Aug 2026· Corporate Board: role, duties and composition· Vol 22, pp. 78· 1 citation· 23 references
TL;DR
This study examines the quality of cybersecurity governance disclosure and the extent to which disclosures reflect symbolic compliance rather than substantive accountability and provides evidence that governance structures may create an appearance of accountability without necessarily generating substantive transparency.
Abstract
Corporate boards are increasingly expected to provide transparent oversight of cybersecurity risk; however, formal governance structures do not necessarily translate into substantive accountability. Building on institutional and legitimacy perspectives (Suchman, 1995; Marquis & Qian, 2014), this study examines the quality of cybersecurity governance disclosure (CGD) and the extent to which disclosures reflect symbolic compliance rather than substantive accountability. Using a hand-collected balanced panel of 70 Saudi Exchange-listed firms (350 firm-year observations) covering 2020–2024, the study develops a CGD index based on 20 disclosure items and introduces a boilerplate ratio to distinguish generic disclosure from firm-specific, verifiable reporting. The findings reveal a mean CGD index of 19.59 and a mean boilerplate ratio of 0.785, indicating that CGD remains heavily dominated by symbolic compliance. The COVID-19 shock significantly increased boilerplate disclosure, highlighting the fragility of voluntary governance reporting under systemic stress. In contrast, board size, Big 4 auditor engagement, and firm size show limited explanatory power for disclosure substantiveness. The study contributes to board governance literature by introducing a portable measure of disclosure quality and providing evidence that governance structures may create an appearance of accountability without necessarily generating substantive transparency.
The evidence shows that cybersecurity reporting includes risk, governance, preventive, incident, and mitigative information, which should not be treated as interchangeable constructs, and future research should prioritize disclosure quality, preventive versus mitigative content, and causal evidence on subsequent cybera...
A. Saputra, Suherni Dwi Listiani, Ridwansyah· Proceeding of International...· 0 citations
This study aims to examine the impact of data breach incidents on the tone of corporate disclosures among US publicly listed firms. As digital infrastructure becomes increasingly vital for businesses, cybersecurity breaches present significant risks not only financially but also in shaping corporate narratives....
Fadhila Hamza, T. Arifin, Afsheen Abrar et al.· International Journal of Acc...· 0 citations
This study aims to investigate the relationship between corporate governance and cybersecurity disclosure in Indonesian banks listed on the Indonesia Stock Exchange that adopt a two-tier governance system. Corporate governance is represented by board size (board of directors and board of commissioners), government...
Aditya Pandu Wicaksono, Layly Rahmawati· Information & Computer S...· 0 citations
The study provides new empirical evidence that cybersecurity and data governance constitute strategic board responsibilities with significant sustainability implications in the digital era, and highlights digital risk governance as a key previously underexplored governance mechanism linking board-level cybersecurity ov...
Syed Amjad Hussain· Corporate Governance : The i...· 0 citations
This editorial introduces the Special Issue on “Corporate Governance and Evolving Corporate Disclosures” and advances a framework for understanding how governance structures and disclosure practices co‐evolve in response to regulatory reforms, stakeholder pressures, and technological change. We conceptualize disc...
V. Athanasakou, Bjørn N. Jørgensen, Gerardo Pérez Cavazos et al.· Corporate governance: An Int...· 0 citations
Islamic banking disclosure is a distinctive accountability mechanism because Islamic banks must explain both financial performance and compliance with Shariah principles. This study aims to synthesize how governance structures, regulatory frameworks, measurement approaches, and emerging reporting issues shape disclosur...
Tomi Erlangga· Proceeding of International...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.