SEC Cybersecurity Disclosures and Capital Markets
Date
relationships.isAuthorOf
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Cybersecurity incidents can have substantial financial and reputational consequences for firms, yet disclosure requirements have historically been driven by consumer- rather than investor-focused regulation. I examine whether the SEC’s new cybersecurity disclosure (CSD) rule, which requires public companies to report material cybersecurity incidents on Form 8-K, enhances the timeliness and informativeness of cybersecurity incident disclosures. I find that 8-Ks are filed more quickly than other disclosure channels following incident discovery, and that after the CSD rule, firms are more likely to file an 8-K, consequently disclosing breaches far more quickly following incident discovery. These initial post-rule 8-Ks are shorter and less specific but also more likely to discuss materiality and to have follow-up 8-Ks. Even after controlling for incident severity, the market response to 8-K disclosures is stronger than the market response to other breach disclosures throughout my sample, consistent with higher quality information, reduced information processing costs, or both. Overall, my findings suggest that the SEC’s CSD rule improves the timeliness and informativeness of cybersecurity incident disclosures despite existing non-SEC disclosure requirements, advancing the SEC’s mission to protect investors and promote efficient markets.
Description
Thesis (Ph.D.)--University of Washington, 2026
