Ronald C. W. Tsang
This study conducts a comparative analysis of the information content embedded in mandatory cybersecurity disclosures and their implications for firm financial performance. Focusing on U.S. public companies from 2019 to 2024, the analysis introduces a novel metric, Disclosure Completeness Intensity (DCI), to evaluate the depth and completeness of cybersecurity-related disclosures within two mandated sections of annual reports: Risk Factors (RF) and Management’s Discussion and Analysis (MDA). The findings reveal a negative association between disclosure completeness and future financial performance, suggesting that more comprehensive disclosures may signal heightened underlying risks. Furthermore, cybersecurity disclosures within the RF section exhibit greater informational value than those in the MDA section, as evidenced by a higher incidence of statistically and economically significant relationships with forward-looking performance indicators. This study provides the first empirical evidence differentiating the informativeness of topic-specific cybersecurity disclosures between RF and MDA. The findings offer important regulatory insights, particularly in the context of the SEC’s 2023 final rule on cybersecurity risk disclosure and contribute practical recommendations for enhancing disclosure guidance. Finally, the study highlights fruitful avenues for future research in topic-specific disclosure and cybersecurity governance.