<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en">
<front> <journal-meta>
<journal-id journal-id-type="publisher-id">Financial risk management</journal-id>
<journal-title-group>
<journal-title xml:lang="en">Financial risk management</journal-title>
<trans-title-group xml:lang="ru">
<trans-title>Управление финансовыми рисками</trans-title>
</trans-title-group>
</journal-title-group>
<issn publication-format="print">2221-7541</issn>
<issn publication-format="electronic">2618-8805</issn>
<publisher>
<publisher-name xml:lang="en">BIBLIO-GLOBUS Publishing House</publisher-name>
</publisher>
</journal-meta><article-meta>
<article-id pub-id-type="publisher-id">126364</article-id>
<article-id pub-id-type="doi">10.18334/ufr.22.3.126364</article-id>
<article-id custom-type="edn" pub-id-type="custom">RECAKE</article-id>
<article-categories>
<subj-group subj-group-type="toc-heading" xml:lang="en">
<subject>Articles</subject>
</subj-group>
<subj-group subj-group-type="toc-heading" xml:lang="ru">
<subject>Статьи</subject>
</subj-group>
<subj-group subj-group-type="article-type">
<subject>Research Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title xml:lang="en">The relationship between information security risks and financial risks in an organization: a theoretical model of integration into ERM</article-title>
<trans-title-group xml:lang="ru">
<trans-title>Взаимосвязь рисков информационной безопасности и финансовых рисков в организации: теоретическая модель интеграции в ERM</trans-title>
</trans-title-group>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-4725-4994</contrib-id><contrib-id contrib-id-type="spin">8100-4320</contrib-id>
<name-alternatives>
<name xml:lang="en">
<surname>Aleksashina</surname>
<given-names>Tatiana Viktorovna</given-names>
</name>
<name xml:lang="ru">
<surname>Алексашина</surname>
<given-names>Татьяна Викторовна</given-names>
</name>
</name-alternatives>
<bio xml:lang="ru">
<p>Доцент Кафедры общего и проектного менеджмента, кандидат экономических наук, доцент</p>
</bio>
<email>altavip@yandex.ru</email>
<xref ref-type="aff" rid="aff1"/>
</contrib>

<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-3422-6051</contrib-id><contrib-id contrib-id-type="spin">5060-8725</contrib-id>
<name-alternatives>
<name xml:lang="en">
<surname>Razinkina</surname>
<given-names>Irina Vladimirovna</given-names>
</name>
<name xml:lang="ru">
<surname>Разинкина</surname>
<given-names>Ирина Владимировна</given-names>
</name>
</name-alternatives>
<bio xml:lang="ru">
<p>Доцент Кафедры общего и проектного менеджмента, кандидат экономических наук, доцент</p>
</bio>
<email>ivrazinkina@fa.ru</email>
<xref ref-type="aff" rid="aff1"/>
</contrib>
</contrib-group><aff-alternatives id="aff1">
<aff>
<institution xml:lang="en">Financial University under the Government of the Russian Federation</institution>
</aff>
<aff>
<institution xml:lang="ru">Финансовый университет при Правительстве Российской Федерации</institution>
</aff>
</aff-alternatives>        
        
<pub-date date-type="pub" iso-8601-date="2026-09-30" publication-format="print">
<day>30</day>
<month>09</month>
<year>2026</year>
</pub-date>
<volume>22</volume>
<issue>3</issue>
<issue-title xml:lang="en">VOL 22, NO3 (2026)</issue-title>
<issue-title xml:lang="ru">ТОМ 22, №3 (2026)</issue-title>
<fpage></fpage>
<lpage></lpage>
<history>
<date date-type="received" iso-8601-date="2026-06-25">
<day>25</day>
<month>06</month>
<year>2026</year>
</date>
<date date-type="accepted" iso-8601-date="2026-07-29">
<day>29</day>
<month>07</month>
<year>2026</year>
</date>
</history>

<permissions>
<copyright-statement xml:lang="en">Copyright ©; 2026, Aleksashina T.V., Razinkina I.V.</copyright-statement>
<copyright-statement xml:lang="ru">Copyright ©; 2026, Алексашина Т.В., Разинкина И.В.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder xml:lang="en">Aleksashina T.V., Razinkina I.V.</copyright-holder>
<copyright-holder xml:lang="ru">Алексашина Т.В., Разинкина И.В.</copyright-holder>
<ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/" start_date="2026-09-30"/>
</permissions>



<self-uri xlink:href="https://1economic.ru/lib/126364">https://1economic.ru/lib/126364</self-uri>
<abstract xml:lang="en"><p>Information security risks amid the digitalization of the economy are a significant source of financial risks for an organization, affecting profit and loss indicators, cash flow stability, business continuity and the cost of attracting resources. The article proposes a theoretical cause-and-effect model describing the mechanisms of translating cyber risks into financial risk categories and substantiates approaches to ensuring comparability of cyber risk scenarios with the corporate risk management system. It is shown that most significant cyber incidents have a multi-channel effect on the organization's finances. Thus, effective management requires a scenario-based financial decomposition of damage and portfolio aggregation in the ERM.</p>
</abstract>
<trans-abstract xml:lang="ru"><p>Риски информационной безопасности в условиях цифровизации экономики являются значимым источником финансовых рисков организации, оказывая влияние на показатели прибыли и убытков, устойчивость денежных потоков, непрерывность деятельности и стоимость привлечения ресурсов. В статье предложена теоретическая причинно-следственная модель, описывающая механизмы трансляции киберрисков в финансовые категории риска, и обоснованы подходы к обеспечению сопоставимости оценки сценариев киберриска с системой корпоративного управления рисками. Показано, что большинство значимых киберинцидентов мультиканально воздействует на финансы организации, поэтому эффективное управление требует сценарной финансовой декомпозиции ущерба и портфельной агрегации в ERM</p>
</trans-abstract>
<kwd-group xml:lang="en">
<kwd>information security</kwd>
<kwd>cyber risk</kwd>
<kwd>financial risks</kwd>
<kwd>organization</kwd>
<kwd>corporate risk management</kwd></kwd-group><kwd-group xml:lang="ru">
<kwd>информационная безопасность; киберриск; финансовые риски; организация; корпоративное управление рисками</kwd></kwd-group>
</article-meta>
</front>
<back> <ref-list>
<ref id="B1">
<label>1.</label>
<mixed-citation>1. 94% россиян сталкивались с мошенничеством за последний год. [Электронный ресурс]. URL: https://nafi.ru/polls/94-rossiyan-stalkivalis-s-moshennichestvom-za-posledniy-god/ (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B2">
<label>2.</label>
<mixed-citation>2. Беляев Е. А., Емельянова О. А., Лившиц И. И. Анализ методик оценки рисков информационной безопасности кредитно-финансовых организаций // Научно-технический вестник информационных технологий, механики и оптики. – 2021. – № 3. – c. 437-441. – doi: 10.17586/2226-1494-2021-21-3-437-441.</mixed-citation>
</ref>
<ref id="B3">
<label>3.</label>
<mixed-citation>3. Доля пользователей мобильного банка растет, но россияне становятся менее бдительными. [Электронный ресурс]. URL: https://nafi.ru/polls/dolya-polzovateley-mobilnogo-banka-rastet-no-rossiyane-stanovyatsya-menee-bditelnymi/ (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B4">
<label>4.</label>
<mixed-citation>4. Исследование НАФИ: что россияне знают о кибербезопасности и кибергигиене. [Электронный ресурс]. URL: https://nafi.ru/polls/issledovanie-nafi-chto-rossiyane-znayut-o-kiberbezopasnosti-i-kibergigiene/ (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B5">
<label>5.</label>
<mixed-citation>5. Каждый второй россиянин сталкивался с кражей денег или утечкой персональных данных в цифровой среде. [Электронный ресурс]. URL: https://nafi.ru/polls/kazhdyy-vtoroy-rossiyanin-stalkivalsya-s-krazhey-deneg-ili-utechkoy-personalnykh-dannykh-v-tsifrovoy/ (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B6">
<label>6.</label>
<mixed-citation>6. Дуглас У. Хаббард, Ричард Сирсен Как оценить риски в кибербезопасности. Лучшие инструменты и практики. / [перевод с англ. М.А. Райтмана]. - М.: Эксмо, 2023. – 464 c.</mixed-citation>
</ref>
<ref id="B7">
<label>7.</label>
<mixed-citation>7. Поповиченко М. А. Управление инновационными проектами компаний на основе риск-ориентированного подхода. / автореф. дис. … канд. экон. наук: 5.2.3 / Поповиченко Марк Андреевич; ФГАОУ ВО Северо-Кавказский федеральный университет. - Ставрополь, 2025. – 30 c.</mixed-citation>
</ref>
<ref id="B8">
<label>8.</label>
<mixed-citation>8. Дробот Е.В., Макаров И.Н., Евсин М.Ю., Зироян Р.А. Потенциальные возможности и вызовы цифровой экономики для устойчивого развития общества // Экономика, предпринимательство и право. – 2025. – № 8. – c. 5359-5384. – doi: 10.18334/epp.15.8.123676.</mixed-citation>
</ref>
<ref id="B9">
<label>9.</label>
<mixed-citation>9. Рабочие данные под угрозой: только 13% россиян делают резервные копии регулярно. [Электронный ресурс]. URL: https://nafi.ru/polls/rabochie-dannye-pod-ugrozoy-tolko-13-rossiyan-delayut-rezervnye-kopii-regulyarno/ (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B10">
<label>10.</label>
<mixed-citation>10. Самойлов М. А. Взаимосвязь экономической и информационной безопасности российской организации // Экономика и бизнес: теория и практика. – 2023. – № 10-2. – c. 132-134. – doi: 10.24412/2411-0450-2023-10-2-132-134.</mixed-citation>
</ref>
<ref id="B11">
<label>11.</label>
<mixed-citation>11. Царегородцев А.В., Романовский С.В., Волков С.Д., Самойлов В.Е. Управление рисками информационной безопасности цифровых продуктов финансовой экосистемы организации // Моделирование, оптимизация и информационные технологии. – 2020. – № 4. – c. 34. – doi: 10.26102/2310-6018/2020.31.4.038.</mixed-citation>
</ref>
<ref id="B12">
<label>12.</label>
<mixed-citation>12. Basel Committee on Banking Supervision. Principles for the Sound Management of Operational Risk. BIS, 2011. [Электронный ресурс]. URL: https://www.bis.org/publ/bcbs195.htm (дата обращения: 23.06.2026).</mixed-citation>
</ref>
<ref id="B13">
<label>13.</label>
<mixed-citation>13. Gordon L. A., Loeb M. P. The Economics of Information Security Investment // ACM Transactions on Information and System Security. – 2002. – № 4. – p. 438-457. – doi: 10.1145/581271.581274.</mixed-citation>
</ref>
<ref id="B14">
<label>14.</label>
<mixed-citation>14. Campbell K., Gordon L. A., Loeb M. P., Zhou L. The economic cost of publicly announced information security breaches: empirical evidence from the stock market // Journal of Computer Security. – 2003. – № 3. – p. 431-448.</mixed-citation>
</ref>
<ref id="B15">
<label>15.</label>
<mixed-citation>15. Cavusoglu H., Mishra B., Raghunathan S. The effect of Internet security breach announcements on market value of breached firms // International Journal of Electronic Commerce. – 2004. – № 1. – p. 69-104. – doi: 10.1080/10864415.2004.11044320.</mixed-citation>
</ref>
<ref id="B16">
<label>16.</label>
<mixed-citation>16. Enterprise Risk Management: Integrating with Strategy and Performance. 2017. COSO. [Электронный ресурс]. URL: https://www.coso.org (дата обращения: 23.06.2026).</mixed-citation>
</ref>
<ref id="B17">
<label>17.</label>
<mixed-citation>17. Cost of a Data Breach Report 2024. IBM Security. [Электронный ресурс]. URL: https://www.ibm.com/reports/data-breach (дата обращения: 23.06.2026).</mixed-citation>
</ref>
<ref id="B18">
<label>18.</label>
<mixed-citation>18. IEC 27005:2022. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO. [Электронный ресурс]. URL: https://www.iso.org/standard/80585.html#lifecycle (дата обращения: 01.06.2026).</mixed-citation>
</ref>
<ref id="B19">
<label>19.</label>
<mixed-citation>19. The NIST Cybersecurity Framework (CSF) 2.0. 2024. NIST. [Электронный ресурс]. URL: https://www.nist.gov/cyberframework (дата обращения: 23.06.2026).</mixed-citation>
</ref>
<ref id="B20">
<label>20.</label>
<mixed-citation>20. Romanosky S. Examining the costs and causes of cyber incidents // Journal of Cybersecurity. – 2016. – № 2. – p. 121–135. – doi: 10.1093/cybsec/tyw001.</mixed-citation>
</ref>
<ref id="B21">
<label>21.</label>
<mixed-citation>21. 2024 Data Breach Investigations Report. Verizon. [Электронный ресурс]. URL: https://www.verizon.com/business/resources/reports/dbir/ (дата обращения: 23.06.2026).</mixed-citation>
</ref>
</ref-list>
</back>
</article>