What happens when what companies say about cybersecurity is not the same as what they actually do?
The Say-Do Gap explores one of the emerging challenges in modern corporate reporting: the distance between cybersecurity rhetoric and substantive cybersecurity governance. In the post-2023 regulatory environment, companies subject to U.S. Securities and Exchange Commission requirements face growing pressure to disclose how they identify, manage, and oversee cybersecurity risks.
But greater disclosure does not necessarily mean greater cybersecurity preparedness.
Focusing on semi-peripheral cross-listed issuers, this book examines whether corporate cybersecurity disclosures represent meaningful improvements in governance and risk management or whether they primarily reflect regulatory expectations, institutional pressures, and sophisticated forms of corporate communication.
At the center of the analysis is the Say-Do Gap: a framework for examining the difference between what organizations publicly claim about cybersecurity and the observable substance behind those claims.
The book investigates key dimensions of cybersecurity disclosure, including:
• Cybersecurity risk management and organizational preparedness
• Board oversight and governance responsibilities
• Management accountability and cybersecurity expertise
• Cybersecurity incident reporting
• Risk identification and mitigation practices
• Disclosure specificity, consistency, and transparency
• Regulatory compliance and institutional legitimacy
• Symbolic compliance and corporate impression management
By examining corporate filings and cybersecurity-related disclosures in the context of the SEC's post-2023 regulatory framework, The Say-Do Gap offers a critical perspective on whether enhanced transparency requirements produce genuine accountability or simply encourage companies to become better at communicating preparedness.
Particularly relevant to emerging-market and foreign issuers with access to U.S. capital markets, the analysis highlights the distinctive pressures created when organizations operate across different institutional, regulatory, and governance environments.
The book connects cybersecurity governance with corporate reporting, accounting, finance, institutional theory, regulatory compliance, and investor communication. It provides researchers, academics, investors, regulators, finance professionals, corporate governance specialists, and graduate students with a structured framework for evaluating not only what companies disclose, but also what those disclosures may reveal—or conceal—about the substance of their cybersecurity governance.
The central question is simple but consequential:
When corporations say they are prepared for cyber risk, how much of that claim represents substance—and how much represents rhetoric?
The answer lies in understanding the gap between the two.
Le informazioni nella sezione "Riassunto" possono far riferimento a edizioni diverse di questo titolo.
Da: PBShop.store US, Wood Dale, IL, U.S.A.
PAP. Condizione: New. New Book. Shipped from UK. Established seller since 2000. Codice articolo L2-9798171279516
Quantità: Più di 20 disponibili
Da: PBShop.store UK, Fairford, GLOS, Regno Unito
PAP. Condizione: New. New Book. Shipped from UK. Established seller since 2000. Codice articolo L2-9798171279516
Quantità: Più di 20 disponibili