Firm Transparency of Risk Oversight: An Examination of Cybersecurity Governance Disclosures

Laurie E. Ereddia

Journal of Information Systems2026https://doi.org/10.2308/isys-2024-012article
AJG 1ABDC A
Weight
0.50

Abstract

In this study, I examine board attributes associated with firm transparency of governance over cybersecurity risk (GCR). Using a sample of firms that report cybersecurity as a material risk, I hand collect GCR data from 8,384 proxy statements filed from 2019 to 2021. Surprisingly, I find that only 57 percent of the filings provide stakeholders information about GCR. In multivariate analysis, I find that a firm’s GCR disclosure is positively associated with board size, independence, information technology expertise, and those boards with a higher proportion of “busy” directors. I further find that boards with longer serving directors provide less GCR disclosure. Finally, I find increasing levels of GCR disclosure over the three-year period, suggesting that firms are responding to stakeholder demand for increased transparency. These findings should be helpful to firms looking to benchmark disclosure practices and to the SEC in evaluating the efficacy of existing cybersecurity disclosure guidance. Data Availability: All data are publicly available from the cited sources in the text. JEL Classifications: G32; G34; M15.

Open via your library →

Cite this paper

https://doi.org/https://doi.org/10.2308/isys-2024-012

Or copy a formatted citation

@article{laurie2026,
  title        = {{Firm Transparency of Risk Oversight: An Examination of Cybersecurity Governance Disclosures}},
  author       = {Laurie E. Ereddia},
  journal      = {Journal of Information Systems},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.2308/isys-2024-012},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Firm Transparency of Risk Oversight: An Examination of Cybersecurity Governance Disclosures

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.