EconPapers    
Economics at your fingertips  
 

Evaluating cyber risk reporting in US financial reports

Ron Fisher, Justin Wood, Celia Porod and Lydia Greco
Additional contact information
Ron Fisher: Idaho National Laboratory, USA
Justin Wood: College of Business, Idaho State University
Celia Porod: Idaho National Laboratory
Lydia Greco: Idaho State University/Idaho National Laboratory

Cyber Security: A Peer-Reviewed Journal, 2020, vol. 3, issue 3, 275-286

Abstract: Cyberthreats are increasing — in 2018 there were over 53,000 cyber security incidents identified. The cost of global cybercrime continues to escalate and is upwards of US$3tr according to 2015 data. US publicly traded companies report business risks in their financial reports filed with the Securities and Exchange Commission (SEC) based on guidance provided on cyber reporting. Additionally, there have been several highly visible public company cyberattacks (eg Sony, Target, Home Depot, Yahoo) in the news. Using the Wharton Research Data Services system for analysing SEC reports, a time series analysis was conducted of US publicly traded companies which submitted SEC filings identifying cyber as a risk from 2002 through 2018. We find that 2.8 per cent of companies identify cyber risk as one of their business risk concerns in their financial reporting (Form 10-K) for 2017. This paper documents the low cyber risk reporting, analyses causation of companies that are reporting, and identifies obstacles to increased reporting (ie cyber insurance coverage, negative publicity, stock price decrease, contingent legal liability and disincentives to reporting). We conclude that the SEC needs to engage relevant stakeholders (eg public companies, investment firms, regulatory offices, US Department of Homeland Security) to develop a cyber risk framework that provides more consistency in reporting cyber risks.

Keywords: cyber risk; financial risk; cyber resilience oversight; cyber security; cyberthreats; cyber insurance (search for similar items in EconPapers)
JEL-codes: M15 (search for similar items in EconPapers)
Date: 2020
References: Add references at CitEc
Citations:

Downloads: (external link)
https://hstalks.com/article/5407/download/ (application/pdf)
https://hstalks.com/article/5407/ (text/html)
Requires a paid subscription for full access.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:aza:csj000:y:2020:v:3:i:3:p:275-286

Access Statistics for this article

More articles in Cyber Security: A Peer-Reviewed Journal from Henry Stewart Publications
Bibliographic data for series maintained by Henry Stewart Talks ().

 
Page updated 2025-03-19
Handle: RePEc:aza:csj000:y:2020:v:3:i:3:p:275-286