Implications of Enhanced Cybersecurity Risk Management Reporting and Independent Assurance

10Citations
Citations of this article
53Readers
Mendeley users who have this article in their library.

Abstract

According to the World Economic Forum (WEF) (2022), cybersecurity risk is the most immediate and financially material sustainability risk that organizations face. Companies experience significant financial and reputational losses in the market after a cyberattack. However, companies are only required to disclose a trivial amount of information about their cybersecurity risk management efforts (SEC 2014; Newman 2018). This paper summarizes Frank, Grenier, and Pyzoha (2019), which examines whether voluntarily providing additional disclosures regarding a company’s cybersecurity efforts, with or without assurance, increases investment attractiveness. Absent assurance, voluntary disclosures about the nature and effectiveness of cybersecurity efforts are sufficient to increase investment attractiveness for companies that have not (versus have) disclosed a prior cyberattack, as investors are less likely to question the disclosure’s reliability. Assurance provides a greater benefit to companies that have (versus have not) disclosed a prior cyberattack, as they benefit more from the reliability enhancement of assurance.

Cite

CITATION STYLE

APA

Frank, M. L., Grenier, J. H., Pyzoha, J. S., & Zielinski, N. B. (2023). Implications of Enhanced Cybersecurity Risk Management Reporting and Independent Assurance. Current Issues in Auditing, 17(1), P11–P18. https://doi.org/10.2308/CIIA-2022-018

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free