← Back to full report

Cybersecurity Risk Disclosure by Publicly Listed Firms: State, Drivers, and Consequences

One-Page Summary

Dr Yuqian Zhang · July 2026

What This Report Is About

This report examines how publicly listed firms disclose cybersecurity risks after the SEC introduced mandatory rules in July 2023. It covers the regulatory landscape in the United States, the European Union, and globally, and analyses what firms actually disclose, what drives their disclosure choices, and how markets respond.

The SEC rules represent the most significant expansion of mandatory non-financial risk disclosure since the Sarbanes-Oxley Act of 2002. They require firms to report material cybersecurity incidents within four business days and to describe their risk management and governance practices in annual filings.

Key Findings

Materiality is the central challenge. In the first year, 55 distinct cyber incidents triggered SEC filings. Over half of these filings characterised materiality as "undetermined" or gave mixed signals across multiple filings. Only about 15 per cent of filings provided dollar amounts or person-count quantification. This suggests firms and their advisors are still working out what "material" means in the cybersecurity context.
Regulatory fragmentation raises costs for multinational firms. The SEC requires disclosure within four business days of materiality determination. The EU NIS2 Directive requires 24-hour early warning. The EU DORA regulation requires initial notification within four hours, the strictest timeline globally. A firm operating across these jurisdictions faces inconsistent and overlapping obligations.
Cybersecurity disclosure affects the cost of capital. Academic research shows that post-breach firms pay about 30 basis points more on bank loans. High-cybersecurity-risk firms earn an 8.3 per cent annual equity premium. The average data breach cost reached a record USD 4.88 million in 2024.

Key Statistics

55 distinct cyber incidents triggered SEC filings in the first year (to January 2025)
12 days on average from detection to filing; about half of firms file within 4 business days
Only about 15% of filings include dollar or person-count quantification
14% of filings describe incidents as material; 33% as immaterial; 28% as undetermined
USD 4.88 million: average data breach cost in 2024 (record high)
8.3% annual equity risk premium for high-cybersecurity-risk firms
Ransomware appeared in 44% of breaches, a 37% increase from the prior year
Third-party involvement in breaches doubled from 15% to 30%
USD 15.3 billion in global cyber insurance premiums in 2024
68% of S&P 100 companies assign full board responsibility for ERM including cybersecurity

Regulatory and Enforcement Landscape

The SEC has signalled it will enforce these rules. In October 2024, the SEC charged four companies for misleading disclosures related to the SolarWinds breach, and in October 2023 it charged SolarWinds and its CISO personally with civil fraud. The message is clear: cybersecurity governance representations are within the enforcement remit, and individual officers can be held personally accountable.

In the EU, NIS2 covers 18 sectors and DORA covers 21 categories of financial entities. Penalties can reach EUR 10 million or 2 per cent of global annual turnover for essential entities under NIS2.

Why It Matters

Cybersecurity disclosure sits at the intersection of accounting, regulation, and corporate governance. As breach costs rise and ransomware evolves into a systemic economic threat (projected to cause USD 265 billion in annual damages by 2031), understanding what firms disclose, why they disclose it, and how markets process that information is of first-order importance for investors, regulators, and corporate boards.

The report provides 13 interactive data visualisations, downloadable datasets, and a structured research agenda for scholars interested in this area.