Same cybersecurity topics in different sections of required filings tracked next-year results differently.
Researchers analyzed topic-specific cybersecurity disclosures using U.S. SEC guidance, building an index to capture how intensively firms discussed eight cybersecurity categories and how those disclosures were distributed across them. They report large differences across topics and firms in how much information appears.
Across 2019 to 2024, higher disclosure intensity at the topic level was associated with weaker subsequent performance, consistent with disclosures reflecting underlying risk. But the strength of the links depended on placement: risk-factor disclosures tracked next-year profitability and valuation more strongly and consistently than comparable narratives in the Management’s Discussion and Analysis section, while rare details about the probability and scale of future incidents showed limited predictive value.
Where disclosures are placed
Using 13,800 firm-years from 2019 to 2024, the study found substantial cross-topic differences in required cybersecurity disclosures. Topics discussed more intensely were associated with weaker subsequent performance, which the authors interpret as consistent with disclosures reflecting underlying cybersecurity risk. The association depended on where the same topics were written: disclosures in the Risk Factors section showed stronger, more consistent links to next-year profitability and valuation than analogous narratives in the Management’s Discussion and Analysis section. The analysis suggests operational exposure-related disclosures drove much of these associations, while less frequently disclosed topics—such as the probability and magnitude of future incidents—had limited predictive content. These patterns also differed across industries with different levels of breach exposure.
// Source
International Journal of Accounting Information Systems · 2026 · DOI: 10.1016/j.accinf.2026.100787
Authors: Ronald C. W. Tsang
Institutions: Mercer University