Cybersecurity disclosure in the UK: the role of board attributes and female director critical mass

2Citations
Citations of this article
49Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Purpose – This study examines the extent of cybersecurity disclosure (CSD) and whether board attributes influence the degree of CSD among UK firms. It further investigates through the lens of critical mass theory whether the impact of board gender diversity varies with the level of representation. Design/methodology/approach – The sample comprises FTSE 100 companies listed in the UK from 2015 to 2021. A CSD index is developed using automated content analysis of cybersecurity- and data security-related terms in annual reports reflecting firms’ exposure to cyber safeguards. We test hypotheses and conduct a battery of robustness tests to validate our findings. Findings – The results show that board size is positively associated with CSD. Firms with a dedicated cybersecurity committee provide more forward-looking information on cyber risks and mitigation measures. While gender diversity overall does not significantly influence CSD, boards with three or more female directors show a strong positive influence, supporting the critical mass effect of their representation. Robustness tests affirm the reliability of these results. Research limitations/implications – This study contributes to the growing cybersecurity literature by applying the resource-based view to show how board structure and specialized committees reduce cyber-related information asymmetry. In the absence of specific regulatory guidelines, institutional pressures appear to motivate boards to enhance CSD for integrated reporting purposes. The findings also emphasize that at least three female directors are necessary to achieve meaningful influence on CSD. Originality/value – As CSD remains voluntary in the UK, this study is among the first to empirically investigate the impact of board attributes on such disclosures within FTSE 100 firms. It uniquely identifies the positive role of directors with expertise in cybersecurity and artificial intelligence in enhancing disclosure levels. It also offers insights into gender diversity by revealing that low female representation may reflect tokenism, as it does not significantly influence CSD.

Cite

CITATION STYLE

APA

Afroze, D., Ghosh, R., & Dey, P. K. (2025). Cybersecurity disclosure in the UK: the role of board attributes and female director critical mass. Journal of Enterprise Information Management, 1–30. https://doi.org/10.1108/JEIM-04-2025-0311

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free