Los puntos clave no están disponibles para este artículo en este momento.
Abstract Reliance on information technologies has heightened companies’ exposure to cyberattacks, intensifying stakeholders’ concerns and demands for comprehensive cybersecurity disclosures. Developing economies are vulnerable to cyberattacks due to lower cybersecurity resilience. However, existing research largely focuses on developed economies, and employs textual or word-frequency analysis methods. This exploratory study addresses these gaps by examining cybersecurity disclosures of the 100 largest capitalised companies on the Johannesburg Stock Exchange in 2020. Guided by established manual content analysis procedures, we developed a disclosure index informed by prior literature and widely accepted cybersecurity disclosure guidance. Our study examines the core questions of the extent of cybersecurity disclosure in the annual reports of JSE-listed companies, the quality of these disclosures, and whether the industry or attack status of the company influences these disclosures. The results suggest that while most companies acknowledge cybersecurity as a material risk, the overall extent and quality of disclosure remain low and vary significantly across companies and industries. Disclosures tend to emphasise cybersecurity governance rather than impacts or mitigation measures, and improvements in disclosures following cyber incidents are generally limited. The disclosure index and empirical insights offer a practical framework for companies seeking to enhance their cybersecurity disclosure, while also informing regulators, investors, and other stakeholders on current cybersecurity disclosure practices.
Lunga et al. (Sat,) studied this question.