Cybersecurity disclosure in the financial sector: an examination of the influence of incident exposure, governance practices, and regulatory context

0Citations
Citations of this article
19Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Cybersecurity has become a critical concern for organizations, prompting increasing demands from various stakeholders for more comprehensive disclosures. This study investigates how banks disclose cybersecurity information, focusing on key drivers, such as regulatory changes, incidents and governance practices. Using legitimacy theory, the research examines factors that influence cybersecurity disclosure practices, including risk exposure, management strategies, and investments. Banks’ annual reports were analyzed using a custom index and content analysis combined with statistical techniques. The findings highlight the need for more targeted and comprehensive cybersecurity regulations, particularly regarding investment and incident disclosure. The study also highlights the importance of gender diversity on boards and media coverage of cyber incidents for greater transparency. The study advocates for financial institutions to implement mechanisms that promote transparency and recommends that regulators enforce specific disclosure requirements, as voluntary reporting is often insufficient.

Cite

CITATION STYLE

APA

López, F. A., Jara-Sarrúa, L., Morales-Parada, F., & Palos-Sánchez, P. R. (2026). Cybersecurity disclosure in the financial sector: an examination of the influence of incident exposure, governance practices, and regulatory context. Electronic Commerce Research. https://doi.org/10.1007/s10660-025-10081-5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free