An Analysis of Cybersecurity in Dutch Annual Reports of Listed Companies

28 Pages Posted: 17 Sep 2020

See all articles by Eva Eijkelenboom

Eva Eijkelenboom

Independent

Bernold Nieuwesteeg

Erasmus University Rotterdam (EUR) - Rotterdam Institute of Law and Economics

Date Written: August 5, 2020

Abstract

In this paper we study the disclosure of cybersecurity information in annual reports, such as cybersecurity measures and cyber incidents, from a financial law and economics perspective. We start our discussion with an analysis of the requirements in financial law to disclose cybersecurity information in annual reports. Hereafter, we discuss the incentives for the board regarding disclosing cybersecurity related information and its effect on stakeholders and shareholders. We draft hypotheses regarding the actual disclosure of cybersecurity information and propose a research design of an exploring empirical study. The results of our study show that although there is no strict legal obligation to do so, 87% of the companies mention cybersecurity or similar words in their annual report in 2018. However, only 4 out of 75 companies disclosed more than six specific cybersecurity measures, while openness would generate the highest surplus for society from a social welfare perspective. Some major Dutch banks and employment agencies did not disclose any specific information with regard to their cybersecurity strategy, while those companies are highly vulnerable for cybersecurity incidents. This hampers the protection of creditors, investors and other stakeholders. Our analysis aims to propel the debate on stimulation of self-regulation or possible obligations in financial law concerning cybersecurity in annual reports.

Keywords: cybersecurity, financial law, annual report, information sharing, security regulation

Suggested Citation

Eijkelenboom, Eva and Nieuwesteeg, Bernold, An Analysis of Cybersecurity in Dutch Annual Reports of Listed Companies (August 5, 2020). Available at SSRN: https://ssrn.com/abstract=3667418 or http://dx.doi.org/10.2139/ssrn.3667418

Eva Eijkelenboom

Independent ( email )

Bernold Nieuwesteeg (Contact Author)

Erasmus University Rotterdam (EUR) - Rotterdam Institute of Law and Economics ( email )

Burgemeester Oudlaan 50
PO box 1738
Rotterdam, 3000 DR
Netherlands

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
208
Abstract Views
1,109
Rank
312,247
PlumX Metrics