EconPapers    
Economics at your fingertips  
 

Is Cybersecurity Risk Factor Disclosure Informative? Evidence from Disclosures Following a Data Breach

Jing Chen (), Elaine Henry () and Xi Jiang ()
Additional contact information
Jing Chen: Stevens Institute of Technology
Elaine Henry: Stevens Institute of Technology
Xi Jiang: Stevens Institute of Technology

Journal of Business Ethics, 2023, vol. 187, issue 1, No 11, 199-224

Abstract: Abstract By examining managers’ decisions about disclosing updated assessments of firms’ risks, we present evidence that the risk factor disclosures are informative. We use the setting of cybersecurity risk factor disclosures after a data breach because data breaches, especially severe breaches, serve as a natural experiment where an exogenous shock to managers’ assessment of their firm’s cybersecurity risks occurs. We analyze the topic from the perspective of two different theoretical lenses: the economic lens of optimal risk exposure and the ethical lens of stakeholder theory. Using a sample of firms experiencing data breaches, we find that firms experiencing a data breach increase the amount of cybersecurity risk factor disclosures compared to matched firms with no data breach. Further investigation reveals that the severity of data breaches affects the results; cybersecurity risk factor disclosures increase only after severe data breaches. While there is no significant market reaction if breached firms’ subsequent annual reports include increased cybersecurity risk factor disclosures, a significant negative market reaction occurs if breached firms decrease cybersecurity risk factor disclosures, regardless of the severity of the breach, implying that the market anticipates increased disclosures after data breaches.

Keywords: Cybersecurity risk factor disclosures; Cyber business ethics; Data breach (search for similar items in EconPapers)
Date: 2023
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (3)

Downloads: (external link)
http://link.springer.com/10.1007/s10551-022-05107-z Abstract (text/html)
Access to full text is restricted to subscribers.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:kap:jbuset:v:187:y:2023:i:1:d:10.1007_s10551-022-05107-z

Ordering information: This journal article can be ordered from
http://www.springer. ... cs/journal/10551/PS2

DOI: 10.1007/s10551-022-05107-z

Access Statistics for this article

Journal of Business Ethics is currently edited by Michelle Greenwood and R. Edward Freeman

More articles in Journal of Business Ethics from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().

 
Page updated 2025-03-19
Handle: RePEc:kap:jbuset:v:187:y:2023:i:1:d:10.1007_s10551-022-05107-z