A Proposed Index for Cybersecurity Risk Disclosure and Its Impact on Faithful Representation of Accounting Information
Ahmed I. Sakr, Hanan Hassan Gad Allah, Randa A. MakledAbstract
This study addresses the critical gap in standardised frameworks for cybersecurity risk disclosure a voluntary practice that often results in ambiguous or incomplete reports, leaving financial stakeholders with insufficient information. To bridge this gap, we propose a novel 54-item Cybersecurity Disclosure Index – that distinguishes between incident/risk disclosure – and examine its impact on faithful representation (FR), measured through discretionary accruals. Using data from a set of major telecommunications and fintech companies operating in Egypt between 2020 and 2024, we provide empirical evidence that increased Cyber Risk Disclosure is significantly associated with lower discretionary accruals, suggesting enhanced FR. In contrast, cybersecurity Governance Disclosure shows a positive association with discretionary accruals, indicating that more extensive disclosures may introduce complexity and create opportunities for earnings management. The analysis employs Panel Least Squares (PLS) regression with firm and year fixed effects to address unobserved heterogeneity. The results from the Modified Jones model and a Kothari robustness check confirm the reliability of these findings. The R-squared values of 0.8936 and 0.8935 in the models indicate strong explanatory power, with significant implications for both corporate governance and financial reporting practices. Overall, the proposed Cybersecurity Disclosure Index offers a standardised and transparent framework that advances the field of cybersecurity risk disclosure and contributes significantly to improving both corporate governance and financial reporting practices.