Skip to content
Review Open access

Cybersecurity Risks in Digitized Capital Markets: A Comparative Regulatory Analysis of Operational Resilience, Disclosure, and Market Integrity

2026 · International journal of research and scientific innovation · Vol 13, pp. 3493-3510 · 0 citations

TL;DR

A multilayered regulatory model is proposed that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing, essential for protecting investors, preserving market continuity, and containing systemic cyber risk.

Abstract

The digitization of capital markets has increased efficiency, connectivity, and innovation, but it has also transformed cybersecurity from an institution-specific technical concern into a systemic threat to market integrity and financial stability. This study evaluates the adequacy and coherence of cybersecurity regulation in digitized capital markets. It employs qualitative policy analysis, doctrinal review, and comparative analysis of the United States Securities and Exchange Commission framework, the European Union’s Digital Operational Resilience Act, and IOSCO/CPMI-IOSCO standards. Regulatory documents and scholarly evidence covering 2020–2026 are assessed through directed content analysis and a comparative matrix spanning governance, incident reporting, disclosure, resilience testing, third-party risk, business continuity, enforcement, and systemic resilience. The findings reveal partial regulatory convergence but persistent structural fragmentation. The United States prioritizes disclosure and investor protection; the European Union adopts a broader operational-resilience model; and international standards emphasize financial-market infrastructures, coordination, and systemic stability. Major deficiencies include weak integration between disclosure and resilience requirements, uneven oversight of critical technology providers, inconsistent incident definitions and reporting timelines, limited cross-border enforcement, and inadequate treatment of contagion and market outages. The study proposes a multilayered regulatory model that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing. Such integration is essential for protecting investors, preserving market continuity, and containing systemic cyber risk.

Read PDF

Similar papers

Open access Aug 2026

Cybersecurity Risks in Digitized Capital Markets: Regulatory and Institutional Responses

The digitization of capital markets has expanded the use of electronic trading systems, fintech platforms, cloud infrastructure, algorithmic trading, and blockchain-based financial services. Although these innovations have improved market efficiency, access, and transaction speed, they have also increased cybersecurity exposure within financial markets and institutions. This study examined cybersecurity risks in digitized capital markets and assessed regulatory and institutional responses across selected developed and emerging economies. Specifically, it investigated the effects of cybersecurity incidents on abnormal returns, investor confidence, and market volatility, compared cyber governance frameworks across jurisdictions, and analyzed the relationship between cyber governance quality and market resilience. The study adopted a multi-method research design, combining event study methodology, qualitative comparative analysis, and panel regression analysis. Secondary data were obtained from Refinitiv, Bloomberg, Hackmageddon, IMF cyber risk reports, IOSCO publications, and World Federation of Exchanges databases for the period 2020 to 2025. The findings showed that cybersecurity incidents produced significant negative abnormal returns and volatility spikes across financial markets. Jurisdictions with stronger cyber governance frameworks, centralized regulatory structures, mandatory disclosure systems, and operational resilience mechanisms demonstrated higher market resilience and faster recovery from cyber disruptions. The study concluded that effective cyber governance strengthens financial market stability and operational resilience in digitized capital markets. It recommends harmonized cyber disclosure standards, mandatory incident reporting, cross-border institutional coordination, and stronger operational resilience frameworks to improve cybersecurity preparedness in global financial systems.

Akomolehin F. Olugbenga · 0 citations
Open access Aug 2026

Weaponised interdependence and European energy security: Infrastructure, systemic vulnerability, and the post-2022 transformation

This article extends a concept developed by Farrell and Newman (2019) beyond its original financial and digital domains to physical energy infrastructure, examining how the Russia–Ukraine war has transformed European energy security from a market-based relationship into a condition of systemic vulnerability. The analysis employs qualitative document analysis of publicly available European Union’s policy instruments, International Energy Agency’s market reports, and European Union Agency for Cybersecurity’s threat assessments, structured around a three-domain framework encompassing physical infrastructure, digital systems, and governance arrangements. Diversification strategies implemented after 2022 reduced dependence on Russian energy but simultaneously reconfigured systemic vulnerability across all three domains: liquified natural gas (LNG) import concentration and deployment of floating storage and regasification units created new physical chokepoints; supervisory control and data acquisition and digital vendor dependencies introduced persistent digital interdependencies; and governance fragmentation among member states amplified vulnerability by producing uneven resilience across interconnected systems. European energy security must be reconceptualised as the management of systemic interdependence across interconnected physical, digital, and institutional domains. The article introduces the concept of structural weaponisation potential—the proposition that networked energy systems generate vulnerability as an emergent property of their architecture, independent of any actor’s intention to exploit it.

Elmir Badalov · 0 citations
Review Open access Sep 2026

Regulatory Fragmentation, Investor Protection, and Market Efficiency in Cryptocurrency Markets: A Comparative Institutional and Policy Analysis (2020–2026)

This study examined how regulatory fragmentation, investor protection and anti-manipulation enforcement shaped market efficiency in cryptocurrency markets between 2020 and 2026. It adopted an integrative literature review, comparative policy analysis and embedded case-study design covering the United States, European Union, China and Singapore. Evidence from peer-reviewed studies, regulatory frameworks and documented market events was synthesized around price discovery, volatility, liquidity, and arbitrage and market integrity. The findings showed that cryptocurrency markets rapidly incorporated material regulatory announcements, although the direction and persistence of market reactions depended on legal clarity, enforcement credibility and market structure. Cross-jurisdiction differences in asset classification, licensing and enforcement sustained market segmentation and impeded price convergence. Investor-protection measures, particularly disclosure requirements, custody safeguards, exchange supervision and market surveillance, reduced information asymmetry and supported market integrity over the medium to long term, despite possible short-run volatility during regulatory adjustment. Anti-manipulation enforcement also strengthened the credibility of price and volume signals. The study concluded that regulation functioned as part of the market's information infrastructure: coherent, proportionate and consistently enforced rules supported semi-strong-form efficiency, whereas ambiguity and fragmented implementation weakened it. Greater international convergence is therefore needed in disclosure, exchange oversight, custody, market-abuse controls and supervisory cooperation, while allowing jurisdictions to retain context-specific approaches to innovation and risk.

O. Akomolehin · 0 citations
Open access Aug 2026

Toward Integrated Global Legal Framework: Cybersecurity Governance, Asset Recovery Mechanisms, and Proactive Enforcement in Engineering and Technology Law

The accelerating integration of digital technologies into engineering systems and financial infrastructures has intensified the vulnerability of states and institutions to cyber-enabled economic crimes. This work interrogates the fragmented landscape of cybersecurity governance and its implications for asset recovery and proactive enforcement within the domain of engineering and technology law. It argues that existing legal regimes remain largely reactive, jurisdictionally constrained, and insufficiently harmonized to address the transnational character of cyber threats and illicit financial flows. Adopting a comparative and interdisciplinary approach, the work examines regulatory models across selected jurisdictions, identifying gaps in legal coordination, enforcement capacity, and technological adaptation. It highlights how cyber intrusions into engineering systems—ranging from critical infrastructure to fintech platforms—facilitate complex asset concealment strategies, thereby undermining traditional recovery mechanisms. In response, the work advances the case for an integrated global legal framework that aligns cybersecurity standards with asset tracing, seizure, and repatriation processes. Central to this framework is the concept of proactive enforcement, which emphasizes anticipatory legal measures, real-time monitoring, and cross-border institutional collaboration. The work explores the role of emerging technologies, including artificial intelligence and blockchain analytics, as tools for enhancing legal oversight while also addressing the attendant risks of regulatory overreach and privacy infringement. It further considers the normative and institutional challenges of achieving global consensus, particularly considering divergent national interests and capacities. Ultimately, the work contributes to ongoing scholarly and policy debates by proposing a recalibrated legal architecture that bridges cybersecurity governance with financial accountability. Such an approach is essential for strengthening global financial integrity and ensuring that legal systems remain resilient in the face of evolving technological threats.

G. P. Dafiel · 0 citations
Review Open access Sep 2026

A Risk-Based Framework for Assessing Cybersecurity Maturity Levels of Savings and Credit Cooperative Societies (SACCOS) in Tanzania

Savings and Credit Cooperative Societies (SACCOS) are central to financial inclusion in Tanzania; however, their digital transformation has advanced faster than their cybersecurity capabilities. National instruments, including the Cybercrimes Act (CAP 443), the Government Cyber Security Strategy 2022–2027, and the TCDC Guidelines on Cybersecurity and Resilience of SACCOS, establish baseline obligations, but none provide a structured, risk-based mechanism for measuring cybersecurity maturity or tracking improvements over time. This study developed and evaluated a context-specific Risk-Based Cybersecurity Maturity Assessment Framework (RBCMAF) for Tanzanian SACCOS by adapting the NIST Cybersecurity Framework (CSF) 2.0 to local governance, regulatory, and resource conditions. A descriptive, analytical, cross-sectional, mixed-methods design guided by Design Science Research principles was used. The quantitative strand is explicitly positioned as an exploratory pilot baseline rather than a nationally representative survey, drawing on respondents from a small number of purposively selected, anonymised digitised SACCOS using a NIST CSF-aligned questionnaire scored across the six CSF functions. Qualitative data were generated through semi-structured interviews with ICT managers, one per SACCOS, and a structured review of regulatory and supervisory documents. The instrument showed very high internal consistency, which should be read with caution because such values may also indicate item redundancy. The baseline placed the sampled SACCOS at the Developing maturity level overall, with Identify and Protect emerging as the strongest functions, and Respond, Recover, and Detect as the weakest. Gap analysis against an optimised target level confirmed that the largest deficits lay in Respond, Recover, and Detect. A risk-weighted assessment similarly prioritised Respond, Recover, Detect, and Govern as the functions most in need of attention. The resulting RBCMAF comprises five integrated layers operationalised through a six-stage assessment process and six design principles. Evaluation through quantitative application, qualitative triangulation, and regulatory benchmarking demonstrates the framework’s internal coherence, contextual fit, and practical utility for institutional self-assessment and risk-based supervision.

Ayoub Jonathan Kitomari, Gustaph Sanga, S. Wambura · 0 citations
Open access Aug 2026

Integrating Accounting Governance, Cybersecurity Governance and Digital Trust for Digital Banking Risk Reduction in Jordanian Banks: A Conceptual Framework for Digital Banking Risk Governance

Beginning with this paper's overall objective is to develop a comprehensive theoretical framework that illustrates how Jordanian banks reduce digital banking risk (DBR) through two distinct but complementary paths: digital trust (DT) and operational resilience (OR). As such, this paper will expand upon the traditional focus on channel-specific risks associated with e-banking by providing an alternative ecosystem-based perspective on digital banking risk governance. This paper uses a structured conceptual synthesis methodology. In doing so, it synthesizes four separate literature streams including those related to cybersecurity governance; digital trust-risk logic in digital financial services; API security and third-party risk management; and operational resilience. To facilitate this process, studies were selected based on relevance for developing theory, clarity regarding constructs, applicability to banking or financial service institutions, and the potential to inform development of specific propositions. Additionally, two institutional sources located in Jordan were relied upon to provide additional contextualization of the proposed conceptual model in terms of the Jordanian banking environment. The paper presents a multi-layered conceptual model illustrating the role that cybersecurity governance plays in supporting both DT and OR, and ultimately reducing DBR. Specifically, four governance capability domains (API security, customer digital awareness, third-party risk management, and incident response capability) are identified as critical domains of practice that link high-level cybersecurity governance practices to tangible reductions in digital banking risk. The paper provides value by integrating previously separate concepts (cybersecurity governance, DT, TPRM, API security, CDA, IRC, and OR) into a cohesive conceptual architecture designed to facilitate understanding of factors that contribute to reductions in DBR. Further, the paper shifts the emphasis from viewing DBR as being primarily attributable to narrow technological or consumer behavioral issues (e.g., Internet banking channels) to viewing DBR as an issue of broader ecosystem governance. From an accounting information systems and internal control lens, the framework also positions digital banking risk as a problem of transaction authorization, auditability, control monitoring, exception reporting, and assurance over digitally processed banking activities.

B. Alrawashdeh · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.