Companies disclose more on cybersecurity – but markets remain indifferent
27.4.2026 09:23:40 EEST | Vaasan yliopisto | Press release
U.S. companies are reporting on cybersecurity in greater detail, yet stock market reactions remain muted. A new study by the University of Vaasa and Aalto University shows that mandatory cybersecurity disclosure does not prompt reactions from investors or stock analysts. Instead, the main benefits appear to materialise within firms themselves.

Mandatory cybersecurity disclosure has increased internal documentation and made cyber risks more visible to senior management, but it has not, at least so far, affected investor or stock analyst behavior. This is the conclusion of a new Finnish study examining the early effects of U.S. cybersecurity regulation. The findings are also relevant in Europe, where the NIS2 Directive places cybersecurity increasingly within the responsibility of corporate leadership.
In their study, Associate Professor Elina Haapamäki from the University of Vaasa and Associate Professor Jukka Sihvonen from Aalto University analyse how U.S. public companies responded to the disclosure requirement that came into force in 2023. Under the rule introduced by the U.S. Securities and Exchange Commission (SEC), listed companies are required to provide more detailed disclosures in their annual reports on cybersecurity governance, risk management, and oversight. The study covers 3,440 U.S. public companies’ 2024 Form 10‑K filings, the first reporting year in which the new disclosure item — known as Item 1C — was applied in full.
Markets remained surprisingly indifferent
According to the study, companies did not merely relocate existing cybersecurity risk language to the new disclosure section. Instead, they produced genuinely new content.
– This was not a cosmetic change. Firms had to describe their cybersecurity governance structures and responsibilities in a much more systematic way, Haapamäki says.
However, the quality and extent of disclosures varied substantially across firms. These differences were only partly explained by firm characteristics such as company size, financial performance, or auditor profile.
– What is particularly interesting is that disclosure quality was not influenced by whether a firm had experienced prior cyber incidents or by how digitalised its business was. This suggests that firms retain significant discretion over what they choose to disclose, Sihvonen notes.
Despite the expansion of disclosure, market reactions remained limited. According to the study, stock prices did not respond systematically, stock analysts did not increase cybersecurity-related discussion, and investor attention to annual reports did not rise.
– This contrasts with the common, experience-based understanding that severe cyberattacks can halt operations, lead to data breaches, and cause substantial financial losses, Haapamäki says.
According to Sihvonen, the findings indicate that investors are not incorporating governance‑level cybersecurity information into firm valuation decisions.
The main benefits accrue to firms themselves
Based on interviews conducted for the study, cybersecurity and corporate responsibility experts conclude that the primary impact of the disclosure mandate, based on first impressions, is not visible in markets but within firms themselves. The requirement forces organisations to document cybersecurity responsibilities, processes, and decision-making more systematically.
– In the United States, cybersecurity is communicated to corporate stakeholders somewhat differently than in Europe. In the EU, the emphasis has been on clearly defined risk management obligations, and reporting primarily concerns the notification of cybersecurity incidents to authorities and customers, says Peter Sund, CEO of Cybersecurity Finland (Kyberala ry).
– From an investor perspective in the EU, the key issue is that a company’s executive management and board of directors take responsibility for cybersecurity risk management and its oversight, Sund adds.
The findings are also relevant in Europe, where the implementation of the NIS2 Directive is currently tightening cybersecurity requirements for companies. Unlike the U.S. approach, EU regulation primarily emphasises internal documentation rather than public disclosure aimed at investors.
The peer‑reviewed study has been published in the International Journal of Accounting Information Systems.
Read the full paper:
Mandatory cybersecurity disclosure: Early evidence from 10‑K reports
Keywords
Contacts
Associate Professor Elina Haapamäki, University of Vaasa, tel. +358 29 449 8471, elina.haapamaki@uwasa.fi
Associate Professor Jukka Sihvonen, Aalto University, tel. +358 50 477 6672, jukka.sihvonen@aalto.fi
Images

Alternative languages
Subscribe to releases from Vaasan yliopisto
Subscribe to all the latest releases from Vaasan yliopisto by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Vaasan yliopisto
Tatiana King ja Vanja Piljak professoreiksi Vaasan yliopistoon – tutkimuksessa korostuvat kestävyys ja rahoitusmarkkinoiden murros25.6.2026 09:15:38 EEST | Tiedote
Vaasan yliopistossa on aloittanut kesäkuussa kaksi uutta professoria, joiden tutkimus tarttuu ajankohtaisiin kestävyyshaasteisiin laskentatoimen ja rahoituksen näkökulmista. Laskentatoimen professori (ESG-raportointi ja kestävä kehitys) Tatiana King tutkii vastuullisuusraportointia ja ilmastoriskejä, kun taas rahoituksen professori (kansainväliset rahoitusmarkkinat) Vanja Piljak keskittyy kestävään rahoitukseen ja sijoittamiseen.
Velka-Suomesta vetovoima-Suomeksi – Vaasan yliopisto kutsuu SuomiAreenaan 23.6.17.6.2026 13:38:34 EEST | Kutsu
Miten Suomen vahvuudet käännetään kestäväksi kasvuksi ja investoinneiksi? Vaasan yliopiston SuomiAreena-keskustelu "Velka-Suomesta vetovoima-Suomeksi – talous kasvuun puhtaalla energialla ja kriisinsietokykyä vahvistamalla" kokoaa tiistaina 23. kesäkuuta Porin Kirkkolavalle Eurooppa- ja omistajaohjausministeri Joakim Strandin, Elinkeinoelämän keskusliiton EK:n toimitusjohtajan Minna Helteen, Hitachi Energy Finlandin toimitusjohtajan Matti Vaattovaaran, Vaasan yliopiston rehtorin Minna Martikaisen ja Sitran yliasiamiehen Atte Jääskeläisen.
Uusi mobiilipeli tukee kestävää luontomatkailua Etelä-Pohjanmaalla17.6.2026 09:24:23 EEST | Tiedote
Joukko eteläpohjalaisia luonto- ja matkailuyrittäjiä on ottanut käyttöönsä Vaasan yliopistossa kehitetyn kännykkäpelin osaksi palvelutarjontaansa. Pelin avulla asiakkaita voi aktivoida, ohjata ja neuvoa nykyaikaisella ja helpolla tavalla. Pelissä hyödynnetään muun muassa satelliitti-, paikkatieto- ja ohjelmointiosaamista.
Vaasan yliopisto sai merkittäviä tutkimusrahoituksia – energiaa, terveydenhuoltoa ja turvallisuutta tarkastellaan eri näkökulmista16.6.2026 08:16:10 EEST | Tiedote
Vaasan yliopisto on saanut merkittävää rahoitusta neljälle tutkimushankkeelle. Kaksi hanketta sai rahoituksen Suomen Akatemialta ja kaksi Interreg Aurora -ohjelmasta. Hankkeet saivat rahoitusta yhteensä noin 1,72 miljoonaa euroa.
Kaupunkien innovaatiohankkeet voivat syventää eriarvoisuutta – ratkaisuksi inklusiivinen innovaatiopolitiikka15.6.2026 08:11:14 EEST | Tiedote
Innovaatioiden edesauttaminen kaupunkikehittämisen keinoin on kasvattanut suosiotaan ympäri maailmaa. Talous- ja teknologiakeskeinen kaupunkikehitys voi kuitenkin epähuomiossa lisätä sosiaalista eriarvoisuutta ja ajaa pienituloisia kaupunkilaisia ahtaalle. Johanna Kalliokosken Vaasan yliopistolle tekemä väitöstutkimus esittää osallistavaa innovaatiopolitiikkaa ratkaisuksi.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom