Cybersecurity Disclosure Mandates and Cross‐Domain Compliance Spillovers
ABSTRACT We examine whether cybersecurity disclosure mandates generate compliance spillovers beyond their intended regulatory domain. Exploiting the staggered adoption of US state breach notification laws (BNLs), we find that mandatory breach disclosure reduces firms’ federal regulatory violations in non‐cyber domains by more than 5% in the first year after adoption. The effect is transitory, dissipating in subsequent years, but extends across several major regulatory domains. Cross‐sectional analyses show that the reduction is stronger among firms with greater organizational capacity and more effective internal controls. The findings are robust to a broad set of identification and sensitivity tests. Overall, the evidence suggests that cybersecurity disclosure mandates can operate as organizational governance shocks, inducing cross‐domain compliance spillovers when firms have stronger preexisting compliance infrastructure.
Authors
- Danling Jiang (ORCID: https://orcid.org/0000-0001-5104-6023)
- Lei Gao (ORCID: https://orcid.org/0000-0002-8961-1734)
- Yan Wendy Wu (ORCID: https://orcid.org/0000-0002-1896-5383)
- Jinghua Wang (ORCID: https://orcid.org/0000-0003-1821-2362)
Institutions
- New Jersey Institute of Technology (US)
- George Mason University (US)
- Stony Brook University (US)
- Wilfrid Laurier University (CA)
Publication Details
- Journal
- Financial Management
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1111/fima.70072
- Primary Topic
- Auditing, Earnings Management, Governance
- Type
- article
- Field-Weighted Citation Impact
- 0.00