DOI: https://doi.org/10.1016/j.jcorpfin.2026.102958
تاريخ النشر: 2026-01-30
المؤلف: Bok Min Choi وآخرون
الموضوع الرئيسي: استقرار البنوك، والتنظيم، والكفاءة
نظرة عامة
تبحث الدراسة في كيفية تقييم المقرضين وتسعير المخاطر السيبرانية السابقة على حدوثها للشركات غير المالية الأمريكية باستخدام بيانات القروض المشتركة. تكشف النتائج أن المقرضين يفرضون معدلات قروض أعلى – تتراوح بين 4 إلى 13 نقطة أساس – عندما تظهر الشركات مخاطر سيبرانية متزايدة. ومن الجدير بالذكر أن استراتيجيات التسعير تختلف حسب نوع المقرض؛ حيث تميل البنوك التجارية إلى اعتماد نهج أكثر تحفظًا مقارنة بالمقرضين غير المصرفيين، حيث تفرض شروطًا مالية أكثر صرامة وتراقب بشكل أكبر مع تصاعد مخاطر الشركات. علاوة على ذلك، داخل البنوك التجارية، فإن المقرضين الذين يكونون أكثر وعيًا بضعفهم السيبراني الخاص ولديهم سياسات إدارة مخاطر داخلية قد يكونون أكثر عرضة لتعديل تسعيرهم وفقًا لذلك.
تؤكد الدراسة على الدور الحاسم لوعي المقرضين في تسعير المخاطر غير التقليدية، مثل المخاطر السيبرانية. بينما تهدف تأمينات المخاطر السيبرانية إلى التخفيف من الخسائر المحتملة الناتجة عن الحوادث السيبرانية، تشير التحليلات إلى أنها لا تقلل بشكل كبير من فروق القروض. تمتد تداعيات هذه النتائج إلى ما هو أبعد من المخاطر السيبرانية، مما يشير إلى أن صانعي السياسات يمكنهم تعزيز مرونة النظام المالي من خلال تنفيذ أدوات مثل اختبارات الضغط لتحسين وعي المقرضين واستراتيجيات التسعير المتعلقة بمخاطر غير تقليدية متنوعة. يمكن أن تساهم هذه المقاربة في الاستقرار العام للنظام المالي في مواجهة التهديدات السيبرانية المتزايدة.
مقدمة
تسلط مقدمة هذه الورقة البحثية الضوء على الأهمية المتزايدة لمخاطر الأمن السيبراني في إدارة المخاطر الحديثة، لا سيما بالنسبة للشركات والبنوك. تؤكد على أن عواقب الهجمات السيبرانية تمتد إلى ما هو أبعد من الخسائر المالية المباشرة لتشمل أضرارًا كبيرة في السمعة، كما يتضح من دراسة كامييا وآخرون (2021). تؤكد مبادرات البنك المركزي الأوروبي (ECB)، بما في ذلك اختبار ضغط مخاطر السيبرانية للبنوك، على ضرورة تعزيز الخبرة في تكنولوجيا المعلومات والاتصالات (ICT) ومخاطر الأمان. تهدف هذه الورقة إلى التحقيق فيما إذا كان المقرضون يعترفون بمخاطر الأمن السيبراني للشركات ويسعرونها بشكل مناسب، مع التركيز على الاختلافات في التسعير بناءً على وعي المقرضين وممارسات إدارة المخاطر.
تتبنى الدراسة منظورًا سابقًا على حدوثه، مما يتناقض مع الأدبيات الحالية التي تدرس بشكل أساسي التعديلات اللاحقة في شروط الإقراض بعد خروقات البيانات. تستخدم مقياس مخاطر الأمن السيبراني الذي طوره فلوراكيس وآخرون (2023)، والذي يحلل إفصاحات الشركات في ملفات 10-K، وتدمج هذا مع بيانات القروض المشتركة. تشير النتائج الرئيسية إلى أن المقرضين يعدلون فروق القروض بناءً على التغيرات في درجة مخاطر الأمن السيبراني للشركة، حيث تظهر البنوك التجارية تسعيرًا أكثر صرامة مقارنة بالمقرضين غير المصرفيين. علاوة على ذلك، تؤثر مناقشات المقرضين حول مخاطرهم السيبرانية الخاصة بشكل كبير على كيفية تسعيرهم لمخاطر المقترضين. تساهم الورقة في الأدبيات المتعلقة بتسعير المخاطر غير التقليدية في الأسواق المالية وتبرز الدور الحاسم لوعي المقرضين في تقييم مخاطر الأمن السيبراني، بينما تتناول أيضًا الاختلافات في استراتيجيات تسعير المخاطر بين المقرضين التجاريين وغير المصرفيين.
مناقشة
في هذا القسم، يناقش المؤلفون المنهجية والنتائج المتعلقة بتقييم مخاطر الأمن السيبراني في تسعير القروض. يستخدمون بيانات من مصادر متعددة، بما في ذلك فلوراكيس وآخرون (2023) لإفصاحات مخاطر الأمن السيبراني في ملفات 10-K وجاميلوف وآخرون (2021) لتغطية تأمين الأمن السيبراني، لبناء مجموعة بيانات شاملة تمتد من 2007 إلى 2019. تركز العينة على القروض الممنوحة للشركات غير المالية الأمريكية من 2012 إلى 2018، مما يعكس زيادة كبيرة في إفصاحات مخاطر الأمن السيبراني بعد توجيهات SEC في 2011. تتكون مجموعة البيانات النهائية من 6,316 قرضًا من 1,765 مقترضًا فريدًا، مع إحصائيات ملخصة تشير إلى أن 82% من الملاحظات تبلغ عن درجة مخاطر الأمن السيبراني أكبر من الصفر، و29% لديها تغطية تأمين سيبراني.
تكشف التحليلات التجريبية أن المقرضين يسعرون مخاطر الأمن السيبراني في فروق القروض، خاصة عند الأخذ في الاعتبار التغيرات داخل الشركة. على وجه التحديد، يرتبط زيادة انحراف معياري واحد في مخاطر الأمن السيبراني بزيادة قدرها 2% في فروق القروض، مما يعادل زيادة متوسطة قدرها 3.87 نقطة أساس. كما تميز التحليلات بين أنواع المقرضين، حيث وجدت أن البنوك التجارية تفرض تسعيرًا أكثر صرامة على مخاطر الأمن السيبراني مقارنة بالمقرضين غير المصرفيين، الذين يظهرون حساسية أقل. بالإضافة إلى ذلك، تزداد وجود الشروط المالية مع ارتفاع مخاطر الأمن السيبراني، مما يشير إلى أن المقرضين يعززون المراقبة للشركات الأكثر خطورة. ومع ذلك، تجد الدراسة أن وجود تأمين للأمن السيبراني لا يقلل بشكل كبير من تسعير هذه المخاطر، مما يشير إلى قيود محتملة في فعالية تغطية التأمين في معالجة نقاط الضعف السيبرانية.
DOI: https://doi.org/10.1016/j.jcorpfin.2026.102958
Publication Date: 2026-01-30
Author(s): Bok Min Choi et al.
Primary Topic: Banking stability, regulation, efficiency
Overview
The research investigates how lenders assess and price the ex-ante cybersecurity risks of U.S. non-financial firms using syndicated loan data. The findings reveal that lenders charge higher loan rates—between 4 to 13 basis points—when firms exhibit increased cybersecurity risks. Notably, the pricing strategies vary by lender type; commercial banks tend to adopt a more conservative approach compared to non-bank lenders, imposing stricter financial covenants and monitoring as firms’ risks escalate. Furthermore, within commercial banks, those lenders who are more aware of their own cybersecurity vulnerabilities and have established internal risk management policies are more likely to adjust their pricing accordingly.
The study emphasizes the critical role of lender awareness in the pricing of unconventional risks, such as cybersecurity. While cybersecurity insurance is intended to mitigate potential losses from cyber incidents, the analysis indicates that it does not significantly reduce loan spreads. The implications of these findings extend beyond cybersecurity, suggesting that policymakers could enhance financial system resilience by implementing tools like stress tests to improve lenders’ awareness and pricing strategies regarding various unconventional risks. This approach could contribute to the overall stability of the financial system in the face of growing cybersecurity threats.
Introduction
The introduction of this research paper highlights the increasing significance of cybersecurity risks in modern risk management, particularly for firms and banks. It emphasizes that the repercussions of cyberattacks extend beyond direct financial losses to include substantial reputational damage, as evidenced by Kamiya et al. (2021). The European Central Bank’s (ECB) initiatives, including a cyber risk stress test for banks, underscore the necessity for enhanced expertise in information and communication technology (ICT) and security risks. This paper aims to investigate whether lenders recognize and appropriately price firms’ cybersecurity risks, focusing on the differences in pricing based on lenders’ awareness and risk management practices.
The study adopts an ex-ante perspective, contrasting with existing literature that primarily examines ex-post adjustments in lending terms following data breaches. It employs a cybersecurity risk measure developed by Florackis et al. (2023), which analyzes firms’ disclosures in 10-K filings, and merges this with syndicated loan data. Key findings indicate that lenders adjust loan spreads based on changes in a firm’s cybersecurity risk score, with commercial banks exhibiting stricter pricing compared to non-bank lenders. Furthermore, lenders’ discussions of their own cybersecurity risks significantly influence how they price borrowers’ risks. The paper contributes to the literature on non-traditional risk pricing in financial markets and highlights the critical role of lender awareness in assessing cybersecurity risks, while also addressing the differences in risk pricing strategies between commercial and non-bank lenders.
Discussion
In this section, the authors discuss the methodology and findings related to the assessment of cybersecurity risks in loan pricing. They utilize data from multiple sources, including Florackis et al. (2023) for cybersecurity risk disclosures in 10-K filings and Jamilov et al. (2021) for cybersecurity insurance coverage, to construct a comprehensive dataset spanning from 2007 to 2019. The sample focuses on loans issued to U.S. non-financial firms from 2012 to 2018, reflecting a significant increase in cybersecurity risk disclosures following SEC guidance in 2011. The final dataset comprises 6,316 loans from 1,765 unique borrowers, with summary statistics indicating that 82% of observations report a cybersecurity risk score greater than zero, and 29% have cybersecurity insurance coverage.
The empirical analysis reveals that lenders price cybersecurity risks in loan spreads, particularly when accounting for within-firm changes. Specifically, a one standard deviation increase in cybersecurity risk correlates with a 2% increase in loan spreads, equating to an average rise of 3.87 basis points. The analysis also differentiates between lender types, finding that commercial banks impose stricter pricing on cybersecurity risks compared to non-bank lenders, who show less sensitivity. Additionally, the presence of financial covenants increases with higher cybersecurity risks, suggesting that lenders enhance monitoring for riskier firms. However, the study finds that having cybersecurity insurance does not significantly mitigate the pricing of these risks, indicating potential limitations in the effectiveness of insurance coverage in addressing cybersecurity vulnerabilities.
