Are there trade-offs with mandating timely disclosure of cybersecurity incidents? Evidence from state-level data breach disclosure laws

被引:5
|
作者
Ashraf, Musaib [1 ]
Jiang, John [1 ]
Wang, Isabel Yanyan [1 ]
机构
[1] Michigan State Univ, Business Complex 632 Bogue St Rm N270, E Lansing, MI 48824 USA
来源
关键词
Cybersecurity; Data breach; Disclosure; Regulation; Disclosure deadline; U.S. Securities and Exchange Commission (SEC); Data breach disclosure laws; Information technology;
D O I
10.1016/j.jfds.2022.08.001
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
On March 23, 2022, the SEC proposed that firms publicly disclose their cybersecurity incidents within four days of discovery. In the U.S., state-level data breach disclosure laws require firms to disclose the occurrence of a data breach, with some mandating disclosure within a deadline while others do not. Exploiting this state-level variation in disclosure deadlines, we find that, when facing a deadline, firms disclose a data breach 90 percent faster but are 58 percent less likely to disclose breach details. Investors respond negatively to delayed breach disclosures but are forgiving of a delay when it is used to gather more breach details. Our study highlights the trade-offs of mandating a disclosure deadline for cybersecurity incidents. (c) 2022 The Authors. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:202 / 213
页数:12
相关论文
共 45 条