Are there trade-offs with mandating timely disclosure of cybersecurity incidents? Evidence from state-level data breach disclosure laws

被引:5
作者
Ashraf, Musaib [1 ]
Jiang, John [1 ]
Wang, Isabel Yanyan [1 ]
机构
[1] Michigan State Univ, Business Complex 632 Bogue St Rm N270, E Lansing, MI 48824 USA
关键词
Cybersecurity; Data breach; Disclosure; Regulation; Disclosure deadline; U.S. Securities and Exchange Commission (SEC); Data breach disclosure laws; Information technology;
D O I
10.1016/j.jfds.2022.08.001
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
On March 23, 2022, the SEC proposed that firms publicly disclose their cybersecurity incidents within four days of discovery. In the U.S., state-level data breach disclosure laws require firms to disclose the occurrence of a data breach, with some mandating disclosure within a deadline while others do not. Exploiting this state-level variation in disclosure deadlines, we find that, when facing a deadline, firms disclose a data breach 90 percent faster but are 58 percent less likely to disclose breach details. Investors respond negatively to delayed breach disclosures but are forgiving of a delay when it is used to gather more breach details. Our study highlights the trade-offs of mandating a disclosure deadline for cybersecurity incidents. (c) 2022 The Authors. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:202 / 213
页数:12
相关论文
共 33 条
[1]  
Abadie A., 2017, 24003 NAT BUR EC RES, DOI DOI 10.3386/W24003
[2]   Do firms underreport information on cyber-attacks? Evidence from capital markets [J].
Amir, Eli ;
Levi, Shai ;
Livne, Tsafrir .
REVIEW OF ACCOUNTING STUDIES, 2018, 23 (03) :1177-1206
[3]  
Ashraf M, 2022, Working paper
[4]  
Audit Analytics, 2022, Audit Analytics cybersecurity data
[5]   Hospital Risk of Data Breaches [J].
Bai, Ge ;
Jiang, John ;
Flasher, Renee .
JAMA INTERNAL MEDICINE, 2017, 177 (06) :878-880
[6]   How much should we trust staggered difference-in-differences estimates? * [J].
Baker, Andrew C. ;
Larcker, David F. ;
Wang, Charles C. Y. .
JOURNAL OF FINANCIAL ECONOMICS, 2022, 144 (02) :370-395
[7]  
BakerHostetler, 2022, Breach notification law interactive map
[8]  
Barrios JohnManuel., 2021, Staggeringly Problematic: A Primer on Staggered DiD for Accounting Researchers
[9]   Enjoying the quiet life? Corporate governance and managerial preferences [J].
Bertrand, M ;
Mullainathan, S .
JOURNAL OF POLITICAL ECONOMY, 2003, 111 (05) :1043-1075
[10]   Shareholder Litigation and Corporate Disclosure: Evidence from Derivative Lawsuits [J].
Bourveau, Thomas ;
Lou, Yun ;
Wang, Rencheng .
JOURNAL OF ACCOUNTING RESEARCH, 2018, 56 (03) :797-842