Board effectiveness and cybersecurity disclosure | SpringerLink
This study explores the impact of board effectiveness on cybersecurity-related disclosure. Based on a sample of 300 firm-years consisting of the largest Canadian listed companies over a period of five years, we find evidence that board effectiveness positively affects a firm’s decision to disclose cybersecurity information, and board independence and financial expertise have a positive impact on the amount of this disclosure. Independent members of the board, acting as a governance and oversight mechanism, significantly increase the disclosure of cybersecurity risks in the company’s financial statements. The board has a fiduciary role to monitor management and board members’ financial expertise contributes to risk assessment and management. Cybersecurity, as an emerging governance topic, demands multiple areas of expertise in technical, ethical, and financial areas. Board members should be continually trained to be aware of the evolution and diversification of business risks and should have appropriate skills and competencies to manage them. Our findings shed light on the positive impact of board members’ financial expertise on the volume of cybersecurity disclosure. However, board size appears to have no impact on this amount, possibly because few board members have cybersecurity expertise.
References Abeysekera, I. (2010). The influence of board size on intellectual capital disclosure by Kenyan listed firms.Journal of intellectual capital Abraham, S., & Cox, P. (2007). Analysing the determinants of narrative risk information in UK FTSE 100 annual reports. The British Accounting Review, 39(3), 227–248 Akerlof, G. A. (1978). The market for “lemons”: Quality uncertainty and the market mechanism. Uncertainty in economics (pp. 235–251). Elsevier Allegrini, M., & Greco, G. (2013). Corporate boards, audit committees and voluntary disclosure: Evidence from Italian listed…
saved by
related reading
- SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companiessec.gov
- Security incident disclosure — July 2026huggingface.co
- Cyber Safety Board Never Probed Causes of SolarWinds Breach — ProPublicapropublica.org
- The Letter - Stop Hacklore!hacklore.org
- Translation: CAC Announces 'Cybersecurity Review' of Ride-Hailing Giant Didi, Just After Its IPO - DigiChinadigichina.stanford.edu
- Frontier AI Cybersecurity Observatorycybergym.io
- Bill Text - SB-253 Climate Corporate Data Accountability Act.leginfo.legislature.ca.gov
- Cloud CISO Perspectives: Our 2024 Cybersecurity Forecast report | Google Cloud Blogcloud.google.com
- Keeping Oxford secure: what we can all do to protect the University from cyber threatsweb.archive.org
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- The dark side of the moon: demystifying cybersecurity business management for CISOs and security practitionersventureinsecurity.net
- Carbon Disclosure Project - Wikipediaen.wikipedia.org