CYBERSECURITY RISK DISCLOSURE IN ANNUAL REPORTS: A CONCEPTUAL FRAMEWORK WITH INSIGHTS FROM MALAYSIA

Authors

DOI:

https://doi.org/10.35631/AIJBES.829020

Keywords:

Annual Reports, Corporate Governance, Cybersecurity Disclosure, Malaysia, Proprietary Cost Theory, Signalling Theory

Abstract

As firms become increasingly dependent on digital technologies, cybersecurity has emerged as a critical governance and reporting issue. Consequently, stakeholders are demanding more transparent and decision-useful cybersecurity risk disclosure (CRD). Although regulatory expectations for cybersecurity reporting have increased, prior studies indicate that CRD remains largely boilerplate, inconsistent, and insufficient for stakeholder decision-making. Moreover, limited research has developed an integrated theoretical framework explaining the factors that influence the quality of CRD, particularly in emerging markets. This study proposes an integrated conceptual framework that explains how governance mechanism, regulatory pressures, and proprietary cost considerations jointly influence the quality of cybersecurity risk disclosure. Drawing on signalling theory, proprietary cost theory, and corporate governance theory, the proposed framework examines how board cybersecurity expertise, regulatory enforcement, and proprietary cost consideration shape firms’ cybersecurity disclosure decisions. The model represents firm's selective disclosure of cybersecurity information, providing testable propositions for future empirical work. Malaysia provides a distinctive research context because of its concentrated ownership structure, varying levels of board cybersecurity expertise, and evolving regulatory expectations under Bursa Malaysia and the Malaysian Code of Conduct Governance (MCCG). The proposed framework extends the accounting and information systems literature by providing a theoretically grounded basis for examining cybersecurity risk disclosure risk disclosure quality in emerging markets and offers testable propositions for future empirical research. 

Downloads

Download data is not yet available.

References

Alodat, A. Y., Hao, Y., Nobanee, H., Ali, H., Mansour, M., & Al Amosh, H. (2024). Board characteristics and cybersecurity disclosure: Evidence from UK listed firms. Electronic Commerce Research. https://doi.org/10.1007/s10660-024-09867-w

Block, M. (2025). Market reactions to material cybersecurity incident disclosures. arXiv. https://arxiv.org/abs/2512.06144

Chen, J., Henry, E., & Jiang, X. (2023). Is cybersecurity risk factor disclosure informative? Evidence from disclosures following a data breach. Journal of Business Ethics, 187(1), 199–224. https://doi.org/10.1007/s10551-022-05107-z

Deloitte. (2025). Cybersecurity disclosure reporting trends under SEC requirements. Deloitte Insights. https://www2.deloitte.com

Gauch, S., Smith, L., & Brown, T. (2025). Mandatory cybersecurity disclosure and investor reactions: Evidence from SEC filings. International Journal of Accounting Information Systems, 57, 100775. https://doi.org/10.1016/j.accinf.2025.100775

Godewatta, K., Wang, Y., & Lee, J. (2025). Cyber risk disclosure quality and market efficiency. Journal of Financial Reporting and Accounting. https://doi.org/10.1108/JFRA-2024-0123

Hagens Berman. (2025). F5, Inc. faces investor scrutiny following cybersecurity incident. Business Wire. https://www.businesswire.com/news/home/20251223511519/en/Hagens-Berman-Announces-Investigation-into-F5-Inc.-FFIV-Which-Faces-Securities-Class-Action-Amid-Cybersecurity-Incident-Questions-About-Disclosure-Timing-and-Impact-on-Companys-Business

Jameel, A., Khan, S., & Ahmed, R. (2025). Symbolic governance and cybersecurity disclosure quality. Corporate Governance: An International Review. https://doi.org/10.1111/corg.12567

Khadim, S., & Kakar, P. (2025). Board expertise and cybersecurity risk disclosure: Evidence from emerging markets. Journal of Business Research, 158, 113–128. https://doi.org/10.1016/j.jbusres.2024.113128

Moll, J., & Yigitbasioglu, O. (2025). The role of accounting in the digital age: AI, analytics, and automation. Accounting, Auditing & Accountability Journal, 38(2), 311–335. https://doi.org/10.1108/AAAJ-2023-0102

Ng, E. Y., & Yap, B. (2022). Digital transformation and governance challenges in Malaysian firms. Asian Journal of Business and Accounting, 15(2), 55–78.

Parra, M., & Rossi, F. (2023). Technostress in digital workplaces: A systematic review. Information Systems Frontiers, 25(3), 789–805. https://doi.org/10.1007/s10796-022-10345-2

Smaili, N., & Radu, C. (2023). Board effectiveness and cybersecurity disclosure. Journal of Management and Governance, 27, 1049–1071. https://doi.org/10.1007/s10997-022-09637-6

Sun, T., & Zhang, P. (2022). Artificial intelligence in accounting: Implications for professional roles. Accounting Horizons, 36(4), 45–60. https://doi.org/10.2308/HORIZONS-2021-015

U.S. Securities and Exchange Commission. (2024). SEC guidance on cybersecurity disclosure. https://www.sec.gov/news/press-release/2024-30

Vo, D. H., & Pham, T. H. (2025). Proprietary costs and voluntary disclosure decisions in cybersecurity reporting. Journal of Accounting Research, 63(1), 89–120. https://doi.org/10.1111/1475-679X.12456.

Downloads

Published

2026-09-10

How to Cite

Zakaria, R. A., Aziz, A. A. A., & Hassan, N. A. C. (2026). CYBERSECURITY RISK DISCLOSURE IN ANNUAL REPORTS: A CONCEPTUAL FRAMEWORK WITH INSIGHTS FROM MALAYSIA. ADVANCED INTERNATIONAL JOURNAL OF BUSINESS, ENTREPRENEURSHIP AND SME’S (AIJBES), 8(29), 374–384. https://doi.org/10.35631/AIJBES.829020