Researchers analyzed topic-specific cybersecurity disclosures using U.S. SEC guidance, building an index to capture how intensively firms discussed eight cybersecurity categories and how those disclosures were distributed across them. They report large differences across topics and firms in how much information appears.

Across 2019 to 2024, higher disclosure intensity at the topic level was associated with weaker subsequent performance, consistent with disclosures reflecting underlying risk. But the strength of the links depended on placement: risk-factor disclosures tracked next-year profitability and valuation more strongly and consistently than comparable narratives in the Management’s Discussion and Analysis section, while rare details about the probability and scale of future incidents showed limited predictive value.