SEC Cybersecurity Disclosures and Capital Markets

relationships.isAuthorOf

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

Cybersecurity incidents can have substantial financial and reputational consequences for firms, yet disclosure requirements have historically been driven by consumer- rather than investor-focused regulation. I examine whether the SEC’s new cybersecurity disclosure (CSD) rule, which requires public companies to report material cybersecurity incidents on Form 8-K, enhances the timeliness and informativeness of cybersecurity incident disclosures. I find that 8-Ks are filed more quickly than other disclosure channels following incident discovery, and that after the CSD rule, firms are more likely to file an 8-K, consequently disclosing breaches far more quickly following incident discovery. These initial post-rule 8-Ks are shorter and less specific but also more likely to discuss materiality and to have follow-up 8-Ks. Even after controlling for incident severity, the market response to 8-K disclosures is stronger than the market response to other breach disclosures throughout my sample, consistent with higher quality information, reduced information processing costs, or both. Overall, my findings suggest that the SEC’s CSD rule improves the timeliness and informativeness of cybersecurity incident disclosures despite existing non-SEC disclosure requirements, advancing the SEC’s mission to protect investors and promote efficient markets.

Description

Thesis (Ph.D.)--University of Washington, 2026

Citation

DOI