Security breaches and modifications on cybersecurity disclosures

Jacob Peng, Chang-Wei Li
{"title":"Security breaches and modifications on cybersecurity disclosures","authors":"Jacob Peng, Chang-Wei Li","doi":"10.24818/jamis.2022.03007","DOIUrl":null,"url":null,"abstract":"Research Question: How do firms approach their cybersecurity disclosure obligations, especially for those who experienced a cyber-attack? Prior research has found that year-after-year modification on textual disclosures adds more appreciable information that makes it more relevant. But do firms provide meaningful disclosures to promote market transparency? Motivation: Because of growing cybersecurity threats in recent years, the U.S. Securities and Exchange Commission (SEC) has issued several regulations and guidance that emphasized on the disclosure of material information on cybersecurity. Given that the mandatory risk factor disclosures in SEC Form 10-K is the first place firms are encouraged to disclose cybersecurity-related assessment, it is important to examine how firms approach their disclosure expectations. Idea: To examine whether firms respond to cyber-attacks with meaningful disclosures, we use the Vector Space Model (VSM) to calculate disclosure modifications before and after major cyber-attack incident. Data: We extracted cybersecurity breach incidents from the Data Breach Database, a centralized and global database of data breaches maintained by a leading security company. In addition, we use the SEC data depository to find firms’ 10-K disclosures. Findings: We find that firms modify their cybersecurity disclosures by increasing the quantity of disclosures, but not necessarily the quality of disclosures as measured by document similarity. Furthermore, we find partial evidence that the degree of modification is positively associated with the severity of cyber-attacks. Contribution: Our evidence suggests that firms tend to use boilerplate language to disclose cybersecurity-related issues. This finding is consistent with prior research. That is, consistent with prior literature, the information content in public company 10-Ks is limited. We find that this seems to be the case as well when it comes to cybersecurity disclosures.","PeriodicalId":14716,"journal":{"name":"Journal of Accounting and Management Information Systems","volume":"35 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2022-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Accounting and Management Information Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.24818/jamis.2022.03007","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Research Question: How do firms approach their cybersecurity disclosure obligations, especially for those who experienced a cyber-attack? Prior research has found that year-after-year modification on textual disclosures adds more appreciable information that makes it more relevant. But do firms provide meaningful disclosures to promote market transparency? Motivation: Because of growing cybersecurity threats in recent years, the U.S. Securities and Exchange Commission (SEC) has issued several regulations and guidance that emphasized on the disclosure of material information on cybersecurity. Given that the mandatory risk factor disclosures in SEC Form 10-K is the first place firms are encouraged to disclose cybersecurity-related assessment, it is important to examine how firms approach their disclosure expectations. Idea: To examine whether firms respond to cyber-attacks with meaningful disclosures, we use the Vector Space Model (VSM) to calculate disclosure modifications before and after major cyber-attack incident. Data: We extracted cybersecurity breach incidents from the Data Breach Database, a centralized and global database of data breaches maintained by a leading security company. In addition, we use the SEC data depository to find firms’ 10-K disclosures. Findings: We find that firms modify their cybersecurity disclosures by increasing the quantity of disclosures, but not necessarily the quality of disclosures as measured by document similarity. Furthermore, we find partial evidence that the degree of modification is positively associated with the severity of cyber-attacks. Contribution: Our evidence suggests that firms tend to use boilerplate language to disclose cybersecurity-related issues. This finding is consistent with prior research. That is, consistent with prior literature, the information content in public company 10-Ks is limited. We find that this seems to be the case as well when it comes to cybersecurity disclosures.
安全漏洞和网络安全披露的修改
研究问题:企业如何履行其网络安全信息披露义务,特别是对那些经历过网络攻击的企业?先前的研究发现,年复一年对文本披露的修改增加了更多有价值的信息,使其更具相关性。但是,公司是否提供了有意义的信息披露来提高市场透明度呢?动机:由于近年来网络安全威胁不断增加,美国证券交易委员会(SEC)发布了几项法规和指南,强调了网络安全重大信息的披露。鉴于SEC表格10-K中的强制性风险因素披露是鼓励公司披露网络安全相关评估的第一个地方,因此研究公司如何接近其披露期望是很重要的。思路:为了检验企业是否以有意义的披露来应对网络攻击,我们使用向量空间模型(VSM)来计算重大网络攻击事件前后的披露修改。数据:我们从数据泄露数据库中提取网络安全泄露事件,数据泄露数据库是由一家领先的安全公司维护的集中的全球数据泄露数据库。此外,我们使用SEC数据存储库来查找公司的10-K披露。研究结果:我们发现,公司通过增加披露的数量来修改其网络安全披露,但不一定通过文件相似度来衡量披露的质量。此外,我们发现部分证据表明,修改程度与网络攻击的严重程度呈正相关。贡献:我们的证据表明,公司倾向于使用模板语言来披露与网络安全相关的问题。这一发现与先前的研究一致。也就是说,与以往文献一致,上市公司10- k的信息内容是有限的。我们发现,在网络安全披露方面,情况似乎也是如此。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信