Cybersecurity has become one of the most significant governance challenges facing corporate boards. Cyber incidents are no longer isolated disruptions; they are recurring threats with material financial, reputational, operational, and regulatory consequences (Agarwal & Zaman, 2026; Agarwal et al., 2025). Evidence shows that attacks involving personal financial data can generate shareholder wealth losses well beyond direct remediation costs, particularly where boards have not previously engaged with risk management (Kamiya et al., 2021). Cyber risk is also increasingly reflected in equity pricing (Florackis et al., 2023).
Regulators have responded by placing greater responsibility on firms and their boards. In the United States, Securities and Exchange Commission rules effective from December 2023 require listed companies to disclose material cyber incidents within four business days and to report annually on cybersecurity risk management, strategy, and governance. The EU’s NIS2 Directive makes boards directly accountable for approving and overseeing cyber risk management measures, while Australia’s Security of Critical Infrastructure Act has moved in a similar direction. These developments provide a valuable cross-jurisdictional setting for examining how regulation shapes cybersecurity governance and accountability.
Recent evidence has intensified concerns about the effectiveness of contemporary cybersecurity governance. Lowry et al. (2026) demonstrate that directors lacking cybersecurity expertise may engage in the same formal oversight activities as their expert counterparts, yet the substance of that oversight is often largely symbolic. Extending this concern, Gao and Calderon (2025) show that governance arrangements shape the nature and quality of firms’ cybersecurity disclosures. However, Haapamäki and Sihvonen (2026), in their analysis of 3,440 mandatory Item 1C disclosures, find little market response and no meaningful association between disclosure characteristics and firms’ underlying cyber exposure. Collectively, these studies suggest a significant disconnect between regulatory compliance and effective governance. Firms may satisfy disclosure obligations and exhibit the formal structures of oversight, while boards remain insufficiently equipped to ensure that cybersecurity reporting is informative, credible, and capable of delivering genuine accountability.
List of topic areas
Theme 1: Board oversight and cybersecurity governance
- Board composition, expertise, and cyber risk oversight, including whether technology or cybersecurity expertise improves outcomes beyond symbolic compliance
- Gender, demographic, and structural board diversity and cybersecurity governance
- CEO and top management team characteristics and cybersecurity investment decisions
- Co-opted boards, managerial entrenchment, and cybersecurity risk-taking
- The role of audit committees in overseeing cyber risk and IT controls
Theme 2: Cyber risk disclosure and reporting
- Voluntary and mandatory cyber risk disclosure under the SEC rules, the EU NIS2 Directive, and Australia’s Security of Critical Infrastructure Act
- The quality, completeness, and informativeness of cybersecurity disclosures in annual reports and regulatory filings
- Incident reporting through current-report channels such as Form 8-K
- “Cyber-washing” and the distinction between performative and substantive cybersecurity disclosure
- Data breach notification laws and their effects on disclosure behaviour, accountability, and stakeholder
Theme 3: Assurance, audit, and internal control
- The role of auditors and third-party specialists in verifying cyber risk disclosures
- Internal control quality as both a determinant and a consequence of breach events
- Audit committee and auditor interaction over IT general controls
- Assurance standards and practitioner capability for cybersecurity reporting
Theme 4: Regulatory frameworks and stakeholder implications
- Comparative analysis of national and supranational cybersecurity governance regimes
- Stakeholder theory perspectives on corporate obligations in the face of cyber risk, including investor and supply chain trust
- The role of media, activist investors, and NGOs in pressuring firms on cybersecurity accountability
- Emerging issues including AI governance, cloud concentration risk, and quantum computing threats
- Small and medium enterprises and their differential governance capacity in managing cyber risk
Submissions Information
Submissions are made using ScholarOne Manuscripts. Registration and access are available at: https://mc.manuscriptcentral.com/cg
Author guidelines must be strictly followed. Please see: https://www.emeraldgrouppublishing.com/journal/cg#author-guidelines
Authors should select (from the drop-down menu) the special issue title at the appropriate step in the submission process, i.e. in response to ““Please select the issue you are submitting to”.
Submitted articles must not have been previously published, nor should they be under consideration for publication anywhere else, while under review for this journal.
Key deadlines
Opening date for manuscripts submissions: 1 December 2026
Closing date for manuscripts submission: 31 March 2027
For more details refer here



