Skip to content
Conference Open access

Beyond Compliance: A Literature Review of Cybersecurity Disclosure, Corporate Governance, and Stakeholder Trust

Sep 2026 · Proceeding of International Conference on Digital, Social, and Science · 0 citations · 44 references

Abstract

This study develops an integrated explanation of cybersecurity disclosure by synthesizing accounting, governance, finance, and information-systems research published between 2019 and 2026. A structured integrative literature review was applied to a curated corpus of 44 publications, identified through searches of Scopus and Google Scholar and screened against topical-relevance criteria. The studies were coded according to disclosure type, measurement attributes, governance and institutional determinants, stakeholder group, outcome, and contextual condition. The evidence shows that cybersecurity reporting includes risk, governance, preventive, incident, and mitigative information, which should not be treated as interchangeable constructs. Board independence,information technology expertise, dedicated cyber committees, gender diversity, internal controls, breach history, regulation, and sectoral exposure shape the extent and content of reporting. Disclosure can reduce information asymmetry, strengthen reputation, support firm value, moderate breach contagion, and inform audit risk assessment. However, longer or more readable reporting does not necessarily indicate stronger preparedness and may reveal heightened cyber exposure, increase stock-price crash risk, or generate adversarial costs. Boilerplate language, delayed incident reporting, strategic news timing, and possible manipulation of incident discovery dates further weaken credibility. The review contributes a Cyber Transparency Security Trust framework in which governance capacity and cyber exposure shape disclosure attributes, stakeholders assess both usefulness and security sensitivity, and resulting responses affect market value, audit fees, reputation, trust, and future cyber risk. The review is limited by its curated rather than exhaustive corpus and its focus on predominantly listed firms in developed economies. Future research should prioritize disclosure quality, preventive versus mitigative content, independent assurance, materiality judgments, emerging economies, artificial-intelligence-based analysis, and causal evidence on subsequent cyberattacks. Keywords: Cybersecurity Disclosure, Cyber Risk, Corporate Governance, Stakeholder Trust, Information Asymmetry.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.