Board governance mechanisms and cybersecurity disclosure quality: Evidence on symbolic versus substantive accountability
Corporate boards are increasingly expected to provide transparent oversight of cybersecurity risk; however, formal governance structures do not necessarily translate into substantive accountability. Building on institutional and legitimacy perspectives (Suchman, 1995; Marquis & Qian, 2014), this study examines the quality of cybersecurity governance disclosure (CGD) and the extent to which disclosures reflect symbolic compliance rather than substantive accountability. Using a hand-collected balanced panel of 70 Saudi Exchange-listed firms (350 firm-year observations) covering 2020–2024, the study develops a CGD index based on 20 disclosure items and introduces a boilerplate ratio to distinguish generic disclosure from firm-specific, verifiable reporting. The findings reveal a mean CGD index of 19.59 and a mean boilerplate ratio of 0.785, indicating that CGD remains heavily dominated by symbolic compliance. The COVID-19 shock significantly increased boilerplate disclosure, highlighting the fragility of voluntary governance reporting under systemic stress. In contrast, board size, Big 4 auditor engagement, and firm size show limited explanatory power for disclosure substantiveness. The study contributes to board governance literature by introducing a portable measure of disclosure quality and providing evidence that governance structures may create an appearance of accountability without necessarily generating substantive transparency.