Salzberger A, Hausruckinger F (2026)
Publication Type: Journal article
Publication year: 2026
DOI: 10.1057/s41288-026-00390-7
Given the significant threat posed by cyber risks and the legal obligation to report on material risks, it is expected that German companies provide comprehensive disclosures on cyber risks in their annual reports. While extensive literature exists on cyber risk disclosure practices for U.S. organizations, where strict and specific disclosure requirements apply, corresponding analyses for German enterprises are lacking. This study addresses this gap by examining how German enterprises report on cyber risks in their annual reports in terms of quantity, quality, and reporting sentiment. Using a text mining approach applied to 76 German firms from 2013 to 2023 (836 firm-year observations), our results reveal a significant increase in cyber disclosure volume, complexity, and negativity over the sample period. Larger firms with an above-median capitalization disclose significantly more on cyber risks, in a more complex and positive way, while smaller firms communicate in a significantly more negative tone regarding cyber risks. Industries dependent on digital infrastructures report more on cyber risks, while disclosure complexity is shaped by sector-specific characteristics. Across all sectors, cyber risks are generally framed negatively, while the financial industry maintains a more neutral cyber disclosure tone, compared to others.
APA:
Salzberger, A., & Hausruckinger, F. (2026). Cyber risk reporting in German listed enterprises: a textual analysis of disclosure informativeness. Geneva Papers on Risk and Insurance: Issues and Practice. https://doi.org/10.1057/s41288-026-00390-7
MLA:
Salzberger, Alina, and Felix Hausruckinger. "Cyber risk reporting in German listed enterprises: a textual analysis of disclosure informativeness." Geneva Papers on Risk and Insurance: Issues and Practice (2026).
BibTeX: Download