European cybersecurity disclosure practices: a textual analysis
摘要
This study analyses cybersecurity disclosure practices of publicly listed companies in the UK, France, and Germany that have reported cybersecurity incidents in their annual reports. Grounded in signalling theory, our analysis examines the readability and tone of cybersecurity-related disclosures compared to the broader report, aiming to uncover companies’ communication strategies to manage public perceptions. Our findings reveal a contrast: while cybersecurity sections employ more complex language than the rest of the report, the descriptions of incidents are notably clear and standardized. The striking similarity across disclosures further suggests that companies may be engaging in impression management to minimize scrutiny. The tension between regulatory transparency requirements and disclosure practices calls for closer investigation.