Cybersecurity Governance: Board Oversight, Risk Disclosure, and Stakeholder Accountability in the Digital Age

Closes:

Introduction

Cybersecurity has become one of the most significant governance challenges facing corporate boards. Cyber incidents are no longer isolated disruptions; they are recurring threats with material financial, reputational, operational, and regulatory consequences (Agarwal & Zaman, 2026; Agarwal et al., 2025). Evidence shows that attacks involving personal financial data can generate shareholder wealth losses well beyond direct remediation costs, particularly where boards have not previously engaged with risk management (Kamiya et al., 2021). Cyber risk is also increasingly reflected in equity pricing (Florackis et al., 2023).

Regulators have responded by placing greater responsibility on firms and their boards. In the United States, Securities and Exchange Commission rules effective from December 2023 require listed companies to disclose material cyber incidents within four business days and to report annually on cybersecurity risk management, strategy, and governance. The EU’s NIS2 Directive makes boards directly accountable for approving and overseeing cyber risk management measures, while Australia’s Security of Critical Infrastructure Act has moved in a similar direction. These developments provide a valuable cross-jurisdictional setting for examining how regulation shapes cybersecurity governance and accountability.

However, the evidence base remains fragmented. Liu and Babar’s (2026) systematic review of 203 empirical studies finds that cybersecurity research is dispersed across twelve disciplines and lacks a shared framework. Existing findings are also mixed. Amir et al. (2018) document systematic underreporting of cyber-attacks, while Richardson et al. (2019) find limited economic impact from privacy breaches. Ashraf and Sunder (2023) show that breach disclosure mandates can reduce shareholder risk by prompting genuine managerial action, whereas Obaydin et al. (2024) find that similar laws may increase managerial hoarding of bad news. These inconsistencies suggest that more research is needed on when cybersecurity regulation produces meaningful accountability rather than formal compliance.

Recent evidence has intensified concerns about the effectiveness of contemporary cybersecurity governance. Lowry et al. (2026) demonstrate that directors lacking cybersecurity expertise may engage in the same formal oversight activities as their expert counterparts, yet the substance of that oversight is often largely symbolic. Extending this concern, Gao and Calderon (2025) show that governance arrangements shape the nature and quality of firms’ cybersecurity disclosures. However, Haapamäki and Sihvonen (2026), in their analysis of 3,440 mandatory Item 1C disclosures, find little market response and no meaningful association between disclosure characteristics and firms’ underlying cyber exposure. Collectively, these studies suggest a significant disconnect between regulatory compliance and effective governance. Firms may satisfy disclosure obligations and exhibit the formal structures of oversight, while boards remain insufficiently equipped to ensure that cybersecurity reporting is informative, credible, and capable of delivering genuine accountability.

This Special Issue seeks to address this disconnect by advancing cybersecurity as a governance and accountability challenge rather than merely a technical or disclosure issue. We invite conceptual, empirical, and review contributions from accounting, finance, management, law, information systems, and related disciplines that examine fundamental questions of accountability: Who is answerable for cybersecurity risk, to whom, and through which governance mechanisms? We particularly welcome research that broadens the analytical lens beyond the U.S. context and beyond shareholder-centric perspectives, including studies of comparative regulatory regimes and the accountability implications of cybersecurity for customers, patients, employees, supply-chain partners, and other affected stakeholders.

To support the development of high-quality submissions, a Paper Development Workshop will be hosted by the School of Accounting, Economics and Finance at Curtin University, Perth, in conjunction with the FBL Research Symposium 2026 during the submission period. Workshop details will be circulated through the journal and the professional networks of the guest editors.

 

References:

Agarwal, N., Agarwal, S., Chalwati, A., Sisodia, S., & Trabelsi, S. (2025). Cybersecurity and cost management. The British Accounting Review, 101783.

Agarwal, N., & Zaman, R. (2026). When protection carries a price: Data breach notification laws and trade credit. Available at SSRN 5956345.

Amir, E., Levi, S., & Livne, T. (2018). Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies, 23(3), 1177–1206. https://doi.org/10.1007/s11142-018-9452-4

Ashraf, M., & Sunder, J. (2023). Can shareholders benefit from consumer protection disclosure mandates? Evidence from data breach disclosure laws. The Accounting Review, 98(4), 1–32. https://doi.org/10.2308/TAR-2020-0787

Florackis, C., Louca, C., Michaely, R., & Weber, M. (2023). Cybersecurity risk. The Review of Financial Studies, 36(1), 351–407. https://doi.org/10.1093/rfs/hhac024

Gao, L., & Calderon, T. G. (2025). Cybersecurity risk governance and companies’ cybersecurity risk disclosures in their 10-K filings. Journal of Accounting and Public Policy, 54, 107376. https://doi.org/10.1016/j.jaccpubpol.2025.107376

Haapamäki, E., & Sihvonen, J. (2026). Mandatory cybersecurity disclosure: Early evidence from 10-K reports. International Journal of Accounting Information Systems, 57, 100775. https://doi.org/10.1016/j.accinf.2026.100775

Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019

Liu, C., & Babar, M. A. (2026). Corporate cybersecurity risk and data breaches: A systematic review of empirical research. Australian Journal of Management, 51(1), 62–92. https://doi.org/10.1177/03128962241293658

Lowry, M., Vance, A., & Vance, M. D. (2026). Inexpert supervision: Field evidence on boards’ oversight of cybersecurity. Management Science, 72(2), 783–804. https://doi.org/10.1287/mnsc.2023.04147

Obaydin, I., Xu, L., & Zurbruegg, R. (2024). The unintended cost of data breach notification laws: Evidence from managerial bad news hoarding. Journal of Business Finance & Accounting, 51(9–10), 2709–2736. https://doi.org/10.1111/jbfa.12794

Richardson, V. J., Smith, R. E., & Watson, M. W. (2019). Much ado about nothing: The lack of economic impact of data privacy breaches. Journal of Information Systems, 33(3), 227–265. https://doi.org/10.2308/isys-52379

 

List of topic areas

Theme 1: Board oversight and cybersecurity governance

  • Board composition, expertise, and cyber risk oversight, including whether technology or cybersecurity expertise improves outcomes beyond symbolic compliance
  • Gender, demographic, and structural board diversity and cybersecurity governance
  • CEO and top management team characteristics and cybersecurity investment decisions
  • Co-opted boards, managerial entrenchment, and cybersecurity risk-taking
  • The role of audit committees in overseeing cyber risk and IT controls

Theme 2: Cyber risk disclosure and reporting

  • Voluntary and mandatory cyber risk disclosure under the SEC rules, the EU NIS2 Directive, and Australia's Security of Critical Infrastructure Act
  • The quality, completeness, and informativeness of cybersecurity disclosures in annual reports and regulatory filings
  • Incident reporting through current-report channels such as Form 8-K
  • “Cyber-washing” and the distinction between performative and substantive cybersecurity disclosure
  • Data breach notification laws and their effects on disclosure behaviour, accountability, and stakeholder

Theme 3: Assurance, audit, and internal control

  • The role of auditors and third-party specialists in verifying cyber risk disclosures
  • Internal control quality as both a determinant and a consequence of breach events
  • Audit committee and auditor interaction over IT general controls
  • Assurance standards and practitioner capability for cybersecurity reporting

Theme 4: Regulatory frameworks and stakeholder implications

  • Comparative analysis of national and supranational cybersecurity governance regimes
  • Stakeholder theory perspectives on corporate obligations in the face of cyber risk, including investor and supply chain trust
  • The role of media, activist investors, and NGOs in pressuring firms on cybersecurity accountability
  • Emerging issues including AI governance, cloud concentration risk, and quantum computing threats
  • Small and medium enterprises and their differential governance capacity in managing cyber risk

 

Submissions Information

Submissions are made using ScholarOne Manuscripts. Registration and access are available at: https://mc.manuscriptcentral.com/cg 

Author guidelines must be strictly followed. Please see: https://www.emeraldgrouppublishing.com/journal/cg#author-guidelines 

Authors should select (from the drop-down menu) the special issue title at the appropriate step in the submission process, i.e. in response to ““Please select the issue you are submitting to”.

Submitted articles must not have been previously published, nor should they be under consideration for publication anywhere else, while under review for this journal.

 

Key deadlines

Opening date for manuscripts submissions: 1 December 2026

Closing date for manuscripts submission: 31 March 2027