{"title":"XBRL reporting in firms with data breach incidents","authors":"Wanying Jiang, Chunhao Xu, Roy Wayne Counts","doi":"10.1002/jcaf.22701","DOIUrl":null,"url":null,"abstract":"<p>The Securities and Exchange Commission (SEC) adopted new rules mandating that firms disclose cybersecurity incidents and risk management procedures for inline XBRL reporting, highlighting the regulator's concern about firms’ response to data breaches. In this study, we examine whether firms use XBRL strategically to hinder external stakeholders from understanding the impact of announced data breaches. We find that firm XBRL filing complexity increases following data breaches. Further investigation suggests that the increased XBRL complexity is concentrated on financial statement note tags instead of financial statement tags. The findings imply that firms with data breach incidents are likely to increase XBRL reporting complexity to mitigate stock market reactions. We also find that analysts following moderate the relationship between the data breach and XBRL reporting timeliness. These findings provide empirical evidence about XBRL reporting changes after data breach incidents and contribute to cybersecurity literature and XBRL filing regulation.</p>","PeriodicalId":0,"journal":{"name":"","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2024-02-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/jcaf.22701","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The Securities and Exchange Commission (SEC) adopted new rules mandating that firms disclose cybersecurity incidents and risk management procedures for inline XBRL reporting, highlighting the regulator's concern about firms’ response to data breaches. In this study, we examine whether firms use XBRL strategically to hinder external stakeholders from understanding the impact of announced data breaches. We find that firm XBRL filing complexity increases following data breaches. Further investigation suggests that the increased XBRL complexity is concentrated on financial statement note tags instead of financial statement tags. The findings imply that firms with data breach incidents are likely to increase XBRL reporting complexity to mitigate stock market reactions. We also find that analysts following moderate the relationship between the data breach and XBRL reporting timeliness. These findings provide empirical evidence about XBRL reporting changes after data breach incidents and contribute to cybersecurity literature and XBRL filing regulation.