This paper provides evidence of the impact of the 2023 U.S. Security and Exchange Commission (SEC) disclosure rules requiring registrants to disclose their approach toward Cybersecurity Risk Management (CRM) in Item 1C (Cybersecurity) of Form 10-K. Specifically, the paper investigates how Material Weaknesses in Internal Control (MWIC) influence a firm’s decision to disclose the integration of its CRM system into its Enterprise Risk Management (ERM) framework in Item 1C. The empirical analysis indicates that firms reporting MWIC are significantly less likely to disclose in Item 1C the fact that they integrated their CRM system into their ERM framework compared to companies that do not report any MWIC. However, companies reporting both IT MWIC and non-IT MWIC are significantly more likely to disclose in Item 1C the fact that they integrated their cyber risk management systems into their overall enterprise risk management framework compared to companies only reporting non-IT MWIC.
Committee of Sponsoring Organizations of the Treadway Commission (COSO) (2004) Enterprise Risk Management—Integrated Framework, Executive Summary.
Committee of Sponsoring Organizations of the Treadway Commission (COSO) (2017) Enterprise Risk Management: Integrating with Strategy and Performance, Executive Summary.
Securities and Exchange Commission (2023) Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure. https://www.sec.gov/files/rules/final/2023/33-11216.pdf
Committee of Sponsoring Organizations of the Treadway Commission (COSO) (2013) Internal Control—Integrated Framework, Executive Summary.
Gordon, L.A. (2007) Incentives for Improving Cybersecurity in the Private Sector: A Cost-Benefit Perspective, Congressional Testimony before Homeland Security Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology. Congressional Record. https://www.govinfo.gov/content/pkg/CHRG-110hhrg48977/html/CHRG-110hhrg48977.htm
Gordon, L.A., Loeb, M.P., Lucyshyn, W. and Zhou, L. (2018) Empirical Evidence on the Determinants of Cybersecurity Investments in Private Sector Firms. Journal of Information Security , 9, 133-153. https://doi.org/10.4236/jis.2018.92010
Allianz Commercial (2024) Allianz Risk Barometer: Identifying the Major Business Risks for 2024. 1-51. https://commercial.allianz.com/content/dam/onemarketing/commercial/commercial/reports/Allianz-Risk-Barometer-2024.pdf
Gordon, L.A., Loeb, M.P., Zhou, L. and Wilford, A.L. (2024) Empirical Evidence on Disclosing Cyber Breaches in an 8-K Report: Initial Exploratory Evidence. Journal of Accounting and Public Policy , 46, Article ID: 107226. https://doi.org/10.1016/j.jaccpubpol.2024.107226
Gordon, L.A., Loeb, M.P. and Zhou, L. (2020) Integrating Cost-Benefit Analysis into the NIST Cybersecurity Framework via the Gordon-Loeb Model. Journal of Cybersecurity , 6, 1-8. https://doi.org/10.1093/cybsec/tyaa005
Bush, G. (2003) The White House. National Strategy to Secure Cyber-Space. https://www.cisa.gov/sites/default/files/publications/cyberspace_strategy.pdf
Obama, B. (2013) Executive Order 13636—Improving Critical Infrastructure Cybersecurity. https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity
Trump, D. (2017) Executive Order 13800—Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. https://www.federalregister.gov/documents/2017/05/16/2017-10004/strengthening-the-cybersecurity-of-federal-networks-and-critical-infrastructure
Biden, J. (2021) Statement by President Joe Biden on Cybersecurity Awareness Month. https://bidenwhitehouse.archives.gov/briefing-room/statements-releases/2021/10/01/statement-by-president-joe-biden-on-cybersecurity-awareness-month/
Audit Analytics (2016) Cybersecurity Disclosure in Risk Factors. https://blog.auditanalytics.com/cybersecurity-disclosures-in-risk-factors/
Amir, E., Levi, S. and Livne, T. (2018) Do Firms Underreport Information on Cyber-Attacks? Evidence from Capital Markets. Review of Accounting Studies , 23, 1177-1206. https://doi.org/10.1007/s11142-018-9452-4
Securities and Exchange Commission (2018) Commission Statement and Guidance on Public Company Cybersecurity Disclosures. https://www.sec.gov/files/rules/interp/2018/33-10459.pdf
Campbell, K., Gordon, L.A., Loeb, M.P. and Zhou, L. (2003) The Economic Cost of Publicly Announced Information Security Breaches: Empirical Evidence from the Stock Market. Journal of Computer Security , 11, 431-448. https://doi.org/10.3233/jcs-2003-11308
Hovav, A. and D'Arcy, J. (2003) The Impact of Denial‐of‐Service Attack Announcements on the Market Value of Firms. Risk Management and Insurance Review , 6, 97-121. https://doi.org/10.1046/j.1098-1616.2003.026.x
Kannan, K., Rees, J. and Sridhar, S. (2007) Market Reactions to Information Security Breach Announcements: An Empirical Analysis. International Journal of Electronic Commerce , 12, 69-91. https://doi.org/10.2753/jec1086-4415120103
Gordon, L.A., Loeb, M.P. and Zhou, L. (2011) The Impact of Information Security Breaches: Has There Been a Downward Shift in Costs? Journal of Computer Security , 19, 33-56. https://doi.org/10.3233/jcs-2009-0398
Hilary, G., Segal, B. and Zhang, M.H. (2016) Cyber-Risk Disclosure: Who Cares? Georgetown McDonough School of Business Research Paper. https://doi.org/10.2139/ssrn.2852519
Spanos, G. and Angelis, L. (2016) The Impact of Information Security Events to the Stock Market: A Systematic Literature Review. Computers & Security , 58, 216-229. https://doi.org/10.1016/j.cose.2015.12.006
Richardson, V.J., Smith, R.E. and Watson, M.W. (2019) Much Ado about Nothing: The (Lack of) Economic Impact of Data Privacy Breaches. Journal of Information Systems , 33, 227-265. https://doi.org/10.2308/isys-52379
Cohen, J., Krishnamoorthy, G. and Wright, A. (2017) Enterprise Risk Management and the Financial Reporting Process: The Experiences of Audit Committee Members, CFOs, and External Auditors. Contemporary Accounting Research , 34, 1178-1209. https://doi.org/10.1111/1911-3846.12294
Rosati, P., Gogolin, F. and Lynn, T. (2020) Cyber-Security Incidents and Audit Quality. European Accounting Review , 31, 701-728. https://doi.org/10.1080/09638180.2020.1856162