inklap

Investigating the impact of publicly announced information security breaches on corporate risk factor disclosure tendencies

Sandra J Cereola, Joanna Dynowska · Journal of Cybersecurity Education, Research and Practice · 2019

As the reported number of data breaches increase and senators push for more disclosure regulation, the SEC staff issued a guidance in 2011 on disclosure obligations relating to cybersecurity risks and incidents. More recently, on February 26, 2018 the SEC Commission issued interpretive guidance to help assist public companies prepare disclosures regarding cybersecurity risks and incidents. As reported incidents of cybersecurity breaches occur, investors are concerned about the risks associated with these incidents and the impact they may have on financial performance. Although the SEC staff guidance warns public companies to make timely disclosure, recognizing the threat that cybercrime poses to investors in the public markets, it does not go far enough to institute direct measures that would compel companies to reveal the nature and scope of a cybersecurity breach. In light of the lack of specific guidance on cybersecurity disclosure, the aim of this study is to develop a better understanding of the cybersecurity disclosure landscape. The purpose of this study is phenomenological in nature, designed to assess the impact of the 2011 SEC staff guidance on the disclosure of cybersecu

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً