussions regarding caveats and
limitations. Research caveats are qualifiers of the results that require contemplation when
considering the implications of the work. An example of a caveat is if a study found that some
caffeine may be beneficial, but too much caffeine may be harmful. Research limitations are
65
boundaries of scope, or constraints to the study. Using the same caffeine example, a limitation
could be that the study did not consider the benefit of caffeine for males versus females.
Study Limitations
There are three notable potential study limitations. The first limitation gravitates around data
collection. A lack of an authoritative breach data is a limitation that challenges all studies using
cybersecurity breaches as a key variable. There is no authoritative source for breach information.
Various companies, academic institutions, and not for profits have built databases that capture
breach information. Each of these databases draws from differing sources to include open source
reporting, company SEC breach reporting notices, and state databases. It is unlikely that any of
these databases captures every breach that has occurred. This study addresses this limitation by
fusing two respected databases into a single dataset which was discussed in Chapter III. The
second limitation involves the study’s generalizability. Behavioral public policy theory asserts a
causal relationship exists between alignment of policy target behavioral attributes and policy tool
selection to policy outcome achievement. This study focuses on the alignment of behavioral
attributes that are conducive to regulatory tools in a specific industry sector. Other industry
sectors may not have the prerequisite behavioral attributes that are conducive for authority tools.
As a result, this study’s findings are generalizable to policy targets with similar behavioral
attributes, but scholar and practitioners should take heed in generalizing findings to all industry
sectors. Finally, this study’s analysis includes data from 2005 – 2020. In 2020 the FTC revised
its Safeguards rule and extended it to companies that were originally excluded. The 2020
modifications opened the covered firm aperture to include companies such as personal property
and real estate appraisers, automobile manufacturers and dealers that extend credit (Federal
66
Trade Commission, 2022). Additionally in 2023, the SEC proposed a modified Safeguards rule
which included additional cybersecurity requirements. The impacts from FTC and SEC rule
expansions may further impact firm breach frequency and severity, but it will take several years
for firms to implement these regulatory changes and additional time for accurate impact
measurement. The impact of these rule expansions are outside the scope of this study. Further
study expanding the scope of the current work is recommended in the years to come.
Implications for Theory
Chapter III provided a detailed characterization of the history, concepts, and current state of
behavioral public policy. The introduction portion of this subsection provides a short review of
that characterization. After the turn of the 21st century, policy scientists assessed that that policy
targets may not be rational actors; that policy targets were “subject to systemic bias” and used
“cognitive shortcuts or rules of thumb” when reacting to policy instruments (Van Duen, et al.,
2018, p. 3). This view contributed to a fusion of concepts from the behavioral decision making
discipline and behavioral economics, which emerged as behavioral public policy (Starassheim,
2019). Behavioral public policy theory moved beyond a traditional resource – based policy
instrumentation approach of balancing the feasibility and acceptability of policy instruments. It
moved to deliberately considering the potential effectiveness of a policy tool by evaluating the
policy target population’s cultural norms and behavioral attributes.
The current state of behavioral public policy research assumes that "policy tool use and
behavioral expectations" (Howlett & Fraser, 2018, p. 101) are linked and that a correlational
relationship exists between alignment of policy target behavioral attributes and policy tool
selection to policy outcome achievement. Behavioral public policy posits that the effectiveness
67
of policy instrumentation and instrument selection is "linked not just to resource availability",
but to an ability of policy instrumentation to shape behavioral "receptors on the part of policy
targets which make them respond in predictable ways" (Howlett & Fraser, 2018, p. 110).
However, even the leading scholars in the behavioral public policy field contend that more
research, in a wider spectrum of policy domains, is needed to validate the theory.
The US financial private sector enjoys the cultural and behavioral attributes that are perceived
as conducive to use of regulatory policy tools. The financial sector is ingrained over much time
with a willingness to respond to “government invoked penalties and proscriptions” (Howlett &
Fraser, 2018, p. 111). The original Securities Exchange Act was signed in 1934. Additionally,
in the financial sector there has been a considerable amount of interaction between the regulated
and the regulators. Atkins and Lawson (2020) offer that financial regulators have worked
together closely with covered entities to draft consistent harmonized regulation. In the Journal of
Internet Banking, Derek Mohammed (2015) notes that the Financial Sector Coordinating Council
“fully supported cybersecurity regulation” (p. 3). Most notably, the White House Office of the
National Cyber Director’s (2024) report on cybersecurity regulation harmonization, stated that
the financial inquiry respondents “broadly supported the need for enhanced cybersecurity
regulation” (p. 19).
For all of these reasons, we should not be surprised that the findings in Chapter IV seem to
substantiate the validity of behavioral public policy theory in the cybersecurity policy domain.
The financial sector, which maintains the cultural and behavioral attributes that behavioral public
policy theory asserts are conducive to use of regulatory authority tools, experienced a significant
breach frequency and severity decrease in the two decades following implementation of
Safeguards regulations relative to other cybersecurity unregulated sectors. An important insight
68
is that this correlation existed while controlling for government use of information and
organization based policy tools in the form of ISAC support and SRMA creation. There are
several implications for theory based on these findings. Supporting the central premise behind
behavioral public policy theory.
The first implication is that a continuum – based perspectives to policy instrumentation seems
more appropriate than an exclusively resource – based perspectives. This is a long standing
debate that dominated policy science circles in the later part of twentieth century. Resource
based approaches, which were more popular in United Kingdom scholarly works, offered that
policy instruments have unique capabilities and policy makers must align the correct instrument
to the correct policy objective. The driving process for instrumentation was viewed as
“determining the parameters of a given policy situation” and matching the correct instrument
resource to the job (Howlett, 1991, p. 3). Continuum based approaches, were more widely
studied in the United States. They viewed policy instruments as largely substitutable, and the
challenge for policy makers was not matching the right instrument to the job but determining
which instrument was most contextually appropriate given the social, political, and economic
environment (Howlett, 1991). Although the concept of behavioral public policy were not
meaningfully discussed at this time, a key implication from this study is that behavioral public
policy can be an effective way to operationalize continuum – based tool section.
A second implication for theory is that policy targets may not be strictly rational actors and
that Van Duen (2018) was correct in contending that that policy targets are “subject to systemic
bias” and use “cognitive shortcuts or rules of thumb” when reacting to policy instruments (p. 3).
This premise is foundational to behavioral public policy theory and separates it from historic
resource – based policy instrumentation approaches. It reaffirms the nexus of bounded rationality
69
and behavioral public policy theory – that there are “limits to human cognition” and “limits to
our knowledge of the social world”. (Sidney, 2007, p. 80). These limits shape policy target’s
internal calculus when evaluating their propensity for policy compliance.
However, there is a notable study caveat to these implications. The results of this study lend
credence to the idea that when specific cultural and behavioral attributes exist, regulation – based
authority tools are an appropriate policy tool selection. However, the study does not provide
insights into if regulation may also be effective when focused on policy targets that do not have
these same cultural and behavioral attributes. A key caveat is that is it possible that enactment of
cybersecurity regulation targeting populations lacking these attributes such as the IT sector may
also prove effective. As the federal government enacts cybersecurity regulation that targets
sectors without a history in regulation, behavioral public policy scientists should continue to
assess if results align with theory
Implications for Practice
For most of the 21st century, federal cyber policy makers outside of the financial sector heavily
relied on a combination of nodal and organizational policy tools to enhancing private sector
cybersecurity. Cybersecurity information campaigns and voluntary opt – in cybersecurity
focused public private partnerships (PPP) have often been the North Star for federal cyber policy
instrumentation. Since the George W. Bush administration, democrat and republican
administrations alike, primarily relied on nodality and organization policy tools to facilitate
cybersecurity in the private sector. The 2003 National Strategy to Secure Cyberspace stated that
“federal regulation will not become a primary means of securing cyberspace” (Healy, 2023a,
Getting Markets to Work Section). This sentiment was subsequently echoed during President
70
Obama’s administration. Hesitance to employ regulatory tools was largely because the majority
of digital infrastructure in the United States is owned and operated by the private sector.
However, federal policy makers are now increasingly adopting regulatory approaches
traditionally leveraged by the financial sector. In March 2022, President Biden signed into law
the most sweeping piece of cybersecurity legislation yet. The Cyber Incident Reporting for
Critical Infrastructure Act requires all private sector critical infrastructure providers to report
cybersecurity incidents within specified time frames (Office of the Federal Register, 2024).
Additionally, Biden administration’s 2023 National Cybersecurity Strategy states “new
authorities will be required to set regulations that can drive better cybersecurity practices at
scale” (The White House, 2023, p. 7). Cybersecurity expert James Lewis notes that the 2023
National Cybersecurity Strategy is a “break from the previous strategies, which focused on
information sharing and public-private partnership as the solution” (Nakashima & Starks, 2023,
4th Paragraph). Jason Healy, one of the 2023 National Cybersecurity Strategy’s lead authors
argues that the new regulation heavy approach will help “break a 50-year [cybersecurity] losing
streak” (Healy, 2023b, in the title of the article).
However, there is little empirical study to illuminate the effectiveness of the federal embrace
of federal cybersecurity regulation. By focusing on the effectiveness of long – standing
cybersecurity regulation in the financial sector, this work offers important implications for
federal cybersecurity practitioners. The most significant implication is that early 21st century
assumptions about cybersecurity regulatory ineffectiveness because the majority of digital
infrastructure is owned and operated by the private sector is incorrect. The financial sector
demonstrates that regulation – based authority tools can be an effective federal policy tool for
reducing breach frequency and severity in the private sector. This study empirically
71
demonstrated that through use of cybersecurity regulations, financial sector regulators were able
to reduce the severity and frequency of breach in financial sector companies. This implication
validates the new federal approach to private sector cybersecurity and substantiates Jason
Healy’s claim.
A second implication is that Hood and Margetts (2007) seem to be correct when arguing
authority tools are necessary when “there are no clear incentives” to adhere to government’s
policy desires (p. 150). Renowned cybersecurity scholar Madeline Car (2016) contends that one
of the biggest reasons for the ineffectiveness of exclusive use of nodal and organization based
cybersecurity policy instrumentation is because of a lack of private sector incentives. As
discussed previously, cybersecurity expenditures are often a business sunk cost and provide few
conduits for additional revenue. Sunk costs are not often associated with incentives. In the
financial sector, regulations have greatly contributed to the incentivizing of cybersecurity
expenditure and reduction of severity and frequency of breach. While this study focuses on
cybersecurity policy domain, this is an implication that is likely generalizable to other policy
domains.
However, these implications must be digested with an awareness of several of caveats. The
first of these caveats is that the Safeguards regulatory regime analyzed in this work is
management – based versus directive – based. This distinction is not trivial. The financial
sector’s management – based Safeguards regulations establish overarching regulatory objectives,
but leave implementation details to the financial sector firm. In other words, Safeguards
regulations tell firms what they must achieve and firms determine how to achieve it. This is
different than directive – based regulatory regimes where regulators mandate not only specifics
of what needs to be achieved, but also the how of it must be achieved. In a dynamic and ever –
72
changing domain such as cybersecurity, it is not reasonable to assume that this study’s findings
about the impacts of cybersecurity regulation on breach severity and frequency can be blindly
transferred to a directive – based regulatory regime. Potential cybersecurity regulations that
mandate specific technical controls may be limited to short –term success because cyber
adversary’s tools and technologies continue to evolve. Cybersecurity policy makers leveraging
authority tools for instrumentation should be optimistic of regulatory potential, but weary of too
specifically crafting regulation. This sentiment also applies to an overly compliance - based risk
management approach. Safeguards cybersecurity regulations are specific enough to provide
articulable objectives, but not so specific that firms are shackled by compliance. If cybersecurity
regulations are so detailed that they become a compliance checklist versus a guiding azimuth,
this study’s findings may not apply.
The second caveat it that since 2014, financial regulators have aggressively executed
Safeguards regulations enforcement. From 2015 - 2018, the SEC executed Safeguards
enforcement actions against R.T. Jones Capital Equities, Craig Scott Capital, and Morgan
Stanley. In the Morgan Stanley action, the SEC stated that "despite having written policies and
procedures, Morgan Stanley had breached the Safeguards rule. The safeguards were not
reasonably designed to protect customers" (Pierotti, 2018, p. 413). This sent a clear message to
financial sector companies that enforcement of cybersecurity regulation was now a SEC priority
and that light-heartened attempts to pay homage to the regulations would not be tolerated. In
2020, the SEC announced enforcement action against eight firms that included Cetera Advisor
Networks LLC, Cetera Investment Services LLC, Cetera Financial Specialists LLC, Cetera
Advisors LLC, and Cetera Investment Advisers LLC (collectively, the Cetera Entities);
Cambridge Investment Research Inc. and Cambridge Investment Research Advisors Inc.
73
(collectively, Cambridge); and KMS Financial Services Inc. (KMS). When addressing these
enforcement actions, the SEC asserted that "it is not enough to write a policy requiring enhanced
security measures if those requirements are not implemented or are only partially implemented,
especially in the face of known attacks" (Securities and Exchange Commission, 2020, 5th
paragraph).
Cybersecurity policy – makers including regulation – based authority tools in their
instrumentation calculus should be weary of assuming this study’s findings are equally
applicable without a credible threat of enforcement. It is likely that the financial sector
Safeguards regulations effectiveness in addressing cyber breach severity and frequency is not
exclusively because of an alignment with associated cultural attributes, but also because of the
regulator’s propensity for enforcement. While this seems obvious, we should not discount the
future impact of the Supreme Court’s ruling in Chevron v. Natural Resources Defense Council
case. In this ruling, the Supreme Court severely restricted the latitude of the Chevron doctrine
which historically asserted that if “federal legislation is ambiguous or leaves an administrative
gap, the courts must defer to the regulatory agency's interpretation if the interpretation is
reasonable” (Public Policy Institute of California, 2024, first paragraph). This study’s findings
may not be transferable to an environment where regulator’s ability to execute enforcement
actions are limited as a result of the court’s decision in Chevron v. Natural Resources Defense
Council.
74
Conclusion
Although cybersecurity has emerged as a national priority, US policy – makers continue to
toil with which policy tools are the most effective to reduce breach severity and frequency in the
private sector. Historic policy instrumentation approaches that relied heavily on nodal and
organization tools are giving way to an emphasis on regulation – based authority tools.
However, this pivot is often not considered within the context of greater public policy theory.
A helpful theory to examine this problem space is behavioral public policy theory. Behavioral
public policy theory asserts a linkage between policy target behavioral attributes and policy tool
selection. This work focused on the US financial sector to both assess the applicability of
behavioral public policy theory in the cybersecurity policy domain and the impact of financial
sector Safeguards cybersecurity regulations on breach severity and frequency. The financial
sector provides a model testbed for these assessments. Since the early 2000s, the financial sector
has employed a regulation heavy approach in the form of Safeguards regulations to facilitate
cybersecurity in financial private sector companies. Additionally, the US financial sector enjoys
the behavioral attributes that should make regulation an effective instrument for achieving
cybersecurity policy ends.
Leveraging secondary cross – sectional data from 2005 – 2020 and difference in difference
analysis, we assessed a statistically and practically significant difference in the severity of a
successful breaches and the likelihood of a successful breaches in financial sector companies
relative to companies not in the financial sector and not subject to cybersecurity regulations.
These findings have two major implications. One, a substantiation of behavioral public policy
theorized linkage between specific cultural / behavioral attributes and effective use of regulatory
75
tools. Two, traditional hesitations about using regulation as a policy tool for cybersecurity should
be reconsidered, and the current shift to a authority tool heavy approach is warranted.
For follow - on researchers, there is great space for additional work to corroborate this study’s
findings or explore gaps that were not addressed because of study limitations. Further
corroboration is necessary. Findings from previous study focusing on public sector organizations
from the likes of Curti et al. (2023) are not aligned with this work’s results. This leaves
important questions such as are there differences in the impact of cybersecurity regulation on
private sector versus public sector organizations? Additionally, further work is needed to fully
substantiate behavioral public policy theory in the cybersecurity domain. From the presented
results, we can see that using behavioral public policy theorized linkage between specific cultural
/ behavioral attributes is effective when predicting the efficacy of regulatory tools. However,
one of this study’s limitations is that it cannot comment on if regulation would be effective when
focusing on policy targets that do not have theorized cultural / behavioral attributes. In other
words, would cybersecurity regulation work equally if applied to other policy targets without the
same behavioral attributes as the financial sector? This limitation calls for additional study. In
summary, this dissertation illuminates needed and important insights regarding behavioral public
policy theory and the effectiveness of regulation as a cybersecurity policy too. But, much more
work is needed, and I encourage the follow – on work.
Students also viewed