ALL Metrics
-
Views
-
Downloads
Get PDF
Get XML
Cite
Export
Track
Research Article

Cybersecurity Disclosure and Financial Performance: The Moderating Role of Board Characteristics

[version 1; peer review: awaiting peer review]
PUBLISHED 28 Jul 2026
Author details Author details
OPEN PEER REVIEW
REVIEWER STATUS AWAITING PEER REVIEW

Abstract

Background

Cybersecurity has become a strategic governance issue that affects firms’ financial performance and long-term resilience. While cybersecurity disclosure may enhance stakeholder confidence by improving transparency, limited evidence exists on whether board characteristics influence the relationship between cybersecurity disclosure and financial performance. This study examines the impact of cybersecurity disclosure on firm financial performance and investigates the moderating roles of board gender diversity and technological expertise in the Saudi Arabian context.

Methods

The study uses an unbalanced panel of 155 non-financial firms listed on the Saudi Exchange (Tadawul) over the period 2020–2024. Pooled ordinary least squares (OLS) regression is employed as the baseline estimation method, while System Generalized Method of Moments (System GMM) is used to address potential endogeneity concerns. Additional robustness analyses are conducted using alternative measures of cybersecurity disclosure and financial performance.

Results

The findings indicate that cybersecurity disclosure is positively associated with firm financial performance, suggesting that greater transparency regarding cybersecurity practices contributes to improved organizational outcomes. In contrast, cybersecurity incident disclosure is negatively associated with financial performance, reflecting the adverse consequences of reported cyber incidents. Furthermore, board gender diversity and board technological expertise significantly strengthen the positive relationship between cybersecurity disclosure and financial performance. The results remain robust across alternative model specifications, disclosure measures, and dynamic estimation techniques.

Conclusions

The findings demonstrate that the financial benefits of cybersecurity disclosure depend not only on the extent of disclosure but also on the quality of corporate governance. Boards with greater gender diversity and technological expertise enhance firms’ ability to translate cybersecurity transparency into superior financial performance. These findings provide practical implications for regulators, corporate boards, and policymakers seeking to strengthen cybersecurity governance, improve disclosure practices, and enhance organizational resilience in support of Saudi Vision 2030.

Keywords

Cybersecurity Disclosure, Financial Performance, Corporate Governance, Board Gender Diversity, and Board Technological Expertise.

1. Introduction

In recent years, cybersecurity has emerged as one of the most critical strategic challenges confronting firms, regulators, and capital market participants worldwide. The accelerated pace of digital transformation, increasing dependence on information systems, and widespread adoption of data-driven business models have substantially heightened firms’ exposure to cyber risks (Muktadir-Al-Mukit & Ali, 2025; Amani et al., 2025). Cybersecurity incident disclosure, including data breaches, ransomware attacks, and system disruptions, can generate severe financial losses, operational interruptions, regulatory sanctions, and long-term reputational damage. Consequently, cybersecurity is no longer perceived as a purely technical or operational concern; rather, it has become a core element of enterprise risk management and a key determinant of firms’ sustainable financial performance (Amani et al., 2025; Sulaiman et al., 2022; Al-Sartawi et al., 2021; Kurair & Adedokun, 2026).

As cyber risks have intensified, stakeholders’ demand for transparency regarding firms’ cybersecurity practices has grown markedly. Investors, creditors, regulators, and other market participants increasingly acknowledge that traditional financial reporting frameworks are insufficient to capture firms’ exposure to non-financial risks, particularly those associated with digital infrastructure, data protection, and information security governance. This recognition has driven growing attention toward cybersecurity disclosure as part of board of directors’ reports and broader non-financial disclosures, through which firms communicate their exposure to cyber risks, governance arrangements, and mitigation strategies. Such disclosure is generally expected to reduce information asymmetry, enhance market discipline, and improve stakeholders’ ability to assess firms’ resilience and long-term viability (Alsadoun & Albaz, 2025; Elsayed et al., 2024; Al Amosh & Khatib, 2025; Yahaya, 2026).

From a theoretical perspective, cybersecurity disclosure can be explained through agency, stakeholder, and legitimacy theories. Agency theory suggests that disclosure reduces information asymmetry between managers and stakeholders by enhancing transparency regarding cybersecurity risks and governance practices (Jensen & Meckling, 1976). Stakeholder theory views cybersecurity disclosure as a response to the expectations of stakeholders concerned with data protection, operational continuity, and digital trust (Freeman, 1984; Elsayed et al., 2024; Ahmadoni, 2025). Legitimacy theory further suggests that firms use cybersecurity disclosure to demonstrate accountability and maintain organizational legitimacy in environments characterized by increasing regulatory scrutiny and public awareness of cyber risks (Suchman, 1995; Amani et al., 2025; Muktadir-Al-Mukit & Ali, 2025; Yahaya, 2026).

Despite the growing relevance of cybersecurity disclosure, empirical evidence regarding its financial implications remains limited and inconclusive. While some studies document a positive association between cybersecurity disclosure and firm performance, suggesting that transparency contributes to stronger governance, improved risk management, and enhanced organizational outcomes (Alsadoun & Albaz, 2025; Elsayed et al., 2024), other studies argue that extensive disclosure may expose vulnerabilities, increase perceived risk, or impose additional reporting costs (Amani et al., 2025; Campbell et al., 2003). Moreover, much of the existing literature treats cybersecurity disclosure as a homogeneous construct and rarely examines the governance mechanisms that may shape its economic consequences. Consequently, our understanding of the conditions under which cybersecurity disclosure contributes to firm performance remains limited.

Boards of directors play a central role in overseeing strategic risks, including cybersecurity risks, and in shaping firms’ disclosure policies. Accordingly, board composition is expected to influence not only the extent of cybersecurity disclosure but also its disclosure quality in improving financial outcomes (Smaili et al., 2023; Alodat et al., 2025). Prior research suggests that female board representation enhances monitoring quality, risk awareness, and ethical orientation, potentially strengthening the cybersecurity governance effectiveness of disclosed cybersecurity information (Radu & Smaili, 2022; Li et al., 2022). Similarly, the presence of board members with technical or cybersecurity-related expertise may improve boards’ ability to understand complex digital risks, evaluate cybersecurity investments, and oversee disclosure quality (Alodat et al., 2025; Smaili et al., 2023). Nevertheless, empirical evidence examining these board characteristics as moderating mechanisms in the relationship between cybersecurity disclosure and financial performance remains scarce, particularly in emerging market contexts.

To the best of our knowledge, this study makes several important contributions to the literature on cybersecurity disclosure, corporate governance, and firm performance. First, we extend the emerging literature on cybersecurity disclosure by examining its financial implications within an integrated framework that distinguishes between two conceptually distinct forms of cybersecurity-related reporting: (i) cybersecurity practices disclosure and (ii) cybersecurity incident disclosure. While prior studies have frequently treated cybersecurity disclosure as a homogeneous construct (Amani et al., 2025; Elsayed et al., 2024), we argue that these two forms of disclosure serve different informational functions. Cybersecurity practices disclosure reflects firms’ communication of cybersecurity governance, policies, and risk-management activities, whereas cybersecurity incident disclosure represents communication regarding realized cyber-related events and associated organizational responses (Campbell et al., 2003; Muktadir-Al-Mukit & Ali, 2025). By distinguishing between these disclosure dimensions, our study provides a more nuanced understanding of how different forms of cybersecurity-related reporting are associated with firm financial performance.

Second, we contribute to the corporate governance literature by examining the moderation role of board characteristics in shaping the effectiveness of cybersecurity disclosure. Specifically, we examine whether female board representation and the presence of directors with technical or cybersecurity-related expertise enhance the effectiveness of cybersecurity disclosure and governance practices. Although prior research highlights the importance of board composition in monitoring and strategic decision-making (Jensen & Meckling, 1976; Radu & Smaili, 2022; Smaili et al., 2023), as well as its role in improving organizational outcomes and financial performance by reducing information asymmetry and enhancing transparency (Almulhim, 2022; Ali et al., 2017; Chung & Hrazdil, 2010), empirical evidence on its moderating role in the cybersecurity disclosure–performance nexus remains scarce. Our study addresses this gap by demonstrating how governance mechanisms influence not only disclosure practices but also their economic consequences.

Third, this study provides novel evidence from an important yet underexplored institutional setting. We focus on the Saudi Stock Exchange (Tadawul), which represents the largest capital market in the Middle East and North Africa (MENA) region and reflects a rapidly evolving economic environment within a G20 economy (Almulhim, 2022). In line with Saudi Vision 2030, the Kingdom has undertaken substantial investments in digital transformation and cybersecurity infrastructure, accompanied by strengthened regulatory frameworks governing corporate transparency, governance practices, and cybersecurity oversight (Aloufi et al., 2025; Malik, 2026). These efforts are further supported by key institutions such as the National Cybersecurity Authority, which has introduced comprehensive frameworks and guidelines to enhance cyber resilience and disclosure practices (Al-Zahrani & Al-Salloum, 2025). In addition, prior evidence from the Saudi context highlights the importance of governance structures in shaping corporate transparency and financial performance (Almulhim, 2022). Despite these significant institutional developments, systematic empirical evidence on cybersecurity disclosure, board structure, and its financial implications remains limited in the Saudi context.

The remainder of the paper is structured as follows. Section 2 reviews the relevant literature and develops the research hypotheses. Section 3 describes the data and research methodology. Section 4 presents and discusses the empirical results. Section 5 provides robustness checks. Section 6 concludes the study and outlines the policy implications.

2. Review of the literature and hypothesis development

2.1 Theoretical foundations of cybersecurity disclosure

Cybersecurity disclosure represents an increasingly important dimension of non-financial reporting, reflecting firms’ responses to the growing strategic significance of digital risks. As organizations become more dependent on digital infrastructure and data-driven operations, cybersecurity has become critical for operational continuity, risk management, and long-term organizational sustainability. Consequently, cybersecurity-related disclosure serves not only as an informational mechanism but also as a governance, accountability, and legitimacy tool through which firms communicate their approaches to managing cyber risks.

Agency theory provides one explanation for cybersecurity disclosure. According to Jensen and Meckling (1976), disclosure reduces information asymmetry between managers and stakeholders by providing information regarding how cyber risks are identified, monitored, and mitigated. Given the technical complexity and opacity of cybersecurity risks, managers may otherwise possess information advantages that limit stakeholders’ ability to evaluate firms cyber preparedness. Cybersecurity disclosure can therefore function as a governance mechanism that enhances transparency and strengthens monitoring, particularly when supported by effective board oversight (Smaili et al., 2023).

Stakeholder theory further suggests that firms are accountable to a broad range of stakeholders whose interests may be directly affected by cybersecurity failures, including customers, investors, employees, regulators, and business partners (Freeman, 1984). From this perspective, cybersecurity disclosure enables firms to demonstrate responsiveness to stakeholder concerns regarding data security, operational reliability, and risk management. Accordingly, disclosure contributes to maintaining stakeholder relationships and supporting organizational sustainability (Elsayed et al., 2024).

Legitimacy theory offers an additional explanation for cybersecurity disclosure. Firms operate within a broader social and regulatory environment and must continuously demonstrate that their actions are consistent with societal expectations and institutional requirements (Suchman, 1995). Cybersecurity disclosure may therefore serve as a mechanism through which firms maintain or restore legitimacy by demonstrating accountability, transparency, and compliance with evolving cybersecurity expectations. This perspective is particularly relevant in the Saudi context, where the National Cybersecurity Authority (NCA), the Essential Cybersecurity Controls (ECC), and broader governance and risk-reporting requirements have increased organizational attention to cybersecurity governance and disclosure. In such settings, cybersecurity disclosure may reflect not only voluntary communication but also firms’ efforts to demonstrate compliance with regulatory expectations and maintain institutional legitimacy (Amani et al., 2025; Muktadir-Al-Mukit & Ali, 2025).

Signaling theory also provides complementary insights into cybersecurity disclosure. Firms with stronger cybersecurity governance and risk-management capabilities may voluntarily disclose cybersecurity-related information to distinguish themselves from less-prepared firms and communicate the quality of their governance practices (Spence, 1978). However, in environments characterized by increasing regulatory oversight and disclosure expectations, cybersecurity disclosure may simultaneously reflect voluntary signaling, stakeholder accountability, and regulatory compliance. Consequently, cybersecurity disclosure should not be viewed solely as a discretionary signal of firm quality but rather as a multidimensional governance mechanism influenced by both market and institutional forces.

Collectively, agency theory, stakeholder theory, legitimacy theory, and signaling theory suggest that cybersecurity disclosure can influence firm performance by enhancing transparency, reducing information asymmetry, supporting stakeholder relationships, strengthening governance processes, and demonstrating compliance with evolving regulatory expectations. These theoretical perspectives provide the foundation for the development of the study’s hypotheses.

2.2 Cybersecurity practices disclosure and financial performance

Prior literature examining the relationship between cybersecurity practices disclosure and firm financial performance provides mixed but increasingly supportive evidence. On the one hand, cybersecurity initiatives require substantial investments in technology, personnel, monitoring systems, and compliance mechanisms. These expenditures may increase operating costs and place pressure on short-term profitability, particularly when the financial benefits of cybersecurity investments are difficult to observe immediately (Amani et al., 2025). Moreover, extensive cybersecurity disclosure may increase reporting costs or draw attention to firms’ exposure to digital risks. On the other hand, cybersecurity practices can strengthen organizational resilience, reduce the likelihood of operational disruptions, improve risk management processes, and support the long-term sustainability of business operations. From a resource dependence perspective, firms that invest in and communicate robust cybersecurity practices are better positioned to manage environmental uncertainty and protect valuable organizational resources (Sulaiman et al., 2022; Al-Sartawi et al., 2021; Kurair & Adedokun, 2026).

Prior studies further suggest that cybersecurity disclosure is shaped by governance structures and organizational incentives. Masoud and Al-Utaibi (2022) identify several determinants of cybersecurity risk disclosure, highlighting the importance of firm characteristics and governance mechanisms in shaping disclosure practices. Similarly, Al-Janadi et al. (2013) finds that stronger corporate governance mechanisms improve disclosure quality among Saudi listed firms, reinforcing the role of governance in enhancing transparency and accountability. This is consistent with broader governance literature, which documents a positive relationship between governance quality and firm performance (Ntim et al., 2015; Bhagat & Bolton, 2008).

Empirical evidence generally supports the view that cybersecurity-related investments and practices contribute to improved organizational outcomes. Dinkova et al. (2024) reports that cybersecurity investment positively affects the financial performance enhancing operational stability and efficiency. Likewise, Al-Somali et al. (2024) show that cybersecurity systems improve sustainable business performance among Saudi SMEs, particularly through enhanced cybersecurity resilience and organizational culture. Havakhor et al. (2026) further document that cybersecurity-related investments are associated with lower financing costs and greater financial stability.

Evidence from disclosure-oriented studies provides additional support. Alsadoun and Albaz (2025) find a positive association between cybersecurity risk disclosure and firm value in Saudi Arabia, while Elsayed et al. (2024) report that cybersecurity disclosure improves the financial performance of banks in the MENA region, particularly when supported by effective governance mechanisms. Similarly, Matemane et al. (2024) document a positive relationship between cybersecurity risk disclosure and firm performance in an emerging market context. Yahaya (2026) also finds that cybersecurity disclosure is positively associated with market valuation. Although these studies examine different outcomes, collectively they suggest that cybersecurity transparency may generate economic benefits through improved governance, stronger risk management, and enhanced organizational credibility.

Recent studies further highlight that cybersecurity transparency contributes to organizational success and broader firm outcomes (Al Amosh & Khatib, 2025), improves financial reporting quality and firm value (Basiouny, 2024), and is influenced by strategic factors that shape disclosure practices (Hasan et al., 2025). These findings are consistent with broader disclosure literature suggesting that transparency in non-financial reporting can improve organizational outcomes and support long-term performance (Alsaifi et al., 2020; Velte, 2024).

From a theoretical perspective, the positive association between cybersecurity practices disclosure and firm performance can be explained through agency, stakeholder, legitimacy, and signaling perspectives. Cybersecurity disclosure reduces information asymmetry, demonstrates accountability in managing cyber risks, strengthens stakeholder relationships, and communicates firms’ commitment to effective governance and regulatory compliance. In the Saudi context, where cybersecurity governance expectations have increased through initiatives such as the National Cybersecurity Authority’s Essential Cybersecurity Controls and broader corporate governance requirements, cybersecurity disclosure may reflect both voluntary transparency and compliance with evolving institutional expectations. Consequently, firms that provide greater cybersecurity practices disclosure are expected to exhibit superior financial performance. Accordingly, the following hypothesis is proposed:

H1:

Cybersecurity practices disclosure has a positive impact on firms’ financial performance.

2.3 Cybersecurity incident disclosure and financial performance

Cybersecurity incident disclosure differs fundamentally from cybersecurity practices disclosure because it is typically reactive and associated with the occurrence of adverse cyber events. Whereas cybersecurity practices disclosure communicates firms’ preparedness and risk-management capabilities, cybersecurity incident disclosure often reflects realized cybersecurity failures, data breaches, or system disruptions. Consequently, the economic implications of incident disclosure may differ substantially from those of proactive cybersecurity reporting.

Legitimacy theory provides one explanation for incident disclosure. Following a cybersecurity incident, firms may disclose relevant information to demonstrate accountability, comply with regulatory expectations, and maintain organizational legitimacy (Suchman, 1995). Transparent disclosure may signal that management is responding appropriately to the incident and implementing corrective actions. Amani et al. (2025) argue that incident disclosure within a broader cybersecurity governance framework can contribute to organizational accountability and support firms’ efforts to manage the consequences of cybersecurity failures. Nevertheless, incident disclosure simultaneously reveals the occurrence of cyber-related problems, creating uncertainty regarding firms’ internal controls, operational resilience, and risk-management effectiveness.

A growing body of literature suggests that cybersecurity incident disclosure can generate substantial economic consequences for firms. Cyber incidents may result in operational disruptions, remediation expenditures, legal liabilities, regulatory penalties, and reputational challenges, all of which can adversely affect organizational performance. Early evidence by Campbell et al. (2003) documents negative capital-market reactions following information security breach announcements. More recently, Muktadir-Al-Mukit and Ali (2025) report significant abnormal negative returns following cyber-attack announcements, with market responses varying according to incident severity and disclosure credibility. Although these studies focus on short-term capital-market consequences rather than accounting performance, they demonstrate the economic significance of cybersecurity incident disclosure and highlight the potential costs associated with cyber-related failures.

Additional evidence indicates that cybersecurity breaches influence both disclosure practices and corporate behavior. Swift et al. (2020) show that cyber incidents significantly affect the content and tone of subsequent cybersecurity disclosures, reflecting firms’ efforts to communicate information regarding cyber-related events and corrective actions. Collectively, this literature suggests that cybersecurity incident disclosure may be associated with weaker financial performance because it reveals the occurrence of events that can impose substantial operational, legal, and reputational costs on firms. Accordingly, the following hypothesis is proposed:

H2:

Cybersecurity incident disclosure has a negative and significant impact on firms’ financial performance.

2.4 Cybersecurity disclosure, board gender diversity, and financial performance

Board gender diversity has been widely recognized as an important corporate governance mechanism that influences monitoring effectiveness, risk oversight, strategic decision-making, and disclosure quality. Agency theory suggests that female directors can strengthen board independence and monitoring functions, thereby reducing managerial opportunism and improving governance outcomes (Jensen & Meckling, 1976). Stakeholder theory further argues that gender-diverse boards are more responsive to stakeholder concerns and societal expectations, particularly in areas related to transparency, accountability, and risk management (Freeman, 1984).

Empirical evidence supports the relevance of board gender diversity in cybersecurity-related settings. Radu and Smaili (2022) show that boards with higher female representation exhibit stronger responses to cyber risks. Remeis (2023) documents a positive association between board gender diversity and cybersecurity disclosure characteristics. In the Saudi context, Li et al. (2022) finds that female board representation is associated with lower corporate risk-taking. More recent studies suggest that female directors contribute to stronger cybersecurity governance and disclosure practices, particularly when a critical mass of female representation is achieved (Afroze et al., 2026). Similarly, Elnahass et al. (2025) report that female leadership is associated with more transparent cybersecurity communication and enhanced disclosure quality.

Board gender diversity is expected to moderate the relationship between cybersecurity disclosure and financial performance by improving board oversight, strengthening risk-monitoring processes, and enhancing the effectiveness of cybersecurity governance. Given the complexity and uncertainty associated with cyber risks, female directors may encourage more comprehensive evaluation of cybersecurity threats, greater attention to risk-management practices, and more transparent communication regarding cyber-related issues. Consequently, cybersecurity disclosures may become more informative and useful for stakeholders when supported by gender-diverse boards, thereby enhancing their potential contribution to firm performance. Accordingly, the following hypothesis is proposed:

H3:

Female board representation positively influences the relationship between cybersecurity disclosure and firms’ financial performance.

2.5 Cybersecurity disclosure, board members’ technical expertise, and financial performance

As cyber threats become increasingly sophisticated, board members’ technical and cybersecurity-related expertise has emerged as an important governance mechanism. Resource dependence theory suggests that boards provide firms with valuable knowledge, skills, and expertise needed to manage environmental uncertainty and complex organizational challenges (Pfeffer & Salancik, 2015). Directors possessing technical expertise are better positioned to evaluate cybersecurity investments, assess cyber-related risks, oversee cybersecurity governance, and monitor the quality of cybersecurity disclosure (Al-Sartawi, 2020; Ahmadoni, 2025).

Empirical evidence supports the importance of board-level technical expertise in cybersecurity-related settings. Alodat et al. (2025) find that board technical expertise significantly enhances the quality of cybersecurity disclosure among UK firms. Smaili et al. (2023) further show that effective cybersecurity oversight is closely linked to directors’ technical competencies. Similarly, Mazumder and Hossain (2023) provide evidence from the banking sector that board composition plays an important role in shaping cybersecurity disclosure practices, highlighting the importance of board expertise and governance structure. Elsayed et al. (2024) report that governance quality, including technical expertise, strengthens the positive association between cybersecurity disclosure and organizational outcomes in the MENA region.

Additional studies reinforce these findings. Héroux and Fortin (2024) demonstrate that board attributes, particularly technical expertise, significantly influence cybersecurity disclosure practices. Likewise, Khadim and Kakar (2025) find that IT governance expertise at the board level enhances both the extent and quality of cybersecurity-related disclosures. Elmarzouky et al. (2025) further emphasize the role of board commitment and regulatory pressures in shaping cybersecurity transparency. Moreover, Yahaya (2026) reports that stronger cybersecurity governance frameworks are associated with improved organizational performance and resilience.

Board members’ technical expertise is therefore expected to moderate the relationship between cybersecurity disclosure and financial performance by strengthening cybersecurity oversight, improving the quality of disclosure processes, and ensuring that cybersecurity-related information accurately reflects firms’ underlying risk-management practices. Directors with relevant technical expertise are better able to interpret cybersecurity risks, evaluate disclosure quality, and support effective cybersecurity governance. Consequently, cybersecurity disclosures are expected to be more informative and useful when supported by technically competent boards, thereby enhancing their contribution to firm performance. Accordingly, the following hypothesis is proposed:

H4:

Board members’ technical expertise positively influences the relationship between cybersecurity disclosure and firms’ financial performance.

3. Data and methodology

3.1 Data sample

This study investigates the impact of cybersecurity disclosure on firm financial performance, with particular emphasis on the moderating roles of women representation and technological expertise on the board of directors. The empirical analysis is based on a comprehensive dataset covering firms listed on the Saudi Stock Exchange. Data collection and screening were conducted carefully to ensure consistency, reliability, and comparability across firms.

The study focuses on the period from 2020 to 2024, a timeframe selected due to the increasing emphasis placed on cybersecurity governance and digital risk management in Saudi Arabia, particularly following major regulatory developments associated with National Cybersecurity Authority initiatives and broader digital transformation efforts aligned with Saudi Vision 2030. This period also coincides with a global surge in cybersecurity awareness and disclosure practices following accelerated digitalization in the post-pandemic era, which significantly increased firms’ exposure to cyber risks and regulatory scrutiny (Amani et al., 2025; Hasan et al., 2025; Elmarzouky et al., 2025). This period captures the heightened corporate awareness of cybersecurity risk and the growing expectations surrounding cybersecurity-related disclosures among listed firms.

Given the nature of the data, board and financial variables were manually collected, while cybersecurity disclosure variables were constructed using automated text analysis in Python. This manual data collection approach ensures greater accuracy in capturing disclosure practices and governance attributes and is consistent with prior studies relying on narrative corporate reporting.

The initial sample consisted of 207 listed firms. A purposive sampling approach was employed, excluding financial institutions and related entities because their financial performance, governance structures, and disclosure practices are subject to unique regulatory frameworks and supervisory requirements that differ substantially from those of non-financial firms. Restricting the sample to non-financial firms enhances comparability and ensures that the analysis reflects firms operating under relatively homogeneous reporting and governance environments (Almulhim, 2023). Accordingly, 40 financial firms were excluded from the initial population of listed companies.

To preserve analytical reliability, only firms with complete financial, governance, and disclosure data required to construct the study variables were retained. That is, observations with missing board of directors’ reports or incomplete governance disclosures, particularly those lacking sufficient cybersecurity-related information, were omitted from the final sample. Consequently, 12 firms were excluded due to missing or incomplete disclosure and governance data. After applying these screening criteria, the final panel dataset comprises 775 firm-year observations from 155 non-financial firms listed on Tadawul over the period 2020–2024.

3.2 Measures

3.2.1 Financial performance variables

Consistent with the established literature, this study employs accounting-based measures of financial performance as dependent variables, namely return on assets (ROA) and return on equity (ROE). ROA is calculated as net income divided by total assets and reflects the efficiency with which firms utilize their assets to generate earnings. ROE is measured as net income divided by total shareholders’ equity and captures the profitability attributable to shareholders. These measures are widely used in prior studies examining the effects of disclosure practices and corporate governance mechanisms on firm performance, particularly within governance and emerging market contexts (Elsayed et al., 2024; Al-Janadi et al., 2013; Buallay, 2020; Velte, 2024; Bhagat & Bolton, 2008).

3.2.2 Cybersecurity disclosure variables

Cybersecurity disclosure constitutes the core independent construct in this study and is measured using three complementary indicators. First, cybersecurity disclosure (CID) is a binary variable that takes the value of 1 if a firm discloses cybersecurity-related information in its board of directors’ report and 0 otherwise. CID therefore captures the presence of cybersecurity-related disclosure board of directors’ report. Second, cybersecurity incident disclosure (CI) is a binary variable that takes the value of 1 if a firm discloses information regarding cybersecurity-related incidents in its board report and 0 otherwise. Accordingly, CI measures the disclosure of cybersecurity incidents board of directors’ report.

The cybersecurity disclosure variables were constructed using automated text-analysis techniques implemented in Python. Annual reports were collected from firms’ official websites, and content analysis was conducted using a predefined cybersecurity keyword dictionary. The resulting measures capture different dimensions of cybersecurity-related reporting, including disclosure presence (CID) and cybersecurity incident disclosure (CI). This approach is consistent with recent empirical studies employing content analysis and textual disclosure measures to assess cybersecurity reporting practices (Amani et al., 2025; Hasan et al., 2025; Masoud & Al-Utaibi, 2022; Basiouny, 2024; Elmarzouky et al., 2025; Swift et al., 2020).

3.2.3 Moderation variables

This study incorporates two moderating variables reflecting board characteristics that may influence the relationship between cybersecurity disclosure and financial performance. The first moderating variable is female board representation (Women), measured as the proportion of female directors relative to the total number of board members. This measurement is widely adopted in prior studies examining the role of gender diversity in enhancing disclosure practices and governance effectiveness (Radu & Smaili, 2022; Li et al., 2022; Elnahass et al., 2025; Afroze et al., 2026).

The second moderating variable is board members’ technical expertise (Tech_Board), measured as the proportion of directors possessing professional backgrounds or expertise in information technology, cybersecurity, or related technical fields. This proxy is supported by recent literature emphasizing the importance of board-level technological competence in improving cybersecurity oversight, disclosure quality, and risk management (Alodat et al., 2025; Héroux & Fortin, 2024; Khadim & Kakar, 2025; Hasan et al., 2025).

3.2.4 Control variables

Consistent with prior research in corporate governance and disclosure studies (Elsayed et al., 2024; Al-Janadi et al., 2013; Bhagat & Bolton, 2008; Ntim et al., 2015), several firm-level control variables are included to account for heterogeneity across firms. Firm size (Size) is measured as the natural logarithm of total assets. Firm age (Age) is defined as the number of years since the firm’s establishment. Board size (BoardSize) is measured as the total number of directors serving on the board. Financial leverage (Leverage) is calculated as total liabilities divided by total shareholders’ equity. In addition, year and industry dummy variables are incorporated to control for time-specific and cross-sectional effects during the study period. Table 1 presents detailed definitions and measurements of all variables employed in the empirical analysis.

Table 1. Definitions and measurement of study variables.

Panel A: Dependent variables
No.Variable nameSymbolMeasurement description
1Return on AssetsROANet income divided by total assets
2Return on EquityROENet income divided by total shareholders’ equity
Panel B: Independent variables
No.Variable nameSymbolMeasurement description
1Cybersecurity DisclosureCIDDummy variable equal to 1 if the firm discloses cybersecurity-related information in the board of directors’ report, and 0 otherwise
2Cybersecurity Incident DisclosureCIDummy variable equal to 1 if the firm discloses cybersecurity incident disclosure, and 0 otherwise
Panel C: Moderating Variables
No.Variable NameSymbolMeasurement Description
1Female Board RepresentationWomenNumber of female directors divided by the total number of board members
2Board Members’ Technical ExpertiseTech_BoardNumber of board members with technical or cybersecurity-related expertise divided by the total number of board members
Panel D: Control Variables
No.Variable NameSymbolMeasurement Description
1Firm SizeSizeNatural logarithm of total assets
2Firm AgeAgeNumber of years since the firm’s establishment
3Board SizeBoardSizeTotal number of board members
4Financial LeverageLeverageTotal liabilities divided by total shareholders’ equity

3.3 Estimation models

This study examines the relationship between cybersecurity disclosure and firm financial performance, while also assessing the moderating roles of women representation and board technological expertise. The empirical framework is designed to capture both the direct effect of cybersecurity disclosure on firm performance and the extent to which board characteristics influence this relationship. To empirically test the proposed hypotheses, a set of regression models is developed, progressing from baseline estimations to moderated specifications.

The models are initially estimated using pooled ordinary least squares (OLS) with year and industry fixed effects to capture average relationships across firms while controlling for time-specific and sectoral influences. Robust standard errors clustered at the firm level are employed to address potential within-firm correlation over time. In addition, all continuous variables are winsorized at the 1st and 99th percentiles to mitigate the influence of extreme observations and reduce the potential impact of outliers on the estimation results. To enhance robustness, alternative specifications are estimated to ensure that the findings are not sensitive to model choice.

Furthermore, to address potential endogeneity concerns, including reverse causality and the dynamic persistence of firm performance, the study employs the two-step System Generalized Method of Moments (System GMM) estimator. Given that firm performance is inherently dynamic, incorporating lagged dependent variables within a dynamic panel framework allows the analysis to capture adjustment processes over time while reducing potential biases arising from omitted variables and simultaneity.

Firm performance is measured using two accounting-based indicators, namely return on assets (ROA) and return on equity (ROE). Cybersecurity disclosure is proxied using alternative measures, including the Cybersecurity Disclosure (CID) and Cyber Incidents (CI), which are introduced separately in the regression specifications to avoid multicollinearity concerns. The baseline model is specified as follows:

(1)
Performanceit=β0+β1CyberDisclosureit+β2Sizeit+β3Ageit+β4BoardSizeit+β5Leverageit+β6Yearit+β7Industryit+εit

To examine whether women representation influences the relationship between cybersecurity disclosure and firm performance, the baseline model is extended by including an interaction term between cybersecurity disclosure and the proportion of female directors on the board. This specification allows for testing whether gender diversity moderates the effect of cybersecurity disclosure on financial performance. The model is specified as follows:

(2)
Performanceit=β0+β1CyberDisclosureit+β2Womenit+β3(CyberDisclosureit×Womenit)+β4Sizeit+β5Ageit+β6BoardSizeit+β7Leverageit+β8Yearit+β9Industryit+εit
Similarly, to assess the moderating role of board technological expertise, an interaction term between cybersecurity disclosure and a proxy for board-level technical expertise (Tech_Board) is incorporated into the model. This variable captures the presence or proportion of directors with information technology or cybersecurity-related expertise, reflecting the board’s ability to effectively oversee digital risks. The model is specified as follows:
(3)
Performanceit=β0+β1CyberDisclosureit+β2Tech_Boardit+β3(CyberDisclosureit×Tech_Boardit)+β4Sizeit+β5Ageit+β6BoardSizeit+β7Leverageit+β8Yearit+β9Industryit+εit
In all specifications, firm size is measured as the natural logarithm of total assets, firm age is defined as the number of years since incorporation, board size represents the total number of directors, and leverage is calculated as total liabilities divided by total shareholders’ equity. Year fixed effects are included to control for macroeconomic conditions and time-specific shocks affecting all firms, while industry fixed effects account for sectoral differences in cybersecurity exposure, governance structures, and disclosure practices.

Overall, this empirical strategy provides a comprehensive and robust framework for examining both the direct and moderating effects of cybersecurity disclosure on firm performance, ensuring that the results are not driven by model specification, omitted variables, or endogeneity concerns. All statistical analyses were performed using STATA, including the estimation of OLS and System GMM models.

4. Results

4.1. Descriptive statistics and correlations

As presented in Table 2, the descriptive statistics provide an overview of firm performance, cybersecurity disclosure, and board characteristics across Saudi listed firms over the study period. The average return on assets (ROA) is 5.4%, while the mean return on equity (ROE) is 11.2%, indicating moderate profitability levels with considerable variation, as reflected in their standard deviations. The minimum values of both ROA and ROE suggest that some firms experienced substantial losses during the sample period, whereas the maximum values indicate the presence of highly profitable firms.

Table 2. Descriptive statistics.

VariableObservationMeanSDMin Max
ROA7750.0540.072−0.2310.284
ROE7750.1120.156−0.4870.521
CID7750.510.490.001.00
CI7750.480.490.001.00
Women7750.160.110.000.45
Tech_Board7750.440.190.000.54
Size77515.821.4712.9419.63
Age77521.610.33.0067
BoardSize7758.111.725.0013
Leverage7750.420.210.160.77

Cybersecurity disclosure measures exhibit moderate prevalence across firms. The Cybersecurity Disclosure (CID) variable has a mean value of 0.51, indicating that approximately 51% of the firm-year observations disclose cybersecurity-related information in their board of directors’ reports. Similarly, the Cyber Incidents (CI) variable shows a mean of 0.48, suggesting that around 48% of firm-year observations disclose cybersecurity-related incidents. These values reflect a relatively balanced distribution of disclosure practices across the sample. With respect to board characteristics, female representation on boards remains relatively limited, with an average of 16%, highlighting the still-emerging role of gender diversity in the Saudi corporate environment. In contrast, directors with technological or cybersecurity-related expertise represent approximately 44% of total board membership on average, reflecting increasing attention to digital governance and cybersecurity oversight.

Regarding control variables, the average firm size (measured as the natural logarithm of total assets) is 15.82, indicating a sample dominated by relatively large firms. Firms in the sample have an average age of approximately 22 years, suggesting a mix of mature and relatively younger firms. The mean board size is around eight members, which is consistent with corporate governance practices in emerging markets. Finally, the average leverage ratio is 42%, indicating a moderate reliance on debt financing, with variation across firms.

Furthermore, Table 3 presents the correlation matrix coefficients among the study variables. The two measures of firm performance (ROA and ROE) are strongly and positively correlated (r = 0.62, p < 0.05), confirming that both indicators capture similar aspects of firms’ financial performance. Cybersecurity disclosure measure (CID) shows positive and significant correlations with both performance measures (e.g., r = 0.21 for ROA and r = 0.18 for ROE), suggesting that higher disclosure is associated with better financial outcomes. In contrast, cyber incidents (CI) exhibit a negative relationship with both ROA and ROE (r = âˆ’0.14 and âˆ’ 0.11), indicating potential adverse effects on firm performance. Nonetheless, the primary objective of this test is to ensure that multicollinearity does not pose a concern among the study’s explanatory variables. As shown in Table 3, the highest observed correlation is between CID and Size (0.35), which remains within acceptable limits and does not indicate serious multicollinearity concerns.

Table 3. Correlation matrix.

VariablesROA ROECIDCI Women Tech_Board Size Leverage AgeBoardSize
ROA1.00
ROE0.62*1.00
CID0.21*0.18*1.00
CI−0.14*−0.11*0.091.00
Women0.10*0.080.22*−0.031.00
Tech_Board0.17*0.14*0.31*−0.050.12*1.00
Size0.23*0.20*0.35*0.060.19*0.27*1.00
Leverage−0.28*−0.31*−0.080.04−0.07−0.050.21*1.00
Age0.070.050.16*0.020.060.11*0.29*0.10*1.00
BoardSize0.12*0.090.25*0.050.15*0.18*0.33*0.080.13*1.00

* Indicates significance level at 5%.

4.2 Cybersecurity disclosure and firm financial performance

Table 4 presents the relationship between cybersecurity disclosure and the financial performance of firms listed on the Saudi Stock Exchange. With respect to cybersecurity practices disclosure (CID), the results reported in Models (1) and (3) indicate a positive and statistically significant association with both ROA (β = 0.0524, p < 0.01) and ROE (β = 0.0996, p < 0.01). These findings suggest that firms disclosing cybersecurity-related practices exhibit superior financial performance relative to non-disclosing firms, thereby supporting Hypothesis 1 (H1). This result is consistent with agency, stakeholder, legitimacy, and signaling perspectives, which collectively suggest that cybersecurity disclosure enhances transparency, reduces information asymmetry, demonstrates effective risk-management practices, and reflects firms’ commitment to cybersecurity governance and regulatory expectations. Through these mechanisms, cybersecurity disclosure may contribute to improved operational resilience and stronger financial outcomes. These findings are consistent with prior studies such as Alsadoun and Albaz (2025), Elsayed et al. (2024), and Matemane et al. (2024), which document positive economic consequences associated with cybersecurity disclosure and transparency. The results are also consistent with broader non-financial disclosure literature suggesting that transparency reduces information asymmetry and supports improved organizational outcomes (Alsaifi et al., 2020).

Table 4. Cybersecurity disclosure and firm performance.

VARIABLES(1)(2)(3)(4)
ROAROAROE ROE
CID0.0524***-0.0996***-
(3.441)(3.618)
CI-−0.0189**-−0.0362**
(−2.267)(−2.412)
Size0.0178***0.0175***0.0319***0.0315***
(3.102)(3.065)(3.587)(3.521)
Age0.00030.00030.00050.0005
(0.472)(0.488)(0.509)(0.533)
BoardSize0.00420.00400.00760.0071
(0.956)(0.927)(1.071)(1.015)
Leverage−0.0396***−0.0392***−0.0711***−0.0705***
(−5.882)(−5.627)(−7.398)(−7.102)
Constant−0.1187**−0.1125**−0.2123**−0.2017**
(−2.034)(−2.015)(−2.121)(−2.089)
Observations775775775775
R-squared 0.3840.3910.4060.409
Year EffectYES YES YES YES
Industry EffectYES YES YES YES

*** p < 0.01,

** p < 0.05,

* p < 0.1

In contrast, the results for cybersecurity incident disclosure (CI) in Models (2) and (4) reveal a negative and statistically significant association with financial performance, with coefficients of (β = âˆ’0.0189, p < 0.05) for ROA and (β = âˆ’0.0362, p < 0.05) for ROE. These findings indicate that the disclosure of cybersecurity incidents is associated with lower financial performance, thus supporting Hypothesis 2 (H2). One possible explanation is that cybersecurity incident disclosure often imposes substantial organizational costs, including operational disruptions, remediation expenditures, regulatory compliance costs, and reputational challenges. Consequently, firms disclosing cybersecurity incidents may experience weaker financial performance than firms that do not report such incidents. These findings are consistent with prior literature documenting the economic consequences of cybersecurity failures. Campbell et al. (2003) and Muktadir-Al-Mukit and Ali (2025) report negative capital-market reactions following cybersecurity breach announcements. Although those studies focus on market-based outcomes rather than accounting performance, they highlight the economic significance of cybersecurity incident disclosure and provide supporting evidence that cyber-related failures can impose meaningful costs on firms.

Regarding the control variables, firm size (Size) exhibits a positive and statistically significant effect at the 1% level on financial performance across all models. This suggests that larger firms achieve higher profitability due to greater resource availability, economies of scale, and enhanced capacity to invest in technological infrastructure, including cybersecurity systems. This finding is consistent with prior literature documenting a positive relationship between firm size and financial performance, particularly in environments requiring substantial technological investments (Bhagat & Bolton, 2008; Ntim et al., 2015; Velte, 2024). In contrast, firm age (Age) and board size (BoardSize) do not exhibit statistically significant effects, as their coefficients are insignificant across all models. This suggests that these factors do not play a decisive role in explaining financial performance within the context of Saudi listed firms during the study period. This may indicate that accumulated experience or board size alone does not necessarily translate into improved operational efficiency or financial outcomes. This finding partially aligns with prior research suggesting that the effect of board characteristics may be indirect and contingent upon other governance factors, such as board quality and expertise diversity (Al-Janadi et al., 2013).

On the other hand, financial leverage (Leverage) shows a negative and highly significant effect at the 1% level across all models, indicating that higher reliance on debt is associated with lower financial performance. This can be attributed to increased financial obligations and higher default risk, which adversely affect firm profitability. This finding is consistent with financial literature suggesting that excessive leverage negatively impacts firm performance, particularly in high-risk environments such as those characterized by cybersecurity threats (Bhagat & Bolton, 2008; Ntim et al., 2015).

4.3 Board gender diversity, cybersecurity disclosure, and financial performance

The regression results presented in Table 5 examine the moderating effect of women representation on the relationship between cybersecurity disclosure and firm financial performance. The findings indicate that cybersecurity practices disclosure (CID) remains positively and statistically significant at the 1% level in Models (1) and (3), with coefficients of (β = 0.0481, p < 0.01) for ROA and (β = 0.0923, p < 0.01) for ROE. Similarly, cybersecurity incident disclosure continues to exhibit a negative and statistically significant effect in Models (2) and (4), indicating that the baseline relationship remains qualitatively unchanged after incorporating board gender diversity and its interaction effects. With respect to women representation (Women), the results show a positive and weakly significant direct effect on financial performance in Models (1) and (3), at the 10% level (β = 0.0215, p < 0.1 for ROA; β = 0.0384, p < 0.1 for ROE). This suggests that firms with higher female representation on boards tend to exhibit slightly better financial performance, although the direct effect remains relatively limited.

Table 5. Moderating effect of women representation on cybersecurity disclosure and firm performance.

VARIABLES(1)(2)(3)(4)
ROAROA ROEROE
CID0.0481***-0.0923***-
(3.112)(3.287)
CI-−0.0167** (−2.081)-−0.0321** (−2.214)
Women0.0215* (1.742)0.0189 (1.512)0.0384* (1.801)0.0327 (1.463)
CID*Women0.0346** (2.217)-0.0618** (2.354)-
CI*Women-0.0285* (1.682)-0.0521* (1.744)
Size0.0176*** (3.045)0.0173*** (3.012)0.0316*** (3.521)0.0312*** (3.487)
Age0.0003 (0.481)0.0003 (0.497)0.0005 (0.521)0.0005 (0.538)
BoardSize0.0041 (0.948)0.0039 (0.915)0.0073 (1.042)0.0069 (0.998)
Leverage−0.0393*** (−5.701)−0.0389*** (−5.442)−0.0708*** (−7.201)−0.0701*** (−6.948)
Constant−0.1162** (−2.021)−0.1104** (−1.998)−0.2087** (−2.103)−0.1983** (−2.074)
Observations775775775775
R-squared 0.4210.4350.4410.555
Year EffectYES YES YES YES
Industry EffectYES YES YES YES

*** p < 0.01,

** p < 0.05,

* p < 0.1.

More importantly, the interaction term between cybersecurity practices disclosure and women representation (CID*Women) is positive and statistically significant at the 5% level in both Models (1) and (3) (β = 0.0346, p < 0.05; β = 0.0618, p < 0.05). The positive interaction term indicates that the performance benefits associated with cybersecurity disclosure are greater in firms with higher levels of female board representation. This finding suggests that board gender diversity enhances the effectiveness of cybersecurity disclosure, potentially by improving board oversight, strengthening monitoring quality, and encouraging greater attention to cyber-related risks and governance practices. Accordingly, the positive association between cybersecurity disclosure and firm performance becomes stronger in firms with more gender-diverse boards. This finding supports Hypothesis 3 (H3). From an agency and stakeholder perspective, female directors are often associated with stronger monitoring, higher ethical standards, and greater sensitivity to risk, which may contribute to higher-quality cybersecurity governance and disclosure processes. Consequently, cybersecurity disclosure may become more informative and more closely associated with improved firm performance when supported by gender-diverse boards. These findings are consistent with prior literature. Radu and Smaili (2022) show that gender-diverse boards are more responsive to cybersecurity risks, while Remeis (2023) documents a positive relationship between female representation and cybersecurity disclosure quality. Similarly, Elnahass et al. (2025) find that female leadership improves the tone and quality of cybersecurity disclosure, and Afroze et al. (2026) highlight the role of female directors in enhancing disclosure practices. In the Saudi context, Li et al. (2022) also reports that female board representation contributes to improved governance outcomes and reduced firm risk.

Furthermore, the interaction term between cybersecurity incident disclosure and women representation (CI*Women) is positive and weakly significant at the 10% level in Models (2) and (4) (β = 0.0285, p < 0.1; β = 0.0521, p < 0.1). This suggests that female board representation weakens the adverse association between cybersecurity incident disclosure and firm performance. In other words, although cybersecurity incident disclosure generally reduces firm performance, their adverse effect becomes less severe in firms with higher female representation. This may be attributed to improved crisis management, enhanced transparency, and more effective communication strategies associated with gender-diverse boards.

Regarding the control variables, the results remain consistent with the baseline models. Firm size continues to exhibit a positive and statistically significant effect, while leverage shows a negative and highly significant impact across all models. In contrast, firm age and board size remain statistically insignificant.

4.4 Board technological expertise, cybersecurity disclosure, and financial performance

The regression results presented in Table 6 examine the moderating role of board technological expertise (Tech_Board) on the relationship between cybersecurity disclosure and firm financial performance. The results indicate that cybersecurity practices disclosure (CID) remains positively and statistically significant at the 1% level in Models (1) and (3), with coefficients of (β = 0.0442, p < 0.01) for ROA and (β = 0.0867, p < 0.01) for ROE. Similarly, cybersecurity incident disclosure continues to exhibit a negative and statistically significant effect in Models (2) and (4), indicating that the baseline relationship remains qualitatively unchanged after incorporating board technological expertise and its interaction effects. With respect to board technological expertise (Tech_Board), the results show a positive and statistically significant direct effect on financial performance across all models, with significance levels ranging from 1% to 10% (e.g., β = 0.0268, p < 0.05 for ROA; β = 0.0492, p < 0.05 for ROE). This suggests that firms with higher levels of technical expertise within their boards tend to achieve better financial outcomes, reflecting the importance of technological competence in enhancing strategic decision-making and risk management capabilities.

Table 6. Moderating role of tech_board on cybersecurity disclosure and firm performance.

VARIABLES(1)(2)(3)(4)
ROAROAROEROE
CID0.0442*** (2.987)-0.0867*** (3.154)-
CI-−0.0158** (−2.043)-−0.0295** (−2.168)
Tech_Board0.0268** (2.104)0.0225* (1.755)0.0492** (2.231)0.0417* (1.812)
CID*Tech_Board0.0419** (2.311)-0.0725*** (2.684)-
CI*Tech_Board-0.0312** (2.012)-0.0586** (2.145)
Size0.0174*** (3.021)0.0171*** (2.988)0.0313*** (3.487)0.0309*** (3.451)
Age0.0003 (0.472)0.0003 (0.489)0.0005 (0.511)0.0005 (0.526)
BoardSize0.0040 (0.921)0.0038 (0.903)0.0071 (1.018)0.0068 (0.987)
Leverage−0.0391*** (−5.612)−0.0387*** (−5.338)−0.0704*** (−7.084)−0.0698*** (−6.821)
Constant−0.1145** (−2.008)−0.1087** (−1.984)−0.2054** (−2.087)−0.1952** (−2.061)
Observations775775775775
R-squared 0.4090.4130.4290.433
Year EffectYES YES YES YES
Industry EffectYES YES YES YES

*** p < 0.01,

** p < 0.05,

* p < 0.1.

More importantly, the interaction term between cybersecurity practices disclosure and board technological expertise (CID*Tech_Board) is positive and statistically significant at the 5% and 1% levels in Models (1) and (3) (β = 0.0419, p < 0.05; β = 0.0725, p < 0.01). This finding indicates that board technological expertise strengthens the positive relationship between cybersecurity disclosure and firm performance. In other words, the performance benefits associated with cybersecurity disclosure become stronger in firms where board members possess relevant technical knowledge. This finding supports Hypothesis 4 (H4) and highlights the critical role of board expertise in enhancing the effectiveness of cybersecurity governance and disclosure practices. From a resource dependence perspective, boards provide firms with valuable knowledge and expertise needed to manage complex technological and cybersecurity challenges. Directors with relevant technical expertise are better able to interpret cybersecurity risks, evaluate disclosure quality, and support effective cybersecurity governance, thereby enhancing the contribution of cybersecurity disclosure to firm performance. These findings are consistent with prior literature. Alodat et al. (2025) show that board technical expertise improves cybersecurity disclosure quality, while Smaili et al. (2023) emphasize the importance of board effectiveness in cybersecurity oversight. Similarly, Héroux and Fortin (2024) and Khadim and Kakar (2025) find that IT expertise at the board level enhances both the extent and quality of cybersecurity disclosure. In addition, Elmarzouky et al. (2025) highlight the role of board commitment and regulatory pressure in shaping cybersecurity transparency.

Furthermore, the interaction term between cybersecurity incident disclosure and board technological expertise (CI*Tech_Board) is positive and statistically significant at the 5% level in Models (2) and (4) (β = 0.0312, p < 0.05; β = 0.0586, p < 0.05). This suggests that board technological expertise mitigates the negative impact of cybersecurity incident disclosure on financial performance. That is, although cybersecurity incident disclosure generally harm firm performance, their adverse effect becomes less severe in firms with technically competent boards. This may be attributed to improved crisis management, faster response to cyber threats, and more effective communication with stakeholders.

Regarding the control variables, the results remain consistent with the previous models. Firm size continues to show a positive and statistically significant effect, while leverage exhibits a negative and highly significant impact across all models. In contrast, firm age and board size remain statistically insignificant.

Robustness Checks

4.5. Board gender diversity, cybersecurity disclosure, and financial performance (GMM)

The System GMM results reported in Table 7 provide additional evidence on the relationship between board gender diversity, cybersecurity disclosure, and firm financial performance while accounting for dynamic effects and potential endogeneity concerns. The positive and statistically significant coefficients on the lagged dependent variable (L.Performance) across all models indicate that firm performance exhibits persistence over time, supporting the use of a dynamic panel specification.

Table 7. Moderating effect of women representation on cybersecurity disclosure and firm performance (GMM).

VARIABLES(1)(2)(3)(4)
ROAROAROEROE
L.Performance0.3774***0.3770***0.3576***0.3543***
(4.023)(4.024)(4.078)(4.077)
CID0.0996**-0.1170***-
(2.013)(2.806)
CI-−0.0716** (−2.011)-−0.0175*** (−3.022)
Women0.0554** (2.062)0.0548** (2.064)0.0897** (2.110)0.0848** (2.024)
CID*Women0.0429* (1.716)-0.0801** (2.172)-
CI*Women-0.0339* (1.713)-0.0754** (2.070)
Size0.1284*** (3.182)0.1284*** (3.183)0.0232*** (3.337)0.0205*** (3.296)
Age0.0062 (0.128)0.0062 (0.131)0.0026 (0.844)0.0026 (0.815)
BoardSize0.0812 (0.195)0.0811 (0.197)0.0058 (0.142)0.0042 (0.101)
Leverage−0.0106*** (−3.022)−0.0106*** (−3.023)−0.0578*** (−3.595)−0.0584*** (−3.608)
Constant(0.011 −0.0021)−0.0018 (−0.010)−0.0045 (−0.062)−0.0039 (−0.057)
Observations620620620620
Year EffectYES YES YES YES
Industry EffectYES YES YES YES
AR(1)0.0000.0000.0000.000
AR(2)0.2210.2180.2310.228
Hansen test0.4120.4370.5280.546

*** p < 0.01,

** p < 0.05,

* p < 0.1

With respect to cybersecurity disclosure, the results show that cybersecurity practices disclosure (CID) remains positively and statistically significantly associated with firm performance, whereas cybersecurity incident disclosure (CI) continues to exhibit a negative and statistically significant association with performance. These findings are consistent with the baseline results and suggest that the positive effects of cybersecurity practices disclosure and the adverse effects associated with cybersecurity incident disclosure remain robust after controlling for endogeneity and performance persistence. Furthermore, Women maintains a positive association with firm performance across the estimated models.

The interaction terms also provide support for the moderating role of board gender diversity. The positive coefficients on CID*Women suggest that female board representation strengthens the positive association between cybersecurity practices disclosure and firm performance. Likewise, the positive coefficients on CI*Women indicate that gender-diverse boards help mitigate the adverse performance implications associated with cybersecurity incident disclosure. These findings are consistent with the argument that female directors contribute to stronger monitoring, enhanced risk oversight, and more effective cybersecurity governance.

Regarding model diagnostics, the Arellano–Bond AR(2) test is statistically insignificant across all specifications, indicating the absence of second-order serial correlation. In addition, the Hansen test statistics suggest that the instruments are valid and that the models do not suffer from over-identification problems. Collectively, these diagnostic results support the reliability of the System GMM estimates.

4.6 Board technological expertise, cybersecurity disclosure, and financial performance (GMM)

The System GMM results reported in Table 8 provide an additional robustness assessment of the baseline findings while accounting for potential endogeneity concerns and the dynamic nature of firm performance. The positive and statistically significant coefficients on the lagged dependent variable (L.Performance) indicate that firm performance exhibits persistence over time, supporting the use of a dynamic panel framework.

Table 8. Moderating role of tech_board on cybersecurity disclosure and firm performance (GMM).

VARIABLES(1)(2)(3)(4)
ROAROAROE ROE
L.Performance0.3652*** (4.028)0.3648*** (4.029)0.4103*** (4.082)0.4150*** (4.081)
CID0.0124** (2.214)-0.0148*** (2.741)-
CI-−0.0391** (−2.173)-−0.0687*** (−2.884)
Tech_Board0.0118* (1.884)0.0109 (0.812)0.0356** (2.143)0.0331** (2.067)
CID*Tech_Board0.0275* (1.711)-0.0812* (1.713)-
CI*Tech_Board-0.0214* (1.722)-0.0679* (1.682)
Size0.0942*** (3.304)0.0940*** (3.302)0.0198*** (3.331)0.0186*** (3.298)
Age0.0054 (0.139)0.0053 (0.141)0.0021 (0.812)0.0020 (0.801)
BoardSize0.0627 (0.221)0.0621 (0.218)0.0049 (0.129)0.0038 (0.101)
Leverage−0.0123*** (−3.031)−0.0121*** (−3.030)−0.0546*** (−3.521)−0.0552*** (−3.548)
Constant−0.0034 (−0.018)−0.0031 (−0.017)−0.0058 (−0.071)−0.0052 (−0.066)
Observations620620620620
Year EffectYES YES YES YES
Industry EffectYES YES YES YES
AR(1)0.0000.0000.0000.000
AR(2)0.2190.2170.2280.225
Hansen test0.4360.4580.5470.563

*** p < 0.01,

** p < 0.05,

* p < 0.1

With respect to cybersecurity disclosure, the results show that cybersecurity practices disclosure (CID) remains positively and statistically significantly associated with firm performance, whereas cybersecurity incident disclosure (CI) continues to exhibit a negative and statistically significant association with firm performance. These findings are broadly consistent with the baseline results reported in Table 6, suggesting that the positive effects of cybersecurity practices disclosure and the adverse effects associated with cybersecurity incident disclosure remain robust after controlling for endogeneity and performance persistence.

The interaction terms provide further support for the moderating role of board technological expertise. The positive coefficients on CID*Tech_Board indicate that board technological expertise strengthens the positive association between cybersecurity practices disclosure and firm performance. Likewise, the positive coefficients on CI*Tech_Board suggest that technically competent boards help mitigate the adverse performance implications associated with cybersecurity incident disclosure. These findings support the argument that directors possessing technological expertise are better positioned to evaluate cyber-related risks, oversee cybersecurity governance, and enhance the effectiveness of cybersecurity-related disclosure practices.

Regarding model diagnostics, the AR(1) test is statistically significant across all specifications, which is expected in first-differenced GMM estimations. More importantly, the AR(2) test is statistically insignificant, indicating the absence of second-order serial correlation and supporting the validity of the dynamic specification. Furthermore, the Hansen test statistics are not statistically significant, providing support for the validity of the selected instruments and the overall specification of the System GMM models. Collectively, these diagnostic results reinforce the reliability of the reported estimates.

Additional Analysis:

4.7 Board gender diversity, board technological expertise, cybersecurity disclosure, and financial performance (alternative measure)

The results reported in Table 9 present an additional analysis using an alternative measure of cybersecurity disclosure, namely the Cyber Terms Index (CTI), to further assess the robustness of the main findings. Unlike CID and CI, which capture the presence of cybersecurity-related disclosure, CTI measures the extent of cybersecurity disclosure based on the frequency of predefined cybersecurity-related terms appearing in firms’ board reports1. This approach has been widely adopted in prior cybersecurity disclosure research (Amani et al., 2025; Hasan et al., 2025; Masoud & Al-Utaibi, 2022; Basiouny, 2024; Elmarzouky et al., 2025; Swift et al., 2020).

Table 9. Moderating role of women representation and Tech_Board on Cyber_Terms_Index and firm performance (Alternative Measure).

VARIABLES(1)(2)(3)(4)
ROAROAROEROE
CTI0.0023*** (3.541)-0.0045*** (3.882)-
Women0.0198* (1.721)0.0176 (1.463)0.0359* (1.783)0.0314 (1.512)
CTI*Women0.0019** (2.114)-0.0035** (2.287)-
Tech_Board0.0249** (2.063)0.0217* (1.744)0.0463** (2.184)0.0398* (1.792)
CTI*Tech_Board0.0024** (2.198)-0.0041*** (2.661)-
Size0.0169*** (2.954)0.0167*** (2.918)0.0305*** (3.398)0.0302*** (3.362)
Age0.0003 (0.512)0.0003 (0.528)0.0006 (0.593)0.0006 (0.611)
BoardSize0.0038 (0.884)0.0037 (0.861)0.0067 (0.972)0.0065 (0.951)
Leverage−0.0387*** (−5.201)−0.0384*** (−4.982)−0.0695*** (−6.711)−0.0691*** (−6.442)
Constant−0.1048** (−1.962)−0.1003** (−1.938)−0.1926** (−2.021)−0.1881** (−1.998)
Observations775775775775
R-squared 0.4860.4920.5070.512
Year EffectYES YES YES YES
Industry EffectYES YES YES YES

*** p < 0.01,

** p < 0.05,

* p < 0.1.

The results indicate that CTI is positively and significantly associated with firm financial performance at the 1% level in Models (1) and (3), with coefficients of (β = 0.0023, p < 0.01) for ROA and (β = 0.0045, p < 0.01) for ROE. These findings suggest that firms providing more extensive cybersecurity-related disclosure tend to exhibit stronger financial performance. The results therefore provide additional support for the positive association between cybersecurity disclosure and firm performance observed in the main analyses.

Regarding board gender diversity, the results show a positive but weakly significant direct association with firm performance. More importantly, the interaction term between CTI and Women (CTI*Women) is positive and statistically significant at the 5% level in both ROA and ROE models. This finding indicates that the positive association between cybersecurity disclosure intensity and firm performance is stronger in firms with higher levels of female board representation. Similarly, board technological expertise (Tech_Board) exhibits a positive and statistically significant association with firm performance across all models. Furthermore, the interaction term between CTI and Tech_Board (CTI Ã— Tech_Board) is positive and statistically significant, indicating that the positive association between cybersecurity disclosure intensity and firm performance is stronger in firms with greater board technological expertise.

The control variables remain broadly consistent with previous models. Firm size exhibits a positive and statistically significant association with firm performance, while leverage remains negatively associated with performance. In contrast, firm age and board size remain statistically insignificant. Overall, the results of this additional analysis support the robustness of the main findings. The positive association between cybersecurity disclosure and firm performance, as well as the moderating roles of board gender diversity and board technological expertise, remain consistent when cybersecurity disclosure is measured using an alternative disclosure proxy.

5. Discussion of results

The findings of this study contribute to the growing literature on cybersecurity disclosure by demonstrating that cybersecurity disclosure should not be treated as a homogeneous construct. A key finding is that cybersecurity practices disclosure and cybersecurity incident disclosure exhibit fundamentally different associations with firm financial performance. While cybersecurity practices disclosure is positively associated with financial performance, cybersecurity incident disclosure is negatively associated with performance. This distinction is important because prior studies frequently aggregate cybersecurity disclosure into a single measure, potentially obscuring the different informational roles played by proactive and reactive disclosures. From a theoretical perspective, the findings suggest that disclosures relating to cybersecurity governance, policies, and risk-management practices are associated with stronger organizational outcomes, whereas disclosures concerning realized cyber incidents are more likely to reflect operational disruptions, governance weaknesses, or increased cyber-risk exposure. Consequently, the study extends the cybersecurity disclosure literature by highlighting the multidimensional nature of cybersecurity-related reporting.

The results also provide important insights into the role of corporate governance in the cybersecurity context. Both board gender diversity and board technological expertise are associated with a stronger positive relationship between cybersecurity disclosure and firm performance and a weaker negative relationship between cybersecurity incident disclosure and firm performance. These findings support the view that the effectiveness of cybersecurity disclosure depends not only on the information disclosed but also on the governance environment within which disclosure occurs. Consistent with agency and stakeholder perspectives, boards appear to play an important role in overseeing cyber-risk management, promoting transparency, and supporting the integration of cybersecurity considerations into strategic decision-making.

An important contribution of the study is the comparison between board gender diversity and board technological expertise. This finding is theoretically meaningful because cybersecurity risks are highly technical, dynamic, and complex. Although gender diversity may strengthen monitoring quality, ethical oversight, and stakeholder responsiveness, technological expertise provides boards with specialized knowledge that directly supports the evaluation of cybersecurity risks, cybersecurity investments, and disclosure practices. The findings therefore suggest that demographic diversity and technical expertise perform complementary but distinct governance functions. In the context of cybersecurity governance, technical expertise appears particularly important because it enhances the board’s capacity to understand and oversee cyber-related challenges.

The study also contributes methodologically to the cybersecurity disclosure literature. By distinguishing between cybersecurity practices disclosure, cybersecurity incident disclosure, and disclosure intensity measured through the Cyber Terms Index, the analysis demonstrates that different disclosure measures capture different dimensions of cybersecurity reporting. The consistency of the results across alternative disclosure measures suggests that both the presence and the extent of cybersecurity disclosure are associated with firm performance. This highlights the importance of carefully specifying cybersecurity disclosure measures and avoiding the assumption that all forms of disclosure have equivalent economic implications.

From a practical perspective, the findings suggest that regulators and firms should place greater emphasis on the quality and governance context of cybersecurity disclosure. The results indicate that disclosure alone may not be sufficient to generate favorable outcomes. Rather, disclosure appears to be most effective when supported by boards possessing the expertise and governance capabilities necessary to oversee cybersecurity risks. For policymakers, the findings provide support for initiatives aimed at strengthening cybersecurity governance and disclosure practices. For firms, the results highlight the importance of incorporating directors with relevant technological expertise and promoting board diversity to support effective oversight of cyber-related risks and reporting practices.

6. Conclusion

This study investigates the impact of cybersecurity disclosure on firm financial performance in the Saudi context, with particular emphasis on the moderating roles of board gender diversity and technological expertise. Using panel data for non-financial firms listed on the Saudi Exchange over the period 2020–2024, the study provides empirical evidence on the financial implications of cybersecurity disclosure within an important emerging market setting.

The findings indicate that cybersecurity practices disclosure is positively and significantly associated with firm performance, whereas cybersecurity incident disclosure is negatively associated with firm performance. These results highlight the multidimensional nature of cybersecurity disclosure. While proactive disclosure of cybersecurity policies, governance structures, and risk-management practices is associated with stronger financial outcomes, cybersecurity incident disclosure reflects the occurrence of cyber-related events that may impose operational, regulatory, and reputational costs on firms.

Importantly, the results reveal that the financial implications of cybersecurity disclosure depend on board characteristics. Both board gender diversity and board technological expertise strengthen the positive association between cybersecurity disclosure and firm performance and mitigate the adverse performance implications associated with cybersecurity incident disclosure. These findings highlight the important role of board composition in strengthening cybersecurity governance, enhancing oversight of cyber-related risks, and supporting effective disclosure practices. The robustness of these findings is further confirmed through additional analyses using an alternative disclosure measure (CTI) and dynamic estimation techniques (System GMM), reinforcing the reliability of the reported results.

The findings have several practical implications. Regulators may benefit from continuing efforts to enhance and standardize cybersecurity disclosure frameworks in order to improve transparency, consistency, and comparability across firms. At the organizational level, strengthening board composition appears particularly important. Increasing female representation may contribute to stronger governance and risk oversight, while appointing directors with technological expertise may improve boards’ ability to evaluate cybersecurity risks and oversee cybersecurity-related strategies and disclosures. Firms may also benefit from adopting a proactive approach to cybersecurity governance by providing comprehensive disclosure regarding cybersecurity policies, risk-management practices, and governance arrangements. These implications are consistent with the objectives of Saudi Vision 2030, particularly those related to digital transformation, institutional transparency, and the empowerment of women in leadership positions.

Despite these contributions, several limitations should be acknowledged. First, the analysis focuses exclusively on non-financial firms listed on the Saudi Exchange, which may limit the generalizability of the findings to other sectors or institutional settings. Future research may extend the analysis to financial firms or conduct cross-country comparisons to enhance external validity. Second, the study covers the period from 2020 to 2024, which may limit the ability to capture longer-term developments in cybersecurity disclosure and firm performance. Future research could employ longer time horizons to examine the stability of these relationships over time. Finally, the study focuses on board gender diversity and technological expertise as moderating factors. Other governance characteristics, including board independence, ownership structure, audit committee effectiveness, and cybersecurity-specific committees, may also influence the relationship between cybersecurity disclosure and firm performance and therefore represent promising avenues for future research.

AI-Enhanced readability

This manuscript has utilized Grammarly to enhance its readability, ensuring clarity, coherence, and accuracy in presenting the research findings, while also verifying that the content has not been altered.

Ethics statement

This study did not involve human participants, human tissue, personal data, or animal subjects. The research relied exclusively on publicly available corporate annual reports and publicly available firm-level financial information obtained from the Saudi Exchange (Tadawul) and commercially licensed financial databases. Consequently, ethical approval and informed consent were not required under the policies of King Faisal University and internationally accepted guidelines for research involving publicly available organizational data.

Comments on this article Comments (0)

Version 1
VERSION 1 PUBLISHED 28 Jul 2026
Comment
Author details Author details
Competing interests
Grant information
Copyright
Download
 
Export To
metrics
Views Downloads
F1000Research - -
PubMed Central
Data from PMC are received and updated monthly.
- -
Citations
CITE
how to cite this article
A. Almulhim A and Busaal B. Cybersecurity Disclosure and Financial Performance: The Moderating Role of Board Characteristics [version 1; peer review: awaiting peer review]. F1000Research 2026, 15:1240 (https://doi.org/10.12688/f1000research.186795.1)
NOTE: If applicable, it is important to ensure the information in square brackets after the title is included in all citations of this article.
track
receive updates on this article
Track an article to receive email alerts on any updates to this article.

Open Peer Review

Current Reviewer Status:
AWAITING PEER REVIEW
AWAITING PEER REVIEW
?
Key to Reviewer Statuses VIEW
ApprovedThe paper is scientifically sound in its current form and only minor, if any, improvements are suggested
Approved with reservations A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit.
Not approvedFundamental flaws in the paper seriously undermine the findings and conclusions

Comments on this article Comments (0)

Version 1
VERSION 1 PUBLISHED 28 Jul 2026
Comment
Alongside their report, reviewers assign a status to the article:
Approved - the paper is scientifically sound in its current form and only minor, if any, improvements are suggested
Approved with reservations - A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit.
Not approved - fundamental flaws in the paper seriously undermine the findings and conclusions
Sign In
If you've forgotten your password, please enter your email address below and we'll send you instructions on how to reset your password.

The email address should be the one you originally registered with F1000.

Email address not valid, please try again

You registered with F1000 via Google, so we cannot reset your password.

To sign in, please click here.

If you still need help with your Google account password, please click here.

You registered with F1000 via Facebook, so we cannot reset your password.

To sign in, please click here.

If you still need help with your Facebook account password, please click here.

Code not correct, please try again
Email us for further assistance.
Server error, please try again.