Skip to content

Does corporate governance drive cybersecurity disclosure? Evidence from the Indonesian banks with a two-tier governance system

Aug 2026 · Information & Computer Security · 0 citations · 100 references

Abstract

This study aims to investigate the relationship between corporate governance and cybersecurity disclosure in Indonesian banks listed on the Indonesia Stock Exchange that adopt a two-tier governance system. Corporate governance is represented by board size (board of directors and board of commissioners), government ownership and foreign ownership. This study uses panel data regression technique with a sample of Indonesian banks listed in the Indonesian Stock Exchange from 2019 to 2024. The extent of cybersecurity disclosure is measured using the total number of words related to cybersecurity information, where its data are collected manually from annual reports and/or sustainability reports. The results indicate that boards with greater number of members (board of directors and board of commissioners) can enhance the level of cybersecurity disclosure by Indonesian listed banks. However, the non-monotonic test reports lower positive regression coefficient when banks have an extreme number of board members although it has a significant effect. It indicates that the changes in cybersecurity disclosure are lower due to an excessive number of board members. In addition, the extent of this disclosure is not driven significantly by independent commissioners. In terms of ownership structure, this study finds that banks with government ownership tend to disclose more cybersecurity information. This study also reveals that the higher the percentage of bank shares owned by foreign investors, the greater the level of cybersecurity disclosure. Within the unique features of a two-tier governance system, the study suggests that banks are not necessarily required to appoint more independent commissioners because board of commissioners has played an essential role in supervising the management. On the other hand, banks need to have a higher number of board members to make sure that issues related to cybersecurity have been effectively addressed. However, banks need to understand the ideal number of board members as an excessive number of board members tends to decrease the changes in disclosure level. This study adds to the limited literature on cybersecurity disclosure by investigating the effect of corporate governance. It investigates Indonesian listed banks because Indonesia adopts a two-tier governance system, which is different from previous studies that analyze companies in a country with a one-tier governance system.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.